57.469 CVE seguite
782 Sfruttate ora
187 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.469 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-23767 | HIGH 8.8 | hanssak securegate This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform various attacks such as obtaining privile | 0,9% | — |
| CVE-2022-23764 | HIGH 8.8 | teruten webcube The vulnerability causing from insufficient verification procedures for downloaded files during WebCube update. Remote attackers can bypass this verification logic to update both digitally signed and unauthorized files, enabling remote code execution. | 0,7% | — |
| CVE-2022-23307 | HIGH 8.8 | apache chainsaw CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. | 54,4% | — |
| CVE-2022-23302 | HIGH 8.8 | apache log4j JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a Topi | 63,6% | — |
| CVE-2022-23294 | HIGH 8.8 | microsoft windows_10 Windows Event Tracing Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2022-23285 | HIGH 8.8 | microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability | 25,6% | — |
| CVE-2022-23277 | HIGH 8.8 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 40,0% | — |
| CVE-2022-23274 | HIGH 8.8 | microsoft dynamics_gp Microsoft Dynamics GP Remote Code Execution Vulnerability | 2,1% | — |
| CVE-2022-23259 | HIGH 8.8 | microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | 2,9% | — |
| CVE-2022-23257 | HIGH 8.8 | microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability | 0,6% | — |
| CVE-2022-23013 | HIGH 8.8 | f5 big-ip_domain_name_system On BIG-IP DNS & GTM version 16.x before 16.1.0, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility | 0,8% | — |
| CVE-2022-22744 | HIGH 8.8 | mozilla firefox The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.<br>*This bug only affects Thunderbird for Windows. Other operating s | 1,3% | — |
| CVE-2022-22493 | HIGH 8.8 | ibm websphere_automation_for_ibm_cloud_pak_for_watson_aiops IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute setting. IBM X-Force ID: 226449. | 0,3% | — |
| CVE-2022-22479 | HIGH 8.8 | ibm spectrum_copy_data_management IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 225887. | 0,3% | — |
| CVE-2022-22472 | HIGH 8.8 | ibm spectrum_protect_plus_container_backup_and_restore IBM Spectrum Protect Plus Container Backup and Restore (10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1.10.2 for Red Hat OpenShift) could allow a remote attacker to bypass IBM Spectrum Protect Plus role based access control restrictions, caused | 0,9% | — |
| CVE-2022-22394 | HIGH 8.8 | ibm spectrum_protect The IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by improper enforcement of access controls. By signing in, an attacker could exploit this vulnerability to bypass security and gain unauthorized ad | 2,2% | — |
| CVE-2022-22182 | HIGH 8.8 | juniper junos A Cross-site Scripting (XSS) vulnerability in Juniper Networks Junos OS J-Web allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions, including an administrator. This issue | 0,7% | — |
| CVE-2022-22026 | HIGH 8.8 | microsoft windows_10 Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | 1,0% | — |
| CVE-2022-22019 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2,6% | — |
| CVE-2022-22017 | HIGH 8.8 | microsoft remote_desktop_client Remote Desktop Client Remote Code Execution Vulnerability | 38,0% | — |
| CVE-2022-22014 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2022-22013 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2022-22005 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 16,4% | — |
| CVE-2022-21990 | HIGH 8.8 | microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability | 18,8% | — |
| CVE-2022-21984 | HIGH 8.8 | microsoft windows_10 Windows DNS Server Remote Code Execution Vulnerability | 4,8% | — |