56.568 CVE seguite
773 Sfruttate ora
181 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.568 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2024-30051 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows DWM Core Library Elevation of Privilege Vulnerability | 5,7% | |
| CVE-2024-30040 | HIGH 8.8 | microsoft windows_10_1507 Windows MSHTML Platform Security Feature Bypass Vulnerability | 3,9% | |
| CVE-2024-29988 | HIGH 8.8 | microsoft windows_10_1809 SmartScreen Prompt Security Feature Bypass Vulnerability | 45,2% | |
| CVE-2024-20359 | MED 6.0 | cisco adaptive_security_appliance_software A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, l | 19,4% | |
| CVE-2024-20353 | HIGH 8.6 | cisco adaptive_security_appliance_software A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting i | 70,7% | |
| CVE-2022-38028 | HIGH 7.8 | microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability | 14,9% | |
| CVE-2024-3400 | CRIT 10.0 | ransomware paloaltonetworks pan-os A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbit | 100,0% | |
| CVE-2023-24955 | HIGH 7.2 | ransomware microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 85,4% | |
| CVE-2023-48788 | CRIT 9.8 | ransomware fortinet forticlient_enterprise_management_server A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted pa | 97,6% | |
| CVE-2024-21338 | HIGH 7.8 | ransomware microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability | 59,8% | |
| CVE-2023-29360 | HIGH 8.4 | microsoft windows_10_1607 Microsoft Streaming Service Elevation of Privilege Vulnerability | 22,1% | |
| CVE-2024-21410 | CRIT 9.8 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 12,7% | |
| CVE-2020-3259 | HIGH 7.5 | ransomware cisco adaptive_security_appliance_software A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could l | 69,3% | |
| CVE-2024-21412 | HIGH 8.1 | ransomware microsoft windows_10_1809 Internet Shortcut Files Security Feature Bypass Vulnerability | 95,4% | |
| CVE-2024-21351 | HIGH 7.6 | microsoft windows_10_1507 Windows SmartScreen Security Feature Bypass Vulnerability | 30,3% | |
| CVE-2024-21762 | CRIT 9.8 | ransomware fortinet fortios A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0 | 84,3% | |
| CVE-2023-4762 | HIGH 8.8 | debian debian_linux Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 38,0% | |
| CVE-2023-34048 | CRIT 9.8 | vmware vcenter_server vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution. | 99,4% | |
| CVE-2023-6549 | HIGH 8.2 | citrix netscaler_application_delivery_controller Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read | 57,6% | |
| CVE-2023-6548 | MED 5.5 | citrix netscaler_application_delivery_controller Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interf | 3,2% | |
| CVE-2023-29357 | CRIT 9.8 | ransomware microsoft sharepoint_server Microsoft SharePoint Server Elevation of Privilege Vulnerability | 99,6% | |
| CVE-2023-27524 | HIGH 8.9 | apache superset Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resourc | 97,4% | |
| CVE-2023-6345 | CRIT 9.6 | debian debian_linux Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High) | 19,5% | |
| CVE-2023-36584 | MED 5.4 | microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability | 3,1% | |
| CVE-2023-36036 | HIGH 7.8 | microsoft windows_10_1507 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 16,7% |