58.378 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.378 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-39456 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 through 9.2.2. Users are recommended to upgrade to version 9.2.3, which fixes the issue. | 53,8% | — |
| CVE-2023-39410 | HIGH 7.5 | apache avro When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11 | 1,8% | — |
| CVE-2023-39198 | HIGH 7.5 | fedoraproject fedora A race condition was found in the QXL driver in the Linux kernel. The qxl_mode_dumb_create() function dereferences the qobj returned by the qxl_gem_object_create_with_handle(), but the handle is the only one holding a reference to it. This flaw allows an attac | 0,4% | — |
| CVE-2023-39179 | HIGH 7.5 | linux linux_kernel A flaw was found within the handling of SMB2 read requests in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to | 1,1% | — |
| CVE-2023-39026 | HIGH 7.5 | filemage filemage Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component. | 17,9% | — |
| CVE-2023-38741 | HIGH 7.5 | ibm txseries_for_multiplatform IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to | 1,0% | — |
| CVE-2023-3866 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate session id and tree id in the compound request This patch validate session id and tree id in compound request. If first operation in the compound is SMB2 ECHO request, ksmbd | 10,5% | — |
| CVE-2023-38522 | HIGH 7.5 | apache traffic_server Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue | 1,0% | — |
| CVE-2023-38434 | HIGH 7.5 | xhttp_project xhttp xHTTP 72f812d has a double free in close_connection in xhttp.c via a malformed HTTP request method. | 1,1% | — |
| CVE-2023-38403 | HIGH 7.5 | apple macos iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field. | 2,0% | — |
| CVE-2023-38184 | HIGH 7.5 | microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1,5% | — |
| CVE-2023-38180 | HIGH 7.5 | fedoraproject fedora .NET and Visual Studio Denial of Service Vulnerability | 14,0% | |
| CVE-2023-38178 | HIGH 7.5 | microsoft .net .NET Core and Visual Studio Denial of Service Vulnerability | 2,6% | — |
| CVE-2023-38172 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2,0% | — |
| CVE-2023-38171 | HIGH 7.5 | microsoft .net Microsoft QUIC Denial of Service Vulnerability | 69,7% | — |
| CVE-2023-38162 | HIGH 7.5 | microsoft windows_server_2012 DHCP Server Service Denial of Service Vulnerability | 10,7% | — |
| CVE-2023-38149 | HIGH 7.5 | microsoft windows_10_1507 Windows TCP/IP Denial of Service Vulnerability | 4,5% | — |
| CVE-2023-38138 | HIGH 7.5 | f5 big-ip_access_policy_manager A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End o | 0,4% | — |
| CVE-2023-38039 | HIGH 7.5 | fedoraproject fedora When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server | 58,1% | — |
| CVE-2023-37930 | HIGH 7.5 | fortinet fortios Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted | 0,6% | — |
| CVE-2023-37544 | HIGH 7.5 | apache pulsar Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication. This issue affects Apache Pulsar WebSocket Proxy: from 2.8.0 through 2.8.*, from 2.9.0 through 2.9.*, from 2 | 1,4% | — |
| CVE-2023-36912 | HIGH 7.5 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2,1% | — |
| CVE-2023-36884 | HIGH 7.5 | ransomware microsoft windows_10_1507 Windows Search Remote Code Execution Vulnerability | 98,9% | |
| CVE-2023-36843 | HIGH 7.5 | juniper junos An Improper Handling of Inconsistent Special Elements vulnerability in the Junos Services Framework (jsf) module of Juniper Networks Junos OS allows an unauthenticated network based attacker to cause a crash in the Packet Forwarding Engine (pfe) and thereby r | 0,5% | — |
| CVE-2023-36841 | HIGH 7.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows a unauthenticated network-based attacker to cause an infinite loop, resulting in a Denial of Service ( | 0,5% | — |