57.080 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.080 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2023-3864 | HIGH 7.2 | snowsoftware snow_license_manager Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal. | 0,6% | — |
| CVE-2023-3863 | MED 6.4 | debian debian_linux A use-after-free flaw was found in nfc_llcp_find_local in net/nfc/llcp_core.c in NFC in the Linux kernel. This flaw allows a local user with special privileges to impact a kernel information leak issue. | 0,2% | — |
| CVE-2023-38581 | HIGH 8.8 | intel power_gadget Buffer overflow in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access. | 0,2% | — |
| CVE-2023-38570 | MED 5.3 | intel unison_software Access of memory location after end of buffer for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via local access. | 0,2% | — |
| CVE-2023-38545 | CRIT 9.8 | fedoraproject fedora This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host na | 78,5% | — |
| CVE-2023-38544 | MED 5.5 | ivanti secure_access_client A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be exploited to compromise the integrity and security of the network on the affected system. | 0,4% | — |
| CVE-2023-38543 | HIGH 7.8 | ivanti secure_access_client A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine. | 0,4% | — |
| CVE-2023-38522 | HIGH 7.5 | apache traffic_server Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue | 1,0% | — |
| CVE-2023-38435 | MED 6.1 | apache felix_health_check_webconsole_plugin An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack. | 2,2% | — |
| CVE-2023-38434 | HIGH 7.5 | xhttp_project xhttp xHTTP 72f812d has a double free in close_connection in xhttp.c via a malformed HTTP request method. | 1,1% | — |
| CVE-2023-38432 | CRIT 9.1 | linux linux_kernel An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relationship between the command payload size and the RFC1002 length specification, leading to an out-of-bounds read. | 2,5% | — |
| CVE-2023-38431 | CRIT 9.1 | linux linux_kernel An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/connection.c in ksmbd does not validate the relationship between the NetBIOS header's length field and the SMB header sizes, via pdu_size in ksmbd_conn_handler_loop, leading to an out-of-b | 1,2% | — |
| CVE-2023-38430 | CRIT 9.1 | linux linux_kernel An issue was discovered in the Linux kernel before 6.3.9. ksmbd does not validate the SMB request protocol ID, leading to an out-of-bounds read. | 1,2% | — |
| CVE-2023-38429 | CRIT 9.8 | linux linux_kernel An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbd_smb2_check_message) that may lead to out-of-bounds access. | 1,2% | — |
| CVE-2023-38428 | CRIT 9.1 | linux linux_kernel An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserName value because it does not consider the address of security buffer, leading to an out-of-bounds read. | 3,2% | — |
| CVE-2023-38427 | CRIT 9.8 | linux linux_kernel An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/smb2pdu.c in ksmbd has an integer underflow and out-of-bounds read in deassemble_neg_contexts. | 1,2% | — |
| CVE-2023-38426 | CRIT 9.1 | linux linux_kernel An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bounds read in smb2_find_context_vals when create_context's name_len is larger than the tag length. | 3,0% | — |
| CVE-2023-38423 | MED 5.4 | f5 big-ip_access_policy_manager A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical | 0,3% | — |
| CVE-2023-38419 | MED 4.3 | f5 big-ip_access_policy_manager An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,5% | — |
| CVE-2023-38418 | HIGH 7.8 | f5 access_policy_manager_clients The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,1% | — |
| CVE-2023-38409 | MED 5.5 | linux linux_kernel An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because an assignment occurs only for the first vc, the fbcon_registered_fb and fbcon_display arrays can be desynchronized in fbcon_mode_deleted (t | 0,2% | — |
| CVE-2023-38403 | HIGH 7.5 | apple macos iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field. | 2,0% | — |
| CVE-2023-38402 | HIGH 7.1 | hp aruba_virtual_intranet_access A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM. A successful exploit could allow these malicious users to create a Denial-of-Service (DoS) conditi | 0,2% | — |
| CVE-2023-38401 | HIGH 7.8 | hp aruba_virtual_intranet_access A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow local users to elevate privileges. Successful exploitation could allow execution of arbitrary code with NT AUTHORITY\SYSTEM privileges on the operating system. | 0,2% | — |
| CVE-2023-38364 | MED 6.1 | ibm cics_tx IBM CICS TX Advanced 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | 0,5% | — |