56.652 CVE seguite
776 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.652 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-20004 | MED 4.4 | cisco roomos Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. These vulnerabilities are due to improper access controls on files | 0,2% | — |
| CVE-2023-20002 | MED 4.4 | cisco roomos A vulnerability in Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to bypass access controls and conduct an SSRF attack through an affected device. This vulnerability is due to improper validation of user-supplied inpu | 0,2% | — |
| CVE-2023-0193 | MED 4.4 | nvidia cuda_toolkit NVIDIA CUDA Toolkit SDK contains a vulnerability in cuobjdump, where a local user running the tool against a malicious binary may cause an out-of-bounds read, which may result in a limited denial of service and limited information disclosure. | 0,2% | — |
| CVE-2023-0008 | MED 4.4 | paloaltonetworks pan-os A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition. | 0,5% | — |
| CVE-2022-44730 | MED 4.4 | apache xml_graphics_batik Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. A malicious SVG can probe user profile / data and send it directly as parameter to a URL. | 0,7% | — |
| CVE-2022-42432 | MED 4.4 | linux linux_kernel This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kernel 6.0-rc2. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerabi | 0,6% | — |
| CVE-2022-42259 | MED 4.4 | debian debian_linux NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of service. | 0,3% | — |
| CVE-2022-41066 | MED 4.4 | microsoft dynamics_365_business_central_2019 Microsoft Dynamics Business Central Information Disclosure Vulnerability | 1,1% | — |
| CVE-2022-39949 | MED 4.4 | fortinet fortiedr An improper control of a resource through its lifetime vulnerability [CWE-664] in FortiEDR CollectorWindows 4.0.0 through 4.1, 5.0.0 through 5.0.3.751, 5.1.0 may allow a privileged user to terminate the FortiEDR processes with special tools and bypass the EDR | 0,2% | — |
| CVE-2022-36416 | MED 4.4 | vmware ixgben Protection mechanism failure in the Intel(R) Ethernet 500 Series Controller drivers for VMware before version 1.10.0.13 may allow an authenticated user to potentially enable escalation of privilege via local access. | 0,2% | — |
| CVE-2022-35821 | MED 4.4 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 1,1% | — |
| CVE-2022-35783 | MED 4.4 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 1,6% | — |
| CVE-2022-34849 | MED 4.4 | intel iris_xe_max_dedicated_graphics Uncaught exception in the Intel(R) Iris(R) Xe MAX drivers for Windows before version 100.0.5.1436(v2) may allow a privileged user to potentially enable denial of service via local access. | 0,2% | — |
| CVE-2022-34667 | MED 4.4 | nvidia cuda_toolkit NVIDIA CUDA Toolkit SDK contains a stack-based buffer overflow vulnerability in cuobjdump, where an unprivileged remote attacker could exploit this buffer overflow condition by persuading a local user to download a specially crafted corrupted file and execute | 0,4% | — |
| CVE-2022-30531 | MED 4.4 | intel iris_xe_max_dedicated_graphics Out-of-bounds read in the Intel(R) Iris(R) Xe MAX drivers for Windows before version 100.0.5.1474 may allow a privileged user to potentially enable information disclosure via local access. | 0,2% | — |
| CVE-2022-26355 | MED 4.4 | citrix federated_authentication_service Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key St | 0,2% | — |
| CVE-2022-23446 | MED 4.4 | fortinet fortiedr A improper control of a resource through its lifetime in Fortinet FortiEDR version 5.0.3 and earlier allows attacker to make the whole application unresponsive via changing its root directory access permission. | 0,2% | — |
| CVE-2022-22307 | MED 4.4 | ibm security_guardium IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges due to incorrect authorization checks. IBM X-Force ID: 216753. | 0,2% | — |
| CVE-2022-22010 | MED 4.4 | microsoft windows_10 Media Foundation Information Disclosure Vulnerability | 2,6% | — |
| CVE-2022-21921 | MED 4.4 | microsoft windows_10 Windows Defender Credential Guard Security Feature Bypass Vulnerability | 0,9% | — |
| CVE-2022-21894 | MED 4.4 | microsoft windows_10 Secure Boot Security Feature Bypass Vulnerability | 6,6% | — |
| CVE-2022-20734 | MED 4.4 | cisco catalyst_sd-wan_manager A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, local attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privi | 0,2% | — |
| CVE-2022-20729 | MED 4.4 | cisco secure_firewall_threat_defense A vulnerability in CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject XML into the command parser. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability | 0,3% | — |
| CVE-2022-20630 | MED 4.4 | cisco catalyst_center A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive information in clear text. This vulnerability is due to the unsecured logging of sensitive information on an affected system. An attacker with a | 0,2% | — |
| CVE-2022-20107 | MED 4.4 | google android In subtitle service, there is a possible application crash due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330673; Issue ID: DTV0333 | 0,1% | — |