EN
57.469 CVE seguite
782 Sfruttate ora
187 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.469 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2023-21676 HIGH 8.8 microsoft windows_10_1809 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 1,5%
CVE-2023-21674 HIGH 8.8 microsoft windows_10_1507 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability 41,8%
CVE-2023-21549 HIGH 8.8 microsoft windows_10_1607 Windows SMB Witness Service Elevation of Privilege Vulnerability 1,4%
CVE-2023-21529 HIGH 8.8 ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 62,1%
CVE-2023-20888 HIGH 8.8 vmware vrealize_network_insight Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in 82,3%
CVE-2023-20886 HIGH 8.8 vmware workspace_one_uem VMware Workspace ONE UEM console contains an open redirect vulnerability. A malicious actor may be able to redirect a victim to an attacker and retrieve their SAML response to login as the victim user. 0,4%
CVE-2023-20877 HIGH 8.8 vmware cloud_foundation VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation. 0,7%
CVE-2023-20872 HIGH 8.8 vmware fusion VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation. 0,9%
CVE-2023-20856 HIGH 8.8 vmware vrealize_operations VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of the authenticated victim user. 0,4%
CVE-2023-20855 HIGH 8.8 vmware vrealize_automation VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sen 1,3%
CVE-2023-20231 HIGH 8.8 cisco ios_xe A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulner 0,7%
CVE-2023-20175 HIGH 8.8 cisco identity_services_engine A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid 0,5%
CVE-2023-20102 HIGH 8.8 cisco secure_network_analytics A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system. This vulnerability is due to insufficient sanitization of user-p 1,0%
CVE-2023-20046 HIGH 8.8 cisco staros A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied credentials 0,9%
CVE-2023-20038 HIGH 8.8 cisco industrial_network_director A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static secret key used to store both local data and credentials for accessing remote systems. This vulnerability is d 0,2%
CVE-2023-20011 HIGH 8.8 cisco application_policy_infrastructure_controller A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an unauthenticated, remote attacker to conduct a cross-site request fo 0,4%
CVE-2023-0932 HIGH 8.8 google chrome Use after free in WebRTC in Google Chrome on Windows prior to 110.0.5481.177 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Hig 0,6%
CVE-2023-0882 HIGH 8.8 krontech single_connect Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Kron Tech Single Connect on Windows allows Privilege Abuse. This issue affects Single Connect: 2.16. 0,7%
CVE-2023-0213 HIGH 8.8 m-files m-files Elevation of privilege issue in M-Files Installer versions before 22.6 on Windows allows user to gain SYSTEM privileges via DLL hijacking. 0,2%
CVE-2023-0189 HIGH 8.8 nvidia virtual_gpu NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. 0,3%
CVE-2022-50493 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix crash when I/O abort times out While performing CPU hotplug, a crash with the following stack was seen: Call Trace: qla24xx_process_response_queue+0x42a/0x970 [qla2x 0,2%
CVE-2022-50419 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sysfs: Fix attempting to call device_add multiple times device_add shall not be called multiple times as stated in its documentation: 'Do not call this routine or device_reg 0,2%
CVE-2022-50413 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix use-after-free We've already freed the assoc_data at this point, so need to use another copy of the AP (MLD) address instead. 0,2%
CVE-2022-50386 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix user-after-free This uses l2cap_chan_hold_unless_zero() after calling __l2cap_get_chan_blah() to prevent the following trace: Bluetooth: l2cap_core.c:static void l2cap 0,4%
CVE-2022-50241 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: fix use-after-free on source server when doing inter-server copy Use-after-free occurred when the laundromat tried to free expired cpntf_state entry on the s2s_cp_stateids list after i 0,4%