58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2022-38376 | MED 6.1 | fortinet fortinac Multiple improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilities [CWE-79] in Fortinet FortiNAC portal UI before 9.4.1 allows an attacker to perform an XSS attack via crafted HTTP requests. | 0,6% | — |
| CVE-2022-38375 | CRIT 9.1 | fortinet fortinac An improper authorization vulnerability [CWE-285] in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests. | 1,1% | — |
| CVE-2022-38374 | HIGH 8.8 | fortinet fortiadc A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiADC 7.0.0 - 7.0.2 and 6.2.0 - 6.2.4 allows an attacker to execute unauthorized code or commands via the URL and User fields observed in the traffic and even | 1,9% | — |
| CVE-2022-38373 | HIGH 8.0 | fortinet fortideceptor An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interface 4.2.0, 4.1.0 through 4.1.1, 4.0.2 may allow an authenticated user to perform a cross site scripting (XSS) attack via sending requests wi | 0,5% | — |
| CVE-2022-38372 | MED 6.7 | fortinet fortitester A hidden functionality vulnerability [CWE-1242] in FortiTester CLI 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow a local, privileged user to obtain a root shell on the device via an undocumented command. | 0,2% | — |
| CVE-2022-38370 | HIGH 7.5 | apache iotdb Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue. | 1,3% | — |
| CVE-2022-38369 | HIGH 8.8 | apache iotdb Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue. | 1,3% | — |
| CVE-2022-38362 | HIGH 8.8 | apache apache-airflow-providers-docker Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host. | 1,9% | — |
| CVE-2022-38221 | CRIT 9.8 | the_isle_evrima_project the_isle_evrima A buffer overflow in the FTcpListener thread in The Isle Evrima (the dedicated server on Windows and Linux) 0.9.88.07 before 2022-08-12 allows a remote attacker to crash any server with an accessible RCON port, or possibly execute arbitrary code. | 1,8% | — |
| CVE-2022-38170 | MED 4.7 | apache airflow In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the `--daemon` flag which could result in a race condition giving world-writable files in the Airflow home directory and allowing local users t | 0,6% | — |
| CVE-2022-38166 | HIGH 7.5 | f-secure elements_endpoint_protection In F-Secure Endpoint Protection for Windows and macOS before channel with Capricorn database 2022-11-22_07, the aerdl.dll unpacker handler crashes. This can lead to a scanning engine crash, triggerable remotely by an attacker for denial of service. | 0,7% | — |
| CVE-2022-38096 | MED 6.3 | linux linux_kernel A NULL pointer dereference vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to | 0,8% | — |
| CVE-2022-38054 | CRIT 9.8 | apache airflow In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation. | 2,1% | — |
| CVE-2022-38053 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 76,4% | — |
| CVE-2022-38051 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 7,3% | — |
| CVE-2022-38050 | HIGH 7.8 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 7,3% | — |
| CVE-2022-38049 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2022-38048 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 1,6% | — |
| CVE-2022-38047 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2022-38046 | HIGH 7.5 | microsoft windows_10 Web Account Manager Information Disclosure Vulnerability | 1,9% | — |
| CVE-2022-38045 | HIGH 8.8 | microsoft windows_10 Windows Server Service Elevation of Privilege Vulnerability | 2,3% | — |
| CVE-2022-38044 | HIGH 7.8 | microsoft windows_10 Windows CD-ROM File System Driver Remote Code Execution Vulnerability | 56,3% | — |
| CVE-2022-38043 | MED 5.5 | microsoft windows_10 Windows Security Support Provider Interface Information Disclosure Vulnerability | 0,6% | — |
| CVE-2022-38042 | HIGH 7.1 | microsoft windows_10 Active Directory Domain Services Elevation of Privilege Vulnerability | 1,4% | — |
| CVE-2022-38041 | HIGH 7.5 | microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability | 2,2% | — |