57.551 CVE seguite
782 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.551 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2022-45135 | CRIT 9.8 | apache cocoon Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue. | 1,1% | — |
| CVE-2022-45109 | LOW 3.3 | intel unison_software Improper initialization for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access. | 0,2% | — |
| CVE-2022-4510 | HIGH 7.8 | microsoft binwalk A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By crafting a malicious PFS filesystem file, an attacker can get binwalk's PFS extractor to extract files at arbitrary locations when binwalk is ru | 22,0% | — |
| CVE-2022-45064 | HIGH 8.0 | apache apache_sling_engine The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-based cross-site scripting issues on the Apache Sling level. The vulnerability is exploitable by an attacker that is able to include a resou | 1,1% | — |
| CVE-2022-45052 | HIGH 8.8 | axiell iguana A Local File Inclusion vulnerability has been found in Axiell Iguana CMS. Due to insufficient neutralisation of user input on the url parameter on the Proxy.type.php endpoint, external users are capable of accessing files on the server. | 0,7% | — |
| CVE-2022-45051 | MED 6.1 | axiell iguana A reflected XSS vulnerability has been found in Axiell Iguana CMS, allowing an attacker to execute code in a victim's browser. The module parameter on the Service.template.cls endpoint does not properly neutralise user input, resulting in the vulnerability. | 0,4% | — |
| CVE-2022-45049 | MED 6.1 | axiell iguana A reflected XSS vulnerability has been found in Axiell Iguana CMS, allowing an attacker to execute code in a victim's browser. The url parameter on the novelist.php endpoint does not properly neutralise user input, resulting in the vulnerability. | 0,4% | — |
| CVE-2022-45048 | HIGH 8.4 | apache ranger Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0. | 1,1% | — |
| CVE-2022-45047 | CRIT 9.8 | apache sshd Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apache MINA SSHD | 3,6% | — |
| CVE-2022-44730 | MED 4.4 | apache xml_graphics_batik Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. A malicious SVG can probe user profile / data and send it directly as parameter to a URL. | 0,9% | — |
| CVE-2022-44729 | HIGH 7.1 | apache xml_graphics_batik Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource | 0,9% | — |
| CVE-2022-44713 | HIGH 7.5 | microsoft office Microsoft Outlook for Mac Spoofing Vulnerability | 1,5% | — |
| CVE-2022-44710 | HIGH 7.8 | microsoft windows_11 DirectX Graphics Kernel Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2022-44708 | HIGH 8.3 | microsoft edge Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1,9% | — |
| CVE-2022-44707 | MED 6.5 | microsoft windows_10 Windows Kernel Denial of Service Vulnerability | 2,5% | — |
| CVE-2022-44704 | HIGH 7.8 | microsoft windows_sysmon Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-44702 | HIGH 7.8 | microsoft terminal Windows Terminal Remote Code Execution Vulnerability | 1,4% | — |
| CVE-2022-44699 | MED 5.5 | microsoft azure_network_watcher_agent Azure Network Watcher Agent Security Feature Bypass Vulnerability | 0,4% | — |
| CVE-2022-44697 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2022-44696 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2022-44695 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2022-44694 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2022-44693 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2022-44692 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2022-44691 | HIGH 7.8 | microsoft 365_apps Microsoft Office OneNote Remote Code Execution Vulnerability | 0,9% | — |