57.056 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.056 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2024-29989 | HIGH 8.4 | microsoft azure_monitor_agent Azure Monitor Agent Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-29987 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 1,2% | — |
| CVE-2024-29986 | MED 5.4 | microsoft edge_chromium Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability | 0,5% | — |
| CVE-2024-29985 | HIGH 8.8 | microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | 2,4% | — |
| CVE-2024-29984 | HIGH 8.8 | microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | 2,4% | — |
| CVE-2024-29983 | HIGH 8.8 | microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | 2,4% | — |
| CVE-2024-29982 | HIGH 8.8 | microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | 2,4% | — |
| CVE-2024-29981 | MED 4.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0,7% | — |
| CVE-2024-29869 | MED 5.5 | apache hive Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set explicitly. Any unauthorized user having access to the directory can read the sensitive information written into t | 0,3% | — |
| CVE-2024-29868 | CRIT 9.1 | apache streampipes Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an attacker to guess the recovery token in a reasonable time and thereby to take over th | 6,0% | — |
| CVE-2024-29834 | MED 6.4 | apache pulsar This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as unloading topics and triggering compaction. These management operations should be restricted to users with the t | 1,4% | — |
| CVE-2024-29831 | HIGH 8.8 | apache dolphinscheduler Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2. | 1,2% | — |
| CVE-2024-2975 | HIGH 8.8 | octopus octopus_server A race condition was identified through which privilege escalation was possible in certain configurations. | 0,4% | — |
| CVE-2024-29737 | MED 4.7 | apache streampark In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to | 1,1% | — |
| CVE-2024-29736 | CRIT 9.1 | apache cxf A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured. | 1,0% | — |
| CVE-2024-29735 | MED 5.3 | apache airflow Improper Preservation of Permissions vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.8.2 through 2.8.3. Airflow's local file task handler in Airflow incorrectly set permissions for all parent folders of log folder, in default configur | 1,5% | — |
| CVE-2024-29733 | LOW 2.7 | apache apache-airflow-providers-ftp Improper Certificate Validation vulnerability in Apache Airflow FTP Provider. The FTP hook lacks complete certificate validation in FTP_TLS connections, which can potentially be leveraged. Implementing proper certificate validation by passing context=ssl.crea | 0,6% | — |
| CVE-2024-29217 | MED 4.6 | apache answer Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0. XSS attack when user changes personal website. A logged-in user, when modifying their personal | 1,0% | — |
| CVE-2024-29195 | MED 6.0 | microsoft azure_c_shared_utility The azure-c-shared-utility is a C library for AMQP/MQTT communication to Azure Cloud Services. This library may be used by the Azure IoT C SDK for communication between IoT Hub and IoT Hub devices. An attacker can cause an integer wraparound or under-allocatio | 5,0% | — |
| CVE-2024-29178 | HIGH 8.8 | apache streampark On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker must successfully log into the system to launch an attack, so this is a moderate-impact vulnerability. Mitigat | 1,2% | — |
| CVE-2024-29133 | MED 5.4 | apache commons_configuration Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue. | 1,7% | — |
| CVE-2024-29131 | HIGH 7.3 | apache commons_configuration Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue. | 2,1% | — |
| CVE-2024-29120 | MED 5.9 | apache streampark In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's u | 0,3% | — |
| CVE-2024-29072 | HIGH 8.2 | foxit pdf_editor A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which can result | 0,5% | — |
| CVE-2024-29070 | CRIT 9.1 | apache streampark On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" as the front-end authentication credential. "Authorization" can still initiate requests and access data even af | 0,8% | — |