58.412 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.412 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-27378 | HIGH 7.5 | f5 big-ip_access_policy_manager Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached | 0,4% | — |
| CVE-2023-26513 | HIGH 7.5 | apache sling_resource_merger Excessive Iteration vulnerability in Apache Software Foundation Apache Sling Resource Merger.This issue affects Apache Sling Resource Merger: from 1.2.0 before 1.4.2. | 1,5% | — |
| CVE-2023-26464 | HIGH 7.5 | apache log4j ** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested) hashmap or hashtable (depending on w | 1,9% | — |
| CVE-2023-26031 | HIGH 7.5 | apache hadoop Relative library resolution in linux container-executor binary in Apache Hadoop 3.3.1-3.3.4 on Linux allows local user to gain root privileges. If the YARN cluster is accepting work from remote (authenticated) users, this MAY permit remote users to gain root p | 2,1% | — |
| CVE-2023-26021 | HIGH 7.5 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service as the server may crash when compiling a specially crafted SQL query using a LIMIT clause. IBM X-Force ID: 247864. | 1,0% | — |
| CVE-2023-25956 | HIGH 7.5 | apache apache-airflow-providers-amazon Generation of Error Message Containing Sensitive Information vulnerability in the Apache Airflow AWS Provider. This issue affects Apache Airflow AWS Provider versions before 7.2.1. | 1,5% | — |
| CVE-2023-25692 | HIGH 7.5 | apache apache-airflow-providers-google Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0. | 1,8% | — |
| CVE-2023-25653 | HIGH 7.5 | cisco node-jose node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for web browsers and node.js-based servers. Prior to version 2.2.0, when using the non-default "fallback" crypto back-end, ECC operations in `node-jose` can trigger a Den | 0,6% | — |
| CVE-2023-25605 | HIGH 7.5 | fortinet fortisoar A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the administrative interface to perform unauthorized actions via crafted HTTP requests. | 0,9% | — |
| CVE-2023-25141 | HIGH 7.5 | apache sling_jcr_base Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or earlier) through utility functions in RepositoryAccessor. The functions getRepository and getRepositoryFromURL allow an application to access | 1,2% | — |
| CVE-2023-24998 | HIGH 7.5 | apache commons_fileupload Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the | 48,8% | — |
| CVE-2023-24977 | HIGH 7.5 | apache inlong Out-of-bounds Read vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7214 h | 1,2% | — |
| CVE-2023-24960 | HIGH 7.5 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 24 | 1,4% | — |
| CVE-2023-24942 | HIGH 7.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1,9% | — |
| CVE-2023-24940 | HIGH 7.5 | microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Denial of Service Vulnerability | 5,2% | — |
| CVE-2023-24939 | HIGH 7.5 | microsoft windows_10_1507 Server for NFS Denial of Service Vulnerability | 4,7% | — |
| CVE-2023-24936 | HIGH 7.5 | microsoft .net .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | 1,6% | — |
| CVE-2023-24931 | HIGH 7.5 | microsoft windows_10_1507 Windows Secure Channel Denial of Service Vulnerability | 2,0% | — |
| CVE-2023-24901 | HIGH 7.5 | microsoft windows_10_1507 Windows NFS Portmapper Information Disclosure Vulnerability | 1,6% | — |
| CVE-2023-24898 | HIGH 7.5 | microsoft windows_server_2022 Windows SMB Denial of Service Vulnerability | 2,1% | — |
| CVE-2023-24860 | HIGH 7.5 | microsoft malware_protection_engine Microsoft Defender Denial of Service Vulnerability | 3,0% | — |
| CVE-2023-24859 | HIGH 7.5 | microsoft windows_10 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | 1,7% | — |
| CVE-2023-24858 | HIGH 7.5 | microsoft windows_10 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 1,4% | — |
| CVE-2023-24856 | HIGH 7.5 | microsoft windows_10 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 1,5% | — |
| CVE-2023-24830 | HIGH 7.5 | apache iotdb Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench component: from 0.13.0 before 0.13.3. | 1,3% | — |