57.057 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.057 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2024-0089 | HIGH 7.8 | nvidia cloud_gaming NVIDIA GPU Display Driver for Windows contains a vulnerability where the information from a previous client or another process could be disclosed. A successful exploit of this vulnerability might lead to code execution, information disclosure, or data tamperin | 0,2% | — |
| CVE-2024-0088 | MED 5.5 | nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability in shared memory APIs, where a user can cause an improper memory access issue by a network API. A successful exploit of this vulnerability might lead to denial of service and data tampering. | 18,9% | — |
| CVE-2024-0087 | CRIT 9.0 | nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists, logs are appended to the file. A successful exploit of this vulnerability might lead to code execution, denia | 19,9% | — |
| CVE-2024-0086 | MED 5.5 | nvidia cloud_gaming NVIDIA vGPU software for Linux contains a vulnerability where the software can dereference a NULL pointer. A successful exploit of this vulnerability might lead to denial of service and undefined behavior in the vGPU plugin. | 0,1% | — |
| CVE-2024-0085 | MED 6.3 | nvidia cloud_gaming NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged operations on the host. A successful exploit of this vulnerability might lead to data tampering, escalation of privileges, and denial of servi | 0,1% | — |
| CVE-2024-0084 | HIGH 7.8 | nvidia cloud_gaming NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where the guest OS could execute privileged operations. A successful exploit of this vulnerability might lead to information disclosure, data tampering, escalation of privilege | 0,2% | — |
| CVE-2024-0083 | MED 6.5 | nvidia chatrtx NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause a cross-site scripting error by network by running malicious scripts in users' browsers. A successful exploit of this vulnerability might lead to code execution, denial | 0,6% | — |
| CVE-2024-0082 | HIGH 8.2 | nvidia chatrtx NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause improper privilege management by sending open file requests to the application. A successful exploit of this vulnerability might lead to local escalation of privileges, | 0,2% | — |
| CVE-2024-0076 | LOW 3.3 | nvidia cuda_toolkit NVIDIA CUDA toolkit for all platforms contains a vulnerability in cuobjdump and nvdisasm where an attacker may cause a crash by tricking a user into reading a malformed ELF file. A successful exploit of this vulnerability may lead to a partial denial of servi | 0,2% | — |
| CVE-2024-0072 | LOW 3.3 | nvidia cuda_toolkit NVIDIA CUDA toolkit for all platforms contains a vulnerability in cuobjdump and nvdisasm where an attacker may cause a crash by tricking a user into reading a malformed ELF file. A successful exploit of this vulnerability may lead to a partial denial of servi | 0,2% | — |
| CVE-2024-0057 | CRIT 9.1 | microsoft .net NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability | 2,8% | — |
| CVE-2024-0056 | HIGH 8.7 | microsoft .net Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability | 1,2% | — |
| CVE-2024-0011 | MED 4.3 | paloaltonetworks pan-os A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of an authenticated Captive Portal user’s browser) if a user clicks on a maliciou | 0,4% | — |
| CVE-2024-0010 | MED 4.3 | paloaltonetworks pan-os A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of a user’s browser) if a user clicks on a malicious link, allowing phishin | 0,5% | — |
| CVE-2024-0009 | MED 6.3 | paloaltonetworks pan-os An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address. | 0,2% | — |
| CVE-2024-0008 | MED 6.6 | paloaltonetworks pan-os Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access. | 0,5% | — |
| CVE-2024-0007 | MED 6.8 | paloaltonetworks pan-os A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances. This enables the impersonation of another | 0,4% | — |
| CVE-2023-7192 | MED 5.5 | linux linux_kernel A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink.c in the Linux Kernel. This issue may allow a local attacker with CAP_NET_ADMIN privileges to cause a denial of service (DoS) attack due to a refcount overflow. | 0,3% | — |
| CVE-2023-7047 | MED 4.4 | devolutions remote_desktop_manager Inadequate validation of permissions when employing remote tools and macros via the context menu within Devolutions Remote Desktop Manager versions 2023.3.31 and earlier permits a user to initiate a connection without proper execution rights via the remote | 0,2% | — |
| CVE-2023-7042 | MED 4.4 | linux linux_kernel A null pointer dereference vulnerability was found in ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev() in drivers/net/wireless/ath/ath10k/wmi-tlv.c in the Linux kernel. This issue could be exploited to trigger a denial of service. | 0,3% | — |
| CVE-2023-7016 | HIGH 7.8 | thalesgroup safenet_authentication_client A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local access. | 0,3% | — |
| CVE-2023-6932 | HIGH 7.8 | debian debian_linux A use-after-free vulnerability in the Linux kernel's ipv4: igmp component can be exploited to achieve local privilege escalation. A race condition can be exploited to cause a timer be mistakenly registered on a RCU read locked object which is freed by another | 0,4% | — |
| CVE-2023-6931 | HIGH 7.8 | debian debian_linux A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_rea | 0,7% | — |
| CVE-2023-6915 | MED 6.2 | linux linux_kernel A Null pointer dereference problem was found in ida_free in lib/idr.c in the Linux Kernel. This issue may allow an attacker using this library to cause a denial of service problem due to a missing check at a function return. | 0,3% | — |
| CVE-2023-6857 | MED 5.3 | debian debian_linux When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Firefox on Unix-based operating systems (Android, Linux, MacOS). Windows is unaffected.* This vulnerability affects | 0,7% | — |