Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Exchange Server CRITICAL 9.8
CVE-2024-21410 KEVEPSS 13%

Microsoft Exchange Server Elevation of Privilege Vulnerability

Patch available
Fix from $2,300 2024-02-13
Windows 10 1507 HIGH 7.6
CVE-2024-21351 KEVEPSS 30%

Windows SmartScreen Security Feature Bypass Vulnerability

Fix: 10.0.10240.20469 / 10.0.14393.6709+
Fix from $1,950 2024-02-13
Windows 10 1809 HIGH 7.8
CVE-2024-21338 KEVEPSS 60%

Windows Kernel Elevation of Privilege Vulnerability

Fix: 10.0.17763.5458 / 10.0.19044.4046+
Fix from $1,950 2024-02-13
Fortiproxy CRITICAL 9.8
CVE-2024-21762 KEVEPSS 84%

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 throug…

Fix: 2.0.14 / 6.0.18+
Fix from $2,300 2024-02-09
Connect Secure HIGH 8.2
CVE-2024-21893 KEVEPSS 100%

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivant…

Mitigation only
Fix from $1,950 2024-01-31
Linux Kernel HIGH 7.8
CVE-2024-1086 KEVEPSS 28%

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nf…

Fix: 5.15.149 / 6.1.76+
Fix from $1,950 2024-01-31
Jenkins CRITICAL 9.8
CVE-2024-23897 KEVEPSS 100%

Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a …

Fix: 2.426.3 / 2.442+
Fix from $2,300 2024-01-24
Safari HIGH 8.8
CVE-2024-23222 KEVEPSS 11%

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16…

Fix: 1.0.2 / 12.7.3+
Fix from $1,950 2024-01-23
Dir 859 Firmware CRITICAL 9.8
CVE-2024-0769 KEVEPSS 83%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some un…

Mitigation only
Fix from $2,300 2024-01-21
Netscaler Application Delivery Controller HIGH 7.5
CVE-2023-6549 KEVEPSS 58%

Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Servi…

Fix: 12.1-55.302 / 13.0-92.21+
Fix from $1,950 2024-01-17
Netscaler Application Delivery Controller HIGH 8.8
CVE-2023-6548 KEV

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP…

Fix: 12.1-55.302 / 13.0-92.21+
Fix from $1,950 2024-01-17
Chrome HIGH 8.8
CVE-2024-0519 KEV

Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a cra…

Fix: 7.2.5 / 120.0.6099.224+
Fix from $1,950 2024-01-16
Confluence Data Center CRITICAL 9.8
CVE-2023-22527 KEVEPSS 100%

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an aff…

Fix: 8.5.4+
Fix from $2,300 2024-01-16
Connect Secure CRITICAL 9.1
CVE-2024-21887 KEVEPSS 100%

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticate…

Mitigation only
Fix from $2,300 2024-01-12
Connect Secure HIGH 8.2
CVE-2023-46805 KEVEPSS 100%

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restr…

Mitigation only
Fix from $1,950 2024-01-12
GitLab CRITICAL 9.8
CVE-2023-7028 KEVEPSS 95%

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior…

Fix: 16.1.6 / 16.2.9+
Fix from $2,300 2024-01-12
Ipados HIGH 7.8
CVE-2023-41974 KEV

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An a…

Fix: 15.8.7 / 17.0+
Fix from $1,950 2024-01-10
Ipados HIGH 7.0
CVE-2022-48618 KEV

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacke…

Fix: 9.2 / 13.1+
Fix from $1,950 2024-01-09
Linux Kernel HIGH 7.8
CVE-2022-2586 KEVEPSS 10%

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was…

Fix: 4.14.316 / 4.19.256+
Fix from $1,950 2024-01-08
Debian Linux HIGH 7.8
CVE-2023-7101 KEVEPSS 17%

Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execut…

Fix: after 0.65
Fix from $1,950 2023-12-24
Chrome HIGH 8.8
CVE-2023-7024 KEVEPSS 7%

Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafte…

Fix: 120.0.6099.129+
Fix from $1,950 2023-12-21
Qvr Firmware HIGH 8.8
CVE-2023-47565 KEVEPSS 73%

An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerabili…

Fix: 5.0.0+
Fix from $1,950 2023-12-08
Ae1021 Firmware HIGH 8.8
CVE-2023-49897 KEVEPSS 51%

An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vu…

Fix: 2.0.10+
Fix from $1,950 2023-12-06
Sma 200 Firmware HIGH 7.2
CVE-2023-44221 KEVEPSS 75%

Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative pri…

Fix: after 10.2.1.9-57sv
Fix from $1,950 2023-12-05
Vision1210 Firmware CRITICAL 9.8
CVE-2023-6448 KEV

Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attack…

Fix: 12.38+
Fix from $2,300 2023-12-05
315 5g Iot Modem Firmware HIGH 7.8
CVE-2023-33107 KEV

Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

Patch available
Fix from $1,950 2023-12-05
Ar8035 Firmware HIGH 7.8
CVE-2023-33106 KEV

Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.

Patch available
Fix from $1,950 2023-12-05
315 5g Iot Modem Firmware HIGH 7.8
CVE-2023-33063 KEV

Memory corruption in DSP Services during a remote call from HLOS to DSP.

Patch available
Fix from $1,950 2023-12-05
Safari HIGH 8.8
CVE-2023-42917 KEVEPSS 9%

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safa…

Fix: 2.42.3 / 14.1.2+
Fix from $1,950 2023-11-30
Safari MEDIUM 6.5
CVE-2023-42916 KEVEPSS 18%

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari …

Fix: 2.42.3 / 14.1.2+
Fix from $1,600 2023-11-30