57.924 CVE seguite
784 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.924 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-39191 | HIGH 8.2 | fedoraproject fedora An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. This may allow an attacker with CAP_BPF p | 0,5% | — |
| CVE-2023-37579 | HIGH 8.2 | apache pulsar Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Function Worker. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. Any authenticated user can retrieve a source's configuration or a sink's configuration without aut | 0,8% | — |
| CVE-2023-37536 | HIGH 8.2 | apache xerces-c\+\+ An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request. | 1,4% | — |
| CVE-2023-36038 | HIGH 8.2 | microsoft asp.net_core ASP.NET Core Denial of Service Vulnerability | 2,8% | — |
| CVE-2023-35335 | HIGH 8.2 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0,8% | — |
| CVE-2023-33171 | HIGH 8.2 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0,7% | — |
| CVE-2023-31027 | HIGH 8.2 | nvidia virtual_gpu NVIDIA GPU Display Driver for Windows contains a vulnerability that allows Windows users with low levels of privilege to escalate privileges when an administrator is updating GPU drivers, which may lead to escalation of privileges. | 0,2% | — |
| CVE-2023-30428 | HIGH 8.2 | apache pulsar Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Broker's Rest Producer allows authenticated user with a custom HTTP header to produce a message to any topic using the broker's admin role. This issue affects Apache Pulsar Broke | 0,8% | — |
| CVE-2023-28960 | HIGH 8.2 | juniper junos_os_evolved An Incorrect Permission Assignment for Critical Resource vulnerability in Juniper Networks Junos OS Evolved allows a local, authenticated low-privileged attacker to copy potentially malicious files into an existing Docker container on the local system. A follo | 0,2% | — |
| CVE-2023-28714 | HIGH 8.2 | intel proset\/wireless_wifi Improper access control in firmware for some Intel(R) PROSet/Wireless WiFi software for Windows before version 22.220 HF (Hot Fix) may allow a privileged user to potentially enable escalation of privilege via local access. | 0,2% | — |
| CVE-2023-28385 | HIGH 8.2 | intel next_unit_of_computing_firmware Improper authorization in the Intel(R) NUC Pro Software Suite for Windows before version 2.0.0.9 may allow a privileged user to potentially enable escalation of privilage via local access. | 0,2% | — |
| CVE-2023-24892 | HIGH 8.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability | 3,5% | — |
| CVE-2023-23383 | HIGH 8.2 | microsoft azure_service_fabric Service Fabric Explorer Spoofing Vulnerability | 11,7% | — |
| CVE-2023-21806 | HIGH 8.2 | microsoft power_bi_report_server Power BI Report Server Spoofing Vulnerability | 0,8% | — |
| CVE-2023-2110 | HIGH 8.2 | obsidian obsidian Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/<absolute-path>". This vulnerability can be exploited if a user opens | 0,4% | — |
| CVE-2023-20869 | HIGH 8.2 | vmware fusion VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. | 2,0% | — |
| CVE-2023-2008 | HIGH 8.2 | linux linux_kernel A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler. This issue occurs due to the lack of proper validation of user-supplied data, which can result in memory access past the end of an array. This may allow an attacker to escala | 1,0% | — |
| CVE-2023-20063 | HIGH 8.2 | cisco secure_firewall_management_center A vulnerability in the inter-device communication mechanisms between devices that are running Cisco Firepower Threat Defense (FTD) Software and devices that are running Cisco Firepower Management (FMC) Software could allow an authenticated, local attacker to e | 0,4% | — |
| CVE-2023-0975 | HIGH 8.2 | trellix agent A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace one of the Agent’s executables before it can be executed. This allows the user to elevate their permissions. | 0,2% | — |
| CVE-2022-49279 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: prevent integer overflow on 32 bit systems On a 32 bit system, the "len * sizeof(*p)" operation can have an integer overflow. | 0,6% | — |
| CVE-2022-46751 | HIGH 8.2 | apache ivy Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy prior to 2.5.2. When Apache Ivy prior to 2.5.2 parses XML file | 2,0% | — |
| CVE-2022-42476 | HIGH 8.2 | fortinet fortios A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.11, FortiProxy version 7.2.0 through 7.2.2 and 7.0.0 through 7.0.8 allows privileged VDOM administrators to escalate their priv | 0,2% | — |
| CVE-2022-42291 | HIGH 8.2 | nvidia geforce_experience NVIDIA GeForce Experience contains a vulnerability in the installer, where a user installing the NVIDIA GeForce Experience software may inadvertently delete data from a linked location, which may lead to data tampering. An attacker does not have explicit cont | 0,2% | — |
| CVE-2022-36396 | HIGH 8.2 | intel aptio_v_uefi_firmware_integrator_tools Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmiEdit-Linux-5.27.06.0017 may allow a privileged user to potentially enable escalation of privilege via local access. | 0,2% | — |
| CVE-2022-34321 | HIGH 8.2 | apache pulsar Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The vulnerable endpoint exposes detailed statistics about live connections, along with the capability to modify the | 1,8% | — |