EN
58.139 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.139 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più alto
CVE-2024-43464 HIGH 7.2 microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability 36,3%
CVE-2024-43463 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 0,9%
CVE-2024-43462 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1,6%
CVE-2024-43460 HIGH 8.1 microsoft dynamics_365_business_central Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network. 0,7%
CVE-2024-43459 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1,6%
CVE-2024-43458 HIGH 7.7 microsoft windows_10_1607 Windows Networking Information Disclosure Vulnerability 1,8%
CVE-2024-43457 HIGH 7.8 microsoft windows_11_24h2 Windows Setup and Deployment Elevation of Privilege Vulnerability 0,6%
CVE-2024-43456 MED 4.8 microsoft windows_server_2008 Windows Remote Desktop Services Tampering Vulnerability 0,7%
CVE-2024-43455 HIGH 8.8 microsoft windows_server_2008 Windows Remote Desktop Licensing Service Spoofing Vulnerability 1,7%
CVE-2024-43454 HIGH 7.1 microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability 21,9%
CVE-2024-43453 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1,5%
CVE-2024-43452 HIGH 7.5 microsoft windows_10_1809 Windows Registry Elevation of Privilege Vulnerability 28,1%
CVE-2024-43450 HIGH 7.5 microsoft windows_server_2008 Windows DNS Spoofing Vulnerability 0,6%
CVE-2024-43449 MED 6.8 microsoft windows_10_1507 Windows USB Video Class System Driver Elevation of Privilege Vulnerability 0,7%
CVE-2024-43447 HIGH 8.1 microsoft windows_server_2022 Windows SMBv3 Server Remote Code Execution Vulnerability 1,5%
CVE-2024-43441 CRIT 9.8 apache hugegraph Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.5.0. Users are recommended to upgrade to version 1.5.0, which fixes the issue. 69,4%
CVE-2024-43394 HIGH 7.5 apache http_server Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via  mod_rewrite or apache expressions that pass unvalidated request input. This issue affects Apache HTTP Server: from 2.4.0 thro 1,1%
CVE-2024-43383 HIGH 8.0 apache lucene.net Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's Replicator library: from 4.8.0-beta00005 through 4.8.0-beta00016. An attacker that can intercept traffic between a replication client and 1,2%
CVE-2024-43373 HIGH 7.7 j4k0xb webcrack webcrack is a tool for reverse engineering javascript. An arbitrary file write vulnerability exists in the webcrack module when processing specifically crafted malicious code on Windows systems. This vulnerability is triggered when using the unpack bundles fea 0,4%
CVE-2024-43204 HIGH 7.5 apache http_server SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker.  Requires an unlikely configuration where mod_headers is configured to modify the Content-Type request or response header w 0,8%
CVE-2024-43202 CRIT 9.8 apache dolphinscheduler Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue. 2,1%
CVE-2024-43196 MED 4.3 ibm openpages_with_watson IBM OpenPages with Watson 8.3 and 9.0  application could allow an authenticated user to manipulate data in the Questionnaires application allowing the user to spoof other users' responses. 0,2%
CVE-2024-43186 MED 5.3 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored locally under certain conditions. 0,3%
CVE-2024-43178 MED 5.9 ibm concert IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. 0,1%
CVE-2024-43176 MED 5.4 ibm openpages_with_watson IBM OpenPages 9.0 could allow an authenticated user to obtain sensitive information such as configurations that should only be available to privileged users. 0,3%