EN
57.056 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.056 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2024-35266 HIGH 7.6 microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability 1,6%
CVE-2024-35265 HIGH 7.0 microsoft windows_10_1809 Windows Perception Service Elevation of Privilege Vulnerability 0,4%
CVE-2024-35264 HIGH 8.1 microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability 2,6%
CVE-2024-35263 MED 5.7 microsoft dynamics_365 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability 1,7%
CVE-2024-35261 HIGH 7.8 microsoft azure_network_watcher_agent Azure Network Watcher VM Extension Elevation of Privilege Vulnerability 0,7%
CVE-2024-35260 HIGH 8.0 microsoft power_platform An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network. 0,8%
CVE-2024-35256 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1,6%
CVE-2024-35255 MED 5.5 microsoft authentication_library Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability 0,8%
CVE-2024-35254 HIGH 7.1 microsoft azure_monitor_agent Azure Monitor Agent Elevation of Privilege Vulnerability 0,8%
CVE-2024-35253 MED 4.4 microsoft azure_file_sync Microsoft Azure File Sync Elevation of Privilege Vulnerability 0,7%
CVE-2024-35252 HIGH 7.5 microsoft azure_storage_data_movement_library Azure Storage Movement Client Library Denial of Service Vulnerability 2,5%
CVE-2024-35249 HIGH 8.8 microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability 3,4%
CVE-2024-35248 HIGH 7.3 microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability 0,9%
CVE-2024-35247 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fpga: region: add owner module and take its refcount The current implementation of the fpga region assumes that the low-level module registers a driver for the parent device and uses its own 0,2%
CVE-2024-35201 MED 6.7 intel server_debug_and_provisioning_tool Incorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may allow an authenticated user to enable escalation of privilege via local access. 0,1%
CVE-2024-35200 MED 5.3 f5 nginx_open_source When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate. 0,9%
CVE-2024-35178 HIGH 7.5 jupyter jupyter_server The Jupyter Server provides the backend for Jupyter web applications. Jupyter Server on Windows has a vulnerability that lets unauthenticated attackers leak the NTLMv2 password hash of the Windows user running the Jupyter server. An attacker can crack this pas 0,7%
CVE-2024-35164 MED 6.8 apache guacamole The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers via text-based protocols like SSH. If a malicious user has access to a text-based connection, a specially-crafted sequence of console codes 0,4%
CVE-2024-35161 HIGH 7.5 apache traffic_server Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue affects Apache Traffic Server: from 8.0.0 th 1,0%
CVE-2024-35117 MED 4.4 ibm openpages_with_watson IBM OpenPages with Watson 9.0 may write sensitive information, under specific configurations, in clear text to the system tracing log files that could be obtained by a privileged user. 0,2%
CVE-2024-34777 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: dma-mapping: benchmark: fix node id validation While validating node ids in map_benchmark_ioctl(), node_possible() may be provided with invalid argument outside of [0,MAX_NUMNODES-1] range l 0,2%
CVE-2024-34750 HIGH 7.5 apache tomcat Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 st 4,6%
CVE-2024-34693 MED 6.8 apache superset Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled. If both the MariaDB server (off by default) and the local mysql client on the web server are set to allow 1,6%
CVE-2024-34457 MED 6.5 apache streampark On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config. Mitigation: all users should upgrade to 2.1.4 0,7%
CVE-2024-34365 CRIT 9.1 apache karaf_cave ** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Karaf Cave.This issue affects all versions of Apache Karaf Cave. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to 1,2%