Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2022-27405 |
|
Out-of-Bounds Read in platform/external/freetype (CVE-2022-27405)
vulnerability in platform/external/freetype (CVE-2022-27405). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `13:2023-07-01` or later.
|
| CVE-2019-17621 KEV |
|
[KEV] OS Command Injection in D-link dir-859-router (CVE-2019-17621)
OS command injection in D-link dir-859-router (CVE-2019-17621). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-20500 KEV |
|
[KEV] OS Command Injection in D-link dwl-2600ap-access-point (CVE-2019-20500)
OS command injection in D-link dwl-2600ap-access-point (CVE-2019-20500). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-25487 KEV |
|
[KEV] Out-of-Bounds Read in Samsung mobile-devices (CVE-2021-25487)
vulnerability in Samsung mobile-devices (CVE-2021-25487). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-25489 KEV |
|
[KEV] Vulnerability in Samsung mobile-devices (CVE-2021-25489)
vulnerability in Samsung mobile-devices (CVE-2021-25489). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-25394 KEV |
|
[KEV] Use-After-Free in Samsung mobile-devices (CVE-2021-25394)
vulnerability in Samsung mobile-devices (CVE-2021-25394). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-25395 KEV |
|
[KEV] Vulnerability in Samsung mobile-devices (CVE-2021-25395)
vulnerability in Samsung mobile-devices (CVE-2021-25395). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-25371 KEV |
|
[KEV] Vulnerability in Samsung mobile-devices (CVE-2021-25371)
vulnerability in Samsung mobile-devices (CVE-2021-25371). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-25372 KEV |
|
[KEV] Out-of-Bounds Write in Samsung mobile-devices (CVE-2021-25372)
out-of-bounds write in Samsung mobile-devices (CVE-2021-25372). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-3390 |
|
Use-After-Free in c (CVE-2023-3390)
vulnerability in c (CVE-2023-3390). Successful exploitation can lead to full system takeover.
|
| CVE-2023-20006 |
|
Vulnerability in dos (CVE-2023-20006)
vulnerability in dos (CVE-2023-20006). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-36664 |
|
Vulnerability in artifex (CVE-2023-36664)
vulnerability in artifex (CVE-2023-36664). Successful exploitation can lead to full system takeover.
|
| CVE-2023-20867 KEV |
|
[KEV] Authentication Bypass in Vmware tools (CVE-2023-20867)
authentication bypass in Vmware tools (CVE-2023-20867). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-27992 KEV |
|
[KEV] OS Command Injection in Zyxel multiple-network-attached-storage-nas-devices (CVE-2023-27992)
OS command injection in Zyxel multiple-network-attached-storage-nas-devices (CVE-2023-27992). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-32434 KEV |
|
[KEV] Vulnerability in Apple multiple-products (CVE-2023-32434)
vulnerability in Apple multiple-products (CVE-2023-32434). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-32435 KEV |
|
[KEV] Out-of-Bounds Write in Apple multiple-products (CVE-2023-32435)
out-of-bounds write in Apple multiple-products (CVE-2023-32435). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-32439 KEV |
|
[KEV] Vulnerability in Apple multiple-products (CVE-2023-32439)
vulnerability in Apple multiple-products (CVE-2023-32439). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-0165 KEV |
|
[KEV] Vulnerability in Microsoft win32k (CVE-2016-0165)
vulnerability in Microsoft win32k (CVE-2016-0165). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-9079 KEV |
|
[KEV] Use-After-Free in Mozilla firefox (CVE-2016-9079)
vulnerability in Mozilla firefox (CVE-2016-9079). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-35730 KEV |
|
[KEV] Cross-Site Scripting (XSS) in roundcube (CVE-2020-35730)
cross-site scripting in roundcube (CVE-2020-35730). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-12641 KEV |
|
[KEV] OS Command Injection in roundcube (CVE-2020-12641)
OS command injection in roundcube (CVE-2020-12641). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-44026 KEV |
|
[KEV] SQL Injection in roundcube (CVE-2021-44026)
SQL injection in roundcube (CVE-2021-44026). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-20887 KEV |
|
[KEV] Command Injection in Vmware aria-operations-for-networks (CVE-2023-20887)
command injection in Vmware aria-operations-for-networks (CVE-2023-20887). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-25747 |
|
Use-After-Free in mozilla (CVE-2023-25747)
vulnerability in mozilla (CVE-2023-25747). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-29534 |
|
Vulnerability in mozilla (CVE-2023-29534)
vulnerability in mozilla (CVE-2023-29534). Confidential information can be exposed externally.
