87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 601–650 of 1,734 in KEV · page 13 of 35

IDTitleSummary
CVE-2023-35082Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability
KEVIvanti
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted fu…
CVE-2023-35081Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability
KEVIvanti
Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file writes to t…
CVE-2023-35078Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability
KEVCVSS 9.8Ivanti
Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to…
CVE-2023-34362Progress MOVEit Transfer SQL Injection Vulnerability
KEVProgress
Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's d…
CVE-2023-34192Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
KEVSynacor
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability that allows a remote authenticated attacker to execute arbitrary c…
CVE-2023-34048VMware vCenter Server Out-of-Bounds Write Vulnerability
KEVVMware
VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code…
CVE-2023-33538TP-Link Multiple Routers Command Injection Vulnerability
KEVTP-Link
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacte…
CVE-2023-33246Apache RocketMQ Command Execution Vulnerability
KEVApache
Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker …
CVE-2023-33107Qualcomm Multiple Chipsets Integer Overflow Vulnerability
KEVQualcomm
Multiple Qualcomm chipsets contain an integer overflow vulnerability due to memory corruption in Graphics Linux while assigning shared virtual memory region du…
CVE-2023-33106Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability
KEVQualcomm
Multiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of syn…
CVE-2023-33063Qualcomm Multiple Chipsets Use-After-Free Vulnerability
KEVQualcomm
Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services during a remote call from HLOS to DSP.
CVE-2023-33010Zyxel Multiple Firewalls Buffer Overflow Vulnerability
KEVZyxel
Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that cou…
CVE-2023-33009Zyxel Multiple Firewalls Buffer Overflow Vulnerability
KEVZyxel
Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that coul…
CVE-2023-32439Apple Multiple Products WebKit Type Confusion Vulnerability
KEVApple
Apple iOS, iPadOS, macOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content…
CVE-2023-32435Apple Multiple Products WebKit Memory Corruption Vulnerability
KEVApple
Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web cont…
CVE-2023-32434Apple Multiple Products Integer Overflow Vulnerability
KEVApple
Apple iOS. iPadOS, macOS, and watchOS contain an integer overflow vulnerability that could allow an application to execute code with kernel privileges.
CVE-2023-32409Apple Multiple Products WebKit Sandbox Escape Vulnerability
KEVApple
Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an unspecified vulnerability that can allow a remote attacker to break out of the Web Conten…
CVE-2023-32373Apple Multiple Products WebKit Use-After-Free Vulnerability
KEVApple
Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously craf…
CVE-2023-32315Ignite Realtime Openfire Path Traversal Vulnerability
KEVIgnite Realtime
Ignite Realtime Openfire contains a path traversal vulnerability that allows an unauthenticated attacker to access restricted pages in the Openfire Admin Conso…
CVE-2023-32049Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability
KEVMicrosoft
Microsoft Windows Defender SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the Open File - Security Warning prom…
CVE-2023-32046Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for privilege escalation.
CVE-2023-3079Google Chromium V8 Type Confusion Vulnerability
KEVGoogle
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.…
CVE-2023-29552Service Location Protocol (SLP) Denial-of-Service Vulnerability
KEVIETF
The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services …
CVE-2023-29492Novi Survey Insecure Deserialization Vulnerability
KEVNovi Survey
Novi Survey contains an insecure deserialization vulnerability that allows remote attackers to execute code on the server in the context of the service account.
CVE-2023-29360Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability
KEVMicrosoft
Microsoft Streaming Service contains an untrusted pointer dereference vulnerability that allows for privilege escalation, enabling a local attacker to gain SYS…
CVE-2023-29357Microsoft SharePoint Server Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication …
CVE-2023-29336Microsoft Win32K Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation up to SYSTEM privileges.
CVE-2023-29300Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
KEVAdobe
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
CVE-2023-29298Adobe ColdFusion Improper Access Control Vulnerability
KEVAdobe
Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass.
CVE-2023-28771Zyxel Multiple Firewalls OS Command Injection Vulnerability
KEVZyxel
Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS comman…
CVE-2023-2868Barracuda Networks ESG Appliance Improper Input Validation Vulnerability
KEVBarracuda Networks
Barracuda Email Security Gateway (ESG) appliance contains an improper input validation vulnerability of a user-supplied .tar file, leading to remote command in…
CVE-2023-28461Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability
KEVCVSS 9.8Array Networks
Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute…
CVE-2023-28434MinIO Security Feature Bypass Vulnerability
KEVMinIO
MinIO contains a security feature bypass vulnerability that allows an attacker to use crafted requests to bypass metadata bucket name checking and put an objec…
CVE-2023-28432MinIO Information Disclosure Vulnerability
KEVMinIO
MinIO contains a vulnerability in a cluster deployment where MinIO returns all environment variables, which allows for information disclosure.
CVE-2023-28252Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
CVE-2023-28229Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limi…
CVE-2023-28206Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability
KEVApple
Apple iOS, iPadOS, and macOS IOSurfaceAccelerator contain an out-of-bounds write vulnerability that allows an app to execute code with kernel privileges.
CVE-2023-28205Apple Multiple Products WebKit Use-After-Free Vulnerability
KEVApple
Apple iOS, iPadOS, macOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content…
CVE-2023-28204Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability
KEVApple
Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing …
CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability
KEVCVSS 9.8Fortinet
Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code …
CVE-2023-27992Zyxel Multiple NAS Devices Command Injection Vulnerability
KEVZyxel
Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker…
CVE-2023-27532Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability
KEVVeeam
Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user op…
CVE-2023-27524Apache Superset Insecure Default Initialization of Resource Vulnerability
KEVApache
Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resourc…
CVE-2023-27351PaperCut NG/MF Improper Authentication Vulnerability
KEVCVSS 7.5PaperCut
PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the S…
CVE-2023-27350PaperCut MF/NG Improper Access Control Vulnerability
KEVPaperCut
PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the co…
CVE-2023-26369Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability
KEVAdobe
Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution.
CVE-2023-26360Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
KEVAdobe
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution.
CVE-2023-26359Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
KEVAdobe
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user.
CVE-2023-26083Arm Mali GPU Kernel Driver Information Disclosure Vulnerability
KEVArm
Arm Mali GPU Kernel Driver contains an information disclosure vulnerability that allows a non-privileged user to make valid GPU processing operations that expo…
CVE-2023-25717Multiple Ruckus Wireless Products CSRF and RCE Vulnerability
KEVCVSS 9.8Ruckus Wireless
Ruckus Wireless Access Point (AP) software contains an unspecified vulnerability in the web services component. If the web services component is enabled on the…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.