58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2023-42007 | MED 5.4 | ibm sterling_control_center IBM Sterling Control Center 6.2.1, 6.3.1, and 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure w | 0,2% | — |
| CVE-2023-41964 | MED 4.3 | f5 big-ip_access_policy_manager The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,2% | — |
| CVE-2023-4194 | MED 5.5 | debian debian_linux A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized access to some resources. The original patches fixing CVE-2023-1076 are incorrect or incomplete. The problem is th | 0,3% | — |
| CVE-2023-41916 | MED 6.5 | apache linkis In Apache Linkis =1.4.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will trigger arbitrary file reading. Therefore, the parameters in the Mysql JDBC URL should | 0,7% | — |
| CVE-2023-41844 | LOW 3.5 | fortinet fortisandbox A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all | 0,4% | — |
| CVE-2023-41843 | HIGH 7.5 | fortinet fortisandbox A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, FortiSandbox 4.2.1 through 4.2.5, FortiSandbox 4.0.0 through 4.0.3, FortiSandbox 3.2 all versions, FortiSandbox 3 | 0,5% | — |
| CVE-2023-41842 | MED 6.7 | fortinet fortianalyzer A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute unauthorized code or commands via specially crafted command arguments. | 0,2% | — |
| CVE-2023-41841 | HIGH 8.1 | fortinet fortios An improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4 allows an attacker belonging to the prof-admin profile to perform elevated actions. | 0,8% | — |
| CVE-2023-41840 | HIGH 7.8 | fortinet forticlient A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to perform a DLL Hijack attack via a malicious OpenSSL engine library in the search path. | 0,3% | — |
| CVE-2023-41838 | HIGH 7.1 | fortinet fortianalyzer An improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 may allow attacker to execute unauthorized code or commands via FortiManager cli. | 0,5% | — |
| CVE-2023-41836 | LOW 3.5 | fortinet fortisandbox An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0, FortiSandbox 4.2.1 through 4.2.4, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, | 0,4% | — |
| CVE-2023-41835 | HIGH 7.5 | apache struts When a Multipart request is performed but some of the fields exceed the maxStringLength limit, the upload files will remain in struts.multipart.saveDir even if the request has been denied. Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 | 7,3% | — |
| CVE-2023-41834 | MED 6.1 | apache flink_stateful_functions Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted HTTP requests. Attackers could | 2,1% | — |
| CVE-2023-41774 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2023-41773 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2023-41772 | HIGH 7.8 | microsoft windows_10_1809 Win32k Elevation of Privilege Vulnerability | 11,8% | — |
| CVE-2023-41771 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2023-41770 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2023-41769 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2023-41768 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2023-41767 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2023-41766 | HIGH 7.8 | microsoft windows_10_1507 Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | 1,3% | — |
| CVE-2023-41765 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2023-41764 | MED 5.5 | microsoft 365_apps Microsoft Office Spoofing Vulnerability | 1,0% | — |
| CVE-2023-41752 | HIGH 7.5 | apache traffic_server Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 8.1.8, from 9.0.0 through 9.2.2. Users are recommended to upgrade to version 8.1.9 or 9.2.3, which f | 1,2% | — |