Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chrome CRITICAL 9.6
CVE-2023-6345 KEVEPSS 16%

Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially p…

Fix: 119.0.2151.97 / 119.0.6045.199+
Fix from $2,300 2023-11-29
Graph Api HIGH 7.5
CVE-2023-49103 KEVEPSS 78%

An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.…

Mitigation only
Fix from $1,950 2023-11-21
Qlik Sense CRITICAL 9.9
CVE-2023-48365 KEVEPSS 25%

Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation o…

Mitigation only
Fix from $2,300 2023-11-15
Windows 10 1507 HIGH 7.8
CVE-2023-36424 KEVEPSS 12%

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Fix: 10.0.10240.20308 / 10.0.14393.6452+
Fix from $1,950 2023-11-14
Windows 10 1507 HIGH 7.8
CVE-2023-36036 KEVEPSS 17%

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Fix: 10.0.10240.20308 / 10.0.14393.6452+
Fix from $1,950 2023-11-14
Windows 10 1809 HIGH 7.8
CVE-2023-36033 KEVEPSS 12%

Windows DWM Core Library Elevation of Privilege Vulnerability

Fix: 10.0.17763.5122 / 10.0.19041.3693+
Fix from $1,950 2023-11-14
Windows 10 1507 HIGH 8.8
CVE-2023-36025 KEVEPSS 88%

Windows SmartScreen Security Feature Bypass Vulnerability

Patch available
Fix from $1,950 2023-11-14
Sysaid CRITICAL 9.8
CVE-2023-47246 KEVEPSS 99%

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as…

Fix: 23.3.36+
Fix from $2,300 2023-11-10
Confluence Data Center CRITICAL 9.8
CVE-2023-22518 KEVEPSS 100%

All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an…

Fix: 7.19.16 / 8.3.4+
Fix from $2,300 2023-10-31
Activemq CRITICAL 9.8
CVE-2023-46604 KEVEPSS 100%

The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to…

Fix: 5.15.16 / 5.16.7+
Fix from $2,300 2023-10-27
Big Ip Access Policy Manager HIGH 8.8
CVE-2023-46748 KEV

An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network acce…

Fix: after 17.1.1
Fix from $1,950 2023-10-26
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2023-46747 KEVEPSS 97%

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the manag…

Fix: after 17.1.1
Fix from $2,300 2023-10-26
Mirth Connect CRITICAL 9.8
CVE-2023-43208 KEVEPSS 83%

NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused …

Fix: 4.4.1+
Fix from $2,300 2023-10-26
Vcenter Server CRITICAL 9.8
CVE-2023-34048 KEVEPSS 99%

vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to v…

Fix: after 5.5
Fix from $2,300 2023-10-25
Ios Xe HIGH 7.2
CVE-2023-20273 KEVEPSS 90%

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges o…

Mitigation only
Fix from $1,950 2023-10-25
Debian Linux MEDIUM 5.4
CVE-2023-5631 KEVEPSS 76%

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because …

Fix: 1.4.15 / 1.5.5+
Fix from $1,600 2023-10-18
Proself HIGH 7.5
CVE-2023-45727 KEV

Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and e…

Fix: 1.09 / 1.66+
Fix from $1,950 2023-10-18
Ios Xe CRITICAL 10.0
CVE-2023-20198 KEVEPSS 100%

Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating…

Fix: 16.12.10a / 17.3.8a+
Fix from $2,300 2023-10-16
Skype For Business Server MEDIUM 5.3
CVE-2023-41763 KEVEPSS 90%

Skype for Business Elevation of Privilege Vulnerability

Patch available
Fix from $1,600 2023-10-10
Windows 10 1507 MEDIUM 5.4
CVE-2023-36584 KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

Fix: 10.0.10240.20232 / 10.0.17763.4974+
Fix from $1,600 2023-10-10
Windows 10 1507 MEDIUM 5.5
CVE-2023-36563 KEVEPSS 21%

Microsoft WordPad Information Disclosure Vulnerability

Fix: 10.0.10240.20232 / 10.0.14393.6351+
Fix from $1,600 2023-10-10
Netscaler Application Delivery Controller HIGH 7.5
CVE-2023-4966 KEVEPSS 100%

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy)…

Fix: 12.1-55.300 / 13.0-92.19+
Fix from $1,950 2023-10-10
Caddy HIGH 7.5
CVE-2023-44487 KEVEPSS 100%

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploite…

Fix: 0.17.0 / 1.20.10+
Fix from $1,950 2023-10-10
Ipados HIGH 7.8
CVE-2023-42824 KEV

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may be able to elevate their priv…

Fix: 16.7.1 / 17.0.3+
Fix from $1,950 2023-10-04
Confluence Data Center CRITICAL 9.8
CVE-2023-22515 KEVEPSS 99%

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnera…

Fix: 8.3.3 / 8.4.3+
Fix from $2,300 2023-10-04
Fedora HIGH 7.8
CVE-2023-4911 KEVEPSS 81%

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue cou…

Patch available
Fix from $1,950 2023-10-03
5th Gen Gpu Architecture Kernel Driver MEDIUM 5.5
CVE-2023-4211 KEV

A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.

Mitigation only
Fix from $1,600 2023-10-01
Firefox HIGH 8.8
CVE-2023-5217 KEVEPSS 49%

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially ex…

Fix: 1.13.1 / 115.3.1+
Fix from $1,950 2023-09-28
iOS MEDIUM 6.6
CVE-2023-20109 KEV

A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authentic…

Mitigation only
Fix from $1,600 2023-09-27
Ws Ftp Server HIGH 8.8
CVE-2023-40044 KEVEPSS 90%

In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Tr…

Fix: 8.7.4 / 8.8.2+
Fix from $1,950 2023-09-27