EN
57.084 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.084 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2023-37579 HIGH 8.2 apache pulsar Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Function Worker. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. Any authenticated user can retrieve a source's configuration or a sink's configuration without aut 0,8%
CVE-2023-37544 HIGH 7.5 apache pulsar Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication. This issue affects Apache Pulsar WebSocket Proxy: from 2.8.0 through 2.8.*, from 2.9.0 through 2.9.*, from 2 1,4%
CVE-2023-37536 HIGH 8.2 apache xerces-c\+\+ An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request. 1,4%
CVE-2023-37464 HIGH 8.6 cisco cjose OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). The AES GCM decryption routine incorrectly uses the Tag length from the actual Authentication Tag provided in the JWE. The spec says that a fixed length of 16 octet 0,7%
CVE-2023-37454 MED 5.5 linux linux_kernel An issue was discovered in the Linux kernel through 6.4.2. A crafted UDF filesystem image causes a use-after-free write operation in the udf_put_super and udf_close_lvid functions in fs/udf/super.c. NOTE: the suse.com reference has a different perspective abou 0,4%
CVE-2023-37453 MED 4.6 linux linux_kernel An issue was discovered in the USB subsystem in the Linux kernel through 6.4.2. There is an out-of-bounds and crash in read_descriptors in drivers/usb/core/sysfs.c. 0,6%
CVE-2023-37415 HIGH 8.8 apache apache-airflow-providers-apache-hive Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider. Patching on top of CVE-2023-35797 Before 6.1.2 the proxy_user option can also inject semicolon. This issue affects Apache Airflow Apache Hive Provider: 1,6%
CVE-2023-37401 MED 5.3 ibm aspera_faspex IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be trusted. 0,2%
CVE-2023-37379 HIGH 8.1 apache airflow Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection edit privileges. This vulnerability allows the user to access connection information and exploit the test connect 2,0%
CVE-2023-37244 MED 5.3 n-able automation_manager The affected AutomationManager.AgentService.exe application contains a TOCTOU race condition vulnerability that allows standard users to create a pseudo-symlink at C:\ProgramData\N-Able Technologies\AutomationManager\Temp, which could be leveraged by an attack 0,2%
CVE-2023-37243 HIGH 7.8 atera agent_package_availability The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM when the system reboots. Since the C:\Windows\Temp\Agent.Package.Availability folder inherits permissions from C:\Windows\Temp and Agent.Pack 0,2%
CVE-2023-37143 MED 5.5 microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function BackwardPass::IsEmptyLoopAfterMemOp(). 0,8%
CVE-2023-37142 MED 5.5 microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::HasInlinees(). 0,8%
CVE-2023-37141 MED 5.5 microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::ProfilingHelpers::ProfiledNewScArray(). 0,8%
CVE-2023-37140 MED 5.5 microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::DiagScopeVariablesWalker::GetChildrenCount(). 0,8%
CVE-2023-37139 MED 5.5 microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a stack overflow vulnerability via the function Js::ScopeSlots::IsDebuggerScopeSlotArray(). 0,9%
CVE-2023-36914 MED 5.5 microsoft windows_10_21h2 Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability 0,6%
CVE-2023-36913 MED 6.5 microsoft windows_10 Microsoft Message Queuing Information Disclosure Vulnerability 1,7%
CVE-2023-36912 HIGH 7.5 microsoft windows_10 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 2,1%
CVE-2023-36911 CRIT 9.8 microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1,7%
CVE-2023-36910 CRIT 9.8 microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 2,5%
CVE-2023-36909 MED 6.5 microsoft windows_10 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 2,1%
CVE-2023-36908 MED 6.5 microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability 1,0%
CVE-2023-36907 MED 5.5 microsoft windows_10 Windows Cryptographic Services Information Disclosure Vulnerability 1,7%
CVE-2023-36906 MED 5.5 microsoft windows_10 Windows Cryptographic Services Information Disclosure Vulnerability 2,0%