57.056 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.056 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-26340 | MED 5.5 | adobe dimension Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requ | 0,3% | — |
| CVE-2023-26339 | MED 5.5 | adobe dimension Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requ | 0,3% | — |
| CVE-2023-26338 | MED 5.5 | adobe dimension Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requ | 0,3% | — |
| CVE-2023-25949 | MED 5.5 | intel aptio_v_uefi_firmware_integrator_tools Uncontrolled resource consumption in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access. | 0,2% | — |
| CVE-2023-25926 | MED 5.5 | ibm security_guardium_key_lifecycle_manager IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume m | 1,4% | — |
| CVE-2023-25878 | MED 5.5 | adobe substance_3d_stager Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this | 0,3% | — |
| CVE-2023-25877 | MED 5.5 | adobe substance_3d_stager Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this | 0,3% | — |
| CVE-2023-25876 | MED 5.5 | adobe substance_3d_stager Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this | 0,3% | — |
| CVE-2023-25875 | MED 5.5 | adobe substance_3d_stager Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this | 0,3% | — |
| CVE-2023-25608 | MED 5.5 | fortinet fortiap An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-W2 7.2.0 through 7.2.1, 7.0.3 through 7.0.5, 7.0.0 through 7.0.1, 6.4 all versions, 6.2 all versions, 6.0 all versions; Fort | 0,5% | — |
| CVE-2023-25604 | MED 5.5 | fortinet fortiguest An insertion of sensitive information into log file vulnerability in Fortinet FortiGuest 1.0.0 allows a local attacker to access plaintext passwords in the RADIUS logs. | 0,2% | — |
| CVE-2023-24945 | MED 5.5 | microsoft windows_10_1507 Windows iSCSI Target Service Information Disclosure Vulnerability | 0,6% | — |
| CVE-2023-24923 | MED 5.5 | microsoft onedrive Microsoft OneDrive for Android Information Disclosure Vulnerability | 0,8% | — |
| CVE-2023-24882 | MED 5.5 | microsoft onedrive Microsoft OneDrive for Android Information Disclosure Vulnerability | 0,7% | — |
| CVE-2023-24862 | MED 5.5 | microsoft windows_10_1507 Windows Secure Channel Denial of Service Vulnerability | 0,5% | — |
| CVE-2023-24486 | MED 5.5 | citrix workspace A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which t | 0,2% | — |
| CVE-2023-24484 | MED 5.5 | citrix workspace A malicious user can cause log files to be written to a directory that they do not have permission to write to. | 0,3% | — |
| CVE-2023-2430 | MED 5.5 | linux linux_kernel A vulnerability was found due to missing lock for IOPOLL flaw in io_cqring_event_overflow() in io_uring.c in Linux Kernel. This flaw allows a local attacker with user privilege to trigger a Denial of Service threat. | 0,2% | — |
| CVE-2023-23586 | MED 5.5 | linux linux_kernel Due to a vulnerability in the io_uring subsystem, it is possible to leak kernel memory information to the user process. timens_install calls current_is_single_threaded to determine if the current process is single-threaded, but this call does not consider io_u | 0,3% | — |
| CVE-2023-23455 | MED 5.5 | debian debian_linux atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results). | 0,3% | — |
| CVE-2023-23454 | MED 5.5 | debian debian_linux cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid class | 0,3% | — |
| CVE-2023-23409 | MED 5.5 | microsoft windows_10_1507 Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability | 0,5% | — |
| CVE-2023-23394 | MED 5.5 | microsoft windows_10_1507 Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability | 0,5% | — |
| CVE-2023-23391 | MED 5.5 | microsoft 365_copilot Office for Android Spoofing Vulnerability | 0,6% | — |
| CVE-2023-23006 | MED 5.5 | linux linux_kernel In the Linux kernel before 5.15.13, drivers/net/ethernet/mellanox/mlx5/core/steering/dr_domain.c misinterprets the mlx5_get_uars_page return value (expects it to be NULL in the error case, whereas it is actually an error pointer). | 0,2% | — |