57.411 CVE seguite
782 Sfruttate ora
186 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.411 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-41090 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tap: add missing verification for short frame The cited commit missed to check against the validity of the frame length in the tap_get_user_xdp() path, which could cause a corrupted skb to b | 0,3% | — |
| CVE-2024-41062 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bluetooth/l2cap: sync sock recv cb and release The problem occurs between the system call to close the sock and hci_rx_work, where the former releases the sock and the latter accesses it wit | 0,3% | — |
| CVE-2024-41046 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ethernet: lantiq_etop: fix double free in detach The number of the currently released descriptor is never incremented which results in the same skb being released multiple times. | 0,4% | — |
| CVE-2024-40911 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: Lock wiphy in cfg80211_get_station Wiphy should be locked before calling rdev_get_station() (see lockdep assert in ieee80211_get_station()). This fixes the following kernel | 0,4% | — |
| CVE-2024-40910 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ax25: Fix refcount imbalance on inbound connections When releasing a socket in ax25_release(), we call netdev_put() to decrease the refcount on the associated ax.25 device. However, the exec | 0,4% | — |
| CVE-2024-40591 | HIGH 8.8 | fortinet fortios An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their priv | 0,6% | — |
| CVE-2024-4018 | HIGH 8.8 | beyondtrust u-series_appliance Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (local appliance api modules) allows Privilege Escalation.This issue affects U-Series Appliance: from 3.4 before 4.0.3. | 0,2% | — |
| CVE-2024-4017 | HIGH 8.8 | beyondtrust u-series_appliance Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (filesystem modules) allows DLL Side-Loading.This issue affects U-Series Appliance: from 3.4 before 4.0.3. | 0,2% | — |
| CVE-2024-39877 | HIGH 8.8 | apache airflow Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that could execute arbitrary code in the scheduler context, which should be forbidden according to the Airflow Secur | 1,7% | — |
| CVE-2024-39565 | HIGH 8.8 | juniper j-web An Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in J-Web shipped with Juniper Networks Junos OS allows an unauthenticated, network-based attacker to execute remote commands on the target device. While an administ | 0,5% | — |
| CVE-2024-38814 | HIGH 8.8 | vmware vmware_hcx An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated user with non-administrator privileges may be able to enter specially crafted SQL queries and perform unauthorized remote code execution o | 15,4% | — |
| CVE-2024-38811 | HIGH 8.8 | vmware fusion VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with standard user privileges may exploit this vulnerability to execute code in the context of the Fusion applicati | 0,3% | — |
| CVE-2024-38620 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HCI: Remove HCI_AMP support Since BT_HS has been remove HCI_AMP controllers no longer has any use so remove it along with the capability of creating AMP controllers. Since we no | 0,3% | — |
| CVE-2024-38381 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfc: nci: Fix uninit-value in nci_rx_work syzbot reported the following uninit-value access issue [1] nci_rx_work() parses received packet from ndev->rx_q. It should be validated header siz | 0,4% | — |
| CVE-2024-38265 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2024-38260 | HIGH 8.8 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | 1,6% | — |
| CVE-2024-38259 | HIGH 8.8 | microsoft windows_11_21h2 Microsoft Management Console Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2024-38255 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability | 1,6% | — |
| CVE-2024-38225 | HIGH 8.8 | microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | 1,4% | — |
| CVE-2024-38212 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1,4% | — |
| CVE-2024-38189 | HIGH 8.8 | microsoft 365_apps Microsoft Project Remote Code Execution Vulnerability | 8,2% | |
| CVE-2024-38180 | HIGH 8.8 | microsoft windows_10_1507 Windows SmartScreen Security Feature Bypass Vulnerability | 1,6% | — |
| CVE-2024-38179 | HIGH 8.8 | microsoft azure_stack_hci Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2024-38154 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1,6% | — |
| CVE-2024-38144 | HIGH 8.8 | microsoft windows_10_1507 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | 32,3% | — |