EN
58.290 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.290 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2023-3181 HIGH 7.8 splashtop mirroring360_receiver The C:\Program Files (x86)\Splashtop\Splashtop Software Updater\uninst.exe process creates a folder at C:\Windows\Temp~nsu.tmp and copies itself to it as Au_.exe. The C:\Windows\Temp~nsu.tmp\Au_.exe file is automatically launched as SYSTEM when the system rebo 0,2% —
CVE-2023-31436 HIGH 7.8 linux linux_kernel qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed QFQ_MIN_LMAX. 0,6% —
CVE-2023-31248 HIGH 7.8 canonical ubuntu_linux Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace 2,1% —
CVE-2023-31132 HIGH 7.8 cacti cacti Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a privilege escalation vulnerability. A low-privileged OS user with access to a Windows host where Cacti is installed can create arbitrary PHP files 0,4% —
CVE-2023-3111 HIGH 7.8 debian debian_linux A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defrag(). 0,4% —
CVE-2023-31102 HIGH 7.8 7-zip 7-zip Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive. 57,1% —
CVE-2023-31019 HIGH 7.8 nvidia virtual_gpu NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation does not restrict or incorrectly restricts access from the named pipe server to a connecting client, which may lead to potential impersonati 0,2% —
CVE-2023-31017 HIGH 7.8 nvidia virtual_gpu NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may be able to write arbitrary data to privileged locations by using reparse points. A successful exploit of this vulnerability may lead to code execution, denial of service, esca 0,2% —
CVE-2023-3090 HIGH 7.8 debian debian_linux A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation. The out-of-bounds write is caused by missing skb->cb initialization in the ipvlan network driver. The vulnerability is 0,5% —
CVE-2023-30601 HIGH 7.8 apache cassandra Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra This issue affects Apache Cassandra: from 4.0.0 through 4.0.9, from 4.1.0 through 4.1.1. WORKAROUND The vulnerability 0,3% —
CVE-2023-2939 HIGH 7.8 google chrome Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to perform privilege escalation via crafted symbolic link. (Chromium security severity: Medium) 0,5% —
CVE-2023-29371 HIGH 7.8 microsoft windows_10_1507 Windows GDI Elevation of Privilege Vulnerability 5,4% —
CVE-2023-29370 HIGH 7.8 microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability 0,7% —
CVE-2023-29367 HIGH 7.8 microsoft windows_server_2012 iSCSI Target WMI Provider Remote Code Execution Vulnerability 0,7% —
CVE-2023-29366 HIGH 7.8 microsoft windows_10_21h2 Windows Geolocation Service Remote Code Execution Vulnerability 0,7% —
CVE-2023-29365 HIGH 7.8 microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability 0,7% —
CVE-2023-29359 HIGH 7.8 microsoft windows_10_1507 GDI Elevation of Privilege Vulnerability 0,5% —
CVE-2023-29358 HIGH 7.8 microsoft windows_10_1507 Windows GDI Elevation of Privilege Vulnerability 4,7% —
CVE-2023-29356 HIGH 7.8 microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability 0,6% —
CVE-2023-29349 HIGH 7.8 microsoft odbc_driver_for_sql_server Microsoft ODBC and OLE DB Remote Code Execution Vulnerability 0,6% —
CVE-2023-29346 HIGH 7.8 microsoft windows_10_1507 NTFS Elevation of Privilege Vulnerability 0,5% —
CVE-2023-29344 HIGH 7.8 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 0,9% —
CVE-2023-29343 HIGH 7.8 microsoft windows_sysmon SysInternals Sysmon for Windows Elevation of Privilege Vulnerability 1,7% —
CVE-2023-29341 HIGH 7.8 microsoft av1_video_extension AV1 Video Extension Remote Code Execution Vulnerability 0,7% —
CVE-2023-29340 HIGH 7.8 microsoft av1_video_extension AV1 Video Extension Remote Code Execution Vulnerability 0,7% —