Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2023-29521
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitr…
Xwiki
13.10.11 / 14.4.8+
HIGH 8.8
CVE-2023-29522
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitr…
Xwiki
14.4.8 / 14.10.3+
HIGH 8.8
CVE-2023-29523
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile…
Xwiki
13.10.11 / 14.4.8+
HIGH 8.8
CVE-2023-29213
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of `org.xwiki.platform:…
Xwiki
13.10.11 / 14.4.7+
CRITICAL 10.0
CVE-2023-30547EPSS 72%
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. There exists a vulnerability in exception sanitization of vm2 …
Vm2
after 3.9.16
HIGH 7.2
CVE-2023-26919
delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can …
Nashorn Sandbox
No fix yet
MEDIUM 6.8
CVE-2023-29389
Toyota RAV4 2021 vehicles automatically trust messages from other ECUs on a CAN bus, which allows physically proximate attackers to drive a vehicle b…
Rav4 Firmware
No fix yet
CRITICAL 9.8
CVE-2023-29374EPSS 40%
In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec method.
Langchain
after 0.0.131
MEDIUM 6.5
CVE-2023-28853
Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Starting in vers…
Mastodon
3.5.8 / 4.0.4+
HIGH 7.2
CVE-2022-43769 KEVEPSS 98%
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property v…
Vantara Pentaho Business Analytics Server
9.3.0.2+
HIGH 8.8
CVE-2023-27533
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously c…
Curl
after 7.881
HIGH 8.8
CVE-2023-28637
DataEase is an open source data visualization analysis tool. In Dataease users are normally allowed to modify data and the data sources are expected …
Dataease
1.18.5+
HIGH 8.8
CVE-2023-26493
Cocos Engine is an open-source framework for building 2D & 3D real-time rendering and interactive content. In the github repo for Cocos Engine the `w…
Cocos Engine
2023-02-20+
CRITICAL 9.8
CVE-2023-27040
Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter.
Simple Image Gallery Web App
No fix yet
HIGH 8.8
CVE-2023-25616
In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code injection …
Business Objects Business Intelligence Platform
Mitigation only
CRITICAL 9.8
CVE-2023-1287
An XSL template vulnerability in
ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution.
Enovia Live Collaboration
No fix yet
CRITICAL 9.8
CVE-2023-26261
In UBIKA WAAP Gateway/Cloud through 6.10, a blind XPath injection leads to an authentication bypass by stealing the session of another connected user…
Waap Cloud
6.5.6 / 6.11.0+
CRITICAL 9.9
CVE-2023-27479
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view righ…
Xwiki
13.10.11 / 14.4.7+
HIGH 7.8
CVE-2023-27635
debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a crafted .deb file. (The path is…
Debmany
Mitigation only
HIGH 7.8
CVE-2022-42797
An injection issue was addressed with improved input validation. This issue is fixed in Xcode 14.1. An app may be able to gain root privileges.
Xcode
14.1+
HIGH 8.8
CVE-2023-1059
A vulnerability classified as critical was found in SourceCodester Doctors Appointment System 1.0. This vulnerability affects unknown code of the fil…
Doctors Appointment System
No fix yet
HIGH 8.8
CVE-2023-1061
A vulnerability, which was classified as critical, has been found in SourceCodester Doctors Appointment System 1.0. This issue affects some unknown p…
Doctors Appointment System
No fix yet
HIGH 7.2
CVE-2023-20858EPSS 17%
VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability. A malicious …
Carbon Black App Control
8.7.8 / 8.8.6+
CRITICAL 9.8
CVE-2023-25613
An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3.
Kerby Ldap Backend
2.0.3+
MEDIUM 6.5
CVE-2022-36775
IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, 10.0.3.0, and10.0.4.0 is vulnerable to HTTP header injection, caused by improper validation …
Security Verify Access
Patch available
MEDIUM 5.4
CVE-2022-42472
A improper neutralization of crlf sequences in http headers ('http response splitting') in Fortinet FortiOS versions 7.2.0 through 7.2.2, 7.0.0 throu…
Fortiproxy
after 7.0.8
MEDIUM 5.4
CVE-2023-23936
Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not protect `host` HTTP he…
Node.js
5.19.1 / 16.19.1+
HIGH 7.5
CVE-2023-25141
Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or earlier) through utility funct…
Sling Jcr Base
3.1.12+
HIGH 8.8
CVE-2023-25719
ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parameters such as the Bin/ConnectWiseControl…
Control
22.9.10032+
HIGH 7.5
CVE-2022-43756
A Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in SUSE Rancher allows remote atta…
Wrangler
0.7.4 / 0.8.5+