57.411 CVE seguite
782 Sfruttate ora
186 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.411 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-43592 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1,7% | — |
| CVE-2024-43589 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1,4% | — |
| CVE-2024-43564 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2024-43549 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2024-43533 | HIGH 8.8 | microsoft windows_11_21h2 Remote Desktop Client Remote Code Execution Vulnerability | 1,5% | — |
| CVE-2024-43532 | HIGH 8.8 | microsoft windows_10_1507 Remote Registry Service Elevation of Privilege Vulnerability | 12,0% | — |
| CVE-2024-43519 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1,4% | — |
| CVE-2024-43518 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Server Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2024-43517 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ActiveX Data Objects Remote Code Execution Vulnerability | 1,4% | — |
| CVE-2024-43488 | HIGH 8.8 | microsoft visual_studio_code Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector. | 1,2% | — |
| CVE-2024-43469 | HIGH 8.8 | microsoft azure_cyclecloud Azure CycleCloud Remote Code Execution Vulnerability | 1,6% | — |
| CVE-2024-43462 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability | 1,6% | — |
| CVE-2024-43461 | HIGH 8.8 | microsoft windows_10_1507 Windows MSHTML Platform Spoofing Vulnerability | 54,5% | |
| CVE-2024-43459 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability | 1,6% | — |
| CVE-2024-43455 | HIGH 8.8 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Spoofing Vulnerability | 1,7% | — |
| CVE-2024-43453 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1,4% | — |
| CVE-2024-43115 | HIGH 8.8 | apache dolphinscheduler Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which | 0,5% | — |
| CVE-2024-43033 | HIGH 8.8 | jpress jpress JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to AttachmentController, such as a .jsp::$DATA file to io.jpress.web.commons.controller.AttachmentController#upload. NOTE: this is | 1,0% | — |
| CVE-2024-42362 | HIGH 8.8 | apache hertzbeat Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/import. This vulnerability is fixed in 1.6.0. | 1,3% | — |
| CVE-2024-42323 | HIGH 8.8 | apache hertzbeat SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.0. Users are recommended to upgrade to vers | 8,3% | — |
| CVE-2024-42318 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: landlock: Don't lose track of restrictions on cred_transfer When a process' cred struct is replaced, this _almost_ always invokes the cred_prepare LSM hook; but in one special case (when KEY | 0,3% | — |
| CVE-2024-42287 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Complete command early within lock A crash was observed while performing NPIV and FW reset, BUG: kernel NULL pointer dereference, address: 000000000000001c #PF: supervisor | 0,3% | — |
| CVE-2024-42083 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ionic: fix kernel panic due to multi-buffer handling Currently, the ionic_run_xdp() doesn't handle multi-buffer packets properly for XDP_TX and XDP_REDIRECT. When a jumbo frame is received, | 0,3% | — |
| CVE-2024-41151 | HIGH 8.8 | apache hertzbeat Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat: before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the iss | 1,0% | — |
| CVE-2024-41091 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tun: add missing verification for short frame The cited commit missed to check against the validity of the frame length in the tun_xdp_one() path, which could cause a corrupted skb to be sen | 0,3% | — |