EN
58.387 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.387 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2023-29413 HIGH 7.5 schneider-electric apc_easy_ups_online_monitoring_software A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor service. 0,7% —
CVE-2023-29350 HIGH 7.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 2,6% —
CVE-2023-29348 HIGH 7.5 microsoft windows_server_2008 Windows Remote Desktop Gateway (RD Gateway) Information Disclosure Vulnerability 2,0% —
CVE-2023-29335 HIGH 7.5 microsoft 365_apps Microsoft Word Security Feature Bypass Vulnerability 1,2% —
CVE-2023-29332 HIGH 7.5 microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability 2,7% —
CVE-2023-29331 HIGH 7.5 microsoft .net .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability 2,6% —
CVE-2023-29255 HIGH 7.5 ibm db2 IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as it may trap when compiling a variation of an anonymous block. IBM X-Force ID: 251991. 1,0% —
CVE-2023-29180 HIGH 7.5 fortinet fortios A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.3, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12, 1.2.0 through 1.2.13 2,6% —
CVE-2023-29163 HIGH 7.5 f5 big-ip_access_policy_manager When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0,6% —
CVE-2023-29055 HIGH 7.5 apache kylin In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.properties', that may contain serverside credentials. When the kylin service runs over HTTP (or other plain text protocol), it is possible f 1,1% —
CVE-2023-28985 HIGH 7.5 juniper junos An Improper Validation of Syntactic Correctness of Input vulnerability in Intrusion Detection and Prevention (IDP) of Juniper Networks SRX Series and MX Series allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Continued receip 0,6% —
CVE-2023-28982 HIGH 7.5 juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). In a BGP rib sharding scen 0,6% —
CVE-2023-28976 HIGH 7.5 juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). If specific traffic is r 0,6% —
CVE-2023-28967 HIGH 7.5 juniper junos A Use of Uninitialized Resource vulnerability in the Border Gateway Protocol (BGP) software of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to send specific genuine BGP packets to a device configured with BGP 0,6% —
CVE-2023-28964 HIGH 7.5 juniper junos An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network based, unauthenticated attacker to cause an RPD crash leading to a Denial of Service (D 0,6% —
CVE-2023-28710 HIGH 7.5 apache apache-airflow-providers-apache-spark Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Spark Provider.This issue affects Apache Airflow Spark Provider: before 4.0.1. 2,2% —
CVE-2023-28709 HIGH 7.5 apache tomcat The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query str 48,0% —
CVE-2023-28707 HIGH 7.5 apache apache-airflow-providers-apache-drill Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider: before 2.3.2. 2,1% —
CVE-2023-28509 HIGH 7.5 rocketsoftware unidata Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption for packet-level security and passwords transferred on the wire. 0,3% —
CVE-2023-28302 HIGH 7.5 microsoft windows_10_1607 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 92,6% —
CVE-2023-28300 HIGH 7.5 microsoft azure_service_connector Azure Service Connector Security Feature Bypass Vulnerability 1,0% —
CVE-2023-28247 HIGH 7.5 microsoft windows_server_2012 Windows Network File System Information Disclosure Vulnerability 1,6% —
CVE-2023-28241 HIGH 7.5 microsoft windows_10_1507 Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability 2,0% —
CVE-2023-28238 HIGH 7.5 microsoft windows_10_1507 Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability 0,9% —
CVE-2023-28234 HIGH 7.5 microsoft windows_11_21h2 Windows Secure Channel Denial of Service Vulnerability 1,7% —