EN
57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2022-23446 MED 4.4 fortinet fortiedr A improper control of a resource through its lifetime in Fortinet FortiEDR version 5.0.3 and earlier allows attacker to make the whole application unresponsive via changing its root directory access permission. 0,2%
CVE-2022-23443 HIGH 7.5 fortinet fortisoar An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API data via crafted HTTP GET requests. 1,3%
CVE-2022-23442 MED 4.3 fortinet fortios An improper access control vulnerability [CWE-284] in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8 and 7.0.0 through 7.0.5 may allow an authenticated attacker with a restricted user profile to gather the checksum information about the other VDOMs 0,5%
CVE-2022-23441 CRIT 9.1 fortinet fortiedr A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiEDR versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow an unauthenticated attacker on the network to disguise as and forge messages from other collectors. 0,9%
CVE-2022-23440 HIGH 7.8 fortinet fortiedr A use of hard-coded cryptographic key vulnerability [CWE-321] in the registration mechanism of FortiEDR collectors versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow a local attacker to disable and uninstall the collectors from the end-points within the same deploy 0,2%
CVE-2022-23439 MED 4.7 fortinet fortiadc A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver 0,4%
CVE-2022-23438 MED 4.7 fortinet fortios An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) 0,7%
CVE-2022-23437 MED 6.5 apache xerces-j There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged durati 11,6%
CVE-2022-23307 HIGH 8.8 apache chainsaw CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. 54,4%
CVE-2022-23305 CRIT 9.8 apache log4j By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate 66,5%
CVE-2022-23302 HIGH 8.8 apache log4j JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a Topi 63,6%
CVE-2022-23301 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 2,3%
CVE-2022-23300 HIGH 7.8 microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability 2,3%
CVE-2022-2330 MED 6.5 mcafee data_loss_prevention_endpoint Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constr 0,9%
CVE-2022-23299 HIGH 7.8 microsoft windows_10 Windows PDEV Elevation of Privilege Vulnerability 7,6%
CVE-2022-23298 HIGH 7.0 microsoft windows_10 Windows NT OS Kernel Elevation of Privilege Vulnerability 0,6%
CVE-2022-23297 MED 5.5 microsoft windows_10 Windows NT Lan Manager Datagram Receiver Driver Information Disclosure Vulnerability 0,8%
CVE-2022-23296 HIGH 7.8 microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability 0,7%
CVE-2022-23295 HIGH 7.8 microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability 2,3%
CVE-2022-23294 HIGH 8.8 microsoft windows_10 Windows Event Tracing Remote Code Execution Vulnerability 2,3%
CVE-2022-23293 HIGH 7.8 microsoft windows_10 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability 0,7%
CVE-2022-23292 LOW 3.7 microsoft on-premises_data_gateway Microsoft Power BI Spoofing Vulnerability 0,8%
CVE-2022-23291 HIGH 7.8 microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability 0,6%
CVE-2022-23290 HIGH 7.8 microsoft windows_10 Windows Inking COM Elevation of Privilege Vulnerability 0,6%
CVE-2022-23288 HIGH 7.0 microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability 0,6%