EN
58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.507 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più basso Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2022-43869 MED 6.5 ibm elastic_storage_system IBM Spectrum Scale (5.1.0.0 through 5.1.2.8 and 5.1.3.0 through 5.1.5.1) and IBM Elastic Storage System (6.1.0.0 through 6.1.2.4 and 6.1.3.0 through 6.1.4.1) could allow an authenticated user to cause a denial of service through the GUI using a format string a 1,0% —
CVE-2022-43516 MED 6.5 microsoft windows_firewall A Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in Windows Firewall after Zabbix agent installation (MSI) 0,9% —
CVE-2022-42474 MED 6.5 fortinet fortios A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.12, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiSwitchManager version 7.2.0 through 7.2.1 and 0,6% —
CVE-2022-42343 MED 6.5 adobe campaign Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the application to make arbitr 1,4% —
CVE-2022-4187 MED 6.5 google chrome Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 108.0.5359.71 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium) 0,7% —
CVE-2022-41813 MED 6.5 f5 big-ip_advanced_firewall_manager In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when BIG-IP is provisioned with PEM or AFM module, an undisclosed input can cause Traffic Management Microkernel (TMM) to terminate. 0,6% —
CVE-2022-41770 MED 6.5 f5 big-ip_access_policy_manager In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ all versions of 8.x and 7.x, an authenticated iControl REST user can cause an increase in memory resource ut 0,6% —
CVE-2022-41553 MED 6.5 hitachi infrastructure_analytics_advisor Insertion of Sensitive Information into Temporary File vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer probe component) allows local users to gain 0,2% —
CVE-2022-41294 MED 6.5 ibm robotic_process_automation IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api. IBM X-Force ID: 236807. 0,3% —
CVE-2022-41291 MED 6.5 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 236699. 0,4% —
CVE-2022-41122 MED 6.5 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 1,6% —
CVE-2022-41097 MED 6.5 microsoft windows_10 Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability 1,6% —
CVE-2022-40675 MED 6.5 fortinet fortinac Some cryptographic issues in Fortinet FortiNAC versions 9.4.0 through 9.4.1, 9.2.0 through 9.2.7, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an attacker to decrypt and forge protoco 0,4% —
CVE-2022-40235 MED 6.5 ibm infosphere_information_server "IBM InfoSphere Information Server 11.7 could allow a user to cause a denial of service by removing the ability to run jobs due to improper input validation. IBM X-Force ID: 235725." 0,7% —
CVE-2022-40160 MED 6.5 apache commons_jxpath ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocation. The CVE was then 1,3% —
CVE-2022-40159 MED 6.5 apache commons_jxpath ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocation. The CVE was then 1,3% —
CVE-2022-38033 MED 6.5 microsoft windows_10 Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability 1,7% —
CVE-2022-38015 MED 6.5 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 0,7% —
CVE-2022-38006 MED 6.5 microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability 2,3% —
CVE-2022-38001 MED 6.5 microsoft 365_apps Microsoft Office Spoofing Vulnerability 1,6% —
CVE-2022-37977 MED 6.5 microsoft windows_10 Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability 1,9% —
CVE-2022-37974 MED 6.5 microsoft windows_10 Windows Mixed Reality Developer Tools Information Disclosure Vulnerability 36,3% —
CVE-2022-37959 MED 6.5 microsoft windows_server_2012 Network Device Enrollment Service (NDES) Security Feature Bypass Vulnerability 2,4% —
CVE-2022-37424 MED 6.5 opennebula opennebula Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery. 0,8% —
CVE-2022-37023 MED 6.5 apache geode Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on Java 8 or Java 11. Any user wishing to protect against deserialization attacks involving REST APIs should upgrade to Apache Geode 1.15 and f 1,7% —