57.139 CVE seguite
779 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.139 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2023-32022 | HIGH 7.6 | microsoft windows_server_2012 Windows Server Service Security Feature Bypass Vulnerability | 0,8% | — |
| CVE-2023-32021 | HIGH 7.1 | microsoft windows_server_2012 Windows SMB Witness Service Security Feature Bypass Vulnerability | 1,2% | — |
| CVE-2023-32020 | MED 5.6 | microsoft windows_server_2008 Windows DNS Spoofing Vulnerability | 0,7% | — |
| CVE-2023-32019 | MED 4.7 | microsoft windows_10_1607 Windows Kernel Information Disclosure Vulnerability | 1,4% | — |
| CVE-2023-32018 | HIGH 7.8 | microsoft windows_11_22h2 Windows Hello Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-32017 | HIGH 7.8 | microsoft windows_10_1507 Microsoft PostScript Printer Driver Remote Code Execution Vulnerability | 0,5% | — |
| CVE-2023-32016 | MED 5.5 | microsoft windows_10_1507 Windows Installer Information Disclosure Vulnerability | 0,7% | — |
| CVE-2023-32015 | CRIT 9.8 | microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | 2,0% | — |
| CVE-2023-32014 | CRIT 9.8 | microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2023-32013 | MED 5.3 | microsoft windows_10_1809 Windows Hyper-V Denial of Service Vulnerability | 1,6% | — |
| CVE-2023-32012 | HIGH 7.8 | microsoft windows_10_21h2 Windows Container Manager Service Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2023-32011 | HIGH 7.5 | microsoft windows_10_1507 Windows iSCSI Discovery Service Denial of Service Vulnerability | 1,9% | — |
| CVE-2023-32010 | HIGH 7.0 | microsoft windows_11_22h2 Windows Bus Filter Driver Elevation of Privilege Vulnerability | 0,3% | — |
| CVE-2023-32009 | HIGH 8.8 | microsoft windows_10_1607 Windows Collaborative Translation Framework Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2023-32008 | HIGH 7.8 | microsoft windows_10_1507 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-32007 | HIGH 8.8 | apache spark ** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACL | 76,0% | — |
| CVE-2023-3181 | HIGH 7.8 | splashtop mirroring360_receiver The C:\Program Files (x86)\Splashtop\Splashtop Software Updater\uninst.exe process creates a folder at C:\Windows\Temp~nsu.tmp and copies itself to it as Au_.exe. The C:\Windows\Temp~nsu.tmp\Au_.exe file is automatically launched as SYSTEM when the system rebo | 0,2% | — |
| CVE-2023-3161 | MED 5.5 | fedoraproject fedora A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width and font->height greater than 32 to fbcon_set_font, since there are no checks in place, a shift-out-of-bounds occurs leading to undefined behavior and possible | 0,2% | — |
| CVE-2023-3159 | MED 6.7 | linux linux_kernel A use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel. In this flaw a local attacker with special privilege may cause a use after free problem when queue_event() fails. | 0,2% | — |
| CVE-2023-31488 | CRIT 9.8 | cisco ironport_email_security_appliance Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, Cisco Secure Email Gateway, and various non-Cisco products, allow attackers to trigger a segmentation fault and execute arbit | 0,7% | — |
| CVE-2023-31469 | HIGH 8.8 | apache streampipes A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles. The issue is resolved by | 1,1% | — |
| CVE-2023-31454 | HIGH 7.5 | apache inlong Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. The attacker can bind any cluster, even if he is not the cluster owner. Users are advi | 1,2% | — |
| CVE-2023-31453 | HIGH 7.5 | apache inlong Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. The attacker can delete others' subscriptions, even if they are not the owner of the del | 1,2% | — |
| CVE-2023-31436 | HIGH 7.8 | linux linux_kernel qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed QFQ_MIN_LMAX. | 0,6% | — |
| CVE-2023-3141 | HIGH 7.1 | debian debian_linux A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak. | 0,4% | — |