57.469 CVE seguite
782 Sfruttate ora
187 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.469 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2023-28228 | MED 5.5 | microsoft windows_10_1507 Windows Spoofing Vulnerability | 0,5% | — |
| CVE-2023-28227 | HIGH 7.5 | microsoft windows_10_1507 Windows Bluetooth Driver Remote Code Execution Vulnerability | 6,6% | — |
| CVE-2023-28226 | MED 5.3 | microsoft windows_10_1507 Windows Enroll Engine Security Feature Bypass Vulnerability | 0,7% | — |
| CVE-2023-28225 | HIGH 7.8 | microsoft windows_10_1507 Windows NTLM Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2023-28224 | HIGH 7.1 | microsoft windows_10_1507 Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability | 0,4% | — |
| CVE-2023-28223 | MED 6.6 | microsoft windows_server_2008 Windows Domain Name Service Remote Code Execution Vulnerability | 1,1% | — |
| CVE-2023-28222 | HIGH 7.1 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2023-28221 | HIGH 7.0 | microsoft windows_10_1507 Windows Error Reporting Service Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2023-28220 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 15,0% | — |
| CVE-2023-28219 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 15,0% | — |
| CVE-2023-28218 | HIGH 7.0 | microsoft windows_10_1507 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 12,3% | — |
| CVE-2023-28217 | HIGH 7.5 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 1,9% | — |
| CVE-2023-28216 | HIGH 7.0 | microsoft windows_10_1507 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2023-28158 | MED 6.5 | apache archiva Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploited only by authenticated users which can create directory name to inject some XSS content and gain some privileges such admin user. | 1,2% | — |
| CVE-2023-28071 | MED 6.3 | dell alienware_update Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folde | 0,2% | — |
| CVE-2023-28065 | MED 6.7 | dell alienware_update Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability leading to privilege escalatio | 0,2% | — |
| CVE-2023-28005 | MED 6.8 | trendmicro trend_micro_endpoint_encryption A vulnerability in Trend Micro Endpoint Encryption Full Disk Encryption version 6.0.0.3204 and below could allow an attacker with physical access to an affected device to bypass Microsoft Windows� Secure Boot process in an attempt to execute other attacks to o | 0,2% | — |
| CVE-2023-28002 | MED 6.4 | fortinet fortios An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.12, 6.4 all versions, 6.2 all versions, 6.0 all versions and VMs may allow a local attacker with admin privileges to boot a malicious imag | 0,2% | — |
| CVE-2023-28001 | MED 4.1 | fortinet fortios An insufficient session expiration in Fortinet FortiOS 7.0.0 - 7.0.12 and 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via reusing the session of a deleted user in the REST API. | 0,5% | — |
| CVE-2023-28000 | MED 6.7 | fortinet fortiadc An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC CLI 7.1.0, 7.0.0 through 7.0.3, 6.2.0 through 6.2.4, 6.1 all versions, 6.0 all versions may allow a local and authenticated attacker to execute unauthorized | 0,2% | — |
| CVE-2023-27999 | HIGH 7.8 | fortinet fortiadc An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 7.2.0, 7.1.0 through 7.1.1 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands. | 0,5% | — |
| CVE-2023-27998 | MED 5.3 | fortinet fortipresence A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1.1 and 1.0 may allow an unauthenticated attacker with the ability to navigate to the login GUI to gain sensitive information via navigating | 0,4% | — |
| CVE-2023-27995 | HIGH 7.2 | fortinet fortisoar A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload. | 1,1% | — |
| CVE-2023-27993 | MED 6.0 | fortinet fortiadc A relative path traversal [CWE-23] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a privileged attacker to delete arbitrary directories from the underlying file system via crafted CLI commands. | 0,2% | — |
| CVE-2023-27987 | CRIT 9.1 | apache linkis In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy for attackers to obtain the default token for the attack. Generation rules should add random values. We recommend users upgrade the vers | 0,8% | — |