57.469 CVE seguite
782 Sfruttate ora
187 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.469 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-21676 | HIGH 8.8 | microsoft windows_10_1809 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1,5% | — |
| CVE-2023-21674 | HIGH 8.8 | microsoft windows_10_1507 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 41,8% | |
| CVE-2023-21549 | HIGH 8.8 | microsoft windows_10_1607 Windows SMB Witness Service Elevation of Privilege Vulnerability | 1,4% | — |
| CVE-2023-21529 | HIGH 8.8 | ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 62,1% | |
| CVE-2023-20888 | HIGH 8.8 | vmware vrealize_network_insight Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in | 82,3% | — |
| CVE-2023-20886 | HIGH 8.8 | vmware workspace_one_uem VMware Workspace ONE UEM console contains an open redirect vulnerability. A malicious actor may be able to redirect a victim to an attacker and retrieve their SAML response to login as the victim user. | 0,4% | — |
| CVE-2023-20877 | HIGH 8.8 | vmware cloud_foundation VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation. | 0,7% | — |
| CVE-2023-20872 | HIGH 8.8 | vmware fusion VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation. | 0,9% | — |
| CVE-2023-20856 | HIGH 8.8 | vmware vrealize_operations VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of the authenticated victim user. | 0,4% | — |
| CVE-2023-20855 | HIGH 8.8 | vmware vrealize_automation VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sen | 1,3% | — |
| CVE-2023-20231 | HIGH 8.8 | cisco ios_xe A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulner | 0,7% | — |
| CVE-2023-20175 | HIGH 8.8 | cisco identity_services_engine A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid | 0,5% | — |
| CVE-2023-20102 | HIGH 8.8 | cisco secure_network_analytics A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system. This vulnerability is due to insufficient sanitization of user-p | 1,0% | — |
| CVE-2023-20046 | HIGH 8.8 | cisco staros A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied credentials | 0,9% | — |
| CVE-2023-20038 | HIGH 8.8 | cisco industrial_network_director A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static secret key used to store both local data and credentials for accessing remote systems. This vulnerability is d | 0,2% | — |
| CVE-2023-20011 | HIGH 8.8 | cisco application_policy_infrastructure_controller A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an unauthenticated, remote attacker to conduct a cross-site request fo | 0,4% | — |
| CVE-2023-0932 | HIGH 8.8 | google chrome Use after free in WebRTC in Google Chrome on Windows prior to 110.0.5481.177 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Hig | 0,6% | — |
| CVE-2023-0882 | HIGH 8.8 | krontech single_connect Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Kron Tech Single Connect on Windows allows Privilege Abuse. This issue affects Single Connect: 2.16. | 0,7% | — |
| CVE-2023-0213 | HIGH 8.8 | m-files m-files Elevation of privilege issue in M-Files Installer versions before 22.6 on Windows allows user to gain SYSTEM privileges via DLL hijacking. | 0,2% | — |
| CVE-2023-0189 | HIGH 8.8 | nvidia virtual_gpu NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | 0,3% | — |
| CVE-2022-50493 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix crash when I/O abort times out While performing CPU hotplug, a crash with the following stack was seen: Call Trace: qla24xx_process_response_queue+0x42a/0x970 [qla2x | 0,2% | — |
| CVE-2022-50419 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sysfs: Fix attempting to call device_add multiple times device_add shall not be called multiple times as stated in its documentation: 'Do not call this routine or device_reg | 0,2% | — |
| CVE-2022-50413 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix use-after-free We've already freed the assoc_data at this point, so need to use another copy of the AP (MLD) address instead. | 0,2% | — |
| CVE-2022-50386 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix user-after-free This uses l2cap_chan_hold_unless_zero() after calling __l2cap_get_chan_blah() to prevent the following trace: Bluetooth: l2cap_core.c:static void l2cap | 0,4% | — |
| CVE-2022-50241 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: fix use-after-free on source server when doing inter-server copy Use-after-free occurred when the laundromat tried to free expired cpntf_state entry on the s2s_cp_stateids list after i | 0,4% | — |