EN
58.254 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.254 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2024-38070 HIGH 7.8 microsoft windows_10_1507 Windows LockDown Policy (WLDP) Security Feature Bypass Vulnerability 0,7% —
CVE-2024-38066 HIGH 7.8 microsoft windows_10_1507 Windows Win32k Elevation of Privilege Vulnerability 0,9% —
CVE-2024-38062 HIGH 7.8 microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability 1,6% —
CVE-2024-38059 HIGH 7.8 microsoft windows_10_21h2 Win32k Elevation of Privilege Vulnerability 3,7% —
CVE-2024-38057 HIGH 7.8 microsoft windows_10_1507 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability 0,8% —
CVE-2024-38054 HIGH 7.8 microsoft windows_10_1507 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability 10,4% —
CVE-2024-38052 HIGH 7.8 microsoft windows_10_1507 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability 7,0% —
CVE-2024-38051 HIGH 7.8 microsoft windows_10_1507 Windows Graphics Component Remote Code Execution Vulnerability 1,1% —
CVE-2024-38050 HIGH 7.8 microsoft windows_10_1507 Windows Workstation Service Elevation of Privilege Vulnerability 0,7% —
CVE-2024-38047 HIGH 7.8 microsoft windows_10_1607 PowerShell Elevation of Privilege Vulnerability 0,7% —
CVE-2024-38046 HIGH 7.8 microsoft windows_10_1507 PowerShell Elevation of Privilege Vulnerability 0,7% —
CVE-2024-38043 HIGH 7.8 microsoft windows_10_1607 PowerShell Elevation of Privilege Vulnerability 0,7% —
CVE-2024-38034 HIGH 7.8 microsoft windows_10_1507 Windows Filtering Platform Elevation of Privilege Vulnerability 0,8% —
CVE-2024-38016 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 0,6% —
CVE-2024-38014 HIGH 7.8 microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability 6,3%
CVE-2024-37391 HIGH 7.8 proton protonvpn ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in Setup/setup.iss. 0,3% —
CVE-2024-37354 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: fix crash on racing fsync and size-extending write into prealloc We have been seeing crashes on duplicate keys in btrfs_set_item_key_safe(): BTRFS critical (device vdb): slot 4 key 0,2% —
CVE-2024-37081 HIGH 7.8 vmware cloud_foundation The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance. 5,0% —
CVE-2024-37078 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential kernel bug due to lack of writeback flag waiting Destructive writes to a block device on which nilfs2 is mounted can cause a kernel bug in the folio/page writeback star 0,3% —
CVE-2024-36979 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: bridge: mst: fix vlan use-after-free syzbot reported a suspicious rcu usage[1] in bridge's mst code. While fixing it I noticed that nothing prevents a vlan to be freed while walking the 0,3% —
CVE-2024-36978 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: sched: sch_multiq: fix possible OOB write in multiq_tune() q->bands will be assigned to qopt->bands to execute subsequent code logic after kmalloc. So the old q->bands should not be use 0,3% —
CVE-2024-36977 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: Wait unconditionally after issuing EndXfer command Currently all controller IP/revisions except DWC3_usb3 >= 310a wait 1ms unconditionally for ENDXFER completion when IOC is not s 0,2% —
CVE-2024-36974 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP If one TCA_TAPRIO_ATTR_PRIOMAP attribute has been provided, taprio_parse_mqprio_opt() must validate it, or userspace can inject arb 0,3% —
CVE-2024-36972 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: af_unix: Update unix_sk(sk)->oob_skb under sk_receive_queue lock. Billy Jheng Bing-Jhong reported a race between __unix_gc() and queue_oob(). __unix_gc() tries to garbage-collect close()d i 0,5% —
CVE-2024-36971 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible UAF. RCU rules are that we must first 2,7%