57.136 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.136 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2023-36557 | HIGH 7.8 | microsoft windows_10_1507 PrintHTML API Remote Code Execution Vulnerability | 1,0% | — |
| CVE-2023-36556 | HIGH 8.8 | fortinet fortimail An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the same web domain via crafted HTTP or HTTP | 0,8% | — |
| CVE-2023-36555 | LOW 3.9 | fortinet fortios An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via the SAML and Security Fabric components. | 0,3% | — |
| CVE-2023-36554 | HIGH 8.1 | fortinet fortimanager A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows attacker to execute unauthorized code or commands via specially crafted HTTP requ | 0,8% | — |
| CVE-2023-36553 | CRIT 9.8 | fortinet fortisiem A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.3.3 and 5.2.5 through 5.2.8 and 5.2.1 through 5.2.2 and 5.1.0 through 5.1.3 and 5.0.0 through 5.0.1 and 4.10.0 | 1,9% | — |
| CVE-2023-36551 | MED 4.3 | fortinet fortisiem A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows attacker to information disclosure via a crafted http request. | 0,6% | — |
| CVE-2023-36550 | CRIT 9.8 | fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get req | 2,1% | — |
| CVE-2023-36549 | HIGH 8.8 | fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get req | 2,1% | — |
| CVE-2023-36548 | CRIT 9.8 | fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get req | 2,1% | — |
| CVE-2023-36547 | CRIT 9.8 | fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get req | 2,1% | — |
| CVE-2023-36543 | MED 6.5 | apache airflow Apache Airflow, versions before 2.6.3, has a vulnerability where an authenticated user can use crafted input to make the current request hang. It is recommended to upgrade to a version that is not affected | 1,6% | — |
| CVE-2023-36542 | HIGH 8.8 | apache nifi Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an authenticated and authorized user to configure a location that enables custom code execution. The resolution in | 1,9% | — |
| CVE-2023-36494 | MED 4.4 | f5 f5os-a Audit logs on F5OS-A may contain undisclosed sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,2% | — |
| CVE-2023-36439 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 4,9% | — |
| CVE-2023-36438 | HIGH 7.5 | microsoft windows_10_1507 Windows TCP/IP Information Disclosure Vulnerability | 1,8% | — |
| CVE-2023-36437 | HIGH 8.8 | microsoft azure_pipelines_agent Azure DevOps Server Remote Code Execution Vulnerability | 2,0% | — |
| CVE-2023-36436 | HIGH 7.8 | microsoft windows_10_1507 Windows MSHTML Platform Remote Code Execution Vulnerability | 1,0% | — |
| CVE-2023-36435 | HIGH 7.5 | microsoft .net Microsoft QUIC Denial of Service Vulnerability | 5,5% | — |
| CVE-2023-36434 | CRIT 9.8 | microsoft windows_10_1507 Windows IIS Server Elevation of Privilege Vulnerability | 2,4% | — |
| CVE-2023-36433 | MED 6.5 | microsoft dynamics_365 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | 1,9% | — |
| CVE-2023-36431 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2,4% | — |
| CVE-2023-36429 | MED 6.5 | microsoft dynamics_365 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | 2,0% | — |
| CVE-2023-36428 | MED 5.5 | microsoft windows_10_1507 Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | 0,8% | — |
| CVE-2023-36427 | HIGH 7.0 | microsoft windows_10_1809 Windows Hyper-V Elevation of Privilege Vulnerability | 1,5% | — |
| CVE-2023-36425 | HIGH 8.0 | microsoft windows_10_1507 Windows Distributed File System (DFS) Remote Code Execution Vulnerability | 1,5% | — |