58.139 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.139 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2024-43464 | HIGH 7.2 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 36,3% | — |
| CVE-2024-43463 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2024-43462 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability | 1,6% | — |
| CVE-2024-43460 | HIGH 8.1 | microsoft dynamics_365_business_central Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2024-43459 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability | 1,6% | — |
| CVE-2024-43458 | HIGH 7.7 | microsoft windows_10_1607 Windows Networking Information Disclosure Vulnerability | 1,8% | — |
| CVE-2024-43457 | HIGH 7.8 | microsoft windows_11_24h2 Windows Setup and Deployment Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2024-43456 | MED 4.8 | microsoft windows_server_2008 Windows Remote Desktop Services Tampering Vulnerability | 0,7% | — |
| CVE-2024-43455 | HIGH 8.8 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Spoofing Vulnerability | 1,7% | — |
| CVE-2024-43454 | HIGH 7.1 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | 21,9% | — |
| CVE-2024-43453 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1,5% | — |
| CVE-2024-43452 | HIGH 7.5 | microsoft windows_10_1809 Windows Registry Elevation of Privilege Vulnerability | 28,1% | — |
| CVE-2024-43450 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Spoofing Vulnerability | 0,6% | — |
| CVE-2024-43449 | MED 6.8 | microsoft windows_10_1507 Windows USB Video Class System Driver Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-43447 | HIGH 8.1 | microsoft windows_server_2022 Windows SMBv3 Server Remote Code Execution Vulnerability | 1,5% | — |
| CVE-2024-43441 | CRIT 9.8 | apache hugegraph Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.5.0. Users are recommended to upgrade to version 1.5.0, which fixes the issue. | 69,4% | — |
| CVE-2024-43394 | HIGH 7.5 | apache http_server Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via mod_rewrite or apache expressions that pass unvalidated request input. This issue affects Apache HTTP Server: from 2.4.0 thro | 1,1% | — |
| CVE-2024-43383 | HIGH 8.0 | apache lucene.net Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's Replicator library: from 4.8.0-beta00005 through 4.8.0-beta00016. An attacker that can intercept traffic between a replication client and | 1,2% | — |
| CVE-2024-43373 | HIGH 7.7 | j4k0xb webcrack webcrack is a tool for reverse engineering javascript. An arbitrary file write vulnerability exists in the webcrack module when processing specifically crafted malicious code on Windows systems. This vulnerability is triggered when using the unpack bundles fea | 0,4% | — |
| CVE-2024-43204 | HIGH 7.5 | apache http_server SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker. Requires an unlikely configuration where mod_headers is configured to modify the Content-Type request or response header w | 0,8% | — |
| CVE-2024-43202 | CRIT 9.8 | apache dolphinscheduler Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue. | 2,1% | — |
| CVE-2024-43196 | MED 4.3 | ibm openpages_with_watson IBM OpenPages with Watson 8.3 and 9.0 application could allow an authenticated user to manipulate data in the Questionnaires application allowing the user to spoof other users' responses. | 0,2% | — |
| CVE-2024-43186 | MED 5.3 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored locally under certain conditions. | 0,3% | — |
| CVE-2024-43178 | MED 5.9 | ibm concert IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | 0,1% | — |
| CVE-2024-43176 | MED 5.4 | ibm openpages_with_watson IBM OpenPages 9.0 could allow an authenticated user to obtain sensitive information such as configurations that should only be available to privileged users. | 0,3% | — |