Di 56.198 vulnerabilità, 770 le stanno sfruttando davvero.
Il punteggio CVSS dice quanto una falla è grave in teoria. Questo tracker incrocia i dati NVD con il catalogo CISA delle vulnerabilità sfruttate e con le probabilità EPSS, e mette in cima quelle che qualcuno sta usando adesso.
Sfruttate attivamente, per probabilità
aggiornato 18:16 · ogni 2 oreA command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbit…
paloaltonetworks pan-osSensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
citrix netscaler_application_delivery_controller · citrix netscaler_gatewayThe HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
akka http_server · amazon opensearch_data_prepper · apache apisix · apache solr · e altri 161HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."
microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_server_2008 · e altri 1GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature …
apple mac_os_x · arista eos · canonical ubuntu_linux · checkpoint security_gateway · e altri 70Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who c…
apache log4j · apple xcode · bentley synchro · bentley synchro_4d · e altri 139