EN
57.811 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.811 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2022-29116 MED 4.7 microsoft windows_11 Windows Kernel Information Disclosure Vulnerability 0,5%
CVE-2022-29115 HIGH 7.8 microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability 2,3%
CVE-2022-29114 MED 5.5 microsoft windows_10 Windows Print Spooler Information Disclosure Vulnerability 1,2%
CVE-2022-29113 HIGH 7.8 microsoft windows_10 Windows Digital Media Receiver Elevation of Privilege Vulnerability 0,4%
CVE-2022-29112 MED 6.5 microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability 3,2%
CVE-2022-29111 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 2,5%
CVE-2022-29110 HIGH 7.8 microsoft excel Microsoft Excel Remote Code Execution Vulnerability 3,7%
CVE-2022-29109 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 2,7%
CVE-2022-29108 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 11,9%
CVE-2022-29107 MED 5.5 microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability 2,9%
CVE-2022-29106 HIGH 7.0 microsoft windows_10 Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability 0,6%
CVE-2022-29105 HIGH 7.8 microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability 2,7%
CVE-2022-29104 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 11,8%
CVE-2022-29103 HIGH 7.8 microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 0,6%
CVE-2022-29102 MED 5.5 microsoft windows_server Windows Failover Cluster Information Disclosure Vulnerability 0,8%
CVE-2022-29072 HIGH 7.8 7-zip 7-zip 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area. This is caused by misconfiguration of 7z.dll and a heap overflow. The command runs in a child process unde 1,5%
CVE-2022-29063 CRIT 9.8 apache ofbiz The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or 4,7%
CVE-2022-29062 MED 6.3 fortinet fortisoar Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to write to the underlying filesystem with nginx permissions via crafted HTTP requests. 0,8%
CVE-2022-29061 HIGH 7.2 fortinet fortisoar An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP GET requests. 1,6%
CVE-2022-29060 HIGH 8.1 fortinet fortiddos A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device. 0,7%
CVE-2022-29059 LOW 2.7 fortinet fortiweb An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb version 7.0.1 and below, 6.4.2 and below, 6.3.20 and below, 6.2.7 and below may allow a privileged attacker to execute SQL commands over 0,4%
CVE-2022-29058 HIGH 7.8 fortinet fortiap An improper neutralization of special elements [CWE-89] used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiAP 6.0.0 through 6.4.7, 7.0.0 through 7.0.3, 7.2.0, FortiAP-S 6.0.0 through 6.4.7, FortiAP-W2 6.0.0 through 6.4.7, 7.0. 0,5%
CVE-2022-29057 MED 5.4 fortinet fortiedr A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiEDR version 5.1.0, 5.0.0 through 5.0.3 Patch 6 and 4.0.0 allows a remote authenticated attacker to perform a reflected cross site scripting attack (XSS) by 0,6%
CVE-2022-29056 LOW 3.7 fortinet fortimail A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before 6.0.9 allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending nume 1,8%
CVE-2022-29055 HIGH 7.5 fortinet fortios A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version 7.0.0 through 7.0.4, 2.0.0 through 2.0.9, 1.2.x allows a remote unauthenticated or authenticated atta 0,9%