Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2023-49248
Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause unauthorized file access.
Emui
No fix yet
MEDIUM 5.0
CVE-2023-40053
A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file share function feature of Ser…
Serv U
Mitigation only
CRITICAL 9.8
CVE-2023-41268
Improper input validation vulnerability in Samsung Open Source Escargot allows stack overflow and segmentation fault. This issue affects Escargot: fr…
Escargot
Patch available
HIGH 7.5
CVE-2023-5188
The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol Configurator is vulnerable to malformed packets. An…
Telecontrol Configurator
1.4.6.0+
HIGH 7.5
CVE-2023-33042
Transient DOS in Modem after RRC Setup message is received.
315 5g Iot Modem Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-48693
Azure RTOS ThreadX is an advanced real-time operating system (RTOS) designed specifically for deeply embedded applications. An attacker can cause arb…
Azure Rtos Threadx
6.3.0+
CRITICAL 9.8
CVE-2023-49291
tj-actions/branch-names is a Github action to retrieve branch or tag names with support for all events. The `tj-actions/branch-names` GitHub Actions …
Branch Names
7.0.0 / 7.0.7+
HIGH 7.8
CVE-2023-40097
In hasPermissionForActivity of PackageManagerHelper.java, there is a possible URI grant due to improper input validation. This could lead to local es…
Android
Patch available
MEDIUM 6.5
CVE-2023-47106
Traefik is an open source HTTP reverse proxy and load balancer. When a request is sent to Traefik with a URL fragment, Traefik automatically URL enco…
Traefik
after 2.10.5
HIGH 7.5
CVE-2023-40687
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted RU…
Db2
after 11.5.9
HIGH 7.5
CVE-2023-29258
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, and 11.5 is vulnerable to a denial of service through a specially crafted fed…
Db2
after 11.5.9
HIGH 7.5
CVE-2023-38727
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted SQ…
Db2
after 11.5.9
HIGH 7.5
CVE-2023-46167
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of service when a specially crafted…
Db2
after 11.5.8
HIGH 7.5
CVE-2023-47701
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu…
Db2
after 11.5.9
HIGH 7.5
CVE-2023-45178
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 CLI is vulnerable to a denial of service when a specially crafted request is u…
Db2
Patch available
HIGH 7.5
CVE-2023-40699
IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper input validation. IBM X-Force ID: …
Infosphere Information Server
11.7.1.0 / 11.7.1.4+
MEDIUM 6.5
CVE-2023-34390
An input validation vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote authenticated attacker to create a denial o…
Sel 451 Firmware
Mitigation only
MEDIUM 5.4
CVE-2023-2267
An Improper Input Validation vulnerability in Schweitzer Engineering Laboratories SEL-411L could allow an attacker to perform reflection attacks agai…
Sel 411l Firmware
No fix yet
HIGH 7.8
CVE-2023-2264
An improper input validation vulnerability in the Schweitzer Engineering Laboratories SEL-411L could allow a malicious actor to manipulate authorized…
Sel 411l Firmware
No fix yet
HIGH 7.5
CVE-2023-49095
nexkey is a microblogging platform. Insufficient validation of ActivityPub requests received in inbox could allow any user to impersonate another use…
Nexkey
12.122.2+
MEDIUM 5.3
CVE-2023-49081
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HT…
Aiohttp
3.9.0+
MEDIUM 5.3
CVE-2023-49082
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the H…
Aiohttp
3.9.0+
MEDIUM 5.5
CVE-2023-35136
An improper input validation vulnerability in the “Quagga” package of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmw…
Zld
after 5.37
HIGH 7.5
CVE-2023-48310
TestingPlatform is a testing platform for Internet Security Standards. Prior to version 2.1.1, user input is not filtered correctly. Nmap options are…
Testing Platform
2.1.1+
MEDIUM 5.9
CVE-2023-48223
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to version 3.3.2, the fast-jwt library does not properly prevent JWT algorithm conf…
Fast Jwt
3.3.2+
MEDIUM 5.3
CVE-2023-26364
@adobe/css-tools version 4.3.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a minor denial of service …
Css Tools
4.3.1+
HIGH 7.5
CVE-2023-22272
Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Input Validation vulnerability that could lead to information disclosure …
Robohelp Server
after 11.4
MEDIUM 6.1
CVE-2023-40314
Cross-site scripting in bootstrap.jsp in multiple versions of OpenNMS Meridian and Horizon allows an attacker access to confidential session informat…
Horizon
32.0.5 / 2023.1.9+
MEDIUM 6.7
CVE-2023-32469
Dell Precision Tower BIOS contains an Improper Input Validation vulnerability. A locally authenticated malicious user with admin privileges could pot…
Precision 5820 Firmware
2.32.0 / 2.36.0+
CRITICAL 9.8
CVE-2023-47003
An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBlock_ItemIsD…
Redisgraph
No fix yet