EN
58.047 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.047 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più alto
CVE-2024-49003 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1,5%
CVE-2024-49002 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1,5%
CVE-2024-49001 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1,5%
CVE-2024-49000 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1,5%
CVE-2024-48999 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1,4%
CVE-2024-48998 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1,4%
CVE-2024-48997 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1,4%
CVE-2024-48996 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1,6%
CVE-2024-48995 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1,6%
CVE-2024-48994 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1,6%
CVE-2024-48993 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1,6%
CVE-2024-48988 HIGH 7.6 apache streampark SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. This vulnerability is present only in the distribution package (Sprin 0,6%
CVE-2024-48962 HIGH 8.8 apache ofbiz Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are r 0,6%
CVE-2024-48944 MED 6.5 apache kylin Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a request to invoke "/kylin/api/xxx/diag" api on another internal host and possibly get leaked information. There are two preconditions: 1) The atta 0,6%
CVE-2024-48903 HIGH 7.8 trendmicro deep_security_agent An improper access control vulnerability in Trend Micro Deep Security Agent 20 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target 0,7%
CVE-2024-48893 MED 6.8 fortinet fortisoar An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via the creation of malicious 0,5%
CVE-2024-48892 MED 6.8 fortinet fortisoar A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacker to read arbitrary files via uploading a malicious solution pack. 0,4%
CVE-2024-48891 HIGH 7.0 fortinet fortisoar An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR 7.6.0 through 7.6.1, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an attacker who has already obtained a non- 0,5%
CVE-2024-48890 MED 6.6 fortinet fortisoar_imap_connector An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may allow an authenticated attacker to execute unauthorized code or commands via a specific 1,1%
CVE-2024-48889 HIGH 7.2 fortinet fortimanager An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager version 7.6.0, version 7.4.4 and below, version 7.2.7 and below, version 7.0.12 and below, version 6.4.14 and below and FortiMa 1,7%
CVE-2024-48887 CRIT 9.8 fortinet fortiswitch A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request 15,7%
CVE-2024-48886 CRIT 9.0 fortinet fortianalyzer A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManager ver 0,5%
CVE-2024-48885 MED 5.3 fortinet fortirecorder A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiVoice 7.0.0 through 7.0.4, FortiVoice 6.4.0 through 6.4.9, FortiVoice 6.0 all 0,8%
CVE-2024-48884 HIGH 7.5 fortinet fortimanager A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, F 15,3%
CVE-2024-48881 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bcache: revert replacing IS_ERR_OR_NULL with IS_ERR again Commit 028ddcac477b ("bcache: Remove unnecessary NULL point check in node allocations") leads a NULL pointer deference in cache_set_ 0,3%