EN
57.921 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.921 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2022-27784 HIGH 7.8 adobe after_effects Adobe After Effects versions 22.2.1 (and earlier) and 18.4.5 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploita 3,8%
CVE-2022-27783 HIGH 7.8 adobe after_effects Adobe After Effects versions 22.2.1 (and earlier) and 18.4.5 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploita 3,8%
CVE-2022-2778 CRIT 9.8 octopus octopus_server In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes. 0,8%
CVE-2022-27772 HIGH 7.8 vmware spring_boot spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerability impacted the org.springframework.boot.web.server.AbstractConfigurableWebServerFactory.createTempDir method. NOTE: This vulnerability only 0,6%
CVE-2022-27674 HIGH 7.5 amd amd_uprof Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to a Windows kernel crash resulting in denial of service. 0,7%
CVE-2022-27666 HIGH 7.8 debian debian_linux A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat. 5,5%
CVE-2022-27662 MED 4.8 f5 traffix_signaling_delivery_controller On F5 Traffix SDC 5.2.x versions prior to 5.2.2 and 5.1.x versions prior to 5.1.35, a stored Cross-Site Template Injection vulnerability exists in an undisclosed page of the Traffix SDC Configuration utility that allows an attacker to execute template language 0,5%
CVE-2022-27659 MED 4.3 f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, an authenticated attacker can modify or delete Dashboards created by other BIG-IP users in the Traffic Management User Interface (TMUI). N 0,5%
CVE-2022-27636 MED 5.5 f5 big-ip_access_policy_manager On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, as well as F5 BIG-IP APM Clients 7.x versions prior to 7.2.1.5, BI 0,2%
CVE-2022-27634 MED 6.5 f5 big-ip_access_policy_manager On 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, BIG-IP APM does not properly validate configurations, allowing an authenticated attacker with high privileges to manipulate the APM policy leading to privilege escalation/remote code e 1,4%
CVE-2022-27535 HIGH 7.8 kaspersky vpn_secure_connection Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its 'Delete All Service Data And Reports' feature by the local authenticated attacker. 0,3%
CVE-2022-27516 MED 5.3 citrix application_delivery_controller_firmware User login brute force protection functionality bypass 0,6%
CVE-2022-27513 HIGH 8.3 citrix application_delivery_controller_firmware Remote desktop takeover via phishing 0,3%
CVE-2022-27512 MED 5.3 citrix application_delivery_management Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM. 1,0%
CVE-2022-27511 HIGH 8.1 citrix application_delivery_management Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the d 12,4%
CVE-2022-27510 CRIT 9.8 citrix application_delivery_controller_firmware Unauthorized access to Gateway user capabilities 1,1%
CVE-2022-27509 MED 6.1 citrix application_delivery_controller_firmware Unauthenticated redirection to a malicious website 0,5%
CVE-2022-27508 HIGH 7.5 citrix application_delivery_controller Unauthenticated denial of service 1,0%
CVE-2022-27507 MED 6.5 citrix application_delivery_controller Authenticated denial of service 1,0%
CVE-2022-27506 LOW 2.7 citrix sd-wan_1000_firmware Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI 0,7%
CVE-2022-27505 MED 6.1 citrix sd-wan_1000_firmware Reflected cross site scripting (XSS) 0,5%
CVE-2022-27503 MED 6.1 citrix storefront_server Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9 0,5%
CVE-2022-27502 HIGH 7.8 realvnc vnc_server RealVNC VNC Server 6.9.0 through 5.1.0 for Windows allows local privilege escalation because an installer repair operation executes %TEMP% files as SYSTEM. 0,7%
CVE-2022-27495 MED 6.5 f5 nginx_service_mesh On all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay network. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated 0,3%
CVE-2022-27491 MED 6.8 fortinet fortios A improper verification of source of a communication channel in Fortinet FortiOS with IPS engine version 7.201 through 7.214, 7.001 through 7.113, 6.001 through 6.121, 5.001 through 5.258 and before 4.086 allows a remote and unauthenticated attacker to trigger 1,4%