56.807 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.807 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-47539 | CRIT 9.8 | fortinet fortimail An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to bypass admin login via a crafted HTTP request. | 1,0% | — |
| CVE-2023-47248 | CRIT 9.8 | apache pyarrow Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (for example user-supplied inp | 14,5% | — |
| CVE-2023-47104 | CRIT 9.8 | vareille tinyfiledialogs tinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign) in titles, messages, and other input data. NOTE: this issue exists because of an incomplete fix for CVE-2020-36767, which only considered s | 0,7% | — |
| CVE-2023-46747 | CRIT 9.8 | ransomware f5 big-ip_access_policy_manager Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have r | 96,5% | |
| CVE-2023-46302 | CRIT 9.8 | apache submarine Apache Software Foundation Apache Submarine has a bug when serializing against yaml. The bug is caused by snakeyaml https://nvd.nist.gov/vuln/detail/CVE-2022-1471 . Apache Submarine uses JAXRS to define REST endpoints. In order to handle YAML requests (usin | 1,8% | — |
| CVE-2023-46279 | CRIT 9.8 | apache dubbo Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the latest version, which fixes the issue. | 1,7% | — |
| CVE-2023-46264 | CRIT 9.8 | ivanti avalanche An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution. | 90,2% | — |
| CVE-2023-46263 | CRIT 9.8 | ivanti avalanche An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution. | 81,9% | — |
| CVE-2023-46261 | CRIT 9.8 | ivanti avalanche An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | 11,3% | — |
| CVE-2023-46260 | CRIT 9.8 | ivanti avalanche An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | 9,8% | — |
| CVE-2023-46259 | CRIT 9.8 | ivanti avalanche An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | 11,3% | — |
| CVE-2023-46258 | CRIT 9.8 | ivanti avalanche An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | 6,8% | — |
| CVE-2023-46257 | CRIT 9.8 | ivanti avalanche An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | 11,3% | — |
| CVE-2023-46226 | CRIT 9.8 | apache iotdb Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2. Users are recommended to upgrade to version 1.3.0, which fixes the issue. | 1,9% | — |
| CVE-2023-46225 | CRIT 9.8 | ivanti avalanche An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | 11,3% | — |
| CVE-2023-46224 | CRIT 9.8 | ivanti avalanche An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | 6,8% | — |
| CVE-2023-46223 | CRIT 9.8 | ivanti avalanche An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | 6,8% | — |
| CVE-2023-46222 | CRIT 9.8 | ivanti avalanche An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | 6,8% | — |
| CVE-2023-46221 | CRIT 9.8 | ivanti avalanche An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | 6,8% | — |
| CVE-2023-46220 | CRIT 9.8 | ivanti avalanche An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | 11,3% | — |
| CVE-2023-46217 | CRIT 9.8 | ivanti avalanche An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | 36,4% | — |
| CVE-2023-46216 | CRIT 9.8 | ivanti avalanche An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | 36,4% | — |
| CVE-2023-44794 | CRIT 9.8 | dromara sa-token An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL. | 1,0% | — |
| CVE-2023-44324 | CRIT 9.8 | adobe framemaker_publishing_server Adobe FrameMaker Publishing Server versions 2022 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An unauthenticated attacker can abuse this vulnerability to access the API and leak default ad | 1,4% | — |
| CVE-2023-43668 | CRIT 9.8 | apache inlong Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, some sensitive params checks will be bypassed, like "autoDeserizalize","allowLoadLocalInfile".... . Users are adv | 1,0% | — |