58.290 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.290 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2024-38219 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2024-38218 | HIGH 8.4 | microsoft edge_chromium Microsoft Edge (HTML-based) Memory Corruption Vulnerability | 0,6% | — |
| CVE-2024-38216 | HIGH 8.2 | microsoft azure_stack_hub Azure Stack Hub Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2024-38215 | HIGH 7.8 | microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-38214 | MED 6.5 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | 1,6% | — |
| CVE-2024-38212 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1,4% | — |
| CVE-2024-38211 | HIGH 8.2 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 1,0% | — |
| CVE-2024-38210 | HIGH 7.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2024-38209 | HIGH 7.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2024-38208 | MED 6.1 | microsoft edge Microsoft Edge for Android Spoofing Vulnerability | 0,4% | — |
| CVE-2024-38207 | MED 6.3 | microsoft edge_chromium Microsoft Edge (HTML-based) Memory Corruption Vulnerability | 0,4% | — |
| CVE-2024-38206 | HIGH 8.5 | microsoft copilot_studio An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network. | 12,3% | — |
| CVE-2024-38204 | HIGH 7.5 | microsoft azure_functions Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2024-38203 | MED 6.2 | microsoft windows_10_1507 Windows Package Library Manager Information Disclosure Vulnerability | 0,7% | — |
| CVE-2024-38202 | HIGH 7.3 | microsoft windows_10_1607 Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of Virtualization | 1,7% | — |
| CVE-2024-38201 | HIGH 7.0 | microsoft azure_stack_hub Azure Stack Hub Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2024-38200 | MED 6.5 | microsoft 365_apps Microsoft Office Spoofing Vulnerability | 20,5% | — |
| CVE-2024-38199 | CRIT 9.8 | microsoft windows_10_1507 Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2024-38198 | HIGH 7.5 | microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2024-38197 | MED 6.5 | microsoft teams Microsoft Teams for iOS Spoofing Vulnerability | 16,1% | — |
| CVE-2024-38196 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 6,0% | — |
| CVE-2024-38195 | HIGH 7.8 | microsoft azure_cyclecloud Azure CycleCloud Remote Code Execution Vulnerability | 0,5% | — |
| CVE-2024-38194 | HIGH 8.4 | microsoft azure_web_apps An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network. | 1,3% | — |
| CVE-2024-38191 | HIGH 7.8 | microsoft windows_10_1607 Kernel Streaming Service Driver Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2024-38190 | HIGH 8.6 | microsoft power_platform Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector. | 1,1% | — |