58.378 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.378 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-35622 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Spoofing Vulnerability | 1,6% | — |
| CVE-2023-35621 | HIGH 7.5 | microsoft dynamics_365 Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability | 2,3% | — |
| CVE-2023-35383 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing Information Disclosure Vulnerability | 3,0% | — |
| CVE-2023-35352 | HIGH 7.5 | microsoft windows_server_2012 Windows Remote Desktop Security Feature Bypass Vulnerability | 1,4% | — |
| CVE-2023-35339 | HIGH 7.5 | microsoft windows_10_1507 Windows CryptoAPI Denial of Service Vulnerability | 1,9% | — |
| CVE-2023-35338 | HIGH 7.5 | microsoft windows_10_1507 Windows Peer Name Resolution Protocol Denial of Service Vulnerability | 2,0% | — |
| CVE-2023-35330 | HIGH 7.5 | microsoft windows_10_1507 Windows Extended Negotiation Denial of Service Vulnerability | 1,9% | — |
| CVE-2023-35325 | HIGH 7.5 | microsoft windows_10_1507 Windows Print Spooler Information Disclosure Vulnerability | 1,8% | — |
| CVE-2023-35309 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2023-35298 | HIGH 7.5 | microsoft windows_11_21h2 HTTP.sys Denial of Service Vulnerability | 1,8% | — |
| CVE-2023-35077 | HIGH 7.5 | ivanti endpoint_manager An out-of-bounds write vulnerability on windows operating systems causes the Ivanti AntiVirus Product to crash. Update to Ivanti AV Product version 7.9.1.285 or above. | 2,2% | — |
| CVE-2023-34984 | HIGH 7.5 | fortinet fortiweb A protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6 through 6.3.23 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests. | 0,7% | — |
| CVE-2023-34981 | HIGH 7.5 | apache tomcat A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (m | 1,1% | — |
| CVE-2023-34434 | HIGH 7.5 | apache inlong Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could bypass the current logic and achieve arbitrary file reading. To solve it, users are adv | 1,7% | — |
| CVE-2023-33933 | HIGH 7.5 | apache traffic_server Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0. 8.x users should upgrade to 8.1.7 or later versions 9.x users shou | 1,5% | — |
| CVE-2023-33850 | HIGH 7.5 | ibm cics_tx IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulne | 1,2% | — |
| CVE-2023-33163 | HIGH 7.5 | microsoft windows_server_2008 Windows Network Load Balancing Remote Code Execution Vulnerability | 0,4% | — |
| CVE-2023-33143 | HIGH 7.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1,5% | — |
| CVE-2023-33141 | HIGH 7.5 | microsoft yet_another_reverse_proxy Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability | 2,2% | — |
| CVE-2023-3312 | HIGH 7.5 | linux linux_kernel A vulnerability was found in drivers/cpufreq/qcom-cpufreq-hw.c in cpufreq subsystem in the Linux Kernel. This flaw, during device unbind will lead to double release problem leading to denial of service. | 0,9% | — |
| CVE-2023-32820 | HIGH 7.5 | google android In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637; Issue | 0,4% | — |
| CVE-2023-32783 | HIGH 7.5 | zohocorp manageengine_adaudit_plus The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix. NOTE: the vendor states "We do not consider this as a security bug and it's an exp | 3,9% | — |
| CVE-2023-32331 | HIGH 7.5 | ibm sterling_connect\ IBM Connect:Express for UNIX 1.5.0 is vulnerable to a buffer overflow that could allow a remote attacker to cause a denial of service through its browser UI. IBM X-Force ID: 254979. | 0,7% | — |
| CVE-2023-32252 | HIGH 7.5 | linux linux_kernel A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_LOGOFF commands. The issue results from the lack of proper validation of a pointer prior to accessing it. An attacker ca | 4,1% | — |
| CVE-2023-32248 | HIGH 7.5 | linux linux_kernel A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_TREE_CONNECT and SMB2_QUERY_INFO commands. The issue results from the lack of proper validation of a pointer prior to ac | 4,1% | — |