57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2022-22753 | HIGH 7.1 | mozilla firefox A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.<br>*This bug only affects Firefox on Windows. Other | 0,6% | — |
| CVE-2022-22750 | MED 6.5 | mozilla firefox By generally accepting and passing resource handles across processes, a compromised content process might have confused higher privileged processes to interact with handles that the unprivileged process should not have access to.<br>*This bug only affects Fire | 0,6% | — |
| CVE-2022-22746 | MED 5.9 | mozilla firefox A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Fi | 0,6% | — |
| CVE-2022-22744 | HIGH 8.8 | mozilla firefox The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.<br>*This bug only affects Thunderbird for Windows. Other operating s | 1,3% | — |
| CVE-2022-22733 | MED 6.5 | apache shardingsphere_elasticjob-ui Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest account to do privilege escalation. This issue affects Apache ShardingSphere ElasticJob-UI Apache ShardingSphere El | 37,6% | — |
| CVE-2022-22728 | HIGH 7.5 | apache libapreq2 A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overflow while processing multipart form uploads. A remote attacker could send a request causing a process crash which could lead to a denial of service attack. | 5,8% | — |
| CVE-2022-22721 | CRIT 9.1 | apache http_server If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier. | 41,9% | — |
| CVE-2022-22720 | CRIT 9.8 | apache http_server Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling | 28,2% | — |
| CVE-2022-22719 | HIGH 7.5 | apache http_server A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier. | 69,8% | — |
| CVE-2022-22717 | HIGH 7.0 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-22716 | MED 5.5 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 4,6% | — |
| CVE-2022-22715 | HIGH 7.8 | microsoft windows_10 Named Pipe File System Elevation of Privilege Vulnerability | 12,6% | — |
| CVE-2022-22713 | MED 5.6 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 0,7% | — |
| CVE-2022-22712 | MED 5.6 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 0,8% | — |
| CVE-2022-22711 | MED 5.7 | microsoft windows_10 Windows BitLocker Information Disclosure Vulnerability | 0,5% | — |
| CVE-2022-22710 | MED 5.5 | microsoft windows_10 Windows Common Log File System Driver Denial of Service Vulnerability | 0,9% | — |
| CVE-2022-22709 | HIGH 7.8 | microsoft vp9_video_extensions VP9 Video Extensions Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2022-22703 | MED 5.5 | stormshield network_security In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe installer. | 0,2% | — |
| CVE-2022-22528 | HIGH 7.8 | sap adaptive_server_enterprise SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platform which, under certain conditions, allows a Standard User to execute malicious Windows binaries which may lead to privile | 0,3% | — |
| CVE-2022-22516 | HIGH 7.8 | codesys control_rte_sl The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space. | 0,3% | — |
| CVE-2022-22496 | MED 6.5 | ibm spectrum_protect_server While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be configured to use SESSIONSECURITY=TRANSITIONAL. While in this mode, it may be susceptible to an offline dictionary attack. IBM X-Force ID: 226942. | 0,4% | — |
| CVE-2022-22494 | MED 5.3 | ibm spectrum_protect_operations_center IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-F | 1,5% | — |
| CVE-2022-22493 | HIGH 8.8 | ibm websphere_automation_for_ibm_cloud_pak_for_watson_aiops IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute setting. IBM X-Force ID: 226449. | 0,3% | — |
| CVE-2022-22490 | MED 4.9 | ibm robotic_process_automation IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342. | 0,8% | — |
| CVE-2022-22489 | CRIT 9.1 | ibm mq IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM | 1,7% | — |