58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-31867 | MED 6.5 | apache zeppelin Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to | 1,2% | — |
| CVE-2024-31865 | MED 6.5 | apache zeppelin Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users ar | 1,7% | — |
| CVE-2024-31860 | MED 6.5 | apache zeppelin Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access. This issue affects Apache Zeppelin: from 0.9.0 before 0 | 1,4% | — |
| CVE-2024-31493 | MED 6.5 | fortinet fortisoar An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may allow an authenticated low privileged user to read Connector passwords in plain-tex | 0,5% | — |
| CVE-2024-31391 | MED 6.5 | apache solr_operator Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator. This issue affects all versions of the Apache Solr Operator from 0.3.0 through 0.8.0. When asked to bootstrap Solr security, the operator will enable basic authentica | 0,8% | — |
| CVE-2024-31141 | MED 6.5 | apache kafka Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accept configuration data for customizing behavior, and includes ConfigProvider plugins in order to manipulate these | 1,2% | — |
| CVE-2024-30403 | MED 6.5 | juniper junos_os_evolved A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). When Layer 2 traffic is sent through a logical interface, MAC | 0,3% | — |
| CVE-2024-30388 | MED 6.5 | juniper junos An Improper Isolation or Compartmentalization vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on QFX5000 Series and EX Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). If a specific malfo | 0,3% | — |
| CVE-2024-30387 | MED 6.5 | juniper junos A Missing Synchronization vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on ACX5448 and ACX710 allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). If an interface flaps while the system gathers st | 0,2% | — |
| CVE-2024-30380 | MED 6.5 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an adjacent unauthenticated attacker to cause a Denial of Service (DoS), which causes the l2cpd process to crash by sending a specific TLV. T | 0,3% | — |
| CVE-2024-30054 | MED 6.5 | microsoft powerbi-javascript Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability | 1,7% | — |
| CVE-2024-30053 | MED 6.5 | microsoft azure_migrate Azure Migrate Cross-Site Scripting Vulnerability | 1,0% | — |
| CVE-2024-30043 | MED 6.5 | microsoft sharepoint_server Microsoft SharePoint Server Information Disclosure Vulnerability | 56,1% | — |
| CVE-2024-30036 | MED 6.5 | microsoft windows_server_2008 Windows Deployment Services Information Disclosure Vulnerability | 2,3% | — |
| CVE-2024-30019 | MED 6.5 | microsoft windows_server_2008 DHCP Server Service Denial of Service Vulnerability | 2,6% | — |
| CVE-2024-30011 | MED 6.5 | microsoft windows_server_2012 Windows Hyper-V Denial of Service Vulnerability | 2,6% | — |
| CVE-2024-29987 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 1,2% | — |
| CVE-2024-28786 | MED 6.5 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man in the middle techniques. | 0,2% | — |
| CVE-2024-28778 | MED 6.5 | ibm cognos_controller IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys. This vulnerability allows users to publish code to private packages or repositories under the name of the organization. | 0,5% | — |
| CVE-2024-28764 | MED 6.5 | ibm websphere_automation IBM WebSphere Automation 1.7.0 could allow an attacker with privileged access to the network to conduct a CSV injection. An attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 285623. | 0,2% | — |
| CVE-2024-27439 | MED 6.5 | apache wicket An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series. Apache Wicket 8.x does not suppo | 0,7% | — |
| CVE-2024-27028 | MED 6.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: spi: spi-mt65xx: Fix NULL pointer access in interrupt handler The TX buffer in spi_transfer can be a NULL pointer, so the interrupt handler may end up writing to the invalid memory and cause | 1,2% | — |
| CVE-2024-26886 | MED 6.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: af_bluetooth: Fix deadlock Attemting to do sock_lock on .recvmsg may cause a deadlock as shown bellow, so instead of using sock_sock this uses sk_receive_queue.lock on bt_sock_ioc | 0,5% | — |
| CVE-2024-26226 | MED 6.5 | microsoft windows_server_2008 Windows Distributed File System (DFS) Information Disclosure Vulnerability | 1,8% | — |
| CVE-2024-26197 | MED 6.5 | microsoft windows_server_2012 Windows Standards-Based Storage Management Service Denial of Service Vulnerability | 2,8% | — |