EN
56.580 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.580 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2022-24497 CRIT 9.8 microsoft windows_10 Windows Network File System Remote Code Execution Vulnerability 34,6%
CVE-2022-24491 CRIT 9.8 microsoft windows_10 Windows Network File System Remote Code Execution Vulnerability 33,5%
CVE-2022-24112 CRIT 9.8 apache apisix An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Ad 96,0%
CVE-2022-23943 CRIT 9.8 apache http_server Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions. 50,4%
CVE-2022-23305 CRIT 9.8 apache log4j By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate 66,5%
CVE-2022-22980 CRIT 9.8 vmware spring_data_mongodb A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized. 17,8%
CVE-2022-22978 CRIT 9.8 netapp active_iq_unified_manager In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression a 12,4%
CVE-2022-22972 CRIT 9.8 vmware cloud_foundation VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to a 56,3%
CVE-2022-22965 CRIT 9.8 cisco cx_cloud_agent A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot 99,7%
CVE-2022-22963 CRIT 9.8 oracle banking_branch In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local r 99,9%
CVE-2022-22956 CRIT 9.8 vmware identity_manager VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authent 50,7%
CVE-2022-22955 CRIT 9.8 vmware identity_manager VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authent 8,1%
CVE-2022-22954 CRIT 9.8 ransomware vmware cloud_foundation VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution. 100,0%
CVE-2022-22720 CRIT 9.8 apache http_server Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling 28,2%
CVE-2022-22487 CRIT 9.8 ibm spectrum_protect_server An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vulnerability using bru 1,4%
CVE-2022-22485 CRIT 9.8 ibm spectrum_protect_operations_center In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this 1,1%
CVE-2022-22425 CRIT 9.8 ibm infosphere_information_server "IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598." 1,1%
CVE-2022-22318 CRIT 9.8 ibm curam_social_program_management IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. 0,4%
CVE-2022-22317 CRIT 9.8 ibm curam_social_program_management IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281. 0,5%
CVE-2022-22012 CRIT 9.8 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 4,0%
CVE-2022-21907 CRIT 9.8 microsoft windows_10 HTTP Protocol Stack Remote Code Execution Vulnerability 92,8%
CVE-2022-21849 CRIT 9.8 microsoft windows_10 Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability 6,2%
CVE-2022-20861 CRIT 9.8 cisco nexus_dashboard Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilit 0,6%
CVE-2022-20858 CRIT 9.8 cisco nexus_dashboard Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilit 1,2%
CVE-2022-20857 CRIT 9.8 cisco nexus_dashboard Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilit 1,5%