57.620 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.620 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2022-37973 | HIGH 7.7 | microsoft windows_10 Windows Local Session Manager (LSM) Denial of Service Vulnerability | 2,9% | — |
| CVE-2022-37972 | HIGH 7.5 | microsoft endpoint_configuration_manager Microsoft Endpoint Configuration Manager Spoofing Vulnerability | 1,6% | — |
| CVE-2022-37971 | HIGH 7.1 | microsoft malware_protection_engine Microsoft Windows Defender Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2022-37970 | HIGH 7.8 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 9,8% | — |
| CVE-2022-37968 | CRIT 10.0 | microsoft azure_arc-enabled_kubernetes Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allow an unauthenticated user to elevate their privileges and potentially gain administrative control over the Kub | 2,5% | — |
| CVE-2022-37967 | HIGH 7.2 | fedoraproject fedora Windows Kerberos Elevation of Privilege Vulnerability | 4,1% | — |
| CVE-2022-37966 | HIGH 8.1 | fedoraproject fedora Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability | 2,5% | — |
| CVE-2022-37965 | MED 5.9 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability | 1,5% | — |
| CVE-2022-37964 | HIGH 7.8 | microsoft windows_7 Windows Kernel Elevation of Privilege Vulnerability | 1,1% | — |
| CVE-2022-37963 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 1,1% | — |
| CVE-2022-37962 | HIGH 7.8 | microsoft 365_apps Microsoft PowerPoint Remote Code Execution Vulnerability | 1,4% | — |
| CVE-2022-37961 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 50,7% | — |
| CVE-2022-37959 | MED 6.5 | microsoft windows_server_2012 Network Device Enrollment Service (NDES) Security Feature Bypass Vulnerability | 2,4% | — |
| CVE-2022-37958 | HIGH 8.1 | microsoft windows_10 SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | 86,0% | — |
| CVE-2022-37957 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 13,6% | — |
| CVE-2022-37956 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 1,3% | — |
| CVE-2022-37955 | HIGH 7.8 | microsoft windows_10 Windows Group Policy Elevation of Privilege Vulnerability | 2,1% | — |
| CVE-2022-37954 | HIGH 7.8 | microsoft windows_10 DirectX Graphics Kernel Elevation of Privilege Vulnerability | 44,9% | — |
| CVE-2022-37866 | HIGH 7.5 | apache ivy When Apache Ivy downloads artifacts from a repository it stores them in the local file system based on a user-supplied "pattern" that may include placeholders for artifacts coordinates like the organisation, module or version. If said coordinates contain "../" | 1,7% | — |
| CVE-2022-37865 | CRIT 9.1 | apache ivy With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip packaging. For artifacts using the "zip", "jar" or "war" packaging Ivy prior to 2.5.1 doesn't verify the targe | 1,9% | — |
| CVE-2022-37771 | MED 6.7 | iobit malware_fighter IObit Malware Fighter v9.2 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator privileges to modify processes within the application and escalate privileges to SYSTEM via a crafted executable. | 0,4% | — |
| CVE-2022-37436 | MED 5.3 | apache http_server Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by t | 61,0% | — |
| CVE-2022-37435 | HIGH 8.8 | apache shenyu Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This issue affects Apache ShenYu 2.4.2 and 2.4.3. | 1,3% | — |
| CVE-2022-37426 | MED 4.3 | opennebula opennebula Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content Injection. | 0,5% | — |
| CVE-2022-37425 | CRIT 9.9 | opennebula opennebula Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion. | 1,6% | — |