Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2023-41993 KEV |
|
[KEV] Vulnerability in Apple java (CVE-2023-41993)
vulnerability in Apple java (CVE-2023-41993). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `1.8.0, 8.0.411` or later.
|
| CVE-2023-41991 KEV |
|
[KEV] Vulnerability in Apple multiple-products (CVE-2023-41991)
vulnerability in Apple multiple-products (CVE-2023-41991). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-41992 KEV |
|
[KEV] Vulnerability in Apple multiple-products (CVE-2023-41992)
vulnerability in Apple multiple-products (CVE-2023-41992). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-41179 KEV |
|
[KEV] Vulnerability in Trend micro trend-micro (CVE-2023-41179)
vulnerability in Trend micro trend-micro (CVE-2023-41179). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-4853 |
|
Vulnerability in dos (CVE-2023-4853)
vulnerability in dos (CVE-2023-4853). Successful exploitation can lead to full system takeover.
|
| CVE-2023-38886 |
|
OS Command Injection in dolibarr (CVE-2023-38886)
OS command injection in dolibarr (CVE-2023-38886). Successful exploitation can lead to full system takeover.
|
| CVE-2023-38887 |
|
Unrestricted File Upload in dolibarr (CVE-2023-38887)
vulnerability in dolibarr (CVE-2023-38887). Successful exploitation can lead to full system takeover.
|
| CVE-2023-40933 |
|
SQL Injection in sqli (CVE-2023-40933)
SQL injection in sqli (CVE-2023-40933). Successful exploitation can lead to full system takeover.
|
| CVE-2023-40934 |
|
SQL Injection in sqli (CVE-2023-40934)
SQL injection in sqli (CVE-2023-40934). Successful exploitation can lead to full system takeover.
|
| CVE-2023-28434 KEV |
|
[KEV] Privilege Escalation in minio (CVE-2023-28434)
vulnerability in minio (CVE-2023-28434). Risk of unauthorized operations or information disclosure. Exploitable via ``PostPolicyBucket``. Listed in CISA KEV — actively exploited.
|
| CVE-2023-41595 |
|
An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password.
An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password.
|
| CVE-2017-6884 KEV |
|
[KEV] OS Command Injection in Zyxel emg2926-routers (CVE-2017-6884)
OS command injection in Zyxel emg2926-routers (CVE-2017-6884). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-3129 KEV |
|
[KEV] Vulnerability in Laravel ignition (CVE-2021-3129)
vulnerability in Laravel ignition (CVE-2021-3129). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2022-22265 KEV |
|
[KEV] Vulnerability in Samsung mobile-devices (CVE-2022-22265)
vulnerability in Samsung mobile-devices (CVE-2022-22265). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2014-8361 KEV |
|
[KEV] Vulnerability in Realtek sdk (CVE-2014-8361)
vulnerability in Realtek sdk (CVE-2014-8361). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-41325 |
|
Vulnerability in trustedfirmware (CVE-2023-41325)
vulnerability in trustedfirmware (CVE-2023-41325). Confidential information can be exposed externally. Exploitable via ``shdr_verify_signature``.
|
| CVE-2023-4664 |
|
Incorrect Default Permissions vulnerability in Saphira Saphira Connect allows Privilege...
Incorrect Default Permissions vulnerability in Saphira Saphira Connect allows Privilege...
|
| CVE-2023-4665 |
|
Incorrect Execution-Assigned Permissions vulnerability in Saphira Saphira Connect allows...
Incorrect Execution-Assigned Permissions vulnerability in Saphira Saphira Connect allows...
|
| CVE-2023-26369 KEV |
|
[KEV] Out-of-Bounds Write in Adobe acrobat-and-reader (CVE-2023-26369)
out-of-bounds write in Adobe acrobat-and-reader (CVE-2023-26369). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-35674 KEV |
|
[KEV] Vulnerability in Android platform/frameworks/base (CVE-2023-35674)
vulnerability in Android platform/frameworks/base (CVE-2023-35674). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `13:2023-09-01` or later.
|
| CVE-2023-4863 KEV |
|
[KEV] Out-of-Bounds Write in Google libwebp-sys2 (CVE-2023-4863)
out-of-bounds write in Google libwebp-sys2 (CVE-2023-4863). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `0.1.8` or later.
