58.290 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.290 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2024-37969 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1,4% | — |
| CVE-2024-37968 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Spoofing Vulnerability | 1,0% | — |
| CVE-2024-37966 | HIGH 7.1 | microsoft sql_server_2017 Microsoft SQL Server Native Scoring Information Disclosure Vulnerability | 2,2% | — |
| CVE-2024-37965 | HIGH 8.8 | microsoft sql_server_2016 Microsoft SQL Server Elevation of Privilege Vulnerability | 1,7% | — |
| CVE-2024-37527 | MED 5.4 | ibm openpages_with_watson IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure | 0,2% | — |
| CVE-2024-37391 | HIGH 7.8 | proton protonvpn ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in Setup/setup.iss. | 0,3% | — |
| CVE-2024-37389 | MED 4.6 | apache nifi Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitra | 24,0% | — |
| CVE-2024-37385 | CRIT 9.8 | roundcube webmail Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641. | 1,5% | — |
| CVE-2024-37358 | HIGH 8.6 | apache james_server Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations Version 3.7. | 0,9% | — |
| CVE-2024-37356 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp: Fix shift-out-of-bounds in dctcp_update_alpha(). In dctcp_update_alpha(), we use a module parameter dctcp_shift_g as follows: alpha -= min_not_zero(alpha, alpha >> dctcp_shift_g); | 0,2% | — |
| CVE-2024-37354 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: fix crash on racing fsync and size-extending write into prealloc We have been seeing crashes on duplicate keys in btrfs_set_item_key_safe(): BTRFS critical (device vdb): slot 4 key | 0,2% | — |
| CVE-2024-37342 | HIGH 7.1 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Information Disclosure Vulnerability | 1,7% | — |
| CVE-2024-37341 | HIGH 8.8 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Elevation of Privilege Vulnerability | 1,4% | — |
| CVE-2024-37340 | HIGH 8.8 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | 1,6% | — |
| CVE-2024-37339 | HIGH 8.8 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | 1,6% | — |
| CVE-2024-37338 | HIGH 8.8 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | 1,6% | — |
| CVE-2024-37337 | HIGH 7.1 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Information Disclosure Vulnerability | 1,7% | — |
| CVE-2024-37336 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1,7% | — |
| CVE-2024-37335 | HIGH 8.8 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | 1,6% | — |
| CVE-2024-37334 | HIGH 8.8 | microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | 1,6% | — |
| CVE-2024-37333 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1,6% | — |
| CVE-2024-37332 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2024-37331 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2024-37330 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1,6% | — |
| CVE-2024-37329 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1,6% | — |