Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2023-36851 KEV A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based atta… Junos Mitigation only Fix from $1,6002023-09-27 MEDIUM 6.1 CVE-2023-43770 KEVEPSS 58% Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/l… Debian Linux 1.4.14 / 1.5.4+ Fix from $1,6002023-09-22 HIGH 8.8 CVE-2023-41993 KEVEPSS 29% The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Ap… Fedora 14.0 / 17.0.1+ Fix from $1,9502023-09-21 HIGH 7.8 CVE-2023-41992 KEV The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attac… Ipados 12.7 / 13.6+ Fix from $1,9502023-09-21 MEDIUM 5.5 CVE-2023-41991 KEV A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to byp… Ipados 13.6 / 16.7+ Fix from $1,6002023-09-21 CRITICAL 9.8 CVE-2023-42793 KEVEPSS 100% In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible Teamcity 2023.05.4+ Fix from $2,3002023-09-19 HIGH 7.2 CVE-2023-41179 KEV A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-F… Apex One Mitigation only Fix from $1,9502023-09-19 HIGH 7.5 CVE-2023-38205 KEVEPSS 100% Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerabili… Coldfusion Mitigation only Fix from $1,9502023-09-14 HIGH 7.8 CVE-2023-26369 KEVEPSS 7% Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write … Acrobat 20.005.30524 / 23.006.20320+ Fix from $1,9502023-09-13 HIGH 7.8 CVE-2023-36802 KEVEPSS 26% Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability Windows 10 1809 10.0.17763.4851 / 10.0.19044.3448+ Fix from $1,9502023-09-12 MEDIUM 6.5 CVE-2023-36761 KEVEPSS 19% Microsoft Word Information Disclosure Vulnerability 365 Apps Patch available Fix from $1,6002023-09-12 HIGH 8.8 CVE-2023-4863 KEVEPSS 100% Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memo… Chrome 1.0.62681.0 / 1.6.00.26463+ Fix from $1,9502023-09-12 HIGH 7.8 CVE-2023-41990 KEV The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS Bi… Ipados 9.3 / 11.7.9+ Fix from $1,9502023-09-12 HIGH 7.8 CVE-2023-35674 KEV In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local e… Android Patch available Fix from $1,9502023-09-11 HIGH 8.8 CVE-2023-39780 KEVEPSS 34% On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist paramete… Rt Ax55 Firmware Mitigation only Fix from $1,9502023-09-11 HIGH 7.8 CVE-2023-41064 KEVEPSS 15% A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macO… Ipados 11.7.10 / 12.6.9+ Fix from $1,9502023-09-07 HIGH 7.8 CVE-2023-41061 KEV A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attac… Ipados 9.6.2 / 16.6.1+ Fix from $1,9502023-09-07 CRITICAL 9.1 CVE-2023-20269 KEVEPSS 22% A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Softwar… Adaptive Security Appliance Software Mitigation only Fix from $2,3002023-09-06 HIGH 8.8 CVE-2023-4762 KEVEPSS 40% Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium … Chrome 116.0.1938.76 / 116.0.5845.179+ Fix from $1,9502023-09-05 MEDIUM 6.5 CVE-2023-41266 KEVEPSS 82% A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlie… Qlik Sense Mitigation only Fix from $1,6002023-08-29 CRITICAL 9.9 CVE-2023-41265 KEVEPSS 84% An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 a… Qlik Sense Mitigation only Fix from $2,3002023-08-29 HIGH 7.5 CVE-2023-4346 KEV KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users bei… Connection Authorization No fix yet Fix from $1,9502023-08-29 HIGH 7.8 CVE-2023-38831 KEVEPSS 98% RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occur… Winrar 6.23+ Fix from $1,9502023-08-23 CRITICAL 9.8 CVE-2023-38035 KEVEPSS 100% A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentica… Mobileiron Sentry after 9.18.0 Fix from $2,3002023-08-21 MEDIUM 5.3 CVE-2023-36847 KEVEPSS 86% A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attac… Junos 20.4+ Fix from $1,6002023-08-17 MEDIUM 5.3 CVE-2023-36846 KEVEPSS 95% A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based atta… Junos 20.4+ Fix from $1,6002023-08-17 CRITICAL 9.8 CVE-2023-36845 KEVEPSS 94% A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, n… Junos 20.4+ Fix from $2,3002023-08-17 MEDIUM 5.3 CVE-2023-36844 KEVEPSS 91% A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attack… Junos 20.4+ Fix from $1,6002023-08-17 CRITICAL 9.8 CVE-2023-35082 KEVEPSS 100% An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of t… Endpoint Manager Mobile 11.11.0+ Fix from $2,3002023-08-15 HIGH 8.8 CVE-2022-48503 KEV The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Sa… Safari 8.7 / 12.5+ Fix from $1,9502023-08-14