57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2022-23446 | MED 4.4 | fortinet fortiedr A improper control of a resource through its lifetime in Fortinet FortiEDR version 5.0.3 and earlier allows attacker to make the whole application unresponsive via changing its root directory access permission. | 0,2% | — |
| CVE-2022-23443 | HIGH 7.5 | fortinet fortisoar An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API data via crafted HTTP GET requests. | 1,3% | — |
| CVE-2022-23442 | MED 4.3 | fortinet fortios An improper access control vulnerability [CWE-284] in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8 and 7.0.0 through 7.0.5 may allow an authenticated attacker with a restricted user profile to gather the checksum information about the other VDOMs | 0,5% | — |
| CVE-2022-23441 | CRIT 9.1 | fortinet fortiedr A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiEDR versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow an unauthenticated attacker on the network to disguise as and forge messages from other collectors. | 0,9% | — |
| CVE-2022-23440 | HIGH 7.8 | fortinet fortiedr A use of hard-coded cryptographic key vulnerability [CWE-321] in the registration mechanism of FortiEDR collectors versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow a local attacker to disable and uninstall the collectors from the end-points within the same deploy | 0,2% | — |
| CVE-2022-23439 | MED 4.7 | fortinet fortiadc A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver | 0,4% | — |
| CVE-2022-23438 | MED 4.7 | fortinet fortios An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) | 0,7% | — |
| CVE-2022-23437 | MED 6.5 | apache xerces-j There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged durati | 11,6% | — |
| CVE-2022-23307 | HIGH 8.8 | apache chainsaw CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. | 54,4% | — |
| CVE-2022-23305 | CRIT 9.8 | apache log4j By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate | 66,5% | — |
| CVE-2022-23302 | HIGH 8.8 | apache log4j JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a Topi | 63,6% | — |
| CVE-2022-23301 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2022-23300 | HIGH 7.8 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2022-2330 | MED 6.5 | mcafee data_loss_prevention_endpoint Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constr | 0,9% | — |
| CVE-2022-23299 | HIGH 7.8 | microsoft windows_10 Windows PDEV Elevation of Privilege Vulnerability | 7,6% | — |
| CVE-2022-23298 | HIGH 7.0 | microsoft windows_10 Windows NT OS Kernel Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2022-23297 | MED 5.5 | microsoft windows_10 Windows NT Lan Manager Datagram Receiver Driver Information Disclosure Vulnerability | 0,8% | — |
| CVE-2022-23296 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-23295 | HIGH 7.8 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2022-23294 | HIGH 8.8 | microsoft windows_10 Windows Event Tracing Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2022-23293 | HIGH 7.8 | microsoft windows_10 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-23292 | LOW 3.7 | microsoft on-premises_data_gateway Microsoft Power BI Spoofing Vulnerability | 0,8% | — |
| CVE-2022-23291 | HIGH 7.8 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2022-23290 | HIGH 7.8 | microsoft windows_10 Windows Inking COM Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2022-23288 | HIGH 7.0 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 0,6% | — |