EN
58.290 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.290 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2024-37328 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1,6% —
CVE-2024-37327 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1,6% —
CVE-2024-37326 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1,6% —
CVE-2024-37325 HIGH 8.1 microsoft azure_data_science_virtual_machine Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability 1,1% —
CVE-2024-37324 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1,6% —
CVE-2024-37323 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1,6% —
CVE-2024-37322 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1,6% —
CVE-2024-37321 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1,6% —
CVE-2024-37320 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1,6% —
CVE-2024-37319 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1,6% —
CVE-2024-37318 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1,9% —
CVE-2024-37304 MED 6.1 microsoft nugetgallery NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequately 0,7% —
CVE-2024-37087 MED 5.3 vmware cloud_foundation The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition. 0,7% —
CVE-2024-37086 MED 6.8 vmware cloud_foundation VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a denial-of-service condition of the host. 0,2% —
CVE-2024-37084 CRIT 9.8 vmware spring_cloud_data_flow In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server 35,2% —
CVE-2024-37081 HIGH 7.8 vmware cloud_foundation The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance. 5,0% —
CVE-2024-37080 CRIT 9.8 vmware vcenter_server vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remo 12,5% —
CVE-2024-37078 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential kernel bug due to lack of writeback flag waiting Destructive writes to a block device on which nilfs2 is mounted can cause a kernel bug in the folio/page writeback star 0,3% —
CVE-2024-37070 MED 4.3 ibm concert IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system. 0,3% —
CVE-2024-37028 MED 5.3 f5 big-ip_next_central_manager BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0,4% —
CVE-2024-37026 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/xe: Only use reserved BCS instances for usm migrate exec queue The GuC context scheduling queue is 2 entires deep, thus it is possible for a migration job to be stuck behind a fault if m 0,2% —
CVE-2024-37021 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fpga: manager: add owner module and take its refcount The current implementation of the fpga manager assumes that the low-level module registers a driver for the parent device and uses its o 0,2% —
CVE-2024-36991 HIGH 7.5 splunk splunk In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows. 13,0% —
CVE-2024-36979 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: bridge: mst: fix vlan use-after-free syzbot reported a suspicious rcu usage[1] in bridge's mst code. While fixing it I noticed that nothing prevents a vlan to be freed while walking the 0,3% —
CVE-2024-36978 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: sched: sch_multiq: fix possible OOB write in multiq_tune() q->bands will be assigned to qopt->bands to execute subsequent code logic after kmalloc. So the old q->bands should not be use 0,3% —