EN
57.808 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.808 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2022-30129 HIGH 8.8 microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability 41,3%
CVE-2022-30128 HIGH 8.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1,8%
CVE-2022-30127 HIGH 8.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1,8%
CVE-2022-30126 MED 5.5 apache tika In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtracting 2,6%
CVE-2022-30055 CRIT 9.8 mersenne prime95 Prime95 30.7 build 9 suffers from a Buffer Overflow vulnerability that could lead to Remote Code Execution. 3,9%
CVE-2022-29968 HIGH 7.8 fedoraproject fedora An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private. 1,1%
CVE-2022-2991 MED 6.7 linux linux_kernel A heap-based buffer overflow was found in the Linux kernel's LightNVM subsystem. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. This vulnerability allows a local 0,4%
CVE-2022-29901 MED 5.6 debian debian_linux Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary 4,8%
CVE-2022-29885 HIGH 7.5 apache tomcat The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the 73,5%
CVE-2022-29839 MED 4.1 westerndigital my_cloud_os Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker who has gained access to a relevant endpoint to use that information to access protected data. This issue affe 0,1%
CVE-2022-29804 HIGH 7.5 golang go Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack. 2,1%
CVE-2022-29800 MED 4.7 microsoft windows_defender_for_endpoint A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being discovered and them being run. An attacker can abuse this vulnerability to replace sc 7,2%
CVE-2022-29799 MED 5.5 microsoft windows_defender_for_endpoint A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeState of networkd-dispatcher. This attack leads to a directory traversal to escape from the “/etc/networkd-dispat 11,8%
CVE-2022-2978 HIGH 7.8 debian debian_linux A flaw use after free in the Linux kernel NILFS file system was found in the way user triggers function security_inode_alloc to fail with following call to function nilfs_mdt_destroy. A local user could use this flaw to crash the system or potentially escalate 0,2%
CVE-2022-2977 HIGH 7.8 linux linux_kernel A flaw was found in the Linux kernel implementation of proxied virtualized TPM devices. On a system where virtualized TPM devices are configured (this is not the default) a local attacker can create a use-after-free and create a situation where it may be possi 0,2%
CVE-2022-2964 HIGH 7.8 linux linux_kernel A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability contains multiple out-of-bounds reads and possible out-of-bounds writes. 0,3%
CVE-2022-2961 HIGH 7.0 fedoraproject fedora A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition by calling bind while simultaneously triggering the rose_bind() function. This flaw allows a local user to crash or potentially escalate th 0,3%
CVE-2022-29599 CRIT 9.8 apache maven_shared_utils In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks. 4,4%
CVE-2022-29594 HIGH 7.8 eginnovations eg_agent eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM. 0,3%
CVE-2022-2959 HIGH 7.0 linux linux_kernel A race condition was found in the Linux kernel's watch queue due to a missing lock in pipe_resize_ring(). The specific flaw exists within the handling of pipe buffers. The issue results from the lack of proper locking when performing operations on an object. T 0,4%
CVE-2022-29583 HIGH 7.8 service_project service service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Windows service executable from the intended directory. NOTE: this finding could not be reproduced by its original reporter or by others. 0,3%
CVE-2022-29582 HIGH 7.0 debian debian_linux In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequ 0,8%
CVE-2022-29581 HIGH 7.8 canonical ubuntu_linux Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions. 0,9%
CVE-2022-29526 MED 5.3 fedoraproject fedora Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible. 3,0%
CVE-2022-29491 HIGH 7.5 f5 big-ip_access_policy_manager On F5 BIG-IP LTM, Advanced WAF, ASM, or APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a virtual server is configured with HTTP, TCP on one side (c 0,9%