EN
58.535 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.535 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2022-21837 HIGH 8.3 microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability 3,0% —
CVE-2022-21836 HIGH 7.8 microsoft windows_10 Windows Certificate Spoofing Vulnerability 0,7% —
CVE-2022-21835 HIGH 7.8 microsoft windows_10 Microsoft Cryptographic Services Elevation of Privilege Vulnerability 0,7% —
CVE-2022-21834 HIGH 7.0 microsoft windows_10 Windows User-mode Driver Framework Reflector Driver Elevation of Privilege Vulnerability 0,6% —
CVE-2022-21833 HIGH 7.8 microsoft windows_10 Virtual Machine IDE Drive Elevation of Privilege Vulnerability 0,6% —
CVE-2022-21827 HIGH 7.1 citrix gateway_plug-in An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt 0,2% —
CVE-2022-21825 HIGH 7.8 citrix workspace An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation. 0,2% —
CVE-2022-21821 HIGH 7.8 nvidia cuda_toolkit NVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in cuobjdump.To exploit this vulnerability, a remote attacker would require a local user to download a specially crafted, corrupted file and locally execute cuobjdump against the file. Such an 2,1% —
CVE-2022-21820 MED 6.3 nvidia data_center_gpu_manager NVIDIA DCGM contains a vulnerability in nvhostengine, where a network user can cause detection of error conditions without action, which may lead to limited code execution, some denial of service, escalation of privileges, and limited impacts to both data conf 16,5% —
CVE-2022-21817 CRIT 9.3 nvidia omniverse_launcher NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can get user to browse malicious site, to acquire access tokens allowing them to access resources in other security 1,7% —
CVE-2022-21815 MED 5.5 nvidia cloud_gaming_guest NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for private IOCTLs where a NULL pointer dereference in the kernel, created within user mode code, may lead to a denial of service in the form of a sy 0,2% —
CVE-2022-21813 MED 6.1 nvidia cloud_gaming_guest NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver, where improper handling of insufficient permissions or privileges may allow an unprivileged local user limited write access to protected memory, which can lead to denial of serv 0,2% —
CVE-2022-21793 MED 5.5 vmware i40en Insufficient control flow management in the Intel(R) Ethernet 500 Series Controller drivers for VMWare before version 1.11.4.0 and in the Intel(R) Ethernet 700 Series Controller drivers for VMWare before version 2.1.5.0 may allow an authenticated user to poten 0,2% —
CVE-2022-2170 MED 4.8 microsoft microsoft_advertising_universal_event_tracking The Microsoft Advertising Universal Event Tracking (UET) WordPress plugin before 1.0.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is di 1,4% —
CVE-2022-2162 HIGH 8.8 fedoraproject fedora Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 103.0.5060.53 allowed a remote attacker to bypass file system access via a crafted HTML page. 1,3% —
CVE-2022-2160 MED 6.5 fedoraproject fedora Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from a user's local files via a crafted HTML pa 0,7% —
CVE-2022-21546 HIGH 7.5 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: scsi: target: Fix WRITE_SAME No Data Buffer crash In newer version of the SBC specs, we have a NDOB bit that indicates there is no data buffer that gets written out. If this bit is set using 0,4% —
CVE-2022-2153 MED 5.5 debian debian_linux A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write to SYNIC/STIMER MSRs, causing a NULL pointer dereference. This flaw allows an unprivileged local attacker on the host to 0,5% —
CVE-2022-21221 MED 5.9 fasthttp_project fasthttp The package github.com/valyala/fasthttp before 1.34.0 are vulnerable to Directory Traversal via the ServeFile function, due to improper sanitization. It is possible to be exploited by using a backslash %5c character in the path. **Note:** This security issue i 2,5% —
CVE-2022-21166 MED 5.5 debian debian_linux Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. 5,8% —
CVE-2022-21155 HIGH 7.5 fernhillsoftware scada_server A specially crafted packet sent to the Fernhill SCADA Server Version 3.77 and earlier may cause an exception, causing the server process (FHSvrService.exe) to exit. 1,1% —
CVE-2022-21125 MED 5.5 debian debian_linux Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. 6,5% —
CVE-2022-21123 MED 5.5 debian debian_linux Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. 6,2% —
CVE-2022-20969 MED 4.8 cisco umbrella A vulnerability in multiple management dashboard pages of Cisco Umbrella could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the Cisco Umbrella dashboard. This vulnerability is due to unsanitized us 0,5% —
CVE-2022-20968 HIGH 8.1 cisco ip_phone_7811_firmware A vulnerability in the Cisco Discovery Protocol processing feature of Cisco IP Phone 7800 and 8800 Series firmware could allow an unauthenticated, adjacent attacker to cause a stack overflow on an affected device. This vulnerability is due to insufficient i 6,1% —