EN
57.924 CVE seguite
784 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.924 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2023-39191 HIGH 8.2 fedoraproject fedora An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. This may allow an attacker with CAP_BPF p 0,5%
CVE-2023-37579 HIGH 8.2 apache pulsar Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Function Worker. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. Any authenticated user can retrieve a source's configuration or a sink's configuration without aut 0,8%
CVE-2023-37536 HIGH 8.2 apache xerces-c\+\+ An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request. 1,4%
CVE-2023-36038 HIGH 8.2 microsoft asp.net_core ASP.NET Core Denial of Service Vulnerability 2,8%
CVE-2023-35335 HIGH 8.2 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0,8%
CVE-2023-33171 HIGH 8.2 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0,7%
CVE-2023-31027 HIGH 8.2 nvidia virtual_gpu NVIDIA GPU Display Driver for Windows contains a vulnerability that allows Windows users with low levels of privilege to escalate privileges when an administrator is updating GPU drivers, which may lead to escalation of privileges. 0,2%
CVE-2023-30428 HIGH 8.2 apache pulsar Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Broker's Rest Producer allows authenticated user with a custom HTTP header to produce a message to any topic using the broker's admin role. This issue affects Apache Pulsar Broke 0,8%
CVE-2023-28960 HIGH 8.2 juniper junos_os_evolved An Incorrect Permission Assignment for Critical Resource vulnerability in Juniper Networks Junos OS Evolved allows a local, authenticated low-privileged attacker to copy potentially malicious files into an existing Docker container on the local system. A follo 0,2%
CVE-2023-28714 HIGH 8.2 intel proset\/wireless_wifi Improper access control in firmware for some Intel(R) PROSet/Wireless WiFi software for Windows before version 22.220 HF (Hot Fix) may allow a privileged user to potentially enable escalation of privilege via local access. 0,2%
CVE-2023-28385 HIGH 8.2 intel next_unit_of_computing_firmware Improper authorization in the Intel(R) NUC Pro Software Suite for Windows before version 2.0.0.9 may allow a privileged user to potentially enable escalation of privilage via local access. 0,2%
CVE-2023-24892 HIGH 8.2 microsoft edge_chromium Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability 3,5%
CVE-2023-23383 HIGH 8.2 microsoft azure_service_fabric Service Fabric Explorer Spoofing Vulnerability 11,7%
CVE-2023-21806 HIGH 8.2 microsoft power_bi_report_server Power BI Report Server Spoofing Vulnerability 0,8%
CVE-2023-2110 HIGH 8.2 obsidian obsidian Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/<absolute-path>". This vulnerability can be exploited if a user opens 0,4%
CVE-2023-20869 HIGH 8.2 vmware fusion VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. 2,0%
CVE-2023-2008 HIGH 8.2 linux linux_kernel A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler. This issue occurs due to the lack of proper validation of user-supplied data, which can result in memory access past the end of an array. This may allow an attacker to escala 1,0%
CVE-2023-20063 HIGH 8.2 cisco secure_firewall_management_center A vulnerability in the inter-device communication mechanisms between devices that are running Cisco Firepower Threat Defense (FTD) Software and devices that are running Cisco Firepower Management (FMC) Software could allow an authenticated, local attacker to e 0,4%
CVE-2023-0975 HIGH 8.2 trellix agent A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace one of the Agent’s executables before it can be executed. This allows the user to elevate their permissions. 0,2%
CVE-2022-49279 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: prevent integer overflow on 32 bit systems On a 32 bit system, the "len * sizeof(*p)" operation can have an integer overflow. 0,6%
CVE-2022-46751 HIGH 8.2 apache ivy Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy prior to 2.5.2. When Apache Ivy prior to 2.5.2 parses XML file 2,0%
CVE-2022-42476 HIGH 8.2 fortinet fortios A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.11, FortiProxy version 7.2.0 through 7.2.2 and 7.0.0 through 7.0.8 allows privileged VDOM administrators to escalate their priv 0,2%
CVE-2022-42291 HIGH 8.2 nvidia geforce_experience NVIDIA GeForce Experience contains a vulnerability in the installer, where a user installing the NVIDIA GeForce Experience software may inadvertently delete data from a linked location, which may lead to data tampering. An attacker does not have explicit cont 0,2%
CVE-2022-36396 HIGH 8.2 intel aptio_v_uefi_firmware_integrator_tools Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmiEdit-Linux-5.27.06.0017 may allow a privileged user to potentially enable escalation of privilege via local access. 0,2%
CVE-2022-34321 HIGH 8.2 apache pulsar Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The vulnerable endpoint exposes detailed statistics about live connections, along with the capability to modify the 1,8%