57.084 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.084 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2023-42027 | MED 4.3 | ibm cics_tx IBM CICS TX Standard 11.1, Advanced 10.1, 11.1, and TXSeries for Multiplatforms 8.1, 8.2, 9.1 are vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trus | 0,3% | — |
| CVE-2023-42022 | MED 5.4 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr | 0,4% | — |
| CVE-2023-42019 | MED 5.9 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper input validation. IBM X-Force ID: 265161. | 0,5% | — |
| CVE-2023-42009 | MED 5.4 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust | 0,4% | — |
| CVE-2023-42007 | MED 5.4 | ibm sterling_control_center IBM Sterling Control Center 6.2.1, 6.3.1, and 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure w | 0,2% | — |
| CVE-2023-41964 | MED 4.3 | f5 big-ip_access_policy_manager The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,2% | — |
| CVE-2023-4194 | MED 5.5 | debian debian_linux A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized access to some resources. The original patches fixing CVE-2023-1076 are incorrect or incomplete. The problem is th | 0,3% | — |
| CVE-2023-41916 | MED 6.5 | apache linkis In Apache Linkis =1.4.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will trigger arbitrary file reading. Therefore, the parameters in the Mysql JDBC URL should | 0,7% | — |
| CVE-2023-41844 | LOW 3.5 | fortinet fortisandbox A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all | 0,4% | — |
| CVE-2023-41843 | HIGH 7.5 | fortinet fortisandbox A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, FortiSandbox 4.2.1 through 4.2.5, FortiSandbox 4.0.0 through 4.0.3, FortiSandbox 3.2 all versions, FortiSandbox 3 | 0,5% | — |
| CVE-2023-41842 | MED 6.7 | fortinet fortianalyzer A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute unauthorized code or commands via specially crafted command arguments. | 0,2% | — |
| CVE-2023-41841 | HIGH 8.1 | fortinet fortios An improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4 allows an attacker belonging to the prof-admin profile to perform elevated actions. | 0,8% | — |
| CVE-2023-41840 | HIGH 7.8 | fortinet forticlient A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to perform a DLL Hijack attack via a malicious OpenSSL engine library in the search path. | 0,3% | — |
| CVE-2023-41838 | HIGH 7.1 | fortinet fortianalyzer An improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 may allow attacker to execute unauthorized code or commands via FortiManager cli. | 0,5% | — |
| CVE-2023-41836 | LOW 3.5 | fortinet fortisandbox An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0, FortiSandbox 4.2.1 through 4.2.4, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, | 0,4% | — |
| CVE-2023-41835 | HIGH 7.5 | apache struts When a Multipart request is performed but some of the fields exceed the maxStringLength limit, the upload files will remain in struts.multipart.saveDir even if the request has been denied. Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 | 6,3% | — |
| CVE-2023-41834 | MED 6.1 | apache flink_stateful_functions Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted HTTP requests. Attackers could | 1,6% | — |
| CVE-2023-41774 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2023-41773 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2023-41772 | HIGH 7.8 | microsoft windows_10_1809 Win32k Elevation of Privilege Vulnerability | 11,8% | — |
| CVE-2023-41771 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2023-41770 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2023-41769 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2023-41768 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2023-41767 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1,3% | — |