EN
58.378 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.378 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2023-39456 HIGH 7.5 apache traffic_server Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 through 9.2.2. Users are recommended to upgrade to version 9.2.3, which fixes the issue. 53,8% —
CVE-2023-39410 HIGH 7.5 apache avro When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11 1,8% —
CVE-2023-39198 HIGH 7.5 fedoraproject fedora A race condition was found in the QXL driver in the Linux kernel. The qxl_mode_dumb_create() function dereferences the qobj returned by the qxl_gem_object_create_with_handle(), but the handle is the only one holding a reference to it. This flaw allows an attac 0,4% —
CVE-2023-39179 HIGH 7.5 linux linux_kernel A flaw was found within the handling of SMB2 read requests in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to 1,1% —
CVE-2023-39026 HIGH 7.5 filemage filemage Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component. 17,9% —
CVE-2023-38741 HIGH 7.5 ibm txseries_for_multiplatform IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to 1,0% —
CVE-2023-3866 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate session id and tree id in the compound request This patch validate session id and tree id in compound request. If first operation in the compound is SMB2 ECHO request, ksmbd 10,5% —
CVE-2023-38522 HIGH 7.5 apache traffic_server Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue 1,0% —
CVE-2023-38434 HIGH 7.5 xhttp_project xhttp xHTTP 72f812d has a double free in close_connection in xhttp.c via a malformed HTTP request method. 1,1% —
CVE-2023-38403 HIGH 7.5 apple macos iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field. 2,0% —
CVE-2023-38184 HIGH 7.5 microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 1,5% —
CVE-2023-38180 HIGH 7.5 fedoraproject fedora .NET and Visual Studio Denial of Service Vulnerability 14,0%
CVE-2023-38178 HIGH 7.5 microsoft .net .NET Core and Visual Studio Denial of Service Vulnerability 2,6% —
CVE-2023-38172 HIGH 7.5 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 2,0% —
CVE-2023-38171 HIGH 7.5 microsoft .net Microsoft QUIC Denial of Service Vulnerability 69,7% —
CVE-2023-38162 HIGH 7.5 microsoft windows_server_2012 DHCP Server Service Denial of Service Vulnerability 10,7% —
CVE-2023-38149 HIGH 7.5 microsoft windows_10_1507 Windows TCP/IP Denial of Service Vulnerability 4,5% —
CVE-2023-38138 HIGH 7.5 f5 big-ip_access_policy_manager A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End o 0,4% —
CVE-2023-38039 HIGH 7.5 fedoraproject fedora When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server 58,1% —
CVE-2023-37930 HIGH 7.5 fortinet fortios Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted 0,6% —
CVE-2023-37544 HIGH 7.5 apache pulsar Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication. This issue affects Apache Pulsar WebSocket Proxy: from 2.8.0 through 2.8.*, from 2.9.0 through 2.9.*, from 2 1,4% —
CVE-2023-36912 HIGH 7.5 microsoft windows_10 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 2,1% —
CVE-2023-36884 HIGH 7.5 ransomware microsoft windows_10_1507 Windows Search Remote Code Execution Vulnerability 98,9%
CVE-2023-36843 HIGH 7.5 juniper junos An Improper Handling of Inconsistent Special Elements vulnerability in the Junos Services Framework (jsf) module of Juniper Networks Junos OS allows an unauthenticated network based attacker to cause a crash in the Packet Forwarding Engine (pfe) and thereby r 0,5% —
CVE-2023-36841 HIGH 7.5 juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows a unauthenticated network-based attacker to cause an infinite loop, resulting in a Denial of Service ( 0,5% —