Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2023-5624
Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow an admin user to alter paramete…
Nessus Network Monitor
6.3.0+
HIGH 8.8
CVE-2023-5043
Ingress nginx annotation injection causes arbitrary command execution.
Ingress Nginx
1.9.0+
HIGH 8.8
CVE-2023-5044EPSS 57%
Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.
Ingress Nginx
1.9.0+
MEDIUM 6.5
CVE-2022-4886
Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.
Ingress Nginx
1.8.0+
HIGH 7.8
CVE-2021-26736
Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low …
Client Connector
3.6+
HIGH 7.8
CVE-2023-45805
pdm is a Python package and dependency manager supporting the latest PEP standards. It's possible to craft a malicious `pdm.lock` file that could all…
Pdm
0.11.2 / 2.10.0+
HIGH 7.5
CVE-2023-39456EPSS 53%
Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 th…
Traffic Server
9.2.3+
HIGH 7.1
CVE-2021-29913
IBM Security Verify Privilege On-Premise 11.5 could allow an authenticated user to obtain sensitive information or perform unauthorized actions due t…
Security Verify Privilege On Premises
11.5+
HIGH 7.5
CVE-2023-40372
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a specially crafted SQL statement usin…
Db2
after 11.5.8
HIGH 7.5
CVE-2023-40373
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to denial of service with a specially crafted query containing common…
Db2
after 11.5.8
HIGH 7.5
CVE-2023-30991
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to denial of service with a specially crafted query. I…
Db2
after 11.5.8
HIGH 7.5
CVE-2023-40374
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a specially crafted query statement. …
Db2
after 11.5.8
HIGH 7.5
CVE-2023-38740
IBM Db2 for Linux, UNIX, and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a specially crafted SQL statement. …
Db2
after 11.5.8
HIGH 7.5
CVE-2023-38728
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted XM…
Db2
11.5.8+
HIGH 8.8
CVE-2023-45128
Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, w…
Fiber
2.50.0+
HIGH 7.5
CVE-2023-30987
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu…
Db2
11.5.8+
HIGH 7.5
CVE-2023-38720
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 and 11.5 is vulnerable to denial of service with a specially crafted ALTER TAB…
Db2
11.5.8+
MEDIUM 5.5
CVE-2023-5421
An attacker who is logged into OTRS as an user with privileges to create and change customer user data may manipulate the CustomerID field to execute…
Otrs
7.0.47 / 8.0.37+
MEDIUM 5.5
CVE-2023-45176
IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.10.0 and IBM Integration Bus 10.1 through 10.1.0.1 are vulnerable to a d…
App Connect Enterprise
after 12.0.10.0
CRITICAL 9.1
CVE-2023-29464EPSS 10%
FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious pa…
Factorytalk Linx
Mitigation only
HIGH 7.5
CVE-2023-5571
Improper Input Validation in GitHub repository vriteio/vrite prior to 0.3.0.
Vrite
0.3.0+
MEDIUM 6.5
CVE-2023-44204
An Improper Validation of Syntactic Correctness of Input vulnerability in Routing Protocol Daemon (rpd) Juniper Networks Junos OS and Junos OS Evolve…
Junos
Mitigation only
HIGH 7.5
CVE-2023-44185
An Improper Input Validation vulnerability in the routing protocol daemon (rpd) of Juniper Networks allows an attacker to cause a Denial of Service (…
Junos
20.4+
HIGH 7.5
CVE-2023-44192
An Improper Input Validation vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS allows an unauthenticated, network-based atta…
Junos
20.4+
MEDIUM 5.3
CVE-2023-44183
An Improper Input Validation vulnerability in the VxLAN packet forwarding engine (PFE) of Juniper Networks Junos OS on QFX5000 Series, EX4600 Series …
Junos
Mitigation only
MEDIUM 5.4
CVE-2023-32721
A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL.
Zabbix
after 6.4.5
HIGH 7.5
CVE-2023-44103
Out-of-bounds read vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.
Harmonyos
No fix yet
MEDIUM 5.3
CVE-2023-45648EPSS 6%
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 thro…
Tomcat
8.5.94 / 9.0.81+
HIGH 7.8
CVE-2023-36731EPSS 8%
Win32k Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20232 / 10.0.14393.6351+
HIGH 8.0
CVE-2023-36697
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Windows 10
10.0.10240.20232 / 10.0.14393.6351+