57.551 CVE seguite
782 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.551 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2022-4696 | HIGH 7.8 | linux linux_kernel There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag, which signals that the operation won't use current->nsproxy, so its reference counter | 0,4% | — |
| CVE-2022-46907 | MED 6.1 | apache jspwiki A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users | 1,2% | — |
| CVE-2022-46872 | HIGH 8.6 | mozilla firefox An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br>*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability aff | 0,8% | — |
| CVE-2022-46870 | MED 5.4 | apache zeppelin An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin allows logged-in users to execute arbitrary javascript in other users' browsers. This issue affects Apache Zeppelin before 0.8.2. Users are | 1,1% | — |
| CVE-2022-46869 | HIGH 7.8 | acronis cyber_protect_home_office Local privilege escalation during installation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40278, Acronis True Image OEM (Windows) before build 42575. | 0,2% | — |
| CVE-2022-46868 | HIGH 7.8 | acronis cyber_protect_home_office Local privilege escalation during recovery due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40173. | 0,2% | — |
| CVE-2022-46769 | MED 5.4 | apache sling_cms An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.2 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in the s | 1,4% | — |
| CVE-2022-46764 | CRIT 9.8 | trueconf server A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution. | 2,1% | — |
| CVE-2022-46763 | HIGH 8.8 | trueconf server A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code. | 1,0% | — |
| CVE-2022-46751 | HIGH 8.2 | apache ivy Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy prior to 2.5.2. When Apache Ivy prior to 2.5.2 parses XML file | 2,0% | — |
| CVE-2022-46651 | MED 6.5 | apache airflow Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Connection edit view. This vulnerability is considered low since it requires someone with access to Connection re | 1,2% | — |
| CVE-2022-46647 | LOW 2.2 | intel unison_software Insertion of sensitive information into log file for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access. | 0,2% | — |
| CVE-2022-46646 | LOW 2.2 | intel unison_software Exposure of sensitive information to an unauthorized actor for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access. | 0,2% | — |
| CVE-2022-4662 | MED 5.5 | linux linux_kernel A flaw incorrect access control in the Linux kernel USB core subsystem was found in the way user attaches usb device. A local user could use this flaw to crash the system. | 0,3% | — |
| CVE-2022-46421 | CRIT 9.8 | apache apache-airflow-providers-apache-hive Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0. | 3,2% | — |
| CVE-2022-46366 | CRIT 9.8 | apache tapestry Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability only affects Apache T | 3,6% | — |
| CVE-2022-46365 | CRIT 9.1 | apache streampark Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a parameter, but not verified whether the user name is the currently logged user and whether the user is legal, T | 1,5% | — |
| CVE-2022-46364 | CRIT 9.8 | apache cxf A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. | 2,4% | — |
| CVE-2022-46363 | HIGH 7.5 | apache cxf A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vulnerability only applies when the CXFServlet is configured with both the static-resources-list and redirect-quer | 1,2% | — |
| CVE-2022-46337 | CRIT 9.8 | apache derby A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this could let an attacker fill up the disk by creating junk Derby databases. In LDAP-authenticated Derby installations, this could also allow th | 1,4% | — |
| CVE-2022-46301 | LOW 1.9 | intel unison_software Improper Initialization for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access. | 0,2% | — |
| CVE-2022-46299 | LOW 3.3 | intel unison_software Insufficient control flow management for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access. | 0,2% | — |
| CVE-2022-46298 | LOW 1.9 | intel unison_software Incomplete cleanup for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access. | 0,2% | — |
| CVE-2022-45935 | MED 5.5 | apache james Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to access private user data in transit. Vulnerable components includes the SMTP stack and IMAP APPEND command. This issue affects Apache James | 0,4% | — |
| CVE-2022-45934 | HIGH 7.8 | debian debian_linux An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets. | 0,7% | — |