Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2023-4323
Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup
Raid Controller Web Interface
Mitigation only
CRITICAL 9.8
CVE-2023-4324
Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers
Raid Controller Web Interface
Mitigation only
CRITICAL 9.8
CVE-2023-4325
Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities
Raid Controller Web Interface
No fix yet
HIGH 7.5
CVE-2023-4326
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites
Raid Controller Web Interface
Mitigation only
MEDIUM 6.5
CVE-2023-4345
Broadcom RAID Controller web interface is vulnerable client-side control bypass leads to unauthorized data access for low privileged user
Raid Controller Web Interface
Mitigation only
HIGH 7.1
CVE-2023-31926
System files could be overwritten using the less command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0.
Brocade Fabric Operating System
9.1.1c+
MEDIUM 5.3
CVE-2023-31927
An information disclosure in the web interface of Brocade Fabric OS versions before Brocade Fabric OS v9.2.0 and v9.1.1c, could allow a remote unauth…
Brocade Fabric Operating System
9.1.1c+
HIGH 7.8
CVE-2023-31432
Through manipulation of passwords or other variables, using commands such as portcfgupload, configupload, license, myid, a non-privileged user could …
Brocade Fabric Operating System
9.1.1c+
MEDIUM 6.1
CVE-2023-31928
A reflected cross-site scripting (XSS) vulnerability exists in Brocade Webtools PortSetting.html of Brocade Fabric OS version before Brocade Fabric …
Brocade Fabric Operating System
9.2.0+
MEDIUM 5.5
CVE-2023-31430
A buffer overflow vulnerability in “secpolicydelete” command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0 could allow an authenti…
Brocade Fabric Operating System
9.1.1c+
MEDIUM 5.5
CVE-2023-31431
A buffer overflow vulnerability in “diagstatus” command in Brocade Fabric OS before Brocade Fabric v9.2.0 and v9.1.1c could allow an authenticated us…
Brocade Fabric Operating System
9.1.1c+
MEDIUM 5.5
CVE-2023-31428
Brocade Fabric OS before Brocade Fabric OS v9.1.1c, v9.2.0 contains a vulnerability in the command line that could allow a local user to dump files u…
Brocade Fabric Operating System
9.1.1c+
HIGH 7.8
CVE-2023-31427
Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c, and v9.2.0 Could allow an authenticated, local user with knowledge of full path names in…
Fabric Operating System
9.1.1c+
MEDIUM 6.5
CVE-2023-31426
The Brocade Fabric OS Commands “configupload” and “configdownload” before Brocade Fabric OS v9.1.1c, v8.2.3d, v9.2.0 print scp, sftp, ftp servers pas…
Fabric Operating System
8.2.3d / 9.1.1c+
HIGH 7.8
CVE-2023-31425
A vulnerability in the fosexec command of Brocade Fabric OS after Brocade Fabric OS v9.1.0 and, before Brocade Fabric OS v9.1.1 could allow a local a…
Fabric Operating System
Mitigation only
MEDIUM 5.5
CVE-2023-31429
Brocade Fabric OS before Brocade Fabric OS 9.1.1c, 9.2.0 contains a vulnerability when using various commands such as “chassisdistribute”, “reboot”, …
Fabric Operating System
9.1.1c+
CRITICAL 9.8
CVE-2023-23952
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability.
Advanced Secure Gateway
3.1.6.0 / 7.3.13.1+
HIGH 8.1
CVE-2023-23955
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Server-Side Request Forgery vulnerability.
Advanced Secure Gateway
3.1.6.0 / 7.3.13.1+
HIGH 7.8
CVE-2023-23953
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to an Elevation of Privilege vulnerability.
Advanced Secure Gateway
3.1.6.0 / 7.3.13.1+
MEDIUM 5.4
CVE-2023-23954
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Stored Cross-Site Scripting vulnerability.
Advanced Secure Gateway
3.1.6.0 / 7.3.13.1+
MEDIUM 5.4
CVE-2023-23956
A user can supply malicious HTML and JavaScript code that will be executed in the client browser
Symantec Siteminder Webagent
No fix yet
MEDIUM 6.1
CVE-2023-20868
NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation. A remote attacker can inject HTML or JavaScript to r…
Vmware Nsx T Data Center
3.2.3+
HIGH 7.5
CVE-2023-27788
An issue found in TCPrewrite v.4.4.3 allows a remote attacker to cause a denial of service via the ports2PORT function at the portmap.c:69 endpoint.
Tcpreplay
Patch available
HIGH 7.5
CVE-2023-27789
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the cidr2cidr function at the cidr.c:178 endpoint.
Tcpreplay
Patch available
HIGH 7.5
CVE-2023-27783
An issue found in TCPreplay tcprewrite v.4.4.3 allows a remote attacker to cause a denial of service via the tcpedit_dlt_cleanup function at plugins/…
Tcpreplay
Patch available
HIGH 7.5
CVE-2023-27784
An issue found in TCPReplay v.4.4.3 allows a remote attacker to cause a denial of service via the read_hexstring function at the utils.c:309 endpoint.
Tcpreplay
Patch available
HIGH 7.5
CVE-2023-27785
An issue found in TCPreplay TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse endpoints function.
Tcpreplay
Patch available
HIGH 7.5
CVE-2023-27786
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the macinstring function.
Tcpreplay
Patch available
HIGH 7.5
CVE-2023-27787
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse_list function at the list.c:81 endpoint.
Tcpreplay
Patch available
MEDIUM 6.1
CVE-2023-23950
User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.
Symantec Identity Governance And Administration
Mitigation only