58.273 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.273 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2024-26166 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 2,0% | — |
| CVE-2024-26165 | HIGH 8.8 | microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability | 1,9% | — |
| CVE-2024-26164 | HIGH 8.8 | microsoft django_backend Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability | 2,1% | — |
| CVE-2024-26163 | MED 4.7 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 2,1% | — |
| CVE-2024-26162 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 2,0% | — |
| CVE-2024-26161 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2024-26160 | MED 5.5 | microsoft windows_11_22h2 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | 11,4% | — |
| CVE-2024-26159 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2024-26158 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Install Service Elevation of Privilege Vulnerability | 12,3% | — |
| CVE-2024-26026 | HIGH 7.5 | f5 big-ip_next_central_manager An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 7,2% | — |
| CVE-2024-26016 | MED 4.3 | apache superset A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby gaining ownership of the object. However, it's important to note that access to the analytical data of these ch | 0,9% | — |
| CVE-2024-26015 | LOW 3.4 | fortinet fortios An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, version 7.2.10 and below, version 7.0.17 and below and FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.15 and below IP | 0,5% | — |
| CVE-2024-26013 | HIGH 7.5 | fortinet fortianalyzer A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet FortiProxy version 7.4.0 | 0,5% | — |
| CVE-2024-26012 | MED 6.7 | fortinet fortiap A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiAP-S 6.2 all verisons, and 6.4.0 through 6.4.9, FortiAP-W2 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.3, and 7.4.0 through 7.4.2, FortiAP 6 | 0,7% | — |
| CVE-2024-26011 | MED 5.3 | fortinet fortimanager A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version 7.4.0 thr | 0,6% | — |
| CVE-2024-26010 | HIGH 7.5 | fortinet fortios A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.1 through 7.0.3, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7. | 0,8% | — |
| CVE-2024-26009 | HIGH 8.1 | fortinet fortios An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions, FortiPAM 1.2.0, FortiPAM 1.1.0 through 1.1.2, FortiPAM 1.0.0 through 1.0.3, Fo | 0,6% | — |
| CVE-2024-26008 | MED 5.3 | fortinet fortios An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version 7.4.0 through 7.4.3 and before 7.2.9, FortiPAM before 1.2.0 and FortiSwitchManager version 7.2.0 through | 0,5% | — |
| CVE-2024-26007 | MED 5.3 | fortinet fortios An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows an unauthenticated attacker to provoke a denial of service on the administrative interface via crafted HTTP requests. | 1,2% | — |
| CVE-2024-26006 | HIGH 7.5 | fortinet fortios An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and belo | 0,6% | — |
| CVE-2024-25938 | HIGH 8.8 | foxit pdf_editor A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Barcode widget. A specially crafted JavaScript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and r | 15,6% | — |
| CVE-2024-25744 | HIGH 8.8 | linux linux_kernel In the Linux kernel before 6.6.7, an untrusted VMM can trigger int80 syscall handling at any given point. This is related to arch/x86/coco/tdx/tdx.c and arch/x86/mm/mem_encrypt_amd.c. | 0,3% | — |
| CVE-2024-25741 | MED 5.5 | linux linux_kernel printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does not properly call usb_ep_queue, which might allow attackers to cause a denial of service or have unspecified other impact. | 0,3% | — |
| CVE-2024-25740 | MED 5.5 | linux linux_kernel A memory leak flaw was found in the UBI driver in drivers/mtd/ubi/attach.c in the Linux kernel through 6.7.4 for UBI_IOCATT, because kobj->name is not released. | 0,2% | — |
| CVE-2024-25739 | MED 5.5 | linux linux_kernel create_empty_lvol in drivers/mtd/ubi/vtbl.c in the Linux kernel through 6.7.4 can attempt to allocate zero bytes, and crash, because of a missing check for ubi->leb_size. | 0,2% | — |