57.057 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.057 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2024-22255 | HIGH 7.1 | vmware cloud_foundation VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process. | 2,3% | — |
| CVE-2024-22254 | HIGH 7.9 | vmware cloud_foundation VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox. | 0,5% | — |
| CVE-2024-22253 | CRIT 9.3 | vmware cloud_foundation VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process runn | 0,6% | — |
| CVE-2024-22252 | CRIT 9.3 | vmware esxi VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process runn | 3,5% | — |
| CVE-2024-22251 | MED 5.9 | vmware fusion VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on a virtual machine may trigger an out-of-bounds read leading to information disclos | 0,2% | — |
| CVE-2024-22241 | MED 4.3 | vmware aria_operations_for_networks Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges can inject a malicious payload into the login banner and takeover the user account. | 37,8% | — |
| CVE-2024-22240 | MED 4.9 | vmware aria_operations_for_networks Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to sensitive information. | 0,6% | — |
| CVE-2024-22239 | MED 5.3 | vmware aria_operations_for_networks Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain regular shell access. | 0,2% | — |
| CVE-2024-22238 | MED 6.4 | vmware aria_operations_for_networks Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious code into user profile configurations due to improper input sanitization. | 0,5% | — |
| CVE-2024-22237 | HIGH 7.8 | vmware aria_operations_for_networks Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain root access to the system. | 0,2% | — |
| CVE-2024-22236 | LOW 3.3 | vmware spring_cloud_contract In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnerable to local information disclosure via temporary directory created with unsafe permissions through the shaded | 0,2% | — |
| CVE-2024-22235 | MED 6.7 | vmware aria_operations VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'. | 0,2% | — |
| CVE-2024-22234 | HIGH 7.4 | vmware spring_security In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to broken access control when it directly uses the AuthenticationTrustResolver.isFullyAuthenticated(Authentication) method. Specifically, an appl | 0,7% | — |
| CVE-2024-22233 | HIGH 7.5 | vmware spring_framework In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the ap | 1,0% | — |
| CVE-2024-22099 | MED 6.3 | linux linux_kernel NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows Overflow Buffers. This vulnerability is associated with program files /net/bluetooth/rfcomm/core.C. This issue affects Linux kernel: v2.6.12 | 0,6% | — |
| CVE-2024-22093 | HIGH 8.7 | f5 big-ip_access_policy_manager When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions | 0,8% | — |
| CVE-2024-22014 | HIGH 8.8 | 360totalsecurity 360_total_security An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated privileges via Symbolic Link Follow to Arbitrary File Delete. | 0,8% | — |
| CVE-2024-21892 | HIGH 7.8 | nodejs node.js On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the process is running with elevated privileges with the only exception of CAP_NET_BIND_SERVICE. Due to a bug in the implementation of this excepti | 0,6% | — |
| CVE-2024-21849 | HIGH 7.5 | f5 big-ip_advanced_web_application_firewall When an Advanced WAF/ASM security policy and a Websockets profile are configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical S | 0,5% | — |
| CVE-2024-21803 | LOW 3.5 | linux linux_kernel Use After Free vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (bluetooth modules) allows Local Execution of Code. This vulnerability is associated with program files https://gitee.Com/anolis/cloud-kernel/blob/devel-5.10/net/bluetooth/af_bluetoot | 0,5% | — |
| CVE-2024-21793 | HIGH 7.5 | f5 big-ip_next_central_manager An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 7,1% | — |
| CVE-2024-21789 | HIGH 7.5 | f5 big-ip_advanced_web_application_firewall When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0,5% | — |
| CVE-2024-21782 | MED 6.7 | f5 big-ip_access_policy_manager BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced shell (bash) can execute arbitrary commands with a specially crafted command string. This vulnerability is due | 0,2% | — |
| CVE-2024-21771 | HIGH 7.5 | f5 big-ip_advanced_firewall_manager For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic against signatures, resulting in Traffic Management Microkernel (TMM) restarting and traffic disruption. Note: Software versions which have rea | 0,5% | — |
| CVE-2024-21763 | HIGH 7.5 | f5 big-ip_advanced_firewall_manager When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclosed queries can cause the Traffic Management Microkernel (TMM) to terminate. NOTE: Software versions which have reached End of Technical Supp | 0,5% | — |