|
| CVE-2023-29546 |
|
Vulnerability in mozilla (CVE-2023-29546)
vulnerability in mozilla (CVE-2023-29546). Confidential information can be exposed externally.
|
| CVE-2023-35823 |
|
Vulnerability in c (CVE-2023-35823)
vulnerability in c (CVE-2023-35823). Successful exploitation can lead to full system takeover.
|
| CVE-2023-3268 |
|
Out-of-Bounds Read in c (CVE-2023-3268)
vulnerability in c (CVE-2023-3268). Confidential information can be exposed externally.
|
| CVE-2023-34832 |
|
Vulnerability in tp-link (CVE-2023-34832)
vulnerability in tp-link (CVE-2023-34832). Successful exploitation can lead to full system takeover.
|
| CVE-2023-34752 |
|
SQL Injection in sqli (CVE-2023-34752)
SQL injection in sqli (CVE-2023-34752). Successful exploitation can lead to full system takeover.
|
| CVE-2023-34944 |
|
Unrestricted File Upload in chamilo (CVE-2023-34944)
vulnerability in chamilo (CVE-2023-34944). Successful exploitation can lead to full system takeover.
|
| CVE-2023-27997 KEV |
|
[KEV] Vulnerability in Fortinet fortios-and-fortiproxy-ssl-vpn (CVE-2023-27997)
vulnerability in Fortinet fortios-and-fortiproxy-ssl-vpn (CVE-2023-27997). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2023-3079 KEV |
|
[KEV] Vulnerability in Google chromium-v8 (CVE-2023-3079)
vulnerability in Google chromium-v8 (CVE-2023-3079). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-27126 |
|
Vulnerability in tp-link (CVE-2023-27126)
vulnerability in tp-link (CVE-2023-27126). Confidential information can be exposed externally.
|
| CVE-2023-33532 |
|
Command Injection in netgear (CVE-2023-33532)
command injection in netgear (CVE-2023-33532). Successful exploitation can lead to full system takeover.
|
| CVE-2023-33530 |
|
Command Injection in tenda (CVE-2023-33530)
command injection in tenda (CVE-2023-33530). Successful exploitation can lead to full system takeover.
|
| CVE-2023-33009 KEV |
|
[KEV] Vulnerability in Zyxel multiple-firewalls (CVE-2023-33009)
vulnerability in Zyxel multiple-firewalls (CVE-2023-33009). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-33010 KEV |
|
[KEV] Vulnerability in Zyxel multiple-firewalls (CVE-2023-33010)
vulnerability in Zyxel multiple-firewalls (CVE-2023-33010). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-29551 |
|
Out-of-Bounds Write in mozilla (CVE-2023-29551)
out-of-bounds write in mozilla (CVE-2023-29551). Successful exploitation can lead to full system takeover.
|
| CVE-2023-29533 |
|
Vulnerability in mozilla (CVE-2023-29533)
vulnerability in mozilla (CVE-2023-29533). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-29535 |
|
Vulnerability in mozilla (CVE-2023-29535)
vulnerability in mozilla (CVE-2023-29535). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-29536 |
|
Use-After-Free in mozilla (CVE-2023-29536)
vulnerability in mozilla (CVE-2023-29536). Successful exploitation can lead to full system takeover.
|
| CVE-2023-29537 |
|
Vulnerability in mozilla (CVE-2023-29537)
vulnerability in mozilla (CVE-2023-29537). Successful exploitation can lead to full system takeover.
|
| CVE-2023-29538 |
|
Vulnerability in mozilla (CVE-2023-29538)
vulnerability in mozilla (CVE-2023-29538). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-29539 |
|
Vulnerability in mozilla (CVE-2023-29539)
vulnerability in mozilla (CVE-2023-29539). Successful exploitation can lead to full system takeover.
|
| CVE-2023-29540 |
|
Open Redirect in mozilla (CVE-2023-29540)
vulnerability in mozilla (CVE-2023-29540). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-29541 |
|
Vulnerability in mozilla (CVE-2023-29541)
vulnerability in mozilla (CVE-2023-29541). Successful exploitation can lead to full system takeover.
|
| CVE-2023-29543 |
|
Use-After-Free in mozilla (CVE-2023-29543)
vulnerability in mozilla (CVE-2023-29543). Successful exploitation can lead to full system takeover.
|
| CVE-2023-29544 |
|
Vulnerability in mozilla (CVE-2023-29544)
vulnerability in mozilla (CVE-2023-29544). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-29548 |
|
Vulnerability in mozilla (CVE-2023-29548)
vulnerability in mozilla (CVE-2023-29548). Data can be tampered with by attackers.
|