Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2023-38896
An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and from_colore…
Langchain
after 0.0.194
CRITICAL 9.8
CVE-2023-39659
An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLT…
Langchain
after 0.0.232
HIGH 8.8
CVE-2020-28848
CSV Injection vulnerability in ChurchCRM version 4.2.0, allows remote attackers to execute arbitrary code via crafted CSV file.
Churchcrm
No fix yet
HIGH 8.8
CVE-2023-31209
Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authe…
Checkmk
2.0.0+
HIGH 8.1
CVE-2023-33242
Crypto wallets implementing the Lindell17 TSS protocol might allow an attacker to extract the full ECDSA private key by exfiltrating a single bit in …
Lindell17
No fix yet
CRITICAL 9.1
CVE-2023-33241
Crypto wallets implementing the GG18 or GG20 TSS protocol might allow an attacker to extract a full ECDSA private key by injecting a malicious pallie…
Gg18
No fix yet
CRITICAL 9.8
CVE-2023-39213
Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticated user to…
Virtual Desktop Infrastructure
5.15.2+
CRITICAL 9.8
CVE-2023-36210EPSS 31%
MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword paramet…
Motocms
No fix yet
HIGH 7.5
CVE-2023-38609
An injection issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.5. An app may be able to bypass certain Priv…
macOS
13.5+
HIGH 8.8
CVE-2023-38060
Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate operations of the OTRS Generic I…
Otrs
7.0.45 / 8.0.35+
MEDIUM 6.5
CVE-2020-24275
A HTTP response header injection vulnerability in Swoole v4.5.2 allows attackers to execute arbitrary code via supplying a crafted URL.
Swoole
Patch available
HIGH 8.8
CVE-2023-37897
Grav is a file-based Web-platform built in PHP. Grav is subject to a server side template injection (SSTI) vulnerability. The fix for another SSTI vu…
Grav
Patch available
CRITICAL 9.8
CVE-2023-3694
A vulnerability, which was classified as critical, has been found in SourceCodester/projectworlds House Rental and Property Listing 1.0. This issue a…
House Rental And Property Listing
No fix yet
HIGH 8.8
CVE-2023-37473
zenstruck/collections is a set of helpers for iterating/paginating/filtering collections. Passing _callable strings_ (ie `system`) caused the functio…
Collection
Patch available
HIGH 8.8
CVE-2023-37462EPSS 91%
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode…
Xwiki
14.4.8 / 14.10.4+
HIGH 7.8
CVE-2023-36830
SQLFluff is a SQL linter. Prior to version 2.1.2, in environments where untrusted users have access to the config files, there is a potential securit…
Sqlfluff
2.1.2+
CRITICAL 9.8
CVE-2023-36188
An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method.
Langchain
Patch available
CRITICAL 9.8
CVE-2023-36812EPSS 17%
OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Execution vulnerability by writin…
Opentsdb
2.4.2+
MEDIUM 6.1
CVE-2023-37360
pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript injection, and possibly privilege escalation, when the attacker controls the URL (wh…
Pacparser
1.4.2+
HIGH 8.8
CVE-2023-36469EPSS 82%
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile…
Xwiki
14.10.6+
HIGH 8.8
CVE-2023-36470
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By either creating a new or editing an exist…
Xwiki
14.10.6+
MEDIUM 5.4
CVE-2023-36471
Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki since version 14.6RC1 allowe…
Commons
14.10.6+
HIGH 8.8
CVE-2023-34203
In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a U…
Openedge
11.7.16 / 12.2.12+
CRITICAL 9.8
CVE-2023-3380
A vulnerability classified as critical has been found in Wavlink WN579X3 up to 20230615. Affected is an unknown function of the file /cgi-bin/adm.cgi…
Wn579x3 Firmware
after 2023-06-15
MEDIUM 6.1
CVE-2023-28016
Host Header Injection vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to supply invalid input to cause …
Bigfix Osd Bare Metal Server
after 311.12
HIGH 7.2
CVE-2023-35810
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Second-Order PHP Object Injection vulnerability has been ident…
Sugarcrm
11.0.6 / 12.0.3+
MEDIUM 6.5
CVE-2023-2797
Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting a specially crafted permalink…
Mattermost
after 7.8.4
MEDIUM 6.5
CVE-2023-28598
Zoom for Linux clients prior to 5.13.10 contain an HTML injection vulnerability. If a victim starts a chat with a malicious user it could result in …
Zoom
5.13.10+
CRITICAL 9.8
CVE-2023-29405
The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running a…
Go
1.19.10 / 1.20.5+
HIGH 8.8
CVE-2019-25150
The Email Templates plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.3. This makes it possible for attackers …
Email Templates
1.3.1+