EN
58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.306 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2023-35898 MED 4.3 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information due to an insecure security configuration in InfoSphere Data Flow Designer. IBM X-Force ID: 259352. 0,5% —
CVE-2023-35896 MED 5.4 ibm content_navigator IBM Content Navigator 3.0.13 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 0,3% —
CVE-2023-35893 CRIT 9.9 ibm security_guardium IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 258824. 1,4% —
CVE-2023-35887 MED 5.0 apache sshd Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" in 1,3% —
CVE-2023-35845 MED 4.7 anaconda anaconda3 Anaconda 3 2023.03-1-Linux allows local users to disrupt TLS certificate validation by modifying the cacert.pem file used by the installed pip program. This occurs because many files are installed as world-writable on Linux, ignoring umask, even when these fil 0,1% —
CVE-2023-35838 MED 5.7 wireguard wireguard The WireGuard client 0.5.3 on Windows insecurely configures the operating system and firewall such that traffic to a local network that uses non-RFC1918 IP addresses is blocked. This allows an adversary to trick the victim into blocking IP traffic to selected 0,7% —
CVE-2023-35829 HIGH 7.0 linux linux_kernel An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in rkvdec_remove in drivers/staging/media/rkvdec/rkvdec.c. 0,4% —
CVE-2023-35828 HIGH 7.0 linux linux_kernel An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesas_usb3_remove in drivers/usb/gadget/udc/renesas_usb3.c. 0,5% —
CVE-2023-35827 HIGH 7.0 linux linux_kernel An issue was discovered in the Linux kernel through 6.3.8. A use-after-free was found in ravb_remove in drivers/net/ethernet/renesas/ravb_main.c. 0,2% —
CVE-2023-35826 HIGH 7.0 linux linux_kernel An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in cedrus_remove in drivers/staging/media/sunxi/cedrus/cedrus.c. 0,2% —
CVE-2023-35824 HIGH 7.0 debian debian_linux An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in dm1105_remove in drivers/media/pci/dm1105/dm1105.c. 0,2% —
CVE-2023-35823 HIGH 7.0 debian debian_linux An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media/pci/saa7134/saa7134-core.c. 0,2% —
CVE-2023-35798 MED 4.3 apache apache-airflow-providers-microsoft-mssql Input Validation vulnerability in Apache Software Foundation Apache Airflow ODBC Provider, Apache Software Foundation Apache Airflow MSSQL Provider.This vulnerability is considered low since it requires DAG code to use `get_sqlalchemy_connection` and someone w 1,3% —
CVE-2023-35797 CRIT 9.8 apache apache-airflow-providers-apache-hive Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects Apache Airflow Apache Hive Provider: before 6.1.1. Before version 6.1.1 it was possible to bypass the security check to RCE via principal pa 2,8% —
CVE-2023-35788 HIGH 7.8 canonical ubuntu_linux An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privileg 0,5% —
CVE-2023-35701 MED 6.6 apache hive Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive. The vulnerability affects the Hive JDBC driver component and it can potentially lead to arbitrary code execution on the machine/endpoint that the JDBC driver (client) is r 1,1% —
CVE-2023-3567 HIGH 7.1 canonical ubuntu_linux A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information. 0,4% —
CVE-2023-35644 HIGH 7.8 microsoft windows_10_1809 Windows Sysmain Service Elevation of Privilege Vulnerability 6,3% —
CVE-2023-35643 HIGH 7.5 microsoft windows_server_2012 DHCP Server Service Information Disclosure Vulnerability 2,6% —
CVE-2023-35642 MED 6.5 microsoft windows_10_1507 Internet Connection Sharing (ICS) Denial of Service Vulnerability 1,3% —
CVE-2023-35641 HIGH 8.8 microsoft windows_10_1507 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability 7,2% —
CVE-2023-35639 HIGH 8.8 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 2,4% —
CVE-2023-35638 HIGH 7.5 microsoft windows_server_2012 DHCP Server Service Denial of Service Vulnerability 3,3% —
CVE-2023-35636 MED 6.5 microsoft 365_apps Microsoft Outlook Information Disclosure Vulnerability 17,7% —
CVE-2023-35635 MED 5.5 microsoft windows_11_22h2 Windows Kernel Denial of Service Vulnerability 1,0% —