57.056 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.056 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2024-35266 | HIGH 7.6 | microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability | 1,6% | — |
| CVE-2024-35265 | HIGH 7.0 | microsoft windows_10_1809 Windows Perception Service Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2024-35264 | HIGH 8.1 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 2,6% | — |
| CVE-2024-35263 | MED 5.7 | microsoft dynamics_365 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | 1,7% | — |
| CVE-2024-35261 | HIGH 7.8 | microsoft azure_network_watcher_agent Azure Network Watcher VM Extension Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-35260 | HIGH 8.0 | microsoft power_platform An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network. | 0,8% | — |
| CVE-2024-35256 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1,6% | — |
| CVE-2024-35255 | MED 5.5 | microsoft authentication_library Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2024-35254 | HIGH 7.1 | microsoft azure_monitor_agent Azure Monitor Agent Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2024-35253 | MED 4.4 | microsoft azure_file_sync Microsoft Azure File Sync Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-35252 | HIGH 7.5 | microsoft azure_storage_data_movement_library Azure Storage Movement Client Library Denial of Service Vulnerability | 2,5% | — |
| CVE-2024-35249 | HIGH 8.8 | microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability | 3,4% | — |
| CVE-2024-35248 | HIGH 7.3 | microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2024-35247 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fpga: region: add owner module and take its refcount The current implementation of the fpga region assumes that the low-level module registers a driver for the parent device and uses its own | 0,2% | — |
| CVE-2024-35201 | MED 6.7 | intel server_debug_and_provisioning_tool Incorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may allow an authenticated user to enable escalation of privilege via local access. | 0,1% | — |
| CVE-2024-35200 | MED 5.3 | f5 nginx_open_source When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate. | 0,9% | — |
| CVE-2024-35178 | HIGH 7.5 | jupyter jupyter_server The Jupyter Server provides the backend for Jupyter web applications. Jupyter Server on Windows has a vulnerability that lets unauthenticated attackers leak the NTLMv2 password hash of the Windows user running the Jupyter server. An attacker can crack this pas | 0,7% | — |
| CVE-2024-35164 | MED 6.8 | apache guacamole The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers via text-based protocols like SSH. If a malicious user has access to a text-based connection, a specially-crafted sequence of console codes | 0,4% | — |
| CVE-2024-35161 | HIGH 7.5 | apache traffic_server Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue affects Apache Traffic Server: from 8.0.0 th | 1,0% | — |
| CVE-2024-35117 | MED 4.4 | ibm openpages_with_watson IBM OpenPages with Watson 9.0 may write sensitive information, under specific configurations, in clear text to the system tracing log files that could be obtained by a privileged user. | 0,2% | — |
| CVE-2024-34777 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: dma-mapping: benchmark: fix node id validation While validating node ids in map_benchmark_ioctl(), node_possible() may be provided with invalid argument outside of [0,MAX_NUMNODES-1] range l | 0,2% | — |
| CVE-2024-34750 | HIGH 7.5 | apache tomcat Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 st | 4,6% | — |
| CVE-2024-34693 | MED 6.8 | apache superset Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled. If both the MariaDB server (off by default) and the local mysql client on the web server are set to allow | 1,6% | — |
| CVE-2024-34457 | MED 6.5 | apache streampark On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config. Mitigation: all users should upgrade to 2.1.4 | 0,7% | — |
| CVE-2024-34365 | CRIT 9.1 | apache karaf_cave ** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Karaf Cave.This issue affects all versions of Apache Karaf Cave. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to | 1,2% | — |