EN
56.565 CVE seguite
773 Sfruttate ora
181 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.565 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più alto
CVE-2024-7965 HIGH 8.8 google chrome Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 18,4%
CVE-2024-38856 CRIT 9.8 apache ofbiz Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code o 99,4%
CVE-2024-7971 CRIT 9.6 google chrome Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 20,5%
CVE-2022-0185 HIGH 8.4 linux linux_kernel A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherw 25,2%
CVE-2021-31196 HIGH 7.2 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 54,1%
CVE-2024-38213 MED 6.5 microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability 13,6%
CVE-2024-38193 HIGH 7.8 microsoft windows_10_1507 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 27,6%
CVE-2024-38189 HIGH 8.8 microsoft 365_apps Microsoft Project Remote Code Execution Vulnerability 8,2%
CVE-2024-38178 HIGH 7.5 microsoft windows_10_1507 Scripting Engine Memory Corruption Vulnerability 41,4%
CVE-2024-38107 HIGH 7.8 microsoft windows_10_1507 Windows Power Dependency Coordinator Elevation of Privilege Vulnerability 1,6%
CVE-2024-38106 HIGH 7.0 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 6,3%
CVE-2024-36971 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible UAF. RCU rules are that we must first 2,7%
CVE-2024-32113 CRIT 9.8 apache ofbiz Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue. 99,4%
CVE-2018-0824 HIGH 8.8 microsoft windows_10_1507 A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1 72,4%
CVE-2024-37085 MED 6.8 ransomware vmware cloud_foundation VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere 26,0%
CVE-2012-4792 HIGH 8.8 microsoft internet_explorer Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnB 78,8%
CVE-2022-22948 MED 6.5 vmware cloud_foundation The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information. 13,8%
CVE-2024-38112 HIGH 7.5 microsoft windows_10_1507 Windows MSHTML Platform Spoofing Vulnerability 84,2%
CVE-2024-38080 HIGH 7.8 microsoft windows_11_21h2 Windows Hyper-V Elevation of Privilege Vulnerability 7,1%
CVE-2024-20399 MED 6.0 cisco nx-os A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insu 4,3%
CVE-2022-2586 MED 5.3 canonical ubuntu_linux It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted. 10,5%
CVE-2024-26169 HIGH 7.8 ransomware microsoft windows_10_1507 Windows Error Reporting Service Elevation of Privilege Vulnerability 4,0%
CVE-2024-4577 CRIT 9.8 ransomware fedoraproject fedora In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 100,0%
CVE-2024-1086 HIGH 7.8 ransomware debian debian_linux A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_s 28,1%
CVE-2020-17519 HIGH 7.5 apache flink A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by 97,9%