EN
57.411 CVE seguite
782 Sfruttate ora
186 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.411 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2024-43592 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1,7%
CVE-2024-43589 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1,4%
CVE-2024-43564 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1,3%
CVE-2024-43549 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1,3%
CVE-2024-43533 HIGH 8.8 microsoft windows_11_21h2 Remote Desktop Client Remote Code Execution Vulnerability 1,5%
CVE-2024-43532 HIGH 8.8 microsoft windows_10_1507 Remote Registry Service Elevation of Privilege Vulnerability 12,0%
CVE-2024-43519 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1,4%
CVE-2024-43518 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Server Remote Code Execution Vulnerability 0,9%
CVE-2024-43517 HIGH 8.8 microsoft windows_10_1507 Microsoft ActiveX Data Objects Remote Code Execution Vulnerability 1,4%
CVE-2024-43488 HIGH 8.8 microsoft visual_studio_code Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector. 1,2%
CVE-2024-43469 HIGH 8.8 microsoft azure_cyclecloud Azure CycleCloud Remote Code Execution Vulnerability 1,6%
CVE-2024-43462 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1,6%
CVE-2024-43461 HIGH 8.8 microsoft windows_10_1507 Windows MSHTML Platform Spoofing Vulnerability 54,5%
CVE-2024-43459 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1,6%
CVE-2024-43455 HIGH 8.8 microsoft windows_server_2008 Windows Remote Desktop Licensing Service Spoofing Vulnerability 1,7%
CVE-2024-43453 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1,4%
CVE-2024-43115 HIGH 8.8 apache dolphinscheduler Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which 0,5%
CVE-2024-43033 HIGH 8.8 jpress jpress JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to AttachmentController, such as a .jsp::$DATA file to io.jpress.web.commons.controller.AttachmentController#upload. NOTE: this is 1,0%
CVE-2024-42362 HIGH 8.8 apache hertzbeat Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/import. This vulnerability is fixed in 1.6.0. 1,3%
CVE-2024-42323 HIGH 8.8 apache hertzbeat SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating).  This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.0. Users are recommended to upgrade to vers 8,3%
CVE-2024-42318 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: landlock: Don't lose track of restrictions on cred_transfer When a process' cred struct is replaced, this _almost_ always invokes the cred_prepare LSM hook; but in one special case (when KEY 0,3%
CVE-2024-42287 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Complete command early within lock A crash was observed while performing NPIV and FW reset, BUG: kernel NULL pointer dereference, address: 000000000000001c #PF: supervisor 0,3%
CVE-2024-42083 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ionic: fix kernel panic due to multi-buffer handling Currently, the ionic_run_xdp() doesn't handle multi-buffer packets properly for XDP_TX and XDP_REDIRECT. When a jumbo frame is received, 0,3%
CVE-2024-41151 HIGH 8.8 apache hertzbeat Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat: before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the iss 1,0%
CVE-2024-41091 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tun: add missing verification for short frame The cited commit missed to check against the validity of the frame length in the tun_xdp_one() path, which could cause a corrupted skb to be sen 0,3%