57.361 CVE seguite
782 Sfruttate ora
186 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.361 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2023-23480 | MED 5.4 | ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disc | 0,4% | — |
| CVE-2023-23477 | HIGH 8.1 | ibm websphere_application_server IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. IBM X-Force ID: 245513. | 1,9% | — |
| CVE-2023-23475 | MED 4.6 | ibm infosphere_information_server IBM Infosphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust | 0,3% | — |
| CVE-2023-23472 | LOW 3.1 | ibm infosphere_information_server IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system. | 0,3% | — |
| CVE-2023-23459 | CRIT 9.1 | priority-software priority Priority Windows may allow Command Execution via SQL Injection using an unspecified method. | 0,9% | — |
| CVE-2023-23455 | MED 5.5 | debian debian_linux atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results). | 0,3% | — |
| CVE-2023-23454 | MED 5.5 | debian debian_linux cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid class | 0,3% | — |
| CVE-2023-23423 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2023-23422 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2023-23421 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2023-23420 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2023-23419 | HIGH 7.8 | microsoft windows_11_22h2 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2023-23418 | HIGH 7.8 | microsoft windows_11_22h2 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2023-23417 | HIGH 7.8 | microsoft windows_10_1607 Windows Partition Management Driver Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2023-23416 | HIGH 7.8 | microsoft windows_10_1507 Windows Cryptographic Services Remote Code Execution Vulnerability | 7,6% | — |
| CVE-2023-23415 | CRIT 9.8 | microsoft windows_10_1507 Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability | 3,5% | — |
| CVE-2023-23414 | HIGH 7.1 | microsoft windows_10_1507 Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability | 0,4% | — |
| CVE-2023-23413 | HIGH 8.8 | microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2023-23412 | HIGH 7.8 | microsoft windows_10_1507 Windows Accounts Picture Elevation of Privilege Vulnerability | 0,3% | — |
| CVE-2023-23411 | MED 6.5 | microsoft windows_10_1507 Windows Hyper-V Denial of Service Vulnerability | 0,6% | — |
| CVE-2023-23410 | HIGH 7.8 | microsoft windows_10_1507 Windows HTTP.sys Elevation of Privilege Vulnerability | 8,0% | — |
| CVE-2023-23409 | MED 5.5 | microsoft windows_10_1507 Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability | 0,5% | — |
| CVE-2023-23408 | MED 4.5 | microsoft azure_hdinsight Azure Apache Ambari Spoofing Vulnerability | 4,0% | — |
| CVE-2023-23407 | HIGH 7.1 | microsoft windows_10_1507 Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability | 0,4% | — |
| CVE-2023-23406 | HIGH 8.8 | microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | 1,3% | — |