87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 651–700 of 1,734 in KEV · page 14 of 35

IDTitleSummary
CVE-2023-2533PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability
KEVPaperCut
PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific conditions, could potentially enable an attacker to alter secu…
CVE-2023-25280D-Link DIR-820 Router OS Command Injection Vulnerability
KEVD-Link
D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafte…
CVE-2023-24955Microsoft SharePoint Server Code Injection Vulnerability
KEVMicrosoft
Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.
CVE-2023-24880Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
KEVMicrosoft
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a spec…
CVE-2023-24489Citrix Content Collaboration ShareFile Improper Access Control Vulnerability
KEVCitrix
Citrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated attacker to remotely compromise customer-man…
CVE-2023-23752Joomla! Improper Access Control Vulnerability
KEVCVSS 5.3Joomla!
Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints.
CVE-2023-23529Apple Multiple Products WebKit Type Confusion Vulnerability
KEVCVSS 8.8Apple
Apple iOS, MacOS, Safari and iPadOS WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content.…
CVE-2023-23397Microsoft Office Outlook Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.
CVE-2023-23376Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
CVE-2023-22952Multiple SugarCRM Products Remote Code Execution Vulnerability
KEVCVSS 8.8SugarCRM
Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injec…
CVE-2023-22527Atlassian Confluence Data Center and Server Template Injection Vulnerability
KEVAtlassian
Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.
CVE-2023-22518Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
KEVAtlassian
Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unaut…
CVE-2023-22515Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
KEVAtlassian
Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administra…
CVE-2023-21839Oracle WebLogic Server Unspecified Vulnerability
KEVCVSS 7.5Oracle
Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle Web…
CVE-2023-21823Microsoft Windows Graphic Component Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation.
CVE-2023-21715Microsoft Office Publisher Security Feature Bypass Vulnerability
KEVCVSS 7.3Microsoft
Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system.
CVE-2023-21674Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability
KEVCVSS 8.8Microsoft
Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation.
CVE-2023-21608Adobe Acrobat and Reader Use-After-Free Vulnerability
KEVCVSS 7.8Adobe
Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user.
CVE-2023-21529Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability
KEVCVSS 8.8Microsoft
Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.
CVE-2023-21492Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability
KEVSamsung
Samsung mobile devices running Android 11, 12, and 13 contain an insertion of sensitive information into log file vulnerability that allows a privileged, local…
CVE-2023-2136Google Chrome Skia Integer Overflow Vulnerability
KEVGoogle
Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform…
CVE-2023-21237Android Pixel Information Disclosure Vulnerability
KEVAndroid
Android Pixel contains a vulnerability in the Framework component, where the UI may be misleading or insufficient, providing a means to hide a foreground servi…
CVE-2023-20963Android Framework Privilege Escalation Vulnerability
KEVAndroid
Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional ex…
CVE-2023-20887Vmware Aria Operations for Networks Command Injection Vulnerability
KEVVMware
VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network a…
CVE-2023-20867VMware Tools Authentication Bypass Vulnerability
KEVVMware
VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate…
CVE-2023-2033Google Chromium V8 Type Confusion Vulnerability
KEVGoogle
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.…
CVE-2023-20273Cisco IOS XE Web UI Command Injection Vulnerability
KEVCisco
Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local us…
CVE-2023-20269Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability
KEVCVSS 5.0Cisco
Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacke…
CVE-2023-20198Cisco IOS XE Web UI Privilege Escalation Vulnerability
KEVCisco
Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an ac…
CVE-2023-20118Cisco Small Business RV Series Routers Command Injection Vulnerability
KEVCisco
Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could…
CVE-2023-20109Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability
KEVCisco
Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated, rem…
CVE-2023-1671Sophos Web Appliance Command Injection Vulnerability
KEVSophos
Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote code execution.
CVE-2023-1389TP-Link Archer AX-21 Command Injection Vulnerability
KEVTP-Link
TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.
CVE-2023-0669Fortra GoAnywhere MFT Remote Code Execution Vulnerability
KEVCVSS 7.2Fortra
Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserial…
CVE-2023-0386Linux Kernel Improper Ownership Management Vulnerability
KEVLinux
Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found…
CVE-2023-0266Linux Kernel Use-After-Free Vulnerability
KEVCVSS 7.9Linux
Linux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from the system user.
CVE-2022-48618Apple Multiple Products Memory Corruption Vulnerability
KEVApple
Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a time-of-check/time-of-use (TOCTOU) memory corruption vulnerability that allows an attacker with read and …
CVE-2022-48503Apple Multiple Products Unspecified Vulnerability
KEVApple
Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when processing web content may lead to arbitrary code …
CVE-2022-47986IBM Aspera Faspex Code Execution Vulnerability
KEVCVSS 9.8IBM
IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.
CVE-2022-47966Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability
KEVCVSS 9.8Zoho
Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apac…
CVE-2022-46169Cacti Command Injection Vulnerability
KEVCVSS 9.8Cacti
Cacti contains a command injection vulnerability that allows an unauthenticated user to execute code.
CVE-2022-44877CWP Control Web Panel OS Command Injection Vulnerability
KEVCVSS 9.8CWP
CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell met…
CVE-2022-44698Microsoft Defender SmartScreen Security Feature Bypass Vulnerability
KEVCVSS 5.4Microsoft
Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a spe…
CVE-2022-43939Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability
KEVHitachi Vantara
Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass author…
CVE-2022-43769Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability
KEVHitachi Vantara
Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, …
CVE-2022-42948Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability
KEVFortra
Fortra Cobalt Strike User Interface contains an unspecified vulnerability rooted in Java Swing that may allow remote code execution.
CVE-2022-42856Apple iOS Type Confusion Vulnerability
KEVCVSS 8.8Apple
Apple iOS contains a type confusion vulnerability when processing maliciously crafted web content leading to code execution.
CVE-2022-42827Apple iOS and iPadOS Out-of-Bounds Write Vulnerability
KEVCVSS 7.8Apple
Apple iOS and iPadOS kernel contain an out-of-bounds write vulnerability which can allow an application to perform code execution with kernel privileges.
CVE-2022-4262Google Chromium V8 Type Confusion Vulnerability
KEVCVSS 8.8Google
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.…
CVE-2022-42475Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability
KEVCVSS 9.8Fortinet
Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.