EN
57.469 CVE seguite
782 Sfruttate ora
187 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.469 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2022-35805 HIGH 8.8 microsoft dynamics_365 Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability 2,5%
CVE-2022-35804 HIGH 8.8 microsoft windows_11 SMB Client and Server Remote Code Execution Vulnerability 2,8%
CVE-2022-35777 HIGH 8.8 microsoft visual_studio Visual Studio Remote Code Execution Vulnerability 2,0%
CVE-2022-35286 HIGH 8.8 ibm security_verify_information_queue IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230814. 0,3%
CVE-2022-35285 HIGH 8.8 ibm security_verify_information_queue IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230812. 0,4%
CVE-2022-34734 HIGH 8.8 microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability 2,3%
CVE-2022-34733 HIGH 8.8 microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1,9%
CVE-2022-34732 HIGH 8.8 microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability 2,3%
CVE-2022-34731 HIGH 8.8 microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1,9%
CVE-2022-34730 HIGH 8.8 microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability 2,3%
CVE-2022-34727 HIGH 8.8 microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability 2,3%
CVE-2022-34726 HIGH 8.8 microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability 2,3%
CVE-2022-34717 HIGH 8.8 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 1,9%
CVE-2022-34700 HIGH 8.8 microsoft dynamics_365 Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability 3,2%
CVE-2022-34691 HIGH 8.8 microsoft windows_10 Active Directory Domain Services Elevation of Privilege Vulnerability 2,1%
CVE-2022-34669 HIGH 8.8 nvidia cloud_gaming NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can access or modify system files or other files that are critical to the application, which may lead to code execution, denial of service 0,3%
CVE-2022-34271 HIGH 8.8 apache atlas A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0. 1,4%
CVE-2022-34158 HIGH 8.8 apache jspwiki A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account. Further examination of this issue established that it could also b 1,2%
CVE-2022-3405 HIGH 8.8 acronis cyber_backup Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Backup 12.5 (Windows, Linux) before buil 5,3%
CVE-2022-33891 HIGH 8.8 apache spark The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in Ht 93,1%
CVE-2022-33869 HIGH 8.8 fortinet fortiwan An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiWAN 4.0.0 through 4.5.9 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to e 1,3%
CVE-2022-33140 HIGH 8.8 apache nifi The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not neutralize arguments for group resolution commands, allowing injection of operating system commands on Linux and macOS platforms. The ShellUse 3,7%
CVE-2022-31739 HIGH 8.8 mozilla firefox When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.<br>*This bug only affects Firefox for Windows. Oth 0,7%
CVE-2022-31696 HIGH 8.8 vmware cloud_foundation VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox. 0,3%
CVE-2022-31673 HIGH 8.8 vmware vrealize_operations VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can create and leak hex dumps, leading to information disclosure. Successful exploitation can lead to a remote code execution. 1,6%