Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2023-37546
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with in…
Control For Beaglebone Sl
4.10.0.0+
MEDIUM 6.5
CVE-2023-37547
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with in…
Control For Beaglebone Sl
4.10.0.0+
MEDIUM 6.5
CVE-2023-37548
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with in…
Control For Beaglebone Sl
4.10.0.0+
MEDIUM 6.5
CVE-2023-37545
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with in…
Control For Beaglebone Sl
4.10.0.0+
MEDIUM 6.5
CVE-2022-4911
Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass content security policy via a cr…
Chrome
106.0.5249.62+
MEDIUM 6.5
CVE-2022-4925
Insufficient validation of untrusted input in QUIC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform header splitting via m…
Chrome
97.0.4692.71+
CRITICAL 9.8
CVE-2023-38495
Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1.11.5, 1.12.3, and 1.13.0, Cr…
Crossplane
1.11.5 / 1.12.3+
HIGH 7.5
CVE-2022-43713
Interactive Forms (IAF) in GX Software XperienCentral versions 10.33.1 until 10.35.0 was vulnerable to invalid data input because form validation cou…
Xperiencentral
after 10.35.0
HIGH 7.2
CVE-2023-28130EPSS 21%
Local user may lead to privilege escalation using Gaia Portal hostnames page.
Gaia Portal
No fix yet
HIGH 7.5
CVE-2022-2502
A vulnerability exists in the HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be e…
Rtu500 Firmware
Mitigation only
MEDIUM 6.5
CVE-2023-38502
TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to version 3.0.7.1, TDengine DataBase crashes on UDF…
Tdengine
3.0.7.1+
MEDIUM 5.3
CVE-2023-35944
Envoy is an open source edge and service proxy designed for cloud-native applications. Envoy allows mixed-case schemes in HTTP/2, however, some inter…
Envoy
1.23.12 / 1.24.10+
HIGH 8.8
CVE-2023-38060
Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate operations of the OTRS Generic I…
Otrs
7.0.45 / 8.0.35+
MEDIUM 5.4
CVE-2023-38057
An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject …
Survey
7.0.32 / 8.0.13+
HIGH 7.5
CVE-2023-37915
OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). OpenDDS crashes while parsing a ma…
Opendds
No fix yet
MEDIUM 6.1
CVE-2023-3466
Reflected Cross-Site Scripting (XSS)
Netscaler Application Delivery Controller
12.1-55.297 / 13.0-91.13+
MEDIUM 6.5
CVE-2022-43908
IBM Security Guardium 11.3 could allow an authenticated user to cause a denial of service due to improper input validation. IBM X-Force ID: 240903.
Security Guardium
Patch available
HIGH 7.5
CVE-2023-28513
IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.3 CD and IBM MQ Appliance 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.2 LTS, under certain configuration…
Mq
Patch available
HIGH 8.8
CVE-2023-3724
If a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share extension) when connecting to a malicious server, a default pr…
Wolfssl
5.6.2+
MEDIUM 6.3
CVE-2023-36888
Microsoft Edge for Android (Chromium-based) Tampering Vulnerability
Edge Chromium
114.0.1823.82+
MEDIUM 5.5
CVE-2023-3433
The "nickname" field within Savoir-faire Linux's Jami application is susceptible to a failed state when a user inserts special characters into the fi…
Jami
Patch available
MEDIUM 5.4
CVE-2023-3434
Improper Input Validation in the hyperlink interpretation in Savoir-faire Linux's Jami (version 20222284) on Windows.
This allows an attacker to se…
Jami
Patch available
MEDIUM 5.7
CVE-2023-30559
The firmware update package for the wireless card is not properly signed and can be modified.
Alaris 8015 Pcu Firmware
after 12.1.3
HIGH 7.5
CVE-2023-29451
Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server or a Zabbix Proxy.
Zabbix
after 6.4.4
MEDIUM 5.4
CVE-2023-29452EPSS 64%
Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attribution text” when selected “Oth…
Zabbix
after 6.0.17
MEDIUM 5.4
CVE-2023-29454
Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the applicat…
Frontend
after 6.0.16
MEDIUM 6.1
CVE-2023-29455
Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser…
Frontend
after 5.0.33
MEDIUM 5.4
CVE-2023-29456
URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL…
Frontend
after 6.4.3
MEDIUM 6.1
CVE-2023-29457
Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script can be activated through …
Frontend
after 6.0.17
HIGH 8.8
CVE-2023-37415
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider.
Patching on top of CVE-2023-35797
Before …
Apache Airflow Providers Apache Hive
6.1.2+