57.084 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.084 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2023-37579 | HIGH 8.2 | apache pulsar Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Function Worker. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. Any authenticated user can retrieve a source's configuration or a sink's configuration without aut | 0,8% | — |
| CVE-2023-37544 | HIGH 7.5 | apache pulsar Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication. This issue affects Apache Pulsar WebSocket Proxy: from 2.8.0 through 2.8.*, from 2.9.0 through 2.9.*, from 2 | 1,4% | — |
| CVE-2023-37536 | HIGH 8.2 | apache xerces-c\+\+ An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request. | 1,4% | — |
| CVE-2023-37464 | HIGH 8.6 | cisco cjose OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). The AES GCM decryption routine incorrectly uses the Tag length from the actual Authentication Tag provided in the JWE. The spec says that a fixed length of 16 octet | 0,7% | — |
| CVE-2023-37454 | MED 5.5 | linux linux_kernel An issue was discovered in the Linux kernel through 6.4.2. A crafted UDF filesystem image causes a use-after-free write operation in the udf_put_super and udf_close_lvid functions in fs/udf/super.c. NOTE: the suse.com reference has a different perspective abou | 0,4% | — |
| CVE-2023-37453 | MED 4.6 | linux linux_kernel An issue was discovered in the USB subsystem in the Linux kernel through 6.4.2. There is an out-of-bounds and crash in read_descriptors in drivers/usb/core/sysfs.c. | 0,6% | — |
| CVE-2023-37415 | HIGH 8.8 | apache apache-airflow-providers-apache-hive Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider. Patching on top of CVE-2023-35797 Before 6.1.2 the proxy_user option can also inject semicolon. This issue affects Apache Airflow Apache Hive Provider: | 1,6% | — |
| CVE-2023-37401 | MED 5.3 | ibm aspera_faspex IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be trusted. | 0,2% | — |
| CVE-2023-37379 | HIGH 8.1 | apache airflow Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection edit privileges. This vulnerability allows the user to access connection information and exploit the test connect | 2,0% | — |
| CVE-2023-37244 | MED 5.3 | n-able automation_manager The affected AutomationManager.AgentService.exe application contains a TOCTOU race condition vulnerability that allows standard users to create a pseudo-symlink at C:\ProgramData\N-Able Technologies\AutomationManager\Temp, which could be leveraged by an attack | 0,2% | — |
| CVE-2023-37243 | HIGH 7.8 | atera agent_package_availability The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM when the system reboots. Since the C:\Windows\Temp\Agent.Package.Availability folder inherits permissions from C:\Windows\Temp and Agent.Pack | 0,2% | — |
| CVE-2023-37143 | MED 5.5 | microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function BackwardPass::IsEmptyLoopAfterMemOp(). | 0,8% | — |
| CVE-2023-37142 | MED 5.5 | microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::HasInlinees(). | 0,8% | — |
| CVE-2023-37141 | MED 5.5 | microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::ProfilingHelpers::ProfiledNewScArray(). | 0,8% | — |
| CVE-2023-37140 | MED 5.5 | microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::DiagScopeVariablesWalker::GetChildrenCount(). | 0,8% | — |
| CVE-2023-37139 | MED 5.5 | microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a stack overflow vulnerability via the function Js::ScopeSlots::IsDebuggerScopeSlotArray(). | 0,9% | — |
| CVE-2023-36914 | MED 5.5 | microsoft windows_10_21h2 Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability | 0,6% | — |
| CVE-2023-36913 | MED 6.5 | microsoft windows_10 Microsoft Message Queuing Information Disclosure Vulnerability | 1,7% | — |
| CVE-2023-36912 | HIGH 7.5 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2,1% | — |
| CVE-2023-36911 | CRIT 9.8 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1,7% | — |
| CVE-2023-36910 | CRIT 9.8 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 2,5% | — |
| CVE-2023-36909 | MED 6.5 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2,1% | — |
| CVE-2023-36908 | MED 6.5 | microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability | 1,0% | — |
| CVE-2023-36907 | MED 5.5 | microsoft windows_10 Windows Cryptographic Services Information Disclosure Vulnerability | 1,7% | — |
| CVE-2023-36906 | MED 5.5 | microsoft windows_10 Windows Cryptographic Services Information Disclosure Vulnerability | 2,0% | — |