EN
58.450 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.450 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più basso Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2024-1883 MED 6.3 papercut papercut_mf This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL that contains a script. When an unsuspecting user clicks on this malicious link, it could potenti 61,5% —
CVE-2024-0129 MED 6.3 nvidia nemo NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extraction. A successful exploit of this vulnerability may lead to code execution and data tampering. 0,2% —
CVE-2024-0085 MED 6.3 nvidia cloud_gaming NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged operations on the host. A successful exploit of this vulnerability might lead to data tampering, escalation of privileges, and denial of servi 0,1% —
CVE-2024-0009 MED 6.3 paloaltonetworks pan-os An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address. 0,2% —
CVE-2023-52644 MED 6.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: wifi: b43: Stop/wake correct queue in DMA Tx path when QoS is disabled When QoS is disabled, the queue priority value will not map to the correct ieee80211 queue since there is only one queu 0,2% —
CVE-2023-52581 MED 6.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix memleak when more than 255 elements expired When more than 255 elements expired we're supposed to switch to a new gc container structure. This never happens: u8 ty 0,3% —
CVE-2023-40791 MED 6.3 linux linux_kernel extract_user_to_sg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails to unpin pages in a certain situation, as demonstrated by a WARNING for try_grab_page. 0,4% —
CVE-2023-40610 MED 6.3 apache superset Improper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the default examples database connection that allows access to both the examples schema and Apache Superset's metadata database, an attacker usin 1,3% —
CVE-2023-36888 MED 6.3 microsoft edge_chromium Microsoft Edge for Android (Chromium-based) Tampering Vulnerability 0,6% —
CVE-2023-36869 MED 6.3 microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability 0,7% —
CVE-2023-33156 MED 6.3 microsoft malware_protection_engine Microsoft Defender Elevation of Privilege Vulnerability 0,3% —
CVE-2023-33132 MED 6.3 microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability 0,9% —
CVE-2023-2971 MED 6.3 typora typora Improper path handling in Typora before 1.7.0-dev on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/typemark/". This vulnerability can be exploited if a user opens a malicious markdo 0,5% —
CVE-2023-28071 MED 6.3 dell alienware_update Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folde 0,2% —
CVE-2023-27869 MED 6.3 ibm db2 IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked logger injection. By sending a specially crafted request using the named tr 1,6% —
CVE-2023-27868 MED 6.3 ibm db2 IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked class instantiation when providing plugin classes. By sending a specially c 1,6% —
CVE-2023-27867 MED 6.3 ibm db2 IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code via JNDI Injection. By sending a specially crafted request using the property clientRerouteServerListJNDIName, an 1,6% —
CVE-2023-25197 MED 6.3 apache fineract Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation apache fineract. Authorized users may be able to exploit this for limited impact on components.   This issue affects apache finera 1,1% —
CVE-2023-24490 MED 6.3 citrix linux_virtual_delivery_agent Users with only access to launch VDA applications can launch an unauthorized desktop 0,3% —
CVE-2023-24487 MED 6.3 citrix application_delivery_controller Arbitrary file read in Citrix ADC and Citrix Gateway  1,1% —
CVE-2023-23389 MED 6.3 microsoft malware_protection_engine Microsoft Defender Elevation of Privilege Vulnerability 0,3% —
CVE-2023-21725 MED 6.3 microsoft windows_malicious_software_removal_tool Windows Malicious Software Removal Tool Elevation of Privilege Vulnerability 0,4% —
CVE-2023-20862 MED 6.3 netapp active_iq_unified_manager In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly sa 0,6% —
CVE-2023-20274 MED 6.3 cisco appdynamics A vulnerability in the installer script of Cisco AppDynamics PHP Agent could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient permissions that are set by the PHP Agent Installer on 0,2% —
CVE-2023-20123 MED 6.3 cisco duo A vulnerability in the offline access mode of Cisco Duo Two-Factor Authentication for macOS and Duo Authentication for Windows Logon and RDP could allow an unauthenticated, physical attacker to replay valid user session credentials and gain unauthorized access 0,2% —