Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 7.5
CVE-2023-38180 KEVEPSS 14%

.NET and Visual Studio Denial of Service Vulnerability

Fix: 2.1.40 / 6.0.21+
Fix from $1,950 2023-08-08
Biotime HIGH 7.5
CVE-2023-38950 KEVEPSS 85%

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a cr…

Fix: 9.0.1+
Fix from $1,950 2023-08-03
Endpoint Manager Mobile HIGH 7.2
CVE-2023-35081 KEVEPSS 64%

A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated admini…

Fix: 11.8.1.2 / 11.9.1.2+
Fix from $1,950 2023-08-03
Zimbra Collaboration Suite MEDIUM 6.1
CVE-2023-37580 KEVEPSS 47%

Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.

Fix: 8.8.15+
Fix from $1,600 2023-07-31
Ipados MEDIUM 5.5
CVE-2023-38606 KEV

This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPa…

Fix: 9.6 / 11.7.9+
Fix from $1,600 2023-07-27
Safari HIGH 8.8
CVE-2023-37450 KEVEPSS 19%

The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS …

Fix: 2.42.3 / 9.6+
Fix from $1,950 2023-07-27
Endpoint Manager Mobile CRITICAL 9.8
CVE-2023-35078 KEVEPSS 100%

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application wi…

Fix: 11.8.1.1 / 11.9.1.1+
Fix from $2,300 2023-07-25
Coldfusion CRITICAL 9.8
CVE-2023-38203 KEVEPSS 97%

Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vu…

Patch available
Fix from $2,300 2023-07-20
Netscaler Application Delivery Controller CRITICAL 9.8
CVE-2023-3519 KEVEPSS 100%

Unauthenticated remote code execution

Fix: 12.1-55.297 / 13.0-91.13+
Fix from $2,300 2023-07-19
Coldfusion CRITICAL 9.8
CVE-2023-29300 KEVEPSS 100%

Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untruste…

Mitigation only
Fix from $2,300 2023-07-12
Coldfusion HIGH 7.5
CVE-2023-29298 KEVEPSS 100%

Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vu…

Mitigation only
Fix from $1,950 2023-07-12
Windows 10 1507 HIGH 7.5
CVE-2023-36884 KEVEPSS 99%

Windows Search Remote Code Execution Vulnerability

Fix: 10.0.10240.20107 / 10.0.14393.6167+
Fix from $1,950 2023-07-11
Windows 10 1507 HIGH 7.8
CVE-2023-36874 KEVEPSS 43%

Windows Error Reporting Service Elevation of Privilege Vulnerability

Fix: 10.0.10240.20048 / 10.0.14393.6085+
Fix from $1,950 2023-07-11
365 Apps HIGH 8.8
CVE-2023-35311 KEVEPSS 16%

Microsoft Outlook Security Feature Bypass Vulnerability

Patch available
Fix from $1,950 2023-07-11
Windows 10 1607 HIGH 8.8
CVE-2023-32049 KEV

Windows SmartScreen Security Feature Bypass Vulnerability

Fix: 10.0.14393.6085 / 10.0.17763.4645+
Fix from $1,950 2023-07-11
Windows 10 1507 HIGH 7.8
CVE-2023-32046 KEVEPSS 10%

Windows MSHTML Platform Elevation of Privilege Vulnerability

Fix: 10.0.10240.20048 / 10.0.14393.6085+
Fix from $1,950 2023-07-11
Sharefile Storage Zones Controller CRITICAL 9.8
CVE-2023-24489 KEVEPSS 94%

A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated at…

Fix: 5.11.24+
Fix from $2,300 2023-07-10
Zimbra Collaboration Suite CRITICAL 9.0
CVE-2023-34192 KEVEPSS 77%

Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to th…

Mitigation only
Fix from $2,300 2023-07-06
Android MEDIUM 5.5
CVE-2023-21237 KEV

In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insuffic…

Mitigation only
Fix from $1,600 2023-06-28
Safari HIGH 8.8
CVE-2023-32439 KEVEPSS 24%

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS V…

Fix: 2.42.3 / 13.4.1+
Fix from $1,950 2023-06-23
Safari HIGH 8.8
CVE-2023-32435 KEVEPSS 23%

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 1…

Fix: 13.3 / 15.7.7+
Fix from $1,950 2023-06-23
Ipados HIGH 7.8
CVE-2023-32434 KEVEPSS 52%

An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 1…

Fix: 8.8.1 / 9.5.2+
Fix from $1,950 2023-06-23
Safari HIGH 8.6
CVE-2023-32409 KEVEPSS 17%

The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8,…

Fix: 9.5 / 13.4+
Fix from $1,950 2023-06-23
Safari HIGH 8.8
CVE-2023-32373 KEVEPSS 12%

A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 a…

Fix: 2.42.3 / 9.5+
Fix from $1,950 2023-06-23
Safari MEDIUM 6.5
CVE-2023-28204 KEVEPSS 14%

An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and…

Fix: 2.42.3 / 9.5+
Fix from $1,600 2023-06-23
Papercut Mf HIGH 8.8
CVE-2023-2533 KEVEPSS 29%

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable a…

Fix: 20.1.8 / 21.2.12+
Fix from $1,950 2023-06-20
Nas326 Firmware CRITICAL 9.8
CVE-2023-27992 KEVEPSS 84%

The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prio…

Fix: 5.21+
Fix from $2,300 2023-06-19
Windows 10 1607 HIGH 8.4
CVE-2023-29360 KEVEPSS 22%

Microsoft Streaming Service Elevation of Privilege Vulnerability

Fix: 10.0.14393.5989 / 10.0.17763.4499+
Fix from $1,950 2023-06-14
Sharepoint Server CRITICAL 9.8
CVE-2023-29357 KEVEPSS 100%

Microsoft SharePoint Server Elevation of Privilege Vulnerability

Patch available
Fix from $2,300 2023-06-14
Fortiproxy CRITICAL 9.8
CVE-2023-27997 KEVEPSS 86%

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version …

Fix: after 7.2.4
Fix from $2,300 2023-06-13