56.571 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.571 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-25696 | CRIT 9.8 | apache apache-airflow-providers-apache-hive Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3. | 2,0% | — |
| CVE-2023-25693 | CRIT 9.8 | apache apache-airflow-providers-apache-sqoop Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1. | 1,9% | — |
| CVE-2023-25691 | CRIT 9.8 | apache apache-airflow-providers-google Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0. | 1,6% | — |
| CVE-2023-25690 | CRIT 9.8 | apache http_server Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pa | 84,5% | — |
| CVE-2023-25613 | CRIT 9.8 | apache kerby_ldap_backend An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3. | 1,5% | — |
| CVE-2023-25610 | CRIT 9.8 | fortinet fortianalyzer A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2 | 18,2% | — |
| CVE-2023-25143 | CRIT 9.8 | trendmicro apex_one An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote code execution state on affected products. | 1,7% | — |
| CVE-2023-24997 | CRIT 9.8 | apache inlong Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inl | 1,4% | — |
| CVE-2023-24943 | CRIT 9.8 | microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | 4,7% | — |
| CVE-2023-24941 | CRIT 9.8 | microsoft windows_server_2012 Windows Network File System Remote Code Execution Vulnerability | 94,7% | — |
| CVE-2023-24831 | CRIT 9.8 | apache iotdb Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 through 0.13.3. Attackers could login without authorization. This is fixed in 0.13.4. | 1,2% | — |
| CVE-2023-24489 | CRIT 9.8 | citrix sharefile_storage_zones_controller A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller. | 94,4% | |
| CVE-2023-23415 | CRIT 9.8 | microsoft windows_10_1507 Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability | 3,5% | — |
| CVE-2023-23397 | CRIT 9.8 | microsoft 365_apps Microsoft Outlook Elevation of Privilege Vulnerability | 97,4% | |
| CVE-2023-23392 | CRIT 9.8 | microsoft windows_11_21h2 HTTP Protocol Stack Remote Code Execution Vulnerability | 1,7% | — |
| CVE-2023-22884 | CRIT 9.8 | apache airflow Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1; Apache Air | 11,1% | — |
| CVE-2023-21803 | CRIT 9.8 | microsoft windows_10 Windows iSCSI Discovery Service Remote Code Execution Vulnerability | 1,8% | — |
| CVE-2023-21716 | CRIT 9.8 | microsoft office Microsoft Word Remote Code Execution Vulnerability | 82,3% | — |
| CVE-2023-21709 | CRIT 9.8 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 2,0% | — |
| CVE-2023-21708 | CRIT 9.8 | microsoft windows_10_1507 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 1,5% | — |
| CVE-2023-21692 | CRIT 9.8 | microsoft windows_10_1507 Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | 21,2% | — |
| CVE-2023-21690 | CRIT 9.8 | microsoft windows_10_1507 Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | 27,5% | — |
| CVE-2023-21689 | CRIT 9.8 | microsoft windows_10_1507 Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | 26,5% | — |
| CVE-2023-21554 | CRIT 9.8 | microsoft windows_10_1607 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 95,5% | — |
| CVE-2023-20887 | CRIT 9.8 | vmware aria_operations_for_networks Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution. | 98,3% |