Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2023-31447
user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers to send a crafted payload to m…
Vigor2620 Firmware
3.9.8.4+
HIGH 8.8
CVE-2023-39445
Hidden functionality vulnerability in LAN-WH300N/RE all versions provided by LOGITEC CORPORATION allows an unauthenticated attacker to execute arbitr…
Wrc 1467ghbk A Firmware
Mitigation only
HIGH 8.0
CVE-2023-38576
Hidden functionality vulnerability in LAN-WH300N/RE all versions provided by LOGITEC CORPORATION allows an authenticated user to execute arbitrary OS…
Lan Wh300n\/re Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-32626
Hidden functionality vulnerability in LAN-W300N/RS all versions, and LAN-W300N/PR5 all versions allows an unauthenticated attacker to log in to the p…
Lan W300n\/rs Firmware
Mitigation only
HIGH 8.8
CVE-2023-40313
A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions earlier than 32.0.2 and in related Meridian versions which could allow…
Horizon
32.0.2 / 2020.1.38+
HIGH 8.8
CVE-2023-37914
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can view `Invitation.WebHome` c…
Xwiki
14.4.8 / 14.10.6+
CRITICAL 9.8
CVE-2023-40252
Improper Control of Generation of Code ('Code Injection') vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite…
Genian Nac
4.0.156 / 5.0.55+
HIGH 7.2
CVE-2023-20209EPSS 41%
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow …
Telepresence Video Communication Server
14.3.1+
CRITICAL 9.8
CVE-2023-38860
An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter.
Langchain
No fix yet
CRITICAL 9.8
CVE-2023-38889
An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.Com…
Alluxio
after 2.9.3
HIGH 7.8
CVE-2023-33469
In instances where the screen is visible and remote mouse connection is enabled, KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior…
Via Go2 Firmware
4.0.1.1326+
HIGH 7.8
CVE-2023-36923
SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03, allows an attacker with local access to the system, to place a malicious…
Powerdesigner
Mitigation only
CRITICAL 9.8
CVE-2023-36095
An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affected funct…
Langchain
Mitigation only
HIGH 8.8
CVE-2023-38943
ShuiZe_0x727 v1.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /iniFile/config.ini.
Shuize 0x727
No fix yet
CRITICAL 9.8
CVE-2023-37470
Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3…
Metabase
0.43.7.3 / 0.44.7.3+
HIGH 8.8
CVE-2023-4141
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus2' par…
Wp Ultimate Csv Importer
after 7.9.8
HIGH 8.8
CVE-2023-4142
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus1' par…
Wp Ultimate Csv Importer
after 7.9.8
HIGH 8.8
CVE-2023-36255EPSS 53%
An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path parameter…
Eramba
Mitigation only
MEDIUM 6.5
CVE-2023-3401
An issue has been discovered in GitLab affecting all versions before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting fro…
GitLab
16.0.8 / 16.1.3+
CRITICAL 9.8
CVE-2023-34644
Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204, RG-NBS and RG-S1930 series …
Rg Ew1200r Firmware
Patch available
CRITICAL 9.8
CVE-2023-34842
Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.ph…
Dedecms
after 5.7.109
HIGH 8.8
CVE-2023-36542
Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an …
Nifi
after 1.22.0
CRITICAL 9.8
CVE-2023-39016
bboss-persistent v6.0.9 and below was discovered to contain a code injection vulnerability in the component com.frameworkset.common.poolman.util.SQLM…
Bboss
after 6.0.9
CRITICAL 9.8
CVE-2023-39017
quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessageJob.exec…
Quartz
after 2.3.2
CRITICAL 9.8
CVE-2023-39018
FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.<constructor>. This vulnerab…
Ffmpeg Cli Wrapper
after 0.7.0
CRITICAL 9.8
CVE-2023-39020
stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2PipedInputStre…
Stanford Parser
4.5.5+
CRITICAL 9.8
CVE-2023-39021
wix-embedded-mysql v4.6.1 and below was discovered to contain a code injection vulnerability in the component com.wix.mysql.distribution.Setup.apply.…
Wix Embedded Mysql
after 4.6.1
CRITICAL 9.8
CVE-2023-39022
oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util.EJBUtils.createStateless. Thi…
Oscore
after 2.2.6
CRITICAL 9.8
CVE-2023-39023
university compass v2.2.0 and below was discovered to contain a code injection vulnerability in the component org.compass.core.executor.DefaultExecut…
University Compass
after 2.2.0
CRITICAL 9.8
CVE-2023-39010
BoofCV 0.42 was discovered to contain a code injection vulnerability via the component boofcv.io.calibration.CalibrationIO.load. This vulnerability i…
Boofcv
No fix yet