|
| CVE-2023-36761 KEV |
|
[KEV] Vulnerability in Microsoft word (CVE-2023-36761)
vulnerability in Microsoft word (CVE-2023-36761). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-36802 KEV |
|
[KEV] Use-After-Free in Microsoft streaming-service-proxy (CVE-2023-36802)
vulnerability in Microsoft streaming-service-proxy (CVE-2023-36802). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-41064 KEV |
|
[KEV] Vulnerability in Apple ios (CVE-2023-41064)
vulnerability in Apple ios (CVE-2023-41064). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-41061 KEV |
|
[KEV] Vulnerability in Apple ios (CVE-2023-41061)
vulnerability in Apple ios (CVE-2023-41061). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-40271 |
|
Vulnerability in trustedfirmware (CVE-2023-40271)
vulnerability in trustedfirmware (CVE-2023-40271). Data can be tampered with by attackers.
|
| CVE-2023-4244 |
|
Use-After-Free in privilege-escalation (CVE-2023-4244)
vulnerability in privilege-escalation (CVE-2023-4244). Successful exploitation can lead to full system takeover.
|
| CVE-2023-33246 KEV |
|
[KEV] Code Injection in Apache rocketmq (CVE-2023-33246)
code injection in Apache rocketmq (CVE-2023-33246). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-4781 |
|
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.
|
| CVE-2023-3375 |
|
Unrestricted File Upload in bookreen (CVE-2023-3375)
vulnerability in bookreen (CVE-2023-3375). Successful exploitation can lead to full system takeover.
|
| CVE-2023-4733 |
|
Use After Free in GitHub repository vim/vim prior to 9.0.1840.
Use After Free in GitHub repository vim/vim prior to 9.0.1840.
|
| CVE-2023-4750 |
|
Use After Free in GitHub repository vim/vim prior to 9.0.1857.
Use After Free in GitHub repository vim/vim prior to 9.0.1857.
|
| CVE-2023-4736 |
|
Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.
Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.
|
| CVE-2023-4735 |
|
Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.
Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.
|
| CVE-2023-4734 |
|
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.
|
| CVE-2023-36088 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2023-36088)
SSRF in ssrf (CVE-2023-36088). Confidential information can be exposed externally.
|
| CVE-2023-39810 |
|
An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.
An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.
|
| CVE-2023-36741 |
|
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
|
| CVE-2023-32079 |
|
Vulnerability in netmaker (CVE-2023-32079)
vulnerability in netmaker (CVE-2023-32079). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.17.1` or later.
|
| CVE-2023-32078 |
|
Vulnerability in netmaker (CVE-2023-32078)
vulnerability in netmaker (CVE-2023-32078). Data can be tampered with by attackers. Mitigation: upgrade to `0.17.1` or later.
|
| CVE-2023-32077 |
|
Vulnerability in github.com/gravitl/netmaker (CVE-2023-32077)
vulnerability in github.com/gravitl/netmaker (CVE-2023-32077). Confidential information can be exposed externally. Mitigation: upgrade to `0.17.1` or later.
|
| CVE-2023-38831 KEV |
|
[KEV] Vulnerability in Rarlab winrar (CVE-2023-38831)
vulnerability in Rarlab winrar (CVE-2023-38831). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2023-32315 KEV |
|
[KEV] Path Traversal in Ignite realtime ignite-realtime (CVE-2023-32315)
path traversal in Ignite realtime ignite-realtime (CVE-2023-32315). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-38035 KEV |
|
[KEV] Authorization Flaw in Ivanti sentry (CVE-2023-38035)
vulnerability in Ivanti sentry (CVE-2023-38035). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-27532 KEV |
|
[KEV] Vulnerability in Veeam backup-replication (CVE-2023-27532)
vulnerability in Veeam backup-replication (CVE-2023-27532). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-36787 |
|
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
|
| CVE-2023-38836 |
|
Unrestricted File Upload in boidcms (CVE-2023-38836)
vulnerability in boidcms (CVE-2023-38836). Successful exploitation can lead to full system takeover.
|
| CVE-2023-38899 |
|
SQL Injection in sqli (CVE-2023-38899)
SQL injection in sqli (CVE-2023-38899). Successful exploitation can lead to full system takeover.
|
| CVE-2023-39785 |
|
Out-of-Bounds Write in tenda (CVE-2023-39785)
out-of-bounds write in tenda (CVE-2023-39785). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-39786 |
|
Out-of-Bounds Write in tenda (CVE-2023-39786)
out-of-bounds write in tenda (CVE-2023-39786). Risk of unauthorized operations or information disclosure.
|