87,929 indexed
CVECVE vulnerabilities
87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 651–700 of 1,734 in KEV · page 14 of 35
| ID | Title | Summary |
|---|---|---|
| CVE-2023-2533 | PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability KEVPaperCut | PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific conditions, could potentially enable an attacker to alter secu… |
| CVE-2023-25280 | D-Link DIR-820 Router OS Command Injection Vulnerability KEVD-Link | D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafte… |
| CVE-2023-24955 | Microsoft SharePoint Server Code Injection Vulnerability KEVMicrosoft | Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely. |
| CVE-2023-24880 | Microsoft Windows SmartScreen Security Feature Bypass Vulnerability KEVMicrosoft | Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a spec… |
| CVE-2023-24489 | Citrix Content Collaboration ShareFile Improper Access Control Vulnerability KEVCitrix | Citrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated attacker to remotely compromise customer-man… |
| CVE-2023-23752 | Joomla! Improper Access Control Vulnerability KEVCVSS 5.3Joomla! | Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints. |
| CVE-2023-23529 | Apple Multiple Products WebKit Type Confusion Vulnerability KEVCVSS 8.8Apple | Apple iOS, MacOS, Safari and iPadOS WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content.… |
| CVE-2023-23397 | Microsoft Office Outlook Privilege Escalation Vulnerability KEVMicrosoft | Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user. |
| CVE-2023-23376 | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. |
| CVE-2023-22952 | Multiple SugarCRM Products Remote Code Execution Vulnerability KEVCVSS 8.8SugarCRM | Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injec… |
| CVE-2023-22527 | Atlassian Confluence Data Center and Server Template Injection Vulnerability KEVAtlassian | Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution. |
| CVE-2023-22518 | Atlassian Confluence Data Center and Server Improper Authorization Vulnerability KEVAtlassian | Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unaut… |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server Broken Access Control Vulnerability KEVAtlassian | Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administra… |
| CVE-2023-21839 | Oracle WebLogic Server Unspecified Vulnerability KEVCVSS 7.5Oracle | Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle Web… |
| CVE-2023-21823 | Microsoft Windows Graphic Component Privilege Escalation Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation. |
| CVE-2023-21715 | Microsoft Office Publisher Security Feature Bypass Vulnerability KEVCVSS 7.3Microsoft | Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system. |
| CVE-2023-21674 | Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability KEVCVSS 8.8Microsoft | Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation. |
| CVE-2023-21608 | Adobe Acrobat and Reader Use-After-Free Vulnerability KEVCVSS 7.8Adobe | Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user. |
| CVE-2023-21529 | Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability KEVCVSS 8.8Microsoft | Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. |
| CVE-2023-21492 | Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability KEVSamsung | Samsung mobile devices running Android 11, 12, and 13 contain an insertion of sensitive information into log file vulnerability that allows a privileged, local… |
| CVE-2023-2136 | Google Chrome Skia Integer Overflow Vulnerability KEVGoogle | Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform… |
| CVE-2023-21237 | Android Pixel Information Disclosure Vulnerability KEVAndroid | Android Pixel contains a vulnerability in the Framework component, where the UI may be misleading or insufficient, providing a means to hide a foreground servi… |
| CVE-2023-20963 | Android Framework Privilege Escalation Vulnerability KEVAndroid | Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional ex… |
| CVE-2023-20887 | Vmware Aria Operations for Networks Command Injection Vulnerability KEVVMware | VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network a… |
| CVE-2023-20867 | VMware Tools Authentication Bypass Vulnerability KEVVMware | VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate… |
| CVE-2023-2033 | Google Chromium V8 Type Confusion Vulnerability KEVGoogle | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.… |
| CVE-2023-20273 | Cisco IOS XE Web UI Command Injection Vulnerability KEVCisco | Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local us… |
| CVE-2023-20269 | Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability KEVCVSS 5.0Cisco | Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacke… |
| CVE-2023-20198 | Cisco IOS XE Web UI Privilege Escalation Vulnerability KEVCisco | Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an ac… |
| CVE-2023-20118 | Cisco Small Business RV Series Routers Command Injection Vulnerability KEVCisco | Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could… |
| CVE-2023-20109 | Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability KEVCisco | Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated, rem… |
| CVE-2023-1671 | Sophos Web Appliance Command Injection Vulnerability KEVSophos | Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote code execution. |
| CVE-2023-1389 | TP-Link Archer AX-21 Command Injection Vulnerability KEVTP-Link | TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution. |
| CVE-2023-0669 | Fortra GoAnywhere MFT Remote Code Execution Vulnerability KEVCVSS 7.2Fortra | Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserial… |
| CVE-2023-0386 | Linux Kernel Improper Ownership Management Vulnerability KEVLinux | Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found… |
| CVE-2023-0266 | Linux Kernel Use-After-Free Vulnerability KEVCVSS 7.9Linux | Linux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from the system user. |
| CVE-2022-48618 | Apple Multiple Products Memory Corruption Vulnerability KEVApple | Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a time-of-check/time-of-use (TOCTOU) memory corruption vulnerability that allows an attacker with read and … |
| CVE-2022-48503 | Apple Multiple Products Unspecified Vulnerability KEVApple | Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when processing web content may lead to arbitrary code … |
| CVE-2022-47986 | IBM Aspera Faspex Code Execution Vulnerability KEVCVSS 9.8IBM | IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw. |
| CVE-2022-47966 | Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability KEVCVSS 9.8Zoho | Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apac… |
| CVE-2022-46169 | Cacti Command Injection Vulnerability KEVCVSS 9.8Cacti | Cacti contains a command injection vulnerability that allows an unauthenticated user to execute code. |
| CVE-2022-44877 | CWP Control Web Panel OS Command Injection Vulnerability KEVCVSS 9.8CWP | CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell met… |
| CVE-2022-44698 | Microsoft Defender SmartScreen Security Feature Bypass Vulnerability KEVCVSS 5.4Microsoft | Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a spe… |
| CVE-2022-43939 | Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability KEVHitachi Vantara | Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass author… |
| CVE-2022-43769 | Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability KEVHitachi Vantara | Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, … |
| CVE-2022-42948 | Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability KEVFortra | Fortra Cobalt Strike User Interface contains an unspecified vulnerability rooted in Java Swing that may allow remote code execution. |
| CVE-2022-42856 | Apple iOS Type Confusion Vulnerability KEVCVSS 8.8Apple | Apple iOS contains a type confusion vulnerability when processing maliciously crafted web content leading to code execution. |
| CVE-2022-42827 | Apple iOS and iPadOS Out-of-Bounds Write Vulnerability KEVCVSS 7.8Apple | Apple iOS and iPadOS kernel contain an out-of-bounds write vulnerability which can allow an application to perform code execution with kernel privileges. |
| CVE-2022-4262 | Google Chromium V8 Type Confusion Vulnerability KEVCVSS 8.8Google | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.… |
| CVE-2022-42475 | Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability KEVCVSS 9.8Fortinet | Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute… |