Vulnerability index

Browse CVEs

479 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Raid Controller Web Interface CRITICAL 9.8
CVE-2023-4323

Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup

Mitigation only
Fix from $2,300 2023-08-15
Raid Controller Web Interface CRITICAL 9.8
CVE-2023-4324

Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers

Mitigation only
Fix from $2,300 2023-08-15
Raid Controller Web Interface CRITICAL 9.8
CVE-2023-4325

Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities

No fix yet
Fix from $2,300 2023-08-15
Raid Controller Web Interface HIGH 7.5
CVE-2023-4326

Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites

Mitigation only
Fix from $1,950 2023-08-15
Raid Controller Web Interface MEDIUM 6.5
CVE-2023-4345

Broadcom RAID Controller web interface is vulnerable client-side control bypass leads to unauthorized data access for low privileged user

Mitigation only
Fix from $1,600 2023-08-15
Brocade Fabric Operating System HIGH 7.1
CVE-2023-31926

System files could be overwritten using the less command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0.

Fix: 9.1.1c+
Fix from $1,950 2023-08-02
Brocade Fabric Operating System MEDIUM 5.3
CVE-2023-31927

An information disclosure in the web interface of Brocade Fabric OS versions before Brocade Fabric OS v9.2.0 and v9.1.1c, could allow a remote unauth…

Fix: 9.1.1c+
Fix from $1,600 2023-08-02
Brocade Fabric Operating System HIGH 7.8
CVE-2023-31432

Through manipulation of passwords or other variables, using commands such as portcfgupload, configupload, license, myid, a non-privileged user could …

Fix: 9.1.1c+
Fix from $1,950 2023-08-02
Brocade Fabric Operating System MEDIUM 6.1
CVE-2023-31928

A reflected cross-site scripting (XSS) vulnerability exists in Brocade Webtools PortSetting.html of Brocade Fabric OS version before Brocade Fabric …

Fix: 9.2.0+
Fix from $1,600 2023-08-02
Brocade Fabric Operating System MEDIUM 5.5
CVE-2023-31430

A buffer overflow vulnerability in “secpolicydelete” command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0 could allow an authenti…

Fix: 9.1.1c+
Fix from $1,600 2023-08-02
Brocade Fabric Operating System MEDIUM 5.5
CVE-2023-31431

A buffer overflow vulnerability in “diagstatus” command in Brocade Fabric OS before Brocade Fabric v9.2.0 and v9.1.1c could allow an authenticated us…

Fix: 9.1.1c+
Fix from $1,600 2023-08-02
Brocade Fabric Operating System MEDIUM 5.5
CVE-2023-31428

Brocade Fabric OS before Brocade Fabric OS v9.1.1c, v9.2.0 contains a vulnerability in the command line that could allow a local user to dump files u…

Fix: 9.1.1c+
Fix from $1,600 2023-08-02
Fabric Operating System HIGH 7.8
CVE-2023-31427

Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c, and v9.2.0 Could allow an authenticated, local user with knowledge of full path names in…

Fix: 9.1.1c+
Fix from $1,950 2023-08-01
Fabric Operating System MEDIUM 6.5
CVE-2023-31426

The Brocade Fabric OS Commands “configupload” and “configdownload” before Brocade Fabric OS v9.1.1c, v8.2.3d, v9.2.0 print scp, sftp, ftp servers pas…

Fix: 8.2.3d / 9.1.1c+
Fix from $1,600 2023-08-01
Fabric Operating System HIGH 7.8
CVE-2023-31425

A vulnerability in the fosexec command of Brocade Fabric OS after Brocade Fabric OS v9.1.0 and, before Brocade Fabric OS v9.1.1 could allow a local a…

Mitigation only
Fix from $1,950 2023-08-01
Fabric Operating System MEDIUM 5.5
CVE-2023-31429

Brocade Fabric OS before Brocade Fabric OS 9.1.1c, 9.2.0 contains a vulnerability when using various commands such as “chassisdistribute”, “reboot”, …

Fix: 9.1.1c+
Fix from $1,600 2023-08-01
Advanced Secure Gateway CRITICAL 9.8
CVE-2023-23952

Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability.

Fix: 3.1.6.0 / 7.3.13.1+
Fix from $2,300 2023-06-01
Advanced Secure Gateway HIGH 8.1
CVE-2023-23955

Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Server-Side Request Forgery vulnerability.

Fix: 3.1.6.0 / 7.3.13.1+
Fix from $1,950 2023-06-01
Advanced Secure Gateway HIGH 7.8
CVE-2023-23953

Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to an Elevation of Privilege vulnerability.

Fix: 3.1.6.0 / 7.3.13.1+
Fix from $1,950 2023-06-01
Advanced Secure Gateway MEDIUM 5.4
CVE-2023-23954

Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Stored Cross-Site Scripting vulnerability.

Fix: 3.1.6.0 / 7.3.13.1+
Fix from $1,600 2023-06-01
Symantec Siteminder Webagent MEDIUM 5.4
CVE-2023-23956

A user can supply malicious HTML and JavaScript code that will be executed in the client browser

No fix yet
Fix from $1,600 2023-05-30
Vmware Nsx T Data Center MEDIUM 6.1
CVE-2023-20868

NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation. A remote attacker can inject HTML or JavaScript to r…

Fix: 3.2.3+
Fix from $1,600 2023-05-26
Tcpreplay HIGH 7.5
CVE-2023-27788

An issue found in TCPrewrite v.4.4.3 allows a remote attacker to cause a denial of service via the ports2PORT function at the portmap.c:69 endpoint.

Patch available
Fix from $1,950 2023-03-16
Tcpreplay HIGH 7.5
CVE-2023-27789

An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the cidr2cidr function at the cidr.c:178 endpoint.

Patch available
Fix from $1,950 2023-03-16
Tcpreplay HIGH 7.5
CVE-2023-27783

An issue found in TCPreplay tcprewrite v.4.4.3 allows a remote attacker to cause a denial of service via the tcpedit_dlt_cleanup function at plugins/…

Patch available
Fix from $1,950 2023-03-16
Tcpreplay HIGH 7.5
CVE-2023-27784

An issue found in TCPReplay v.4.4.3 allows a remote attacker to cause a denial of service via the read_hexstring function at the utils.c:309 endpoint.

Patch available
Fix from $1,950 2023-03-16
Tcpreplay HIGH 7.5
CVE-2023-27785

An issue found in TCPreplay TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse endpoints function.

Patch available
Fix from $1,950 2023-03-16
Tcpreplay HIGH 7.5
CVE-2023-27786

An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the macinstring function.

Patch available
Fix from $1,950 2023-03-16
Tcpreplay HIGH 7.5
CVE-2023-27787

An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse_list function at the list.c:81 endpoint.

Patch available
Fix from $1,950 2023-03-16
Symantec Identity Governance And Administration MEDIUM 6.1
CVE-2023-23950

User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.

Mitigation only
Fix from $1,600 2023-01-26