57.298 CVE seguite
779 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.298 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2023-28350 | MED 6.1 | faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. Attacker-supplied input is not validated/sanitized before being rendered in both the Teacher and Student Console applications, enabling an attacker to execute JavaScript in these applications. | 1,1% | — |
| CVE-2023-28349 | HIGH 8.8 | faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a crafted program that functions similarly to the Teacher Console. This can compel Student Consoles to connect and put themselves at risk automatically. | 1,2% | — |
| CVE-2023-28348 | HIGH 7.4 | faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in-the-middle attack on either a connected student or teacher, enabling them to intercept student keystrokes or modify executable files being | 0,4% | — |
| CVE-2023-28347 | CRIT 9.6 | faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a proof-of-concept script that functions similarly to a Student Console, providing unauthenticated attackers with the ability to exploit XSS vulnerabili | 2,8% | — |
| CVE-2023-28346 | HIGH 7.3 | faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private API endpoints exposed at /login, /consoleSettings, /console, etc. despite Virtual Host Routing being used to block this acce | 0,9% | — |
| CVE-2023-28345 | MED 4.6 | faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application exposes the teacher's Console password in cleartext via an API endpoint accessible from localhost. Attackers with physical access to the Teacher Console | 0,3% | — |
| CVE-2023-28344 | HIGH 7.1 | faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers to view constantly updated screenshots of student desktops and to submit falsified screenshots on behalf of students. At | 0,9% | — |
| CVE-2023-28328 | MED 5.5 | linux linux_kernel A NULL pointer dereference flaw was found in the az6027 driver in drivers/media/usb/dev-usb/az6027.c in the Linux Kernel. The message from user space is not checked properly before transferring into the device. This flaw allows a local user to crash the system | 0,2% | — |
| CVE-2023-28327 | MED 5.5 | linux linux_kernel A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag.c In unix_diag_get_exact in the Linux Kernel. The newly allocated skb does not have sk, leading to a NULL pointer. This flaw allows a local user to crash or potentially cause a den | 0,2% | — |
| CVE-2023-28326 | CRIT 9.8 | apache openmeetings Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privileges in any room | 1,3% | — |
| CVE-2023-28314 | MED 6.1 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0,7% | — |
| CVE-2023-28313 | MED 6.1 | microsoft send_customer_voice_survey_from_dynamics_365 Microsoft Dynamics 365 Customer Voice Cross-Site Scripting Vulnerability | 0,7% | — |
| CVE-2023-28312 | MED 6.5 | microsoft azure_machine_learning Azure Machine Learning Information Disclosure Vulnerability | 1,8% | — |
| CVE-2023-28311 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 2,7% | — |
| CVE-2023-28310 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 25,0% | — |
| CVE-2023-28309 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0,7% | — |
| CVE-2023-28308 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2023-28307 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2023-28306 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2023-28305 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2023-28304 | HIGH 7.8 | microsoft odbc Microsoft ODBC and OLE DB Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2023-28303 | LOW 3.3 | microsoft snip_\&_sketch Windows Snipping Tool Information Disclosure Vulnerability | 2,0% | — |
| CVE-2023-28302 | HIGH 7.5 | microsoft windows_10_1607 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 92,6% | — |
| CVE-2023-28301 | LOW 3.7 | microsoft edge Microsoft Edge (Chromium-based) Tampering Vulnerability | 0,9% | — |
| CVE-2023-28300 | HIGH 7.5 | microsoft azure_service_connector Azure Service Connector Security Feature Bypass Vulnerability | 1,0% | — |