Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2023-0896
A default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device access to an attacker with l…
Smart Clock Essential With Alexa Built In Firmware
90+
HIGH 7.5
CVE-2023-26021
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service as the server may crash when com…
Db2
11.1.4 / 11.5.8+
HIGH 7.5
CVE-2023-26022
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash when an Out of Memory …
Db2
11.1.4 / 11.5.8+
MEDIUM 5.9
CVE-2023-25930
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 11.1, and 11.5 is vulnerable to a denial of service. Under rare conditions, …
Db2
11.1.4 / 11.5.8+
HIGH 7.5
CVE-2023-27555
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 is vulnerable to a denial of service when attempting to use ACR client affinit…
Db2
11.1.4 / 11.5.8+
HIGH 7.5
CVE-2023-29255
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as it may trap when compi…
Db2
11.1.4 / 11.5.8+
HIGH 7.5
CVE-2023-27559
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash w…
Db2
11.1.4 / 11.5.8+
HIGH 7.5
CVE-2022-25273
Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This co…
Drupal
9.2.18 / 9.3.12+
HIGH 8.1
CVE-2023-30269
CLTPHP <=6.0 is vulnerable to Improper Input Validation via application/admin/controller/Template.php.
Cltphp
after 6.0
MEDIUM 6.5
CVE-2023-29530
Laminas Diactoros provides PSR HTTP Message implementations. In versions 2.18.0 and prior, 2.19.0, 2.20.0, 2.21.0, 2.22.0, 2.23.0, 2.24.0, and 2.25.0…
Fedora
1.9.1 / 2.4.5+
HIGH 7.5
CVE-2023-29780
Third Reality Smart Blind 1.00.54 contains a denial-of-service vulnerability, which allows a remote attacker to send malicious Zigbee messages to a v…
3rsb015bz Firmware
No fix yet
HIGH 8.1
CVE-2023-22916
The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FLEX 50(W)…
Usg Flex 100 Firmware
after 5.35
CRITICAL 9.8
CVE-2023-22581
White Rabbit Switch contains a vulnerability which makes it possible for an attacker to perform system commands under the context of the web applicat…
White Rabbit Switch Firmware
after 6.0.1
CRITICAL 9.8
CVE-2022-29606
An issue was discovered in ONOS 2.5.1. An intent with a large port number shows the CORRUPT state, which is misleading to a network operator. Imprope…
Onos
No fix yet
HIGH 7.8
CVE-2023-21092
In retrieveServiceLocked of ActiveServices.java, there is a possible way to dynamically register a BroadcastReceiver using permissions of System App …
Android
Patch available
MEDIUM 5.3
CVE-2023-27043
The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 heade…
Fedora
3.8.20 / 3.9.20+
HIGH 8.8
CVE-2023-29410
A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated
attacker to gain the same privilege as the application on …
Insighthome Firmware
1.16+
MEDIUM 6.5
CVE-2023-28856
Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` command to create an invalid hash f…
Redis
6.0.19 / 6.2.12+
MEDIUM 6.5
CVE-2023-28981
An Improper Input Validation vulnerability in the kernel of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attack…
Junos
Mitigation only
HIGH 8.8
CVE-2023-30542
OpenZeppelin Contracts is a library for secure smart contract development. The proposal creation entrypoint (`propose`) in `GovernorCompatibilityBrav…
Contracts
4.8.3+
HIGH 8.8
CVE-2023-30535
Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Users of the Snowflake …
Snowflake Jdbc
3.13.29+
CRITICAL 9.8
CVE-2022-33211
memory corruption in modem due to improper check while calculating size of serialized CoAP message
Mdm8207 Firmware
Mitigation only
HIGH 7.8
CVE-2023-26388
Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by an Improper Input Validation vulnerability that could result in arbitrary code e…
Substance 3d Stager
after 2.0.1
HIGH 7.8
CVE-2023-26407
Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Input Validation vulnerability th…
Acrobat
after 23.001.20093
HIGH 7.8
CVE-2023-26405
Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Input Validation vulnerability th…
Acrobat
after 23.001.20093
HIGH 7.8
CVE-2023-28304
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
Odbc
17.10.3.1 / 18.2.1.1+
HIGH 7.8
CVE-2023-28291
Raw Image Extension Remote Code Execution Vulnerability
Raw Image Extension
2.0.60612.0 / 2.1.60611.0+
HIGH 7.5
CVE-2023-28302EPSS 93%
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Windows 10 1607
10.0.14393.5850 / 10.0.17763.4252+
HIGH 7.8
CVE-2023-28274EPSS 7%
Windows Win32k Elevation of Privilege Vulnerability
Windows 10 1809
10.0.17763.4252 / 10.0.19042.2846+
HIGH 7.8
CVE-2023-24893
Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code
1.77.0+