57.479 CVE seguite
782 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.479 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2023-25148 | HIGH 7.8 | trendmicro apex_one A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to exploit the vulnerability by changing a specific file into a pseudo-symlink, allowing privilege escalation on affected installations. Please note: an attac | 0,4% | — |
| CVE-2023-25147 | MED 6.7 | trendmicro apex_one An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the protection by using a specifically crafted DLL during a specific update process. Please note: an attacker must | 0,2% | — |
| CVE-2023-25146 | HIGH 7.8 | trendmicro apex_one A security agent link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to quarantine a file, delete the original folder and replace with a junction to an arbitrary location, ultimately leading to an arbitrary file dropped | 0,4% | — |
| CVE-2023-25145 | HIGH 7.8 | trendmicro apex_one A link following vulnerability in the scanning function of Trend Micro Apex One agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the | 0,4% | — |
| CVE-2023-25144 | HIGH 7.8 | trendmicro apex_one An improper access control vulnerability in the Trend Micro Apex One agent could allow a local attacker to gain elevated privileges and create arbitrary directories with arbitrary ownership. | 0,3% | — |
| CVE-2023-25143 | CRIT 9.8 | trendmicro apex_one An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote code execution state on affected products. | 1,7% | — |
| CVE-2023-25141 | HIGH 7.5 | apache sling_jcr_base Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or earlier) through utility functions in RepositoryAccessor. The functions getRepository and getRepositoryFromURL allow an application to access | 1,2% | — |
| CVE-2023-2513 | MED 6.7 | linux linux_kernel A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode size for extended attributes. This flaw could allow a privileged local user to cause a system crash or other undefined behaviors. | 0,2% | — |
| CVE-2023-25071 | MED 5.6 | intel arc_a_graphics NULL pointer dereference in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows Drviers before version 31.0.101.4255 may allow authenticated user to potentially enable denial of service via local access. | 0,2% | — |
| CVE-2023-25069 | HIGH 8.8 | trendmicro txone_stellarone TXOne StellarOne has an improper access control privilege escalation vulnerability in every version before V2.0.1160 that could allow a malicious, falsely authenticated user to escalate his privileges to administrator level. With these privileges, an attacker | 1,0% | — |
| CVE-2023-25012 | MED 4.6 | linux linux_kernel The Linux kernel through 6.1.9 has a Use-After-Free in bigben_remove in drivers/hid/hid-bigbenff.c via a crafted USB device because the LED controllers remain registered for too long. | 0,8% | — |
| CVE-2023-24998 | HIGH 7.5 | apache commons_fileupload Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the | 48,8% | — |
| CVE-2023-24997 | CRIT 9.8 | apache inlong Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inl | 1,4% | — |
| CVE-2023-24977 | HIGH 7.5 | apache inlong Out-of-bounds Read vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7214 h | 1,2% | — |
| CVE-2023-24965 | MED 5.8 | ibm aspera_faspex IBM Aspera Faspex 5.0.5 does not restrict or incorrectly restricts access to a resource from an unauthorized actor. IBM X-Force ID: 246713. | 0,5% | — |
| CVE-2023-24964 | MED 6.2 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information from a log files. IBM X-Force ID: 246463. | 0,1% | — |
| CVE-2023-24960 | HIGH 7.5 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 24 | 1,4% | — |
| CVE-2023-24954 | MED 6.5 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Information Disclosure Vulnerability | 1,8% | — |
| CVE-2023-24953 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-24950 | MED 6.5 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 67,5% | — |
| CVE-2023-24949 | HIGH 7.8 | microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability | 24,6% | — |
| CVE-2023-24948 | HIGH 7.4 | microsoft windows_10_1507 Windows Bluetooth Driver Elevation of Privilege Vulnerability | 1,0% | — |
| CVE-2023-24947 | HIGH 8.8 | microsoft windows_10_1607 Windows Bluetooth Driver Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-24946 | HIGH 7.8 | microsoft windows_10_1507 Windows Backup Service Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2023-24945 | MED 5.5 | microsoft windows_10_1507 Windows iSCSI Target Service Information Disclosure Vulnerability | 0,6% | — |