56.855 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.855 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-31656 | CRIT 9.8 | vmware access_connector VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to a | 22,9% | — |
| CVE-2022-30136 | CRIT 9.8 | microsoft windows_server_2012 Windows Network File System Remote Code Execution Vulnerability | 74,7% | — |
| CVE-2022-30133 | CRIT 9.8 | microsoft windows_10 Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability | 2,7% | — |
| CVE-2022-30055 | CRIT 9.8 | mersenne prime95 Prime95 30.7 build 9 suffers from a Buffer Overflow vulnerability that could lead to Remote Code Execution. | 3,9% | — |
| CVE-2022-29599 | CRIT 9.8 | apache maven_shared_utils In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks. | 4,4% | — |
| CVE-2022-29379 | CRIT 9.8 | f5 njs Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/njs_module.c. NOTE: multiple third parties dispute this report, e.g., the behavior is only found in unreleased development code that was not p | 1,8% | — |
| CVE-2022-29130 | CRIT 9.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 3,8% | — |
| CVE-2022-29063 | CRIT 9.8 | apache ofbiz The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or | 3,9% | — |
| CVE-2022-28890 | CRIT 9.8 | apache jena A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities. | 2,5% | — |
| CVE-2022-28331 | CRIT 9.8 | apache portable_runtime On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of integer overflow. | 1,6% | — |
| CVE-2022-28054 | CRIT 9.8 | vandyke vshell Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted value. | 31,2% | — |
| CVE-2022-2778 | CRIT 9.8 | octopus octopus_server In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes. | 0,7% | — |
| CVE-2022-27518 | CRIT 9.8 | citrix application_delivery_controller_firmware Unauthenticated remote arbitrary code execution | 6,9% | |
| CVE-2022-27510 | CRIT 9.8 | citrix application_delivery_controller_firmware Unauthorized access to Gateway user capabilities | 1,2% | — |
| CVE-2022-27479 | CRIT 9.8 | apache superset Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue. | 2,9% | — |
| CVE-2022-27115 | CRIT 9.8 | std42 elfinder In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload. | 28,6% | — |
| CVE-2022-27007 | CRIT 9.8 | f5 njs nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_function_frame_save(). | 1,6% | — |
| CVE-2022-26937 | CRIT 9.8 | microsoft windows_server Windows Network File System Remote Code Execution Vulnerability | 76,5% | — |
| CVE-2022-26809 | CRIT 9.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 91,0% | — |
| CVE-2022-26612 | CRIT 9.8 | apache hadoop In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR entry may create a symlink under the expected extraction directory which points to an external directory. A sub | 4,2% | — |
| CVE-2022-26184 | CRIT 9.8 | python-poetry poetry Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs when the application | 1,9% | — |
| CVE-2022-26112 | CRIT 9.8 | apache pinot In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support. In order to avoid this, we disabled the groovy function support by default from Pin | 1,4% | — |
| CVE-2022-25757 | CRIT 9.8 | apache apisix In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSON with a duplicate key, the attacker can bypass the body_schema validation in the request-validation plugin. Fo | 2,5% | — |
| CVE-2022-25371 | CRIT 9.8 | apache ofbiz Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142) it is possible to perform a remote code execution | 4,2% | — |
| CVE-2022-25330 | CRIT 9.8 | trendmicro serverprotect Integer overflow conditions that exist in Trend Micro ServerProtect 6.0/5.8 Information Server could allow a remote attacker to crash the process or achieve remote code execution. | 5,2% | — |