EN
57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più alto
CVE-2022-30304 MED 4.3 fortinet fortianalyzer An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAnalyzer versions prior to 7.2.1, 7.0.4 and 6.4.8 may allow a remote unauthenticated attacker to perform a stored cross site scripting (XSS) attack via the URL parame 0,7%
CVE-2022-30303 HIGH 8.8 fortinet fortiweb An improper neutralization of special elements used in an os command ('OS Command Injection') [CWE-78] in FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versions may allow an authenticated attacker to execute arbitrary shell code as `root` user vi 2,5%
CVE-2022-30302 MED 6.5 fortinet fortideceptor Multiple relative path traversal vulnerabilities [CWE-23] in FortiDeceptor management interface 1.0.0 through 3.2.x, 3.3.0 through 3.3.2, 4.0.0 through 4.0.1 may allow a remote and authenticated attacker to retrieve and delete arbitrary files from the underlyi 0,9%
CVE-2022-30301 HIGH 7.8 fortinet fortiap-u A path traversal vulnerability [CWE-22] in FortiAP-U CLI 6.2.0 through 6.2.3, 6.0.0 through 6.0.4, 5.4.0 through 5.4.6 may allow an admin user to delete and access unauthorized files and data via specifically crafted CLI commands. 0,2%
CVE-2022-30300 MED 6.5 fortinet fortiweb A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3.18, 6.4 all versions may allow an authenticated attacker to obtain unauthorized access to files and data via specifically crafted HTTP GET requests. 0,8%
CVE-2022-30299 MED 5.3 fortinet fortiweb A path traversal vulnerability [CWE-23] in the API of FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versions, 6.2 all versions, 6.1 all versions, 6.0 all versions may allow an authenticated attacker to retrieve specific parts of files from the un 0,5%
CVE-2022-30298 HIGH 7.0 fortinet fortisoar An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root. 0,2%
CVE-2022-3028 HIGH 7.0 debian debian_linux A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak 0,2%
CVE-2022-30226 HIGH 7.1 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0,8%
CVE-2022-30225 HIGH 7.1 microsoft windows_10 Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability 0,6%
CVE-2022-30224 HIGH 7.0 microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability 0,5%
CVE-2022-30223 MED 5.7 microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability 0,8%
CVE-2022-30222 HIGH 8.4 microsoft windows_10 Windows Shell Remote Code Execution Vulnerability 0,7%
CVE-2022-30221 HIGH 8.8 microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability 2,1%
CVE-2022-30220 HIGH 7.8 microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability 5,2%
CVE-2022-30216 HIGH 8.8 microsoft windows_10 Windows Server Service Tampering Vulnerability 88,9%
CVE-2022-30215 HIGH 7.5 microsoft windows_server_2016 Active Directory Federation Services Elevation of Privilege Vulnerability 1,8%
CVE-2022-30214 MED 6.6 microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability 1,0%
CVE-2022-30213 MED 5.5 microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability 0,7%
CVE-2022-30212 MED 4.7 microsoft windows_10 Windows Connected Devices Platform Service Information Disclosure Vulnerability 0,5%
CVE-2022-30211 HIGH 7.5 microsoft windows_10 Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability 2,0%
CVE-2022-30209 HIGH 7.4 microsoft windows_10 Windows IIS Server Elevation of Privilege Vulnerability 2,5%
CVE-2022-30208 MED 6.5 microsoft windows_10 Windows Security Account Manager (SAM) Denial of Service Vulnerability 2,4%
CVE-2022-30206 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 2,2%
CVE-2022-30205 MED 6.6 microsoft windows_10 Windows Group Policy Elevation of Privilege Vulnerability 1,2%