57.588 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.588 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2022-41035 | MED 5.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1,4% | — |
| CVE-2022-41034 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 67,5% | — |
| CVE-2022-41032 | HIGH 7.8 | fedoraproject fedora NuGet Client Elevation of Privilege Vulnerability | 1,1% | — |
| CVE-2022-41031 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2022-40955 | HIGH 8.8 | apache inlong In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL parameters and to write arbitrary data to the MySQL database, could cause this data to be deserialized by Apache InLong, potentially leadin | 2,3% | — |
| CVE-2022-40954 | MED 5.5 | apache airflow Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Spark Provider, Apache Airflow allows an attacker to read arbtrary files in the task execution context, without write access to DAG files | 1,4% | — |
| CVE-2022-4095 | HIGH 7.8 | linux linux_kernel A use-after-free flaw was found in Linux kernel before 5.19.2. This issue occurs in cmd_hdl_filter in drivers/staging/rtl8712/rtl8712_cmd.c, allowing an attacker to launch a local denial of service attack and gain escalation of privileges. | 0,3% | — |
| CVE-2022-40768 | MED 5.5 | debian debian_linux drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case. | 0,3% | — |
| CVE-2022-40754 | MED 6.1 | apache airflow In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint. | 1,6% | — |
| CVE-2022-40753 | MED 5.4 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trus | 0,4% | — |
| CVE-2022-40752 | CRIT 9.8 | ibm infosphere_information_server IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: 236687. | 1,9% | — |
| CVE-2022-40750 | MED 5.4 | ibm websphere_application_server IBM WebSphere Application Server 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within | 0,4% | — |
| CVE-2022-40748 | MED 5.4 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust | 0,6% | — |
| CVE-2022-40747 | CRIT 9.1 | ibm infosphere_information_server "IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 236 | 1,0% | — |
| CVE-2022-40746 | HIGH 7.2 | ibm i_access_client_solutions IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability. By placing a specially crafted file in a compromised fol | 0,4% | — |
| CVE-2022-40743 | MED 6.1 | apache traffic_server Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can lead to cross site scripting and cache poisoning attacks.This issue affects Apache Traffic Server: 9.0.0 to 9.1.3. Users should upgrade to 9.1 | 1,1% | — |
| CVE-2022-40733 | MED 5.0 | microsoft windows_11_21h2 An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafte | 0,8% | — |
| CVE-2022-40732 | MED 5.0 | microsoft windows_11_21h2 An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafte | 0,8% | — |
| CVE-2022-40710 | HIGH 7.8 | trendmicro deep_security_agent A link following vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute | 0,2% | — |
| CVE-2022-40709 | LOW 3.3 | trendmicro deep_security_agent An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the abi | 0,4% | — |
| CVE-2022-40708 | LOW 3.3 | trendmicro deep_security_agent An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the abi | 0,2% | — |
| CVE-2022-40707 | LOW 3.3 | trendmicro deep_security_agent An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the abi | 0,2% | — |
| CVE-2022-40705 | HIGH 7.5 | apache soap An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files over HTTP. This issue affects Apache SOAP version 2.2 and later versions. It is unknown whether previous versio | 1,6% | — |
| CVE-2022-40683 | HIGH 7.8 | fortinet fortiweb A double free in Fortinet FortiWeb version 7.0.0 through 7.0.3 may allows attacker to execute unauthorized code or commands via specially crafted commands | 0,2% | — |
| CVE-2022-40682 | HIGH 7.8 | fortinet forticlient A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pipe. | 0,2% | — |