Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2024-21410 KEVEPSS 13% Microsoft Exchange Server Elevation of Privilege Vulnerability Exchange Server Patch available Fix from $2,3002024-02-13 HIGH 7.6 CVE-2024-21351 KEVEPSS 30% Windows SmartScreen Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.20469 / 10.0.14393.6709+ Fix from $1,9502024-02-13 HIGH 7.8 CVE-2024-21338 KEVEPSS 60% Windows Kernel Elevation of Privilege Vulnerability Windows 10 1809 10.0.17763.5458 / 10.0.19044.4046+ Fix from $1,9502024-02-13 CRITICAL 9.8 CVE-2024-21762 KEVEPSS 84% A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 throug… Fortiproxy 2.0.14 / 6.0.18+ Fix from $2,3002024-02-09 HIGH 8.2 CVE-2024-21893 KEVEPSS 100% A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivant… Connect Secure Mitigation only Fix from $1,9502024-01-31 HIGH 7.8 CVE-2024-1086 KEVEPSS 28% A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nf… Linux Kernel 5.15.149 / 6.1.76+ Fix from $1,9502024-01-31 CRITICAL 9.8 CVE-2024-23897 KEVEPSS 100% Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a … Jenkins 2.426.3 / 2.442+ Fix from $2,3002024-01-24 HIGH 8.8 CVE-2024-23222 KEVEPSS 11% A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16… Safari 1.0.2 / 12.7.3+ Fix from $1,9502024-01-23 CRITICAL 9.8 CVE-2024-0769 KEVEPSS 83% ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some un… Dir 859 Firmware Mitigation only Fix from $2,3002024-01-21 HIGH 7.5 CVE-2023-6549 KEVEPSS 58% Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Servi… Netscaler Application Delivery Controller 12.1-55.302 / 13.0-92.21+ Fix from $1,9502024-01-17 HIGH 8.8 CVE-2023-6548 KEV Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP… Netscaler Application Delivery Controller 12.1-55.302 / 13.0-92.21+ Fix from $1,9502024-01-17 HIGH 8.8 CVE-2024-0519 KEV Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a cra… Chrome 7.2.5 / 120.0.6099.224+ Fix from $1,9502024-01-16 CRITICAL 9.8 CVE-2023-22527 KEVEPSS 100% A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an aff… Confluence Data Center 8.5.4+ Fix from $2,3002024-01-16 CRITICAL 9.1 CVE-2024-21887 KEVEPSS 100% A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticate… Connect Secure Mitigation only Fix from $2,3002024-01-12 HIGH 8.2 CVE-2023-46805 KEVEPSS 100% An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restr… Connect Secure Mitigation only Fix from $1,9502024-01-12 CRITICAL 9.8 CVE-2023-7028 KEVEPSS 95% An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior… GitLab 16.1.6 / 16.2.9+ Fix from $2,3002024-01-12 HIGH 7.8 CVE-2023-41974 KEV A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An a… Ipados 15.8.7 / 17.0+ Fix from $1,9502024-01-10 HIGH 7.0 CVE-2022-48618 KEV The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacke… Ipados 9.2 / 13.1+ Fix from $1,9502024-01-09 HIGH 7.8 CVE-2022-2586 KEVEPSS 10% It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was… Linux Kernel 4.14.316 / 4.19.256+ Fix from $1,9502024-01-08 HIGH 7.8 CVE-2023-7101 KEVEPSS 17% Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execut… Debian Linux after 0.65 Fix from $1,9502023-12-24 HIGH 8.8 CVE-2023-7024 KEVEPSS 7% Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafte… Chrome 120.0.6099.129+ Fix from $1,9502023-12-21 HIGH 8.8 CVE-2023-47565 KEVEPSS 73% An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerabili… Qvr Firmware 5.0.0+ Fix from $1,9502023-12-08 HIGH 8.8 CVE-2023-49897 KEVEPSS 51% An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vu… Ae1021 Firmware 2.0.10+ Fix from $1,9502023-12-06 HIGH 7.2 CVE-2023-44221 KEVEPSS 75% Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative pri… Sma 200 Firmware after 10.2.1.9-57sv Fix from $1,9502023-12-05 CRITICAL 9.8 CVE-2023-6448 KEV Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attack… Vision1210 Firmware 12.38+ Fix from $2,3002023-12-05 HIGH 7.8 CVE-2023-33107 KEV Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. 315 5g Iot Modem Firmware Patch available Fix from $1,9502023-12-05 HIGH 7.8 CVE-2023-33106 KEV Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND. Ar8035 Firmware Patch available Fix from $1,9502023-12-05 HIGH 7.8 CVE-2023-33063 KEV Memory corruption in DSP Services during a remote call from HLOS to DSP. 315 5g Iot Modem Firmware Patch available Fix from $1,9502023-12-05 HIGH 8.8 CVE-2023-42917 KEVEPSS 9% A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safa… Safari 2.42.3 / 14.1.2+ Fix from $1,9502023-11-30 MEDIUM 6.5 CVE-2023-42916 KEVEPSS 18% An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari … Safari 2.42.3 / 14.1.2+ Fix from $1,6002023-11-30