56.571 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.571 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-39864 | CRIT 9.8 | apache cloudstack The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integration.api.port global setting) for internal portal integrations and for testing purposes. By default, the integrati | 1,8% | — |
| CVE-2024-39462 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: clk: bcm: dvp: Assign ->num before accessing ->hws Commit f316cdff8d67 ("clk: Annotate struct clk_hw_onecell_data with __counted_by") annotated the hws member of 'struct clk_hw_onecell_data' | 0,8% | — |
| CVE-2024-39293 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Revert "xsk: Support redirect to any socket bound to the same umem" This reverts commit 2863d665ea41282379f108e4da6c8a2366ba66db. This patch introduced a potential kernel crash when multipl | 0,3% | — |
| CVE-2024-38856 | CRIT 9.8 | apache ofbiz Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code o | 99,4% | |
| CVE-2024-38812 | CRIT 9.8 | vmware cloud_foundation The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to | 54,6% | |
| CVE-2024-38570 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix potential glock use-after-free on unmount When a DLM lockspace is released and there ares still locks in that lockspace, DLM will unlock those locks automatically. Commit fb6791d1 | 0,7% | — |
| CVE-2024-38544 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix seg fault in rxe_comp_queue_pkt In rxe_comp_queue_pkt() an incoming response packet skb is enqueued to the resp_pkts queue and then a decision is made whether to run the comple | 0,8% | — |
| CVE-2024-38476 | CRIT 9.8 | apache http_server Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2 | 41,6% | — |
| CVE-2024-38474 | CRIT 9.8 | apache http_server Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be execu | 2,5% | — |
| CVE-2024-38346 | CRIT 9.8 | apache cloudstack The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and CloudStack management server hosts. Some of these commands were found to have command injection vulnerabilities | 3,3% | — |
| CVE-2024-38199 | CRIT 9.8 | microsoft windows_10_1507 Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2024-38183 | CRIT 9.8 | microsoft groupme An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2024-38140 | CRIT 9.8 | microsoft windows_10_1507 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | 3,8% | — |
| CVE-2024-38077 | CRIT 9.8 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | 75,4% | — |
| CVE-2024-38076 | CRIT 9.8 | microsoft windows_server_2016 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2024-38074 | CRIT 9.8 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2024-38063 | CRIT 9.8 | microsoft windows_10_1507 Windows TCP/IP Remote Code Execution Vulnerability | 70,6% | — |
| CVE-2024-37385 | CRIT 9.8 | roundcube webmail Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641. | 1,5% | — |
| CVE-2024-37084 | CRIT 9.8 | vmware spring_cloud_data_flow In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server | 35,2% | — |
| CVE-2024-37080 | CRIT 9.8 | vmware vcenter_server vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remo | 12,5% | — |
| CVE-2024-37079 | CRIT 9.8 | vmware cloud_foundation vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remo | 22,4% | |
| CVE-2024-36958 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix nfsd4_encode_fattr4() crasher Ensure that args.acl is initialized early. It is used in an unconditional call to kfree() on the way out of nfsd4_encode_fattr4(). | 0,5% | — |
| CVE-2024-36911 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Don't free decrypted memory In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error is returned and | 0,6% | — |
| CVE-2024-36886 | CRIT 9.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in error path Sam Page (sam4k) working with Trend Micro Zero Day Initiative reported a UAF in the tipc_buf_append() error path: BUG: KASAN: slab-use-after-free in kfree_skb_li | 1,3% | — |
| CVE-2024-36522 | CRIT 9.8 | apache wicket The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when processing input from an untrusted source without validation. Users are recommended to upgrade to versions 10.1.0, 9.18.0 or 8.16.0, which fix t | 2,1% | — |