57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2024-6913 | HIGH 8.8 | perkinelmer processplus Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windows system.This issue affects ProcessPlus: through 1.11.6507.0. | 1,4% | — |
| CVE-2024-6912 | CRIT 9.8 | perkinelmer processplus Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0. | 1,1% | — |
| CVE-2024-6746 | MED 4.3 | easyspider easyspider A vulnerability classified as problematic was found in NaiboWang EasySpider 0.6.2 on Windows. Affected by this vulnerability is an unknown functionality of the file \EasySpider\resources\app\server.js of the component HTTP GET Request Handler. The manipulation | 3,3% | — |
| CVE-2024-6714 | HIGH 8.8 | canonical ubuntu_desktop_provision An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege. | 0,3% | — |
| CVE-2024-6677 | HIGH 7.8 | citrix uberagent Privilege escalation in uberAgent | 0,2% | — |
| CVE-2024-6293 | HIGH 8.8 | fedoraproject fedora Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0,6% | — |
| CVE-2024-6292 | HIGH 8.8 | fedoraproject fedora Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0,6% | — |
| CVE-2024-6286 | HIGH 7.8 | citrix workspace Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | 0,4% | — |
| CVE-2024-6236 | HIGH 7.5 | citrix netscaler_agent Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX | 0,7% | — |
| CVE-2024-6235 | HIGH 8.8 | citrix netscaler_console Sensitive information disclosure in NetScaler Console | 21,2% | — |
| CVE-2024-6222 | HIGH 7.0 | docker desktop In Docker Desktop before v4.29.0, an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the host by passing extensions and dashboard related IPC messages. Docker Desktop v4.29.0 https://docs.docker.com/ | 0,6% | — |
| CVE-2024-6151 | HIGH 7.8 | citrix virtual_apps_and_desktops Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps and Desktops and Citrix DaaS | 0,2% | — |
| CVE-2024-6150 | MED 4.3 | citrix provisioning A non-admin user can cause short-term disruption in Target VM availability in Citrix Provisioning | 0,2% | — |
| CVE-2024-6149 | MED 6.1 | citrix workspace Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5 | 0,2% | — |
| CVE-2024-6148 | HIGH 8.8 | citrix workspace Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5 | 0,4% | — |
| CVE-2024-6053 | MED 4.3 | teamviewer meeting Improper access control in the clipboard synchronization feature in TeamViewer Full Client prior version 15.57 and TeamViewer Meeting prior version 15.55.3 can lead to unintentional sharing of the clipboard with the current presenter of a meeting. | 0,4% | — |
| CVE-2024-5921 | HIGH 8.8 | paloaltonetworks globalprotect An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subn | 1,5% | — |
| CVE-2024-5920 | MED 4.8 | paloaltonetworks pan-os A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administra | 0,3% | — |
| CVE-2024-5919 | MED 6.5 | paloaltonetworks pan-os A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the fi | 0,3% | — |
| CVE-2024-5918 | MED 4.3 | paloaltonetworks pan-os An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user | 0,2% | — |
| CVE-2024-5917 | MED 4.9 | paloaltonetworks pan-os A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible. | 0,5% | — |
| CVE-2024-5916 | MED 4.4 | paloaltonetworks pan-os An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of external systems. A read-only administrator who has access to the config log, can rea | 0,2% | — |
| CVE-2024-5915 | HIGH 7.8 | paloaltonetworks globalprotect A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. | 0,2% | — |
| CVE-2024-5914 | CRIT 9.8 | paloaltonetworks cortex_xsoar_commonscripts A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container. | 1,2% | — |
| CVE-2024-5913 | MED 6.1 | paloaltonetworks pan-os An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to tamper with the physical file system to elevate privileges. | 0,2% | — |