Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2023-51714

An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x before 6.6.2…

Fix: 5.15.17 / 6.2.11+
Fix from $2,300 2023-12-24
Debian Linux HIGH 7.0
CVE-2023-6932

A use-after-free vulnerability in the Linux kernel's ipv4: igmp component can be exploited to achieve local privilege escalation. A race condition c…

Fix: 4.14.332 / 4.19.301+
Fix from $1,950 2023-12-19
Debian Linux MEDIUM 6.5
CVE-2023-51385EPSS 20%

In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by a…

Fix: 9.6+
Fix from $1,600 2023-12-18
Debian Linux MEDIUM 5.5
CVE-2023-51384

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during ad…

Fix: 9.6+
Fix from $1,600 2023-12-18
Debian Linux HIGH 8.8
CVE-2023-6509

Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI i…

Fix: 120.0.6099.62+
Fix from $1,950 2023-12-06
Debian Linux HIGH 8.8
CVE-2023-6510

Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI inter…

Fix: 120.0.6099.62+
Fix from $1,950 2023-12-06
Debian Linux MEDIUM 6.5
CVE-2023-6512

Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the contents of…

Fix: 120.0.6099.62+
Fix from $1,600 2023-12-06
Debian Linux HIGH 7.5
CVE-2023-40462

The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in…

Fix: after 4.16.0
Fix from $1,950 2023-12-04
Debian Linux MEDIUM 5.9
CVE-2023-5981

A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts wit…

Fix: 3.8.2+
Fix from $1,600 2023-11-28
Debian Linux HIGH 7.8
CVE-2023-23583

Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable es…

Mitigation only
Fix from $1,950 2023-11-14
Debian Linux MEDIUM 6.1
CVE-2023-46734

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and pr…

Fix: 4.4.51 / 5.4.31+
Fix from $1,600 2023-11-10
Debian Linux HIGH 7.5
CVE-2023-46234

browserify-sign is a package to duplicate the functionality of node's crypto public key functions, much of this is based on Fedor Indutny's work on i…

Fix: 4.2.2+
Fix from $1,950 2023-10-26
Debian Linux HIGH 7.5
CVE-2023-31122

Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.

Fix: 2.4.58+
Fix from $1,950 2023-10-23
Debian Linux MEDIUM 5.4
CVE-2023-5631 KEVEPSS 76%

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because …

Fix: 1.4.15 / 1.5.5+
Fix from $1,600 2023-10-18
Debian Linux HIGH 8.8
CVE-2023-45133

Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, usin…

Fix: 0.4.3 / 0.4.6+
Fix from $1,950 2023-10-12
Debian Linux HIGH 7.5
CVE-2023-45363EPSS 23%

An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It allows attac…

Fix: 1.35.12 / 1.39.5+
Fix from $1,950 2023-10-09
Debian Linux MEDIUM 5.3
CVE-2023-45364

An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision exis…

Fix: 1.39.5+
Fix from $1,600 2023-10-09
Debian Linux HIGH 8.8
CVE-2023-39928

A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability …

Mitigation only
Fix from $1,950 2023-10-06
Debian Linux HIGH 8.8
CVE-2023-43655

Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed …

Fix: 1.10.27 / 2.2.21+
Fix from $1,950 2023-09-29
Debian Linux MEDIUM 6.6
CVE-2023-5197

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Addition…

Fix: 5.10.198 / 5.15.134+
Fix from $1,600 2023-09-27
Debian Linux HIGH 7.3
CVE-2023-3550

Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attack…

No fix yet
Fix from $1,950 2023-09-25
Debian Linux HIGH 7.8
CVE-2023-34319

The fix for XSA-423 added logic to Linux'es netback driver to deal with a frontend splitting a packet in a way such that not all of the headers would…

Fix: 4.10 / 4.14.321+
Fix from $1,950 2023-09-22
Debian Linux MEDIUM 6.1
CVE-2023-43770 KEVEPSS 58%

Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/l…

Fix: 1.4.14 / 1.5.4+
Fix from $1,600 2023-09-22
Debian Linux CRITICAL 9.8
CVE-2023-42464

A Type Confusion vulnerability was found in the Spotlight RPC functions in afpd in Netatalk 3.1.x before 3.1.17. When parsing Spotlight RPC packets, …

Fix: 3.1.17+
Fix from $2,300 2023-09-20
Debian Linux CRITICAL 9.8
CVE-2019-19450

paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar…

Fix: 3.5.31+
Fix from $2,300 2023-09-20
Debian Linux MEDIUM 5.3
CVE-2023-40167

Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accepts the `+` character proceedi…

Fix: 9.4.52 / 10.0.16+
Fix from $1,600 2023-09-15
Debian Linux MEDIUM 5.7
CVE-2023-4875

Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12

Fix: 2.2.12+
Fix from $1,600 2023-09-09
Debian Linux MEDIUM 6.5
CVE-2023-4874

Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12

Fix: 2.2.12+
Fix from $1,600 2023-09-09
Debian Linux HIGH 7.8
CVE-2023-4781

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.

Fix: 9.0.1873 / 14.1+
Fix from $1,950 2023-09-05
Debian Linux HIGH 7.5
CVE-2023-41909

An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes,…

Fix: after 9.0
Fix from $1,950 2023-09-05