57.921 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.921 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2022-27784 | HIGH 7.8 | adobe after_effects Adobe After Effects versions 22.2.1 (and earlier) and 18.4.5 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploita | 3,8% | — |
| CVE-2022-27783 | HIGH 7.8 | adobe after_effects Adobe After Effects versions 22.2.1 (and earlier) and 18.4.5 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploita | 3,8% | — |
| CVE-2022-2778 | CRIT 9.8 | octopus octopus_server In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes. | 0,8% | — |
| CVE-2022-27772 | HIGH 7.8 | vmware spring_boot spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerability impacted the org.springframework.boot.web.server.AbstractConfigurableWebServerFactory.createTempDir method. NOTE: This vulnerability only | 0,6% | — |
| CVE-2022-27674 | HIGH 7.5 | amd amd_uprof Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to a Windows kernel crash resulting in denial of service. | 0,7% | — |
| CVE-2022-27666 | HIGH 7.8 | debian debian_linux A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat. | 5,5% | — |
| CVE-2022-27662 | MED 4.8 | f5 traffix_signaling_delivery_controller On F5 Traffix SDC 5.2.x versions prior to 5.2.2 and 5.1.x versions prior to 5.1.35, a stored Cross-Site Template Injection vulnerability exists in an undisclosed page of the Traffix SDC Configuration utility that allows an attacker to execute template language | 0,5% | — |
| CVE-2022-27659 | MED 4.3 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, an authenticated attacker can modify or delete Dashboards created by other BIG-IP users in the Traffic Management User Interface (TMUI). N | 0,5% | — |
| CVE-2022-27636 | MED 5.5 | f5 big-ip_access_policy_manager On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, as well as F5 BIG-IP APM Clients 7.x versions prior to 7.2.1.5, BI | 0,2% | — |
| CVE-2022-27634 | MED 6.5 | f5 big-ip_access_policy_manager On 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, BIG-IP APM does not properly validate configurations, allowing an authenticated attacker with high privileges to manipulate the APM policy leading to privilege escalation/remote code e | 1,4% | — |
| CVE-2022-27535 | HIGH 7.8 | kaspersky vpn_secure_connection Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its 'Delete All Service Data And Reports' feature by the local authenticated attacker. | 0,3% | — |
| CVE-2022-27516 | MED 5.3 | citrix application_delivery_controller_firmware User login brute force protection functionality bypass | 0,6% | — |
| CVE-2022-27513 | HIGH 8.3 | citrix application_delivery_controller_firmware Remote desktop takeover via phishing | 0,3% | — |
| CVE-2022-27512 | MED 5.3 | citrix application_delivery_management Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM. | 1,0% | — |
| CVE-2022-27511 | HIGH 8.1 | citrix application_delivery_management Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the d | 12,4% | — |
| CVE-2022-27510 | CRIT 9.8 | citrix application_delivery_controller_firmware Unauthorized access to Gateway user capabilities | 1,1% | — |
| CVE-2022-27509 | MED 6.1 | citrix application_delivery_controller_firmware Unauthenticated redirection to a malicious website | 0,5% | — |
| CVE-2022-27508 | HIGH 7.5 | citrix application_delivery_controller Unauthenticated denial of service | 1,0% | — |
| CVE-2022-27507 | MED 6.5 | citrix application_delivery_controller Authenticated denial of service | 1,0% | — |
| CVE-2022-27506 | LOW 2.7 | citrix sd-wan_1000_firmware Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI | 0,7% | — |
| CVE-2022-27505 | MED 6.1 | citrix sd-wan_1000_firmware Reflected cross site scripting (XSS) | 0,5% | — |
| CVE-2022-27503 | MED 6.1 | citrix storefront_server Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9 | 0,5% | — |
| CVE-2022-27502 | HIGH 7.8 | realvnc vnc_server RealVNC VNC Server 6.9.0 through 5.1.0 for Windows allows local privilege escalation because an installer repair operation executes %TEMP% files as SYSTEM. | 0,7% | — |
| CVE-2022-27495 | MED 6.5 | f5 nginx_service_mesh On all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay network. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0,3% | — |
| CVE-2022-27491 | MED 6.8 | fortinet fortios A improper verification of source of a communication channel in Fortinet FortiOS with IPS engine version 7.201 through 7.214, 7.001 through 7.113, 6.001 through 6.121, 5.001 through 5.258 and before 4.086 allows a remote and unauthenticated attacker to trigger | 1,4% | — |