imPC@ndo EN

Di 56.198 vulnerabilità, 770 le stanno sfruttando davvero.

Il punteggio CVSS dice quanto una falla è grave in teoria. Questo tracker incrocia i dati NVD con il catalogo CISA delle vulnerabilità sfruttate e con le probabilità EPSS, e mette in cima quelle che qualcuno sta usando adesso.

Sfruttate attivamente, per probabilità

aggiornato 18:16 · ogni 2 ore
CVE-2024-3400
Ransomware Critica 10.0

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbit…

paloaltonetworks pan-os
1.00EPSS
CVE-2023-4966
Ransomware Critica 9.4

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
1.00EPSS
CVE-2023-44487
Sfruttata Alta 7.5

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

akka http_server · amazon opensearch_data_prepper · apache apisix · apache solr · e altri 161
1.00EPSS
CVE-2015-1635
Sfruttata Critica 9.8

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_server_2008 · e altri 1
1.00EPSS
CVE-2014-6271
Sfruttata Critica 9.8

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature …

apple mac_os_x · arista eos · canonical ubuntu_linux · checkpoint security_gateway · e altri 70
1.00EPSS
CVE-2021-44228
Ransomware Critica 10.0

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who c…

apache log4j · apple xcode · bentley synchro · bentley synchro_4d · e altri 139
1.00EPSS
Vedi tutte le 770 → 56.198 CVE in archivio · 173 usate da ransomware