56.832 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.832 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-28502 | CRIT 9.8 | rocketsoftware unidata Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "udadmin" service that can lead to remote code execution as the root user. | 61,1% | — |
| CVE-2023-28501 | CRIT 9.8 | rocketsoftware unidata Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based buffer overflow in the unirpcd daemon that, if successfully exploited, can lead to remote code execution a | 1,4% | — |
| CVE-2023-28326 | CRIT 9.8 | apache openmeetings Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privileges in any room | 1,3% | — |
| CVE-2023-28250 | CRIT 9.8 | microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | 2,0% | — |
| CVE-2023-27997 | CRIT 9.8 | ransomware fortinet fortios A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, ver | 85,7% | |
| CVE-2023-27603 | CRIT 9.8 | apache linkis In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability. We recommend users upgrade the version of Linkis to version 1.3.2. | 1,8% | — |
| CVE-2023-27602 | CRIT 9.8 | apache linkis In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recommend users upgrade the version of Linkis to version 1.3.2. For versions <=1.3.1, we suggest turning on the fi | 2,0% | — |
| CVE-2023-26512 | CRIT 9.8 | apache eventmesh-connector-rabbitmq CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via rabbitmq messages. | 1,4% | — |
| CVE-2023-25754 | CRIT 9.8 | apache airflow Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0. | 2,3% | — |
| CVE-2023-25696 | CRIT 9.8 | apache apache-airflow-providers-apache-hive Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3. | 2,0% | — |
| CVE-2023-25693 | CRIT 9.8 | apache apache-airflow-providers-apache-sqoop Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1. | 1,9% | — |
| CVE-2023-25691 | CRIT 9.8 | apache apache-airflow-providers-google Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0. | 1,6% | — |
| CVE-2023-25690 | CRIT 9.8 | apache http_server Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pa | 84,5% | — |
| CVE-2023-25613 | CRIT 9.8 | apache kerby_ldap_backend An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3. | 1,5% | — |
| CVE-2023-25610 | CRIT 9.8 | fortinet fortianalyzer A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2 | 18,2% | — |
| CVE-2023-25143 | CRIT 9.8 | trendmicro apex_one An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote code execution state on affected products. | 1,7% | — |
| CVE-2023-24997 | CRIT 9.8 | apache inlong Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inl | 1,4% | — |
| CVE-2023-24943 | CRIT 9.8 | microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | 4,7% | — |
| CVE-2023-24941 | CRIT 9.8 | microsoft windows_server_2012 Windows Network File System Remote Code Execution Vulnerability | 94,7% | — |
| CVE-2023-24831 | CRIT 9.8 | apache iotdb Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 through 0.13.3. Attackers could login without authorization. This is fixed in 0.13.4. | 1,2% | — |
| CVE-2023-24489 | CRIT 9.8 | citrix sharefile_storage_zones_controller A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller. | 97,3% | |
| CVE-2023-23415 | CRIT 9.8 | microsoft windows_10_1507 Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability | 3,5% | — |
| CVE-2023-23397 | CRIT 9.8 | microsoft 365_apps Microsoft Outlook Elevation of Privilege Vulnerability | 97,4% | |
| CVE-2023-23392 | CRIT 9.8 | microsoft windows_11_21h2 HTTP Protocol Stack Remote Code Execution Vulnerability | 1,7% | — |
| CVE-2023-22884 | CRIT 9.8 | apache airflow Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1; Apache Air | 11,1% | — |