58.352 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.352 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-43642 | HIGH 7.5 | microsoft windows_11_22h2 Windows SMB Denial of Service Vulnerability | 62,7% | — |
| CVE-2024-43575 | HIGH 7.5 | microsoft windows_server_2016 Windows Hyper-V Denial of Service Vulnerability | 2,3% | — |
| CVE-2024-43567 | HIGH 7.5 | microsoft windows_server_2012 Windows Hyper-V Denial of Service Vulnerability | 2,3% | — |
| CVE-2024-43566 | HIGH 7.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1,1% | — |
| CVE-2024-43565 | HIGH 7.5 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 2,2% | — |
| CVE-2024-43562 | HIGH 7.5 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 2,2% | — |
| CVE-2024-43545 | HIGH 7.5 | microsoft windows_server_2008 Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability | 2,2% | — |
| CVE-2024-43544 | HIGH 7.5 | microsoft windows_server_2008 Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability | 2,2% | — |
| CVE-2024-43541 | HIGH 7.5 | microsoft windows_server_2008 Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability | 2,3% | — |
| CVE-2024-43521 | HIGH 7.5 | microsoft windows_server_2012 Windows Hyper-V Denial of Service Vulnerability | 2,4% | — |
| CVE-2024-43515 | HIGH 7.5 | microsoft windows_10_1507 Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability | 2,3% | — |
| CVE-2024-43506 | HIGH 7.5 | microsoft windows_10_1507 BranchCache Denial of Service Vulnerability | 2,3% | — |
| CVE-2024-43499 | HIGH 7.5 | microsoft .net .NET and Visual Studio Denial of Service Vulnerability | 2,6% | — |
| CVE-2024-43485 | HIGH 7.5 | microsoft .net .NET and Visual Studio Denial of Service Vulnerability | 3,1% | — |
| CVE-2024-43484 | HIGH 7.5 | microsoft .net .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | 2,9% | — |
| CVE-2024-43483 | HIGH 7.5 | microsoft .net .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | 2,9% | — |
| CVE-2024-43477 | HIGH 7.5 | microsoft entra_id Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant. | 1,0% | — |
| CVE-2024-43467 | HIGH 7.5 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | 1,1% | — |
| CVE-2024-43452 | HIGH 7.5 | microsoft windows_10_1809 Windows Registry Elevation of Privilege Vulnerability | 28,1% | — |
| CVE-2024-43450 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Spoofing Vulnerability | 0,6% | — |
| CVE-2024-43394 | HIGH 7.5 | apache http_server Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via mod_rewrite or apache expressions that pass unvalidated request input. This issue affects Apache HTTP Server: from 2.4.0 thro | 1,1% | — |
| CVE-2024-43204 | HIGH 7.5 | apache http_server SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker. Requires an unlikely configuration where mod_headers is configured to modify the Content-Type request or response header w | 0,8% | — |
| CVE-2024-42516 | HIGH 7.5 | apache http_server HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 b | 0,7% | — |
| CVE-2024-42361 | HIGH 7.5 | apache hertzbeat Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoint to download job metrics. In the process, it executes a SQL query with user-controlled data, allowing for SQL | 1,1% | — |
| CVE-2024-42286 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: validate nvme_local_port correctly The driver load failed with error message, qla2xxx [0000:04:00.0]-ffff:0: register_localport failed: ret=ffffffef and with a kernel crash, | 0,9% | — |