Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.6 CVE-2023-6345 KEVEPSS 16% Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially p… Chrome 119.0.2151.97 / 119.0.6045.199+ Fix from $2,3002023-11-29 HIGH 7.5 CVE-2023-49103 KEVEPSS 78% An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.… Graph Api Mitigation only Fix from $1,9502023-11-21 CRITICAL 9.9 CVE-2023-48365 KEVEPSS 25% Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation o… Qlik Sense Mitigation only Fix from $2,3002023-11-15 HIGH 7.8 CVE-2023-36424 KEVEPSS 12% Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20308 / 10.0.14393.6452+ Fix from $1,9502023-11-14 HIGH 7.8 CVE-2023-36036 KEVEPSS 17% Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20308 / 10.0.14393.6452+ Fix from $1,9502023-11-14 HIGH 7.8 CVE-2023-36033 KEVEPSS 12% Windows DWM Core Library Elevation of Privilege Vulnerability Windows 10 1809 10.0.17763.5122 / 10.0.19041.3693+ Fix from $1,9502023-11-14 HIGH 8.8 CVE-2023-36025 KEVEPSS 88% Windows SmartScreen Security Feature Bypass Vulnerability Windows 10 1507 Patch available Fix from $1,9502023-11-14 CRITICAL 9.8 CVE-2023-47246 KEVEPSS 99% In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as… Sysaid 23.3.36+ Fix from $2,3002023-11-10 CRITICAL 9.8 CVE-2023-22518 KEVEPSS 100% All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an… Confluence Data Center 7.19.16 / 8.3.4+ Fix from $2,3002023-10-31 CRITICAL 9.8 CVE-2023-46604 KEVEPSS 100% The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to… Activemq 5.15.16 / 5.16.7+ Fix from $2,3002023-10-27 HIGH 8.8 CVE-2023-46748 KEV An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network acce… Big Ip Access Policy Manager after 17.1.1 Fix from $1,9502023-10-26 CRITICAL 9.8 CVE-2023-46747 KEVEPSS 97% Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the manag… Big Ip Access Policy Manager after 17.1.1 Fix from $2,3002023-10-26 CRITICAL 9.8 CVE-2023-43208 KEVEPSS 83% NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused … Mirth Connect 4.4.1+ Fix from $2,3002023-10-26 CRITICAL 9.8 CVE-2023-34048 KEVEPSS 99% vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to v… Vcenter Server after 5.5 Fix from $2,3002023-10-25 HIGH 7.2 CVE-2023-20273 KEVEPSS 90% A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges o… Ios Xe Mitigation only Fix from $1,9502023-10-25 MEDIUM 5.4 CVE-2023-5631 KEVEPSS 76% Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because … Debian Linux 1.4.15 / 1.5.5+ Fix from $1,6002023-10-18 HIGH 7.5 CVE-2023-45727 KEV Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and e… Proself 1.09 / 1.66+ Fix from $1,9502023-10-18 CRITICAL 10.0 CVE-2023-20198 KEVEPSS 100% Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating… Ios Xe 16.12.10a / 17.3.8a+ Fix from $2,3002023-10-16 MEDIUM 5.3 CVE-2023-41763 KEVEPSS 90% Skype for Business Elevation of Privilege Vulnerability Skype For Business Server Patch available Fix from $1,6002023-10-10 MEDIUM 5.4 CVE-2023-36584 KEV Windows Mark of the Web Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.20232 / 10.0.17763.4974+ Fix from $1,6002023-10-10 MEDIUM 5.5 CVE-2023-36563 KEVEPSS 21% Microsoft WordPad Information Disclosure Vulnerability Windows 10 1507 10.0.10240.20232 / 10.0.14393.6351+ Fix from $1,6002023-10-10 HIGH 7.5 CVE-2023-4966 KEVEPSS 100% Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy)… Netscaler Application Delivery Controller 12.1-55.300 / 13.0-92.19+ Fix from $1,9502023-10-10 HIGH 7.5 CVE-2023-44487 KEVEPSS 100% The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploite… Caddy 0.17.0 / 1.20.10+ Fix from $1,9502023-10-10 HIGH 7.8 CVE-2023-42824 KEV The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may be able to elevate their priv… Ipados 16.7.1 / 17.0.3+ Fix from $1,9502023-10-04 CRITICAL 9.8 CVE-2023-22515 KEVEPSS 99% Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnera… Confluence Data Center 8.3.3 / 8.4.3+ Fix from $2,3002023-10-04 HIGH 7.8 CVE-2023-4911 KEVEPSS 81% A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue cou… Fedora Patch available Fix from $1,9502023-10-03 MEDIUM 5.5 CVE-2023-4211 KEV A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory. 5th Gen Gpu Architecture Kernel Driver Mitigation only Fix from $1,6002023-10-01 HIGH 8.8 CVE-2023-5217 KEVEPSS 49% Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially ex… Firefox 1.13.1 / 115.3.1+ Fix from $1,9502023-09-28 MEDIUM 6.6 CVE-2023-20109 KEV A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authentic… iOS Mitigation only Fix from $1,6002023-09-27 HIGH 8.8 CVE-2023-40044 KEVEPSS 90% In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Tr… Ws Ftp Server 8.7.4 / 8.8.2+ Fix from $1,9502023-09-27