58.414 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.414 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-41085 | HIGH 7.5 | microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-41058 | HIGH 7.5 | microsoft windows_10 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 2,1% | — |
| CVE-2022-41056 | HIGH 7.5 | microsoft windows_10 Network Policy Server (NPS) RADIUS Protocol Denial of Service Vulnerability | 2,1% | — |
| CVE-2022-41053 | HIGH 7.5 | microsoft windows_10 Windows Kerberos Denial of Service Vulnerability | 2,1% | — |
| CVE-2022-40705 | HIGH 7.5 | apache soap An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files over HTTP. This issue affects Apache SOAP version 2.2 and later versions. It is unknown whether previous versio | 1,9% | — |
| CVE-2022-40676 | HIGH 7.5 | fortinet fortinac A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 all | 0,5% | — |
| CVE-2022-40604 | HIGH 7.5 | apache airflow In Apache Airflow 2.3.0 through 2.3.4, part of a url was unnecessarily formatted, allowing for possible information extraction. | 2,1% | — |
| CVE-2022-40308 | HIGH 7.5 | apache archiva If anonymous read enabled, it's possible to read the database file directly without logging in. | 1,3% | — |
| CVE-2022-40146 | HIGH 7.5 | apache batik Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14. | 7,4% | — |
| CVE-2022-40141 | HIGH 7.5 | trendmicro apex_one A vulnerability in Trend Micro Apex One and Apex One as a Service could allow an attacker to intercept and decode certain communication strings that may contain some identification attributes of a particular Apex One server. | 0,9% | — |
| CVE-2022-40082 | HIGH 7.5 | cloudwego hertz Hertz v0.3.0 ws discovered to contain a path traversal vulnerability via the normalizePath function. | 0,9% | — |
| CVE-2022-39337 | HIGH 7.5 | apache hertzbeat Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat versions 1.20 and prior have a permission bypass vulnerability. System authentication can be bypassed and invoke | 1,1% | — |
| CVE-2022-38370 | HIGH 7.5 | apache iotdb Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue. | 1,3% | — |
| CVE-2022-38166 | HIGH 7.5 | f-secure elements_endpoint_protection In F-Secure Endpoint Protection for Windows and macOS before channel with Capricorn database 2022-11-22_07, the aerdl.dll unpacker handler crashes. This can lead to a scanning engine crash, triggerable remotely by an attacker for denial of service. | 0,7% | — |
| CVE-2022-38046 | HIGH 7.5 | microsoft windows_10 Web Account Manager Information Disclosure Vulnerability | 1,9% | — |
| CVE-2022-38041 | HIGH 7.5 | microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability | 2,2% | — |
| CVE-2022-38036 | HIGH 7.5 | microsoft windows_11 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability | 2,2% | — |
| CVE-2022-38013 | HIGH 7.5 | fedoraproject fedora .NET Core and Visual Studio Denial of Service Vulnerability | 4,0% | — |
| CVE-2022-37978 | HIGH 7.5 | microsoft windows_10 Windows Active Directory Certificate Services Security Feature Bypass | 1,5% | — |
| CVE-2022-37972 | HIGH 7.5 | microsoft endpoint_configuration_manager Microsoft Endpoint Configuration Manager Spoofing Vulnerability | 1,9% | — |
| CVE-2022-37866 | HIGH 7.5 | apache ivy When Apache Ivy downloads artifacts from a repository it stores them in the local file system based on a user-supplied "pattern" that may include placeholders for artifacts coordinates like the organisation, module or version. If said coordinates contain "../" | 1,7% | — |
| CVE-2022-36946 | HIGH 7.5 | debian debian_linux nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service (panic) because, in the case of an nf_queue verdict with a one-byte nfta_payload attribute, an skb_pull can encounter a neg | 7,6% | — |
| CVE-2022-36374 | HIGH 7.5 | intel aptio_v_uefi_firmware_integrator_tools Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmi Windows 5.27.03.0003 may allow a privileged user to potentially enable escalation of privilege via local access. | 0,2% | — |
| CVE-2022-36127 | HIGH 7.5 | apache skywalking_nodejs_agent A vulnerability in Apache SkyWalking NodeJS Agent prior to 0.5.1. The vulnerability will cause NodeJS services that has this agent installed to be unavailable if the OAP is unhealthy and NodeJS agent can't establish the connection. | 1,8% | — |
| CVE-2022-36125 | HIGH 7.5 | apache avro It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which addr | 1,5% | — |