56.565 CVE seguite
773 Sfruttate ora
181 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.565 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2024-7965 | HIGH 8.8 | google chrome Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 18,4% | |
| CVE-2024-38856 | CRIT 9.8 | apache ofbiz Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code o | 99,4% | |
| CVE-2024-7971 | CRIT 9.6 | google chrome Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 20,5% | |
| CVE-2022-0185 | HIGH 8.4 | linux linux_kernel A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherw | 25,2% | |
| CVE-2021-31196 | HIGH 7.2 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 54,1% | |
| CVE-2024-38213 | MED 6.5 | microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability | 13,6% | |
| CVE-2024-38193 | HIGH 7.8 | microsoft windows_10_1507 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 27,6% | |
| CVE-2024-38189 | HIGH 8.8 | microsoft 365_apps Microsoft Project Remote Code Execution Vulnerability | 8,2% | |
| CVE-2024-38178 | HIGH 7.5 | microsoft windows_10_1507 Scripting Engine Memory Corruption Vulnerability | 41,4% | |
| CVE-2024-38107 | HIGH 7.8 | microsoft windows_10_1507 Windows Power Dependency Coordinator Elevation of Privilege Vulnerability | 1,6% | |
| CVE-2024-38106 | HIGH 7.0 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 6,3% | |
| CVE-2024-36971 | HIGH 7.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible UAF. RCU rules are that we must first | 2,7% | |
| CVE-2024-32113 | CRIT 9.8 | apache ofbiz Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue. | 99,4% | |
| CVE-2018-0824 | HIGH 8.8 | microsoft windows_10_1507 A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1 | 72,4% | |
| CVE-2024-37085 | MED 6.8 | ransomware vmware cloud_foundation VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere | 26,0% | |
| CVE-2012-4792 | HIGH 8.8 | microsoft internet_explorer Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnB | 78,8% | |
| CVE-2022-22948 | MED 6.5 | vmware cloud_foundation The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information. | 13,8% | |
| CVE-2024-38112 | HIGH 7.5 | microsoft windows_10_1507 Windows MSHTML Platform Spoofing Vulnerability | 84,2% | |
| CVE-2024-38080 | HIGH 7.8 | microsoft windows_11_21h2 Windows Hyper-V Elevation of Privilege Vulnerability | 7,1% | |
| CVE-2024-20399 | MED 6.0 | cisco nx-os A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insu | 4,3% | |
| CVE-2022-2586 | MED 5.3 | canonical ubuntu_linux It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted. | 10,5% | |
| CVE-2024-26169 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows Error Reporting Service Elevation of Privilege Vulnerability | 4,0% | |
| CVE-2024-4577 | CRIT 9.8 | ransomware fedoraproject fedora In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 | 100,0% | |
| CVE-2024-1086 | HIGH 7.8 | ransomware debian debian_linux A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_s | 28,1% | |
| CVE-2020-17519 | HIGH 7.5 | apache flink A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by | 97,9% |