57.057 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.057 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2024-1656 | LOW 2.6 | octopus octopus_server Affected versions of Octopus Server had a weak content security policy. | 0,2% | — |
| CVE-2024-1654 | HIGH 7.2 | papercut papercut_mf This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of both an internal system identifier and details of another valid user to explo | 1,3% | — |
| CVE-2024-1552 | HIGH 7.5 | debian debian_linux Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8. | 0,7% | — |
| CVE-2024-1545 | MED 5.9 | wolfssl wolfssl Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process to disclose information and escalate privileges vi | 0,6% | — |
| CVE-2024-1460 | MED 5.6 | msi afterburner MSI Afterburner v4.6.5.16370 is vulnerable to a Kernel Memory Leak vulnerability by triggering the 0x80002040 IOCTL code of the RTCore64.sys driver. The handle to the driver can only be obtained from a high integrity process. | 0,2% | — |
| CVE-2024-1443 | MED 4.4 | msi afterburner MSI Afterburner v4.6.5.16370 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002000 IOCTL code of the RTCore64.sys driver. The handle to the driver can only be obtained from a high integrity process. | 0,2% | — |
| CVE-2024-14027 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fs/xattr: missing fdput() in fremovexattr error path In the Linux kernel, the fremovexattr() syscall calls fdget() to acquire a file reference but returns early without calling fdput() when | 0,2% | — |
| CVE-2024-13178 | MED 4.3 | google chrome Inappropriate implementation in Fullscreen in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | 0,2% | — |
| CVE-2024-1312 | MED 5.1 | fedoraproject fedora A use-after-free flaw was found in the Linux kernel's Memory Management subsystem when a user wins two races at the same time with a fail in the mas_prev_slot function. This issue could allow a local user to crash the system. | 0,2% | — |
| CVE-2024-12753 | HIGH 7.3 | foxit pdf_editor Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code o | 0,3% | — |
| CVE-2024-12752 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader AcroForm Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in t | 0,3% | — |
| CVE-2024-12751 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader AcroForm Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in | 0,4% | — |
| CVE-2024-12672 | HIGH 7.3 | rockwellautomation arena A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To | 0,2% | — |
| CVE-2024-12284 | HIGH 8.8 | citrix netscaler_agent Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows. | 13,3% | — |
| CVE-2024-1223 | MED 4.8 | papercut papercut_mf This vulnerability potentially allows unauthorized enumeration of information from the embedded device APIs. An attacker must already have existing knowledge of some combination of valid usernames, device names and an internal system key. For such an attack to | 0,4% | — |
| CVE-2024-1222 | HIGH 8.6 | papercut papercut_mf This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/MF API calls. | 64,0% | — |
| CVE-2024-1221 | LOW 3.1 | papercut papercut_mf This vulnerability potentially allows files on a PaperCut NG/MF server to be exposed using a specifically formed payload against the impacted API endpoint. The attacker must carry out some reconnaissance to gain knowledge of a system token. This CVE only affec | 0,5% | — |
| CVE-2024-12108 | CRIT 9.6 | progress whatsup_gold In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API. | 6,8% | — |
| CVE-2024-1151 | MED 5.5 | debian debian_linux A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs when a recursive operation of code push recursively calls into the code block. The OVS module does not validate the stack depth, pushing too many frames and cau | 0,3% | — |
| CVE-2024-1149 | HIGH 7.8 | snowsoftware snow_inventory_agent Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, Snow Software Inventory Agent on Linux allows File Manipulation through Snow Update Packages.This issue affects | 0,1% | — |
| CVE-2024-11395 | HIGH 8.8 | google chrome Type Confusion in V8 in Google Chrome prior to 131.0.6778.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0,4% | — |
| CVE-2024-11364 | HIGH 7.3 | rockwellautomation arena Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor c | 0,3% | — |
| CVE-2024-11114 | HIGH 8.3 | google chrome Inappropriate implementation in Views in Google Chrome on Windows prior to 131.0.6778.69 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | 0,4% | — |
| CVE-2024-11112 | HIGH 8.8 | google chrome Use after free in Media in Google Chrome on Windows prior to 131.0.6778.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | 0,4% | — |
| CVE-2024-1085 | HIGH 7.8 | linux linux_kernel A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_setelem_catchall_deactivate() function checks whether the catch-all set element is active in the current genera | 0,3% | — |