Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Coldfusion CRITICAL 9.8
CVE-2023-26359 KEVEPSS 18%

Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerabil…

Patch available
Fix from $2,300 2023-03-23
Minio HIGH 8.8
CVE-2023-28434 KEVEPSS 7%

Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucke…

Fix: 2023-03-20t20-16-18z+
Fix from $1,950 2023-03-22
Minio HIGH 7.5
CVE-2023-28432 KEVEPSS 84%

Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T2…

Fix: 2023-03-20t20-16-18z+
Fix from $1,950 2023-03-22
Debian Linux HIGH 7.8
CVE-2023-0386 KEVEPSS 8%

A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s…

Fix: 5.15.91 / 6.1.9+
Fix from $1,950 2023-03-22
Dir 820l Firmware CRITICAL 9.8
CVE-2023-25280 KEVEPSS 98%

OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_a…

Mitigation only
Fix from $2,300 2023-03-16
Arrayos Ag CRITICAL 9.8
CVE-2023-28461 KEVEPSS 68%

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gat…

Fix: after 9.4.0.481
Fix from $2,300 2023-03-15
Archer Ax21 Firmware HIGH 8.8
CVE-2023-1389 KEVEPSS 100%

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cg…

Fix: 1.1.4+
Fix from $1,950 2023-03-15
365 Apps CRITICAL 9.8
CVE-2023-23397 KEVEPSS 97%

Microsoft Outlook Elevation of Privilege Vulnerability

Patch available
Fix from $2,300 2023-03-14
Veeam Backup \& Replication HIGH 7.5
CVE-2023-27532 KEVEPSS 78%

Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead…

Fix: 11.0.1.1261+
Fix from $1,950 2023-03-10
Fortios HIGH 7.1
CVE-2022-41328 KEVEPSS 12%

A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2…

Fix: 6.2.14 / 6.4.12+
Fix from $1,950 2023-03-07
Codeready Linux Builder HIGH 8.8
CVE-2019-8720 KEV

A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution.…

Mitigation only
Fix from $1,950 2023-03-06
Safari HIGH 8.8
CVE-2023-23529 KEVEPSS 10%

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS V…

Fix: 13.2.1 / 15.7.4+
Fix from $1,950 2023-02-27
Aspera Faspex CRITICAL 9.8
CVE-2022-47986 KEVEPSS 100%

IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserializa…

Fix: after 4.4.1
Fix from $2,300 2023-02-17
Joomla\! MEDIUM 5.3
CVE-2023-23752 KEVEPSS 100%

An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

Fix: 4.2.8+
Fix from $1,600 2023-02-16
Windows 10 1507 HIGH 7.8
CVE-2023-21823 KEVEPSS 6%

Windows Graphics Component Remote Code Execution Vulnerability

Fix: 10.0.10240.19747 / 10.0.14393.5717+
Fix from $1,950 2023-02-14
Windows 10 1507 HIGH 7.8
CVE-2023-23376 KEVEPSS 11%

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Fix: 10.0.10240.19747 / 10.0.14393.5717+
Fix from $1,950 2023-02-14
365 Apps HIGH 7.3
CVE-2023-21715 KEVEPSS 12%

Microsoft Publisher Security Feature Bypass Vulnerability

Patch available
Fix from $1,950 2023-02-14
Exchange Server HIGH 8.8
CVE-2023-21529 KEVEPSS 62%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-02-14
Ruckus Wireless Admin CRITICAL 9.8
CVE-2023-25717 KEVEPSS 98%

Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_us…

Fix: 3.6.2.0.795 / 5.2.1.3+
Fix from $2,300 2023-02-13
Terramaster Operating System HIGH 7.5
CVE-2022-24990 KEVEPSS 83%

TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mo…

Fix: 4.2.31+
Fix from $1,950 2023-02-07
Goanywhere Managed File Transfer HIGH 7.2
CVE-2023-0669 KEVEPSS 100%

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due t…

Fix: 7.1.2+
Fix from $1,950 2023-02-06
Debian Linux HIGH 7.0
CVE-2023-0266 KEV

A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be u…

Fix: 4.14.303 / 4.19.270+
Fix from $1,950 2023-01-30
Acrobat Dc HIGH 7.8
CVE-2023-21608 KEVEPSS 61%

Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free …

Fix: after 22.003.20282
Fix from $1,950 2023-01-18
Manageengine Access Manager Plus CRITICAL 9.8
CVE-2022-47966 KEVEPSS 100%

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xm…

Fix: 4.3 / 5.1+
Fix from $2,300 2023-01-18
Weblogic Server HIGH 7.5
CVE-2023-21839 KEVEPSS 100%

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3…

Patch available
Fix from $1,950 2023-01-18
Sugarcrm HIGH 8.8
CVE-2023-22952 KEVEPSS 80%

In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.

Fix: 11.0.5 / 12.0.2+
Fix from $1,950 2023-01-11
Windows 10 1507 HIGH 8.8
CVE-2023-21674 KEVEPSS 42%

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

Fix: 10.0.10240.19685 / 10.0.14393.5648+
Fix from $1,950 2023-01-10
Webpanel CRITICAL 9.8
CVE-2022-44877 KEVEPSS 100%

login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via s…

Fix: 0.9.8.1147+
Fix from $2,300 2023-01-05
Fortios CRITICAL 9.8
CVE-2022-42475 KEVEPSS 99%

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through…

Fix: 2.0.12 / 6.0.15+
Fix from $2,300 2023-01-02
Firefox CRITICAL 9.6
CVE-2022-26486 KEV

An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in th…

Fix: 91.6.1 / 91.6.2+
Fix from $2,300 2022-12-22