Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Windows 10 1507 CRITICAL 9.8
CVE-2023-32015

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

Fix: 10.0.10240.19983 / 10.0.14393.5989+
Fix from $2,300 2023-06-14
.net MEDIUM 6.5
CVE-2023-32032

.NET and Visual Studio Elevation of Privilege Vulnerability

Fix: 7.0.7 / 17.0.22+
Fix from $1,600 2023-06-14
Windows 10 1507 HIGH 7.8
CVE-2023-29359

GDI Elevation of Privilege Vulnerability

Fix: 10.0.10240.19983 / 10.0.14393.5989+
Fix from $1,950 2023-06-14
Windows 10 1507 HIGH 7.8
CVE-2023-29371EPSS 5%

Windows GDI Elevation of Privilege Vulnerability

Fix: 10.0.10240.19983 / 10.0.14393.5989+
Fix from $1,950 2023-06-14
Sysinternals MEDIUM 5.5
CVE-2023-29353

Sysinternals Process Monitor for Windows Denial of Service Vulnerability

Fix: 3.94 / 2023.6+
Fix from $1,600 2023-06-14
PostgreSQL HIGH 7.2
CVE-2023-2454

schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with el…

Fix: 11.20 / 12.15+
Fix from $1,950 2023-06-09
PostgreSQL MEDIUM 5.4
CVE-2023-2455

Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-…

Fix: 11.20 / 12.15+
Fix from $1,600 2023-06-09
Directorist HIGH 8.8
CVE-2023-1888

The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4. This is due to a lack…

Fix: after 7.5.4
Fix from $1,950 2023-06-09
Gradio CRITICAL 9.1
CVE-2023-34239

Gradio is an open-source Python library that is used to build machine learning and data science. Due to a lack of path filtering Gradio does not prop…

Fix: 3.34.0+
Fix from $2,300 2023-06-08
Grafana CRITICAL 9.8
CVE-2023-34111

The `Release PR Merged` workflow in the github repo taosdata/grafanaplugin is subject to a command injection vulnerability which allows for arbitrary…

Fix: after 2023-05-22
Fix from $2,300 2023-06-06
Ar8035 Firmware HIGH 7.8
CVE-2023-21656

Memory corruption in WLAN HOST while receiving an WMI event from firmware.

Patch available
Fix from $1,950 2023-06-06
Csra6620 Firmware HIGH 7.8
CVE-2023-21657

Memoru corruption in Audio when ADSP sends input during record use case.

Patch available
Fix from $1,950 2023-06-06
Avo HIGH 8.8
CVE-2023-34102

Avo is an open source ruby on rails admin panel creation framework. The polymorphic field type stores the classes to operate on when updating a recor…

Fix: after 2.33.2
Fix from $1,950 2023-06-05
Libspdm HIGH 7.5
CVE-2023-32690

libspdm is a sample implementation that follows the DMTF SPDM specifications. Prior to versions 2.3.3 and 3.0, following a successful CAPABILITIES re…

Fix: 2.3.3+
Fix from $1,950 2023-06-01
Sprecon E P Dq6 1 Firmware MEDIUM 6.8
CVE-2022-4332

In Sprecher Automation SPRECON-E-C/P/T3 CPU in variant PU244x a vulnerable firmware verification has been identified. Through physical access and har…

Mitigation only
Fix from $1,600 2023-06-01
Mx Chain Go HIGH 7.5
CVE-2023-33964

mx-chain-go is an implementation of the MultiversX blockchain protocol written in the Go language. Metachain cannot process a cross-shard miniblock. …

Fix: 1.4.16+
Fix from $1,950 2023-05-31
Fedora CRITICAL 9.8
CVE-2023-34152EPSS 8%

A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.

Fix: 7.1.1-11+
Fix from $2,300 2023-05-30
Zephyr HIGH 7.7
CVE-2023-0779

At the most basic level, an invalid pointer can be input that crashes the device, but with more knowledge of the device’s memory layout, further expl…

Fix: after 3.2.0
Fix from $1,950 2023-05-30
Joomla\! MEDIUM 6.1
CVE-2023-23754

An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection s…

Fix: 4.3.2+
Fix from $1,600 2023-05-30
Mattermost MEDIUM 5.3
CVE-2023-2808

Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink, allowing an attacker to tr…

Fix: 7.1.9 / 7.8.4+
Fix from $1,600 2023-05-29
Openemr HIGH 8.1
CVE-2023-2942

Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.1.

Fix: 7.0.1+
Fix from $1,950 2023-05-27
Socket.io Parser HIGH 7.5
CVE-2023-32695

socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol. A specially crafted Socket.…

Fix: 3.4.3 / 4.2.3+
Fix from $1,950 2023-05-27
Parse Server Push Adapter HIGH 7.5
CVE-2023-32688

parse-server-push-adapter is the official Push Notification adapter for Parse Server. The Parse Server Push Adapter can crash Parse Server due to an …

Fix: 4.1.3+
Fix from $1,950 2023-05-27
Ckan CRITICAL 9.8
CVE-2023-32321

CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have been discovered in Ckan which ma…

Fix: 2.9.9+
Fix from $2,300 2023-05-26
Galaxy Store HIGH 8.8
CVE-2023-21514

Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install …

Fix: 4.5.49.8+
Fix from $1,950 2023-05-26
Galaxy Store HIGH 8.8
CVE-2023-21515

InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute jav…

Fix: 4.5.49.8+
Fix from $1,950 2023-05-26
Galaxy Store CRITICAL 9.6
CVE-2023-21516

XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy St…

Fix: 4.5.49.8+
Fix from $2,300 2023-05-26
Email Security Gateway 300 Firmware CRITICAL 9.8
CVE-2023-2868 KEVEPSS 87%

A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3…

Fix: after 9.2.0.006
Fix from $2,300 2023-05-24
Ingress Nginx MEDIUM 6.5
CVE-2021-25748

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the san…

Fix: 1.2.1+
Fix from $1,600 2023-05-24
Powervm Hypervisor HIGH 7.9
CVE-2023-30440

IBM PowerVM Hypervisor FW860.00 through FW860.B3, FW950.00 through FW950.70, FW1010.00 through FW1010.50, FW1020.00 through FW1020.30, and FW1030.00 …

Mitigation only
Fix from $1,950 2023-05-23