Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Aria Operations For Networks CRITICAL 9.8
CVE-2023-20887 KEVEPSS 98%

Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks…

Fix: after 6.10.0
Fix from $2,300 2023-06-07
Tl Wr940n Firmware HIGH 8.8
CVE-2023-33538 KEVEPSS 42%

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm…

Mitigation only
Fix from $1,950 2023-06-07
Chrome HIGH 8.8
CVE-2023-3079 KEVEPSS 32%

Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 7.1.5 / 114.0.5735.110+
Fix from $1,950 2023-06-05
Moveit Cloud CRITICAL 9.8
CVE-2023-34362 KEVEPSS 100%

In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection…

Fix: 14.0.5.45 / 14.1.6.97+
Fix from $2,300 2023-06-02
Openfire HIGH 7.5
CVE-2023-32315 KEVEPSS 100%

Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be…

Fix: 4.6.8 / 4.7.5+
Fix from $1,950 2023-05-26
Email Security Gateway 300 Firmware CRITICAL 9.8
CVE-2023-2868 KEVEPSS 87%

A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3…

Fix: after 9.2.0.006
Fix from $2,300 2023-05-24
Rocketmq CRITICAL 9.8
CVE-2023-33246 KEVEPSS 97%

For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, inclu…

Fix: 4.9.6 / 5.1.1+
Fix from $2,300 2023-05-24
Atp100 Firmware CRITICAL 9.8
CVE-2023-33010 KEVEPSS 29%

A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmwa…

Fix: 5.36+
Fix from $2,300 2023-05-24
Atp100 Firmware CRITICAL 9.8
CVE-2023-33009 KEVEPSS 28%

A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmwar…

Fix: 5.36+
Fix from $2,300 2023-05-24
Windows 10 1507 HIGH 7.8
CVE-2023-29336 KEVEPSS 41%

Win32k Elevation of Privilege Vulnerability

Fix: 10.0.10240.19926 / 10.0.14393.5921+
Fix from $1,950 2023-05-09
Sharepoint Enterprise Server HIGH 7.2
CVE-2023-24955 KEVEPSS 85%

Microsoft SharePoint Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-05-09
Esxi HIGH 7.5
CVE-2023-29552 KEVEPSS 66%

The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacke…

Fix: 7.0+
Fix from $1,950 2023-04-25
Atp100 Firmware CRITICAL 9.8
CVE-2023-28771 KEVEPSS 99%

Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG F…

Fix: 5.35 / 5.36+
Fix from $2,300 2023-04-25
Superset CRITICAL 9.8
CVE-2023-27524 KEVEPSS 97%

Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_K…

Fix: after 2.0.1
Fix from $2,300 2023-04-24
Papercut Mf HIGH 7.5
CVE-2023-27351 KEVEPSS 77%

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is …

Fix: 20.1.7 / 21.2.11+
Fix from $1,950 2023-04-20
Papercut Mf CRITICAL 9.8
CVE-2023-27350 KEVEPSS 100%

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is …

Fix: 20.1.7 / 21.2.11+
Fix from $2,300 2023-04-20
Chrome CRITICAL 9.6
CVE-2023-2136 KEVEPSS 6%

Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially p…

Fix: 112.0.5615.137+
Fix from $2,300 2023-04-19
Chrome HIGH 8.8
CVE-2023-2033 KEVEPSS 41%

Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 7.1.5 / 112.0.5615.121+
Fix from $1,950 2023-04-14
Rv016 Firmware HIGH 7.2
CVE-2023-20118 KEVEPSS 54%

A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could all…

Mitigation only
Fix from $1,950 2023-04-13
Windows 10 1507 HIGH 7.8
CVE-2023-28252 KEVEPSS 49%

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Fix: 10.0.10240.19869 / 10.0.14393.5850+
Fix from $1,950 2023-04-11
Windows 10 1507 HIGH 7.0
CVE-2023-28229 KEV

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

Fix: 10.0.10240.19869 / 10.0.14393.5850+
Fix from $1,950 2023-04-11
Novi Survey CRITICAL 9.8
CVE-2023-29492 KEV

Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not pro…

Fix: 8.9.43676+
Fix from $2,300 2023-04-11
Ipados HIGH 8.6
CVE-2023-28206 KEVEPSS 25%

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS 16.4.1…

Fix: 11.7.6 / 12.6.5+
Fix from $1,950 2023-04-10
Safari HIGH 8.8
CVE-2023-28205 KEVEPSS 27%

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 and iPadOS 15.7.5, iOS 16.4.1 …

Fix: 13.3.1 / 15.7.5+
Fix from $1,950 2023-04-10
Web Appliance CRITICAL 9.8
CVE-2023-1671 KEVEPSS 100%

A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitr…

Fix: 4.3.10.4+
Fix from $2,300 2023-04-04
Vantara Pentaho Business Analytics Server CRITICAL 9.8
CVE-2022-43939 KEVEPSS 92%

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canoni…

Fix: 9.3.0.2+
Fix from $2,300 2023-04-03
Vantara Pentaho Business Analytics Server HIGH 7.2
CVE-2022-43769 KEVEPSS 98%

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property v…

Fix: 9.3.0.2+
Fix from $1,950 2023-04-03
Android HIGH 7.8
CVE-2023-20963 KEV

In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. …

Patch available
Fix from $1,950 2023-03-24
Cobalt Strike CRITICAL 9.8
CVE-2022-42948 KEV

Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to…

Mitigation only
Fix from $2,300 2023-03-24
Coldfusion HIGH 8.6
CVE-2023-26360 KEVEPSS 97%

Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that …

Patch available
Fix from $1,950 2023-03-23