57.148 CVE seguite
779 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.148 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2023-30268 | CRIT 9.8 | cltphp cltphp CLTPHP <=6.0 is vulnerable to Improper Input Validation. | 0,8% | — |
| CVE-2023-3022 | MED 5.5 | linux linux_kernel A flaw was found in the IPv6 module of the Linux kernel. The arg.result was not used consistently in fib6_rule_lookup, sometimes holding rt6_info and other times fib6_info. This was not accounted for in other parts of the code where rt6_info was expected uncon | 0,2% | — |
| CVE-2023-3006 | MED 5.5 | linux linux_kernel A known cache speculation vulnerability, known as Branch History Injection (BHI) or Spectre-BHB, becomes actual again for the new hw AmpereOne. Spectre-BHB is similar to Spectre v2, except that malicious code uses the shared branch history (stored in the CPU B | 0,3% | — |
| CVE-2023-2985 | MED 5.5 | linux linux_kernel A use after free flaw was found in hfsplus_put_super in fs/hfsplus/super.c in the Linux Kernel. This flaw could allow a local user to cause a denial of service problem. | 0,2% | — |
| CVE-2023-2984 | HIGH 8.8 | pimcore pimcore Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22. | 0,9% | — |
| CVE-2023-2971 | MED 6.3 | typora typora Improper path handling in Typora before 1.7.0-dev on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/typemark/". This vulnerability can be exploited if a user opens a malicious markdo | 0,5% | — |
| CVE-2023-29542 | CRIT 9.8 | mozilla firefox A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code. *This bug only affects Firefox an | 0,9% | — |
| CVE-2023-29532 | MED 5.5 | mozilla firefox A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-l | 0,2% | — |
| CVE-2023-29487 | CRIT 9.1 | heimdalsecurity thor An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to cause a denial of service (DoS) via the Threat To Process Correlation threat prevention module. NOTE: Heimdal asserts this is | 0,7% | — |
| CVE-2023-29486 | CRIT 9.8 | heimdalsecurity thor An issue was discovered in Heimdal Thor agent versions 3.4.2 and before 3.7.0 on Windows, allows attackers to bypass USB access restrictions, execute arbitrary code, and obtain sensitive information via Next-Gen Antivirus component. NOTE: Heimdal argues that t | 1,0% | — |
| CVE-2023-29485 | CRIT 9.8 | heimdalsecurity thor An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to bypass network filtering, execute arbitrary code, and obtain sensitive information via DarkLayer Guard threat prevention modul | 1,0% | — |
| CVE-2023-29413 | HIGH 7.5 | schneider-electric apc_easy_ups_online_monitoring_software A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor service. | 0,7% | — |
| CVE-2023-29412 | CRIT 9.8 | schneider-electric apc_easy_ups_online_monitoring_software CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface. | 1,2% | — |
| CVE-2023-29411 | CRIT 9.8 | schneider-electric apc_easy_ups_online_monitoring_software A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface. | 1,3% | — |
| CVE-2023-2939 | HIGH 7.8 | google chrome Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to perform privilege escalation via crafted symbolic link. (Chromium security severity: Medium) | 0,5% | — |
| CVE-2023-29373 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2023-29372 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2023-29371 | HIGH 7.8 | microsoft windows_10_1507 Windows GDI Elevation of Privilege Vulnerability | 5,4% | — |
| CVE-2023-29370 | HIGH 7.8 | microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-29369 | MED 6.5 | microsoft windows_server_2012 Remote Procedure Call Runtime Denial of Service Vulnerability | 2,0% | — |
| CVE-2023-29368 | HIGH 7.0 | microsoft windows_10_1507 Windows Filtering Platform Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2023-29367 | HIGH 7.8 | microsoft windows_server_2012 iSCSI Target WMI Provider Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-29366 | HIGH 7.8 | microsoft windows_10_21h2 Windows Geolocation Service Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-29365 | HIGH 7.8 | microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-29364 | HIGH 7.0 | microsoft windows_10_1507 Windows Authentication Elevation of Privilege Vulnerability | 0,4% | — |