EN
57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più alto
CVE-2022-22753 HIGH 7.1 mozilla firefox A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.<br>*This bug only affects Firefox on Windows. Other 0,6%
CVE-2022-22750 MED 6.5 mozilla firefox By generally accepting and passing resource handles across processes, a compromised content process might have confused higher privileged processes to interact with handles that the unprivileged process should not have access to.<br>*This bug only affects Fire 0,6%
CVE-2022-22746 MED 5.9 mozilla firefox A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Fi 0,6%
CVE-2022-22744 HIGH 8.8 mozilla firefox The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.<br>*This bug only affects Thunderbird for Windows. Other operating s 1,3%
CVE-2022-22733 MED 6.5 apache shardingsphere_elasticjob-ui Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest account to do privilege escalation. This issue affects Apache ShardingSphere ElasticJob-UI Apache ShardingSphere El 37,6%
CVE-2022-22728 HIGH 7.5 apache libapreq2 A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overflow while processing multipart form uploads. A remote attacker could send a request causing a process crash which could lead to a denial of service attack. 5,8%
CVE-2022-22721 CRIT 9.1 apache http_server If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier. 41,9%
CVE-2022-22720 CRIT 9.8 apache http_server Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling 28,2%
CVE-2022-22719 HIGH 7.5 apache http_server A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier. 69,8%
CVE-2022-22717 HIGH 7.0 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0,7%
CVE-2022-22716 MED 5.5 microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability 4,6%
CVE-2022-22715 HIGH 7.8 microsoft windows_10 Named Pipe File System Elevation of Privilege Vulnerability 12,6%
CVE-2022-22713 MED 5.6 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 0,7%
CVE-2022-22712 MED 5.6 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 0,8%
CVE-2022-22711 MED 5.7 microsoft windows_10 Windows BitLocker Information Disclosure Vulnerability 0,5%
CVE-2022-22710 MED 5.5 microsoft windows_10 Windows Common Log File System Driver Denial of Service Vulnerability 0,9%
CVE-2022-22709 HIGH 7.8 microsoft vp9_video_extensions VP9 Video Extensions Remote Code Execution Vulnerability 2,3%
CVE-2022-22703 MED 5.5 stormshield network_security In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe installer. 0,2%
CVE-2022-22528 HIGH 7.8 sap adaptive_server_enterprise SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platform which, under certain conditions, allows a Standard User to execute malicious Windows binaries which may lead to privile 0,3%
CVE-2022-22516 HIGH 7.8 codesys control_rte_sl The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space. 0,3%
CVE-2022-22496 MED 6.5 ibm spectrum_protect_server While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be configured to use SESSIONSECURITY=TRANSITIONAL. While in this mode, it may be susceptible to an offline dictionary attack. IBM X-Force ID: 226942. 0,4%
CVE-2022-22494 MED 5.3 ibm spectrum_protect_operations_center IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-F 1,5%
CVE-2022-22493 HIGH 8.8 ibm websphere_automation_for_ibm_cloud_pak_for_watson_aiops IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute setting. IBM X-Force ID: 226449. 0,3%
CVE-2022-22490 MED 4.9 ibm robotic_process_automation IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342. 0,8%
CVE-2022-22489 CRIT 9.1 ibm mq IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM 1,7%