57.136 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.136 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2023-36701 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Resilient File System (ReFS) Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2023-36698 | MED 4.4 | microsoft windows_10_1809 Windows Kernel Security Feature Bypass Vulnerability | 0,5% | — |
| CVE-2023-36697 | MED 6.8 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 2,1% | — |
| CVE-2023-36696 | HIGH 7.8 | microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2023-36642 | MED 6.7 | fortinet fortitester An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 3.0.0 through 7.2.3 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments t | 0,2% | — |
| CVE-2023-36641 | MED 6.5 | fortinet fortios A numeric truncation error in Fortinet FortiProxy version 7.2.0 through 7.2.4, FortiProxy version 7.0.0 through 7.0.10, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1, all versions, FortiProxy 1.0 all versions, FortiOS version 7.4.0, | 1,3% | — |
| CVE-2023-36640 | MED 6.7 | fortinet fortios A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0.0 through 6.0.16, FortiPAM 1.1.0, FortiPAM 1.0 all vers | 0,3% | — |
| CVE-2023-36639 | HIGH 7.2 | fortinet fortios A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, FortiOS versions 7.4.0, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiPA | 1,1% | — |
| CVE-2023-36638 | MED 4.3 | fortinet fortianalyzer An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 al | 0,3% | — |
| CVE-2023-36637 | LOW 3.5 | fortinet fortimail An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to inject HTML tags in FortiMail's calendar via input fields. | 0,4% | — |
| CVE-2023-36635 | HIGH 7.1 | fortinet fortiswitchmanager An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2 7.0.0 through 7.0.1 may allow a remote authenticated read-only user to modify the interface settings via the API. | 0,4% | — |
| CVE-2023-36634 | HIGH 7.1 | fortinet fortiap-u An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to list and delete arbi | 0,5% | — |
| CVE-2023-36633 | MED 5.4 | fortinet fortimail An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests. | 0,5% | — |
| CVE-2023-36606 | HIGH 7.5 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 67,2% | — |
| CVE-2023-36605 | HIGH 7.4 | microsoft windows_10_1809 Windows Named Pipe Filesystem Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2023-36603 | HIGH 7.5 | microsoft windows_10_1809 Windows TCP/IP Denial of Service Vulnerability | 2,3% | — |
| CVE-2023-36602 | HIGH 7.5 | microsoft windows_10_1507 Windows TCP/IP Denial of Service Vulnerability | 2,3% | — |
| CVE-2023-36598 | HIGH 7.8 | microsoft windows_10_1507 Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability | 1,0% | — |
| CVE-2023-36596 | HIGH 7.5 | microsoft windows_10_1507 Remote Procedure Call Information Disclosure Vulnerability | 2,0% | — |
| CVE-2023-36594 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability | 11,6% | — |
| CVE-2023-36593 | HIGH 7.8 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1,0% | — |
| CVE-2023-36592 | HIGH 7.3 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1,0% | — |
| CVE-2023-36591 | HIGH 7.3 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2023-36590 | HIGH 7.3 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1,0% | — |
| CVE-2023-36589 | HIGH 7.3 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1,0% | — |