Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2023-32015
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Windows 10 1507
10.0.10240.19983 / 10.0.14393.5989+
MEDIUM 6.5
CVE-2023-32032
.NET and Visual Studio Elevation of Privilege Vulnerability
.net
7.0.7 / 17.0.22+
HIGH 7.8
CVE-2023-29359
GDI Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.19983 / 10.0.14393.5989+
HIGH 7.8
CVE-2023-29371EPSS 5%
Windows GDI Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.19983 / 10.0.14393.5989+
MEDIUM 5.5
CVE-2023-29353
Sysinternals Process Monitor for Windows Denial of Service Vulnerability
Sysinternals
3.94 / 2023.6+
HIGH 7.2
CVE-2023-2454
schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with el…
PostgreSQL
11.20 / 12.15+
MEDIUM 5.4
CVE-2023-2455
Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-…
PostgreSQL
11.20 / 12.15+
HIGH 8.8
CVE-2023-1888
The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4. This is due to a lack…
Directorist
after 7.5.4
CRITICAL 9.1
CVE-2023-34239
Gradio is an open-source Python library that is used to build machine learning and data science. Due to a lack of path filtering Gradio does not prop…
Gradio
3.34.0+
CRITICAL 9.8
CVE-2023-34111
The `Release PR Merged` workflow in the github repo taosdata/grafanaplugin is subject to a command injection vulnerability which allows for arbitrary…
Grafana
after 2023-05-22
HIGH 7.8
CVE-2023-21656
Memory corruption in WLAN HOST while receiving an WMI event from firmware.
Ar8035 Firmware
Patch available
HIGH 7.8
CVE-2023-21657
Memoru corruption in Audio when ADSP sends input during record use case.
Csra6620 Firmware
Patch available
HIGH 8.8
CVE-2023-34102
Avo is an open source ruby on rails admin panel creation framework. The polymorphic field type stores the classes to operate on when updating a recor…
Avo
after 2.33.2
HIGH 7.5
CVE-2023-32690
libspdm is a sample implementation that follows the DMTF SPDM specifications. Prior to versions 2.3.3 and 3.0, following a successful CAPABILITIES re…
Libspdm
2.3.3+
MEDIUM 6.8
CVE-2022-4332
In Sprecher Automation SPRECON-E-C/P/T3 CPU in variant PU244x a vulnerable firmware verification has been identified. Through physical access and har…
Sprecon E P Dq6 1 Firmware
Mitigation only
HIGH 7.5
CVE-2023-33964
mx-chain-go is an implementation of the MultiversX blockchain protocol written in the Go language. Metachain cannot process a cross-shard miniblock. …
Mx Chain Go
1.4.16+
CRITICAL 9.8
CVE-2023-34152EPSS 8%
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
Fedora
7.1.1-11+
HIGH 7.7
CVE-2023-0779
At the most basic level, an invalid pointer can be input that crashes the device, but with more knowledge of the device’s memory layout, further expl…
Zephyr
after 3.2.0
MEDIUM 6.1
CVE-2023-23754
An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection s…
Joomla\!
4.3.2+
MEDIUM 5.3
CVE-2023-2808
Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink, allowing an attacker to tr…
Mattermost
7.1.9 / 7.8.4+
HIGH 8.1
CVE-2023-2942
Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.1.
Openemr
7.0.1+
HIGH 7.5
CVE-2023-32695
socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol. A specially crafted Socket.…
Socket.io Parser
3.4.3 / 4.2.3+
HIGH 7.5
CVE-2023-32688
parse-server-push-adapter is the official Push Notification adapter for Parse Server. The Parse Server Push Adapter can crash Parse Server due to an …
Parse Server Push Adapter
4.1.3+
CRITICAL 9.8
CVE-2023-32321
CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have been discovered in Ckan which ma…
Ckan
2.9.9+
HIGH 8.8
CVE-2023-21514
Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install …
Galaxy Store
4.5.49.8+
HIGH 8.8
CVE-2023-21515
InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute jav…
Galaxy Store
4.5.49.8+
CRITICAL 9.6
CVE-2023-21516
XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy St…
Galaxy Store
4.5.49.8+
CRITICAL 9.8
CVE-2023-2868 KEVEPSS 87%
A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3…
Email Security Gateway 300 Firmware
after 9.2.0.006
MEDIUM 6.5
CVE-2021-25748
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the san…
Ingress Nginx
1.2.1+
HIGH 7.9
CVE-2023-30440
IBM PowerVM Hypervisor FW860.00 through FW860.B3, FW950.00 through FW950.70, FW1010.00 through FW1010.50, FW1020.00 through FW1020.30, and FW1030.00 …
Powervm Hypervisor
Mitigation only