Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Junos MEDIUM 5.3
CVE-2023-36851 KEV

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based atta…

Mitigation only
Fix from $1,600 2023-09-27
Debian Linux MEDIUM 6.1
CVE-2023-43770 KEVEPSS 58%

Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/l…

Fix: 1.4.14 / 1.5.4+
Fix from $1,600 2023-09-22
Fedora HIGH 8.8
CVE-2023-41993 KEVEPSS 29%

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Ap…

Fix: 14.0 / 17.0.1+
Fix from $1,950 2023-09-21
Ipados HIGH 7.8
CVE-2023-41992 KEV

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attac…

Fix: 12.7 / 13.6+
Fix from $1,950 2023-09-21
Ipados MEDIUM 5.5
CVE-2023-41991 KEV

A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to byp…

Fix: 13.6 / 16.7+
Fix from $1,600 2023-09-21
Teamcity CRITICAL 9.8
CVE-2023-42793 KEVEPSS 100%

In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible

Fix: 2023.05.4+
Fix from $2,300 2023-09-19
Apex One HIGH 7.2
CVE-2023-41179 KEV

A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-F…

Mitigation only
Fix from $1,950 2023-09-19
Coldfusion HIGH 7.5
CVE-2023-38205 KEVEPSS 100%

Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerabili…

Mitigation only
Fix from $1,950 2023-09-14
Acrobat HIGH 7.8
CVE-2023-26369 KEVEPSS 7%

Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write …

Fix: 20.005.30524 / 23.006.20320+
Fix from $1,950 2023-09-13
Windows 10 1809 HIGH 7.8
CVE-2023-36802 KEVEPSS 26%

Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

Fix: 10.0.17763.4851 / 10.0.19044.3448+
Fix from $1,950 2023-09-12
365 Apps MEDIUM 6.5
CVE-2023-36761 KEVEPSS 19%

Microsoft Word Information Disclosure Vulnerability

Patch available
Fix from $1,600 2023-09-12
Chrome HIGH 8.8
CVE-2023-4863 KEVEPSS 100%

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memo…

Fix: 1.0.62681.0 / 1.6.00.26463+
Fix from $1,950 2023-09-12
Ipados HIGH 7.8
CVE-2023-41990 KEV

The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS Bi…

Fix: 9.3 / 11.7.9+
Fix from $1,950 2023-09-12
Android HIGH 7.8
CVE-2023-35674 KEV

In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local e…

Patch available
Fix from $1,950 2023-09-11
Rt Ax55 Firmware HIGH 8.8
CVE-2023-39780 KEVEPSS 34%

On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist paramete…

Mitigation only
Fix from $1,950 2023-09-11
Ipados HIGH 7.8
CVE-2023-41064 KEVEPSS 15%

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macO…

Fix: 11.7.10 / 12.6.9+
Fix from $1,950 2023-09-07
Ipados HIGH 7.8
CVE-2023-41061 KEV

A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attac…

Fix: 9.6.2 / 16.6.1+
Fix from $1,950 2023-09-07
Adaptive Security Appliance Software CRITICAL 9.1
CVE-2023-20269 KEVEPSS 22%

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Softwar…

Mitigation only
Fix from $2,300 2023-09-06
Chrome HIGH 8.8
CVE-2023-4762 KEVEPSS 40%

Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium …

Fix: 116.0.1938.76 / 116.0.5845.179+
Fix from $1,950 2023-09-05
Qlik Sense MEDIUM 6.5
CVE-2023-41266 KEVEPSS 82%

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlie…

Mitigation only
Fix from $1,600 2023-08-29
Qlik Sense CRITICAL 9.9
CVE-2023-41265 KEVEPSS 84%

An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 a…

Mitigation only
Fix from $2,300 2023-08-29
Connection Authorization HIGH 7.5
CVE-2023-4346 KEV

KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users bei…

No fix yet
Fix from $1,950 2023-08-29
Winrar HIGH 7.8
CVE-2023-38831 KEVEPSS 98%

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occur…

Fix: 6.23+
Fix from $1,950 2023-08-23
Mobileiron Sentry CRITICAL 9.8
CVE-2023-38035 KEVEPSS 100%

A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentica…

Fix: after 9.18.0
Fix from $2,300 2023-08-21
Junos MEDIUM 5.3
CVE-2023-36847 KEVEPSS 86%

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attac…

Fix: 20.4+
Fix from $1,600 2023-08-17
Junos MEDIUM 5.3
CVE-2023-36846 KEVEPSS 95%

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based atta…

Fix: 20.4+
Fix from $1,600 2023-08-17
Junos CRITICAL 9.8
CVE-2023-36845 KEVEPSS 94%

A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, n…

Fix: 20.4+
Fix from $2,300 2023-08-17
Junos MEDIUM 5.3
CVE-2023-36844 KEVEPSS 91%

A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attack…

Fix: 20.4+
Fix from $1,600 2023-08-17
Endpoint Manager Mobile CRITICAL 9.8
CVE-2023-35082 KEVEPSS 100%

An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of t…

Fix: 11.11.0+
Fix from $2,300 2023-08-15
Safari HIGH 8.8
CVE-2022-48503 KEV

The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Sa…

Fix: 8.7 / 12.5+
Fix from $1,950 2023-08-14