56.794 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.794 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-32549 | MED 5.3 | apache sling_api Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files. | 2,3% | — |
| CVE-2022-31772 | MED 5.3 | ibm mq IBM MQ 8.0, 9.0 LTS, 9.1 CD, 9.1 LTS, 9.2 CD, and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service to the MQTT channels. IBM X-Force ID: 228335. | 0,7% | — |
| CVE-2022-31769 | MED 5.3 | ibm spectrum_copy_data_management IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 could allow a remote attacker to view product configuration information stored in PostgreSQL, which could be used in further attacks against the system. IBM X-Force ID: 228219. | 1,2% | — |
| CVE-2022-31711 | MED 5.3 | vmware vrealize_log_insight VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authentication. | 21,7% | — |
| CVE-2022-31701 | MED 5.3 | vmware access VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3. | 0,5% | — |
| CVE-2022-31698 | MED 5.3 | vmware cloud_foundation The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to trigger a denial-of-service condition by sending a specially crafted hea | 47,8% | — |
| CVE-2022-30532 | MED 5.3 | octopus octopus_server In affected versions of Octopus Deploy, there is no logging of changes to artifacts within Octopus Deploy. | 0,5% | — |
| CVE-2022-30299 | MED 5.3 | fortinet fortiweb A path traversal vulnerability [CWE-23] in the API of FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versions, 6.2 all versions, 6.1 all versions, 6.0 all versions may allow an authenticated attacker to retrieve specific parts of files from the un | 0,5% | — |
| CVE-2022-30154 | MED 5.3 | microsoft windows_10 Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege Vulnerability | 1,6% | — |
| CVE-2022-29526 | MED 5.3 | fedoraproject fedora Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible. | 2,8% | — |
| CVE-2022-29480 | MED 5.3 | f5 big-ip_access_policy_manager On F5 BIG-IP 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when multiple route domains are configured, undisclosed requests to big3d can cause an increase in CPU resource utilization. Note: Software versions which have reached End of | 0,9% | — |
| CVE-2022-29479 | MED 5.3 | f5 big-ip_access_policy_manager On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, and F5 BIG-IQ Centralized Management all versions of 8.x and 7.x, when an IPv6 self IP address is configu | 0,9% | — |
| CVE-2022-28614 | MED 5.3 | apache http_server The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function. Modules compiled and distribu | 5,0% | — |
| CVE-2022-28330 | MED 5.3 | apache http_server Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module. | 3,8% | — |
| CVE-2022-27516 | MED 5.3 | citrix application_delivery_controller_firmware User login brute force protection functionality bypass | 0,6% | — |
| CVE-2022-27512 | MED 5.3 | citrix application_delivery_management Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM. | 0,9% | — |
| CVE-2022-27182 | MED 5.3 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, when BIG-IP packet filters are enabled and a virtual server is configured with the type set to Reject, undisclosed requests can cause an i | 0,9% | — |
| CVE-2022-27181 | MED 5.3 | f5 big-ip_access_policy_manager On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when APM is configured on a virtual server and the associated acce | 0,9% | — |
| CVE-2022-26910 | MED 5.3 | microsoft skype_for_business_server Skype for Business and Lync Spoofing Vulnerability | 2,3% | — |
| CVE-2022-26907 | MED 5.3 | microsoft azure_sdk_for_.net Azure SDK for .NET Information Disclosure Vulnerability | 2,2% | — |
| CVE-2022-2663 | MED 5.3 | debian debian_linux An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly matches the message. A firewall may be able to be bypassed when users are using unencrypted IRC with nf_conntrack_irc configured. | 3,2% | — |
| CVE-2022-26130 | MED 5.3 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when an Active mode-enabled FTP profile is configured on a virtual server, undisclosed traffic can cause | 0,9% | — |
| CVE-2022-2602 | MED 5.3 | canonical ubuntu_linux io_uring UAF, Unix SCM garbage collection | 1,4% | — |
| CVE-2022-25990 | MED 5.3 | f5 f5os-a On 1.0.x versions prior to 1.0.1, systems running F5OS-A software may expose certain registry ports externally. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0,7% | — |
| CVE-2022-2588 | MED 5.3 | canonical ubuntu_linux It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if its handle had the value 0. | 5,9% | — |