57.808 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.808 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2022-29480 | MED 5.3 | f5 big-ip_access_policy_manager On F5 BIG-IP 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when multiple route domains are configured, undisclosed requests to big3d can cause an increase in CPU resource utilization. Note: Software versions which have reached End of | 0,9% | — |
| CVE-2022-29479 | MED 5.3 | f5 big-ip_access_policy_manager On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, and F5 BIG-IQ Centralized Management all versions of 8.x and 7.x, when an IPv6 self IP address is configu | 0,9% | — |
| CVE-2022-29474 | MED 4.3 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, a directory traversal vulnerability exists in iControl SOAP that allow | 1,5% | — |
| CVE-2022-29473 | MED 5.9 | f5 big-ip_access_policy_manager On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when an IPSec ALG profile is configured on a virtual server, undisclosed responses can cause Traffic Management Microkernel(TMM) to terminat | 0,8% | — |
| CVE-2022-29405 | MED 6.5 | apache archiva In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8 | 1,7% | — |
| CVE-2022-29404 | HIGH 7.5 | apache http_server In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size. | 6,4% | — |
| CVE-2022-2938 | HIGH 7.8 | fedoraproject fedora A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the feature is disabled by default, it could allow an attacker to crash the system or have other memory-corruption side effects. | 0,3% | — |
| CVE-2022-29379 | CRIT 9.8 | f5 njs Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/njs_module.c. NOTE: multiple third parties dispute this report, e.g., the behavior is only found in unreleased development code that was not p | 1,8% | — |
| CVE-2022-29376 | HIGH 8.8 | apachefriends xampp Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory. | 1,3% | — |
| CVE-2022-29369 | HIGH 7.5 | f5 njs Nginx NJS v0.7.2 was discovered to contain a segmentation violation via njs_lvlhsh_bucket_find at njs_lvlhsh.c. | 1,2% | — |
| CVE-2022-29266 | HIGH 7.5 | apache apisix In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information. | 8,1% | — |
| CVE-2022-29265 | HIGH 7.5 | apache nifi Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to resolve XML External Entity references when viewing formatted XML files. The followi | 2,6% | — |
| CVE-2022-29263 | HIGH 7.8 | f5 access_policy_manager_clients On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, as well as F5 BIG-IP APM Clients 7.x versions prior to 7.2.1.5, th | 0,2% | — |
| CVE-2022-29158 | HIGH 7.5 | apache ofbiz Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, unauthenticated users. Upgrade to 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12599 | 2,0% | — |
| CVE-2022-29156 | HIGH 7.8 | linux linux_kernel drivers/infiniband/ulp/rtrs/rtrs-clt.c in the Linux kernel before 5.16.12 has a double free related to rtrs_clt_dev_release. | 0,4% | — |
| CVE-2022-29151 | HIGH 7.0 | microsoft windows_server Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2022-29150 | HIGH 7.0 | microsoft windows_server Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2022-29149 | HIGH 7.8 | microsoft azure_automation_state_configuration Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2022-29148 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability | 2,8% | — |
| CVE-2022-29147 | LOW 3.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0,6% | — |
| CVE-2022-29146 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1,0% | — |
| CVE-2022-29145 | HIGH 7.5 | fedoraproject fedora .NET and Visual Studio Denial of Service Vulnerability | 5,1% | — |
| CVE-2022-29144 | HIGH 7.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1,0% | — |
| CVE-2022-29143 | HIGH 7.5 | microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2022-29142 | HIGH 7.0 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 5,1% | — |