EN
58.378 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.378 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2023-35622 HIGH 7.5 microsoft windows_server_2008 Windows DNS Spoofing Vulnerability 1,6% —
CVE-2023-35621 HIGH 7.5 microsoft dynamics_365 Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability 2,3% —
CVE-2023-35383 HIGH 7.5 microsoft windows_10_1507 Microsoft Message Queuing Information Disclosure Vulnerability 3,0% —
CVE-2023-35352 HIGH 7.5 microsoft windows_server_2012 Windows Remote Desktop Security Feature Bypass Vulnerability 1,4% —
CVE-2023-35339 HIGH 7.5 microsoft windows_10_1507 Windows CryptoAPI Denial of Service Vulnerability 1,9% —
CVE-2023-35338 HIGH 7.5 microsoft windows_10_1507 Windows Peer Name Resolution Protocol Denial of Service Vulnerability 2,0% —
CVE-2023-35330 HIGH 7.5 microsoft windows_10_1507 Windows Extended Negotiation Denial of Service Vulnerability 1,9% —
CVE-2023-35325 HIGH 7.5 microsoft windows_10_1507 Windows Print Spooler Information Disclosure Vulnerability 1,8% —
CVE-2023-35309 HIGH 7.5 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 0,8% —
CVE-2023-35298 HIGH 7.5 microsoft windows_11_21h2 HTTP.sys Denial of Service Vulnerability 1,8% —
CVE-2023-35077 HIGH 7.5 ivanti endpoint_manager An out-of-bounds write vulnerability on windows operating systems causes the Ivanti AntiVirus Product to crash. Update to Ivanti AV Product version 7.9.1.285 or above. 2,2% —
CVE-2023-34984 HIGH 7.5 fortinet fortiweb A protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6 through 6.3.23 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests. 0,7% —
CVE-2023-34981 HIGH 7.5 apache tomcat A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (m 1,1% —
CVE-2023-34434 HIGH 7.5 apache inlong Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0.  The attacker could bypass the current logic and achieve arbitrary file reading. To solve it, users are adv 1,7% —
CVE-2023-33933 HIGH 7.5 apache traffic_server Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0. 8.x users should upgrade to 8.1.7 or later versions 9.x users shou 1,5% —
CVE-2023-33850 HIGH 7.5 ibm cics_tx IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulne 1,2% —
CVE-2023-33163 HIGH 7.5 microsoft windows_server_2008 Windows Network Load Balancing Remote Code Execution Vulnerability 0,4% —
CVE-2023-33143 HIGH 7.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1,5% —
CVE-2023-33141 HIGH 7.5 microsoft yet_another_reverse_proxy Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability 2,2% —
CVE-2023-3312 HIGH 7.5 linux linux_kernel A vulnerability was found in drivers/cpufreq/qcom-cpufreq-hw.c in cpufreq subsystem in the Linux Kernel. This flaw, during device unbind will lead to double release problem leading to denial of service. 0,9% —
CVE-2023-32820 HIGH 7.5 google android In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637; Issue 0,4% —
CVE-2023-32783 HIGH 7.5 zohocorp manageengine_adaudit_plus The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix. NOTE: the vendor states "We do not consider this as a security bug and it's an exp 3,9% —
CVE-2023-32331 HIGH 7.5 ibm sterling_connect\ IBM Connect:Express for UNIX 1.5.0 is vulnerable to a buffer overflow that could allow a remote attacker to cause a denial of service through its browser UI. IBM X-Force ID: 254979. 0,7% —
CVE-2023-32252 HIGH 7.5 linux linux_kernel A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_LOGOFF commands. The issue results from the lack of proper validation of a pointer prior to accessing it. An attacker ca 4,1% —
CVE-2023-32248 HIGH 7.5 linux linux_kernel A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_TREE_CONNECT and SMB2_QUERY_INFO commands. The issue results from the lack of proper validation of a pointer prior to ac 4,1% —