VYPR

CVEs

1,665 total · page 11 of 34

  • CVE-2023-20198CriKEVOct 16, 2023
    risk 0.88cvss 10.0epss 1.00

    Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two…

  • CVE-2023-41763MedKEVOct 10, 2023
    risk 0.54cvss 5.3epss 0.90

    Skype for Business Elevation of Privilege Vulnerability

  • CVE-2023-36584MedKEVOct 10, 2023
    risk 0.47cvss 5.4epss 0.03

    Windows Mark of the Web Security Feature Bypass Vulnerability

  • CVE-2023-36563MedKEVOct 10, 2023
    risk 0.56cvss 6.5epss 0.21

    Microsoft WordPad Information Disclosure Vulnerability

  • CVE-2023-4966CriKEVOct 10, 2023
    risk 0.90cvss 9.4epss 1.00

    Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

  • CVE-2023-44487HigKEVOct 10, 2023
    risk 0.65cvss 7.5epss 1.00

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • CVE-2023-42824HigKEVOct 4, 2023
    risk 0.63cvss 7.8epss 0.01

    The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.6.

  • CVE-2023-22515CriKEVOct 4, 2023
    risk 0.93cvss 9.8epss 0.99

    Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts…

  • CVE-2023-4911HigKEVOct 3, 2023
    risk 0.65cvss 7.8epss 0.81

    A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID…

  • CVE-2023-4211MedKEVOct 1, 2023
    risk 0.48cvss 5.5epss 0.01

    A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.

  • CVE-2023-5217HigKEVSep 28, 2023
    risk 0.66cvss 8.8epss 0.49

    Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-20109MedKEVSep 27, 2023
    risk 0.55cvss 6.6epss 0.02

    A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an…

  • CVE-2023-40044CriKEVSep 27, 2023
    risk 0.93cvss 10.0epss 0.90

    In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.

  • CVE-2023-36851MedKEVSep 27, 2023
    risk 0.47cvss 5.3epss 0.01

    A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't…

  • CVE-2023-43770MedKEVSep 22, 2023
    risk 0.17cvss 6.1epss 0.58

    Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.

  • CVE-2023-41993HigKEVSep 21, 2023
    risk 0.72cvss 8.8epss 0.29

    The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

  • CVE-2023-41992HigKEVSep 21, 2023
    risk 0.63cvss 7.8epss 0.03

    The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against…

  • CVE-2023-41991MedKEVSep 21, 2023
    risk 0.48cvss 5.5epss 0.05

    A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS…

  • CVE-2023-42793CriKEVSep 19, 2023
    risk 0.93cvss 9.8epss 1.00

    In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible

  • CVE-2023-41179HigKEVSep 19, 2023
    risk 0.59cvss 7.2epss 0.05

    A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected…

  • CVE-2023-38205HigKEVSep 14, 2023
    risk 0.69cvss 7.5epss 1.00

    Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM…

  • CVE-2023-26369HigKEVSep 13, 2023
    risk 0.63cvss 7.8epss 0.07

    Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…

  • CVE-2023-36802HigKEVSep 12, 2023
    risk 0.65cvss 7.8epss 0.26

    Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

  • CVE-2023-36761MedKEVSep 12, 2023
    risk 0.56cvss 6.5epss 0.19

    Microsoft Word Information Disclosure Vulnerability

  • CVE-2023-4863HigKEVSep 12, 2023
    risk 0.70cvss 8.8epss 1.00

    Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2023-41990HigKEVSep 12, 2023
    risk 0.63cvss 7.8epss 0.01

    The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Ventura 13.2, watchOS 9.3. Processing a font file may lead to arbitrary code…

  • CVE-2023-35674HigKEVSep 11, 2023
    risk 0.63cvss 7.8epss 0.02

    In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-39780HigKEVSep 11, 2023
    risk 0.72cvss 8.8epss 0.34

    On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token-generated module" issue, see CVE-2023-41345; for the similar "token-refresh module" issue, see…

  • CVE-2023-41064HigKEVSep 7, 2023
    risk 0.64cvss 7.8epss 0.15

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9 and iPadOS 15.7.9, macOS Big Sur 11.7.10. Processing a maliciously crafted image may lead to…

  • CVE-2023-41061HigKEVSep 7, 2023
    risk 0.63cvss 7.8epss 0.03

    A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

  • CVE-2023-20269MedKEVSep 6, 2023
    risk 0.52cvss 5.0epss 0.22

    A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and…

  • CVE-2023-4762HigKEVSep 5, 2023
    risk 0.72cvss 8.8epss 0.38

    Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-41266HigKEVAug 29, 2023
    risk 0.78cvss 8.2epss 0.82

    A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unauthenticated remote attacker to generate…

  • CVE-2023-41265CriKEVAug 29, 2023
    risk 0.87cvss 9.6epss 0.84

    An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their…

  • CVE-2023-4346HigKEVAug 29, 2023
    risk 0.61cvss 7.5epss 0.01

    KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the…

  • CVE-2023-38831HigKEVAug 23, 2023
    risk 0.80cvss 7.8epss 0.98

    RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the…

  • CVE-2023-38035CriKEVAug 21, 2023
    risk 0.93cvss 9.8epss 1.00

    A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

  • CVE-2023-36847MedKEVAug 17, 2023
    risk 0.53cvss 5.3epss 0.85

    A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't…

  • CVE-2023-36846MedKEVAug 17, 2023
    risk 0.54cvss 5.3epss 0.94

    A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require…

  • CVE-2023-36845CriKEVAug 17, 2023
    risk 0.86cvss 9.8epss 0.94

    A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request which sets the variable PHPRC an attacker is able to…

  • CVE-2023-36844MedKEVAug 17, 2023
    risk 0.54cvss 5.3epss 0.91

    A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP…

  • CVE-2023-35082CriKEVAug 15, 2023
    risk 0.90cvss 9.8epss 1.00

    An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

  • CVE-2022-48503HigKEVAug 14, 2023
    risk 0.69cvss 8.8epss 0.03

    The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web content may lead to arbitrary code execution.

  • CVE-2023-38180HigKEVAug 8, 2023
    risk 0.62cvss 7.5epss 0.15

    .NET and Visual Studio Denial of Service Vulnerability

  • CVE-2023-38950HigKEVAug 3, 2023
    risk 0.68cvss 7.5epss 0.85

    A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.

  • CVE-2023-35081HigKEVAug 3, 2023
    risk 0.64cvss 7.2epss 0.64

    A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated administrator to write arbitrary files onto the appliance.

  • CVE-2023-37580MedKEVJul 31, 2023
    risk 0.56cvss 6.1epss 0.47

    Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.

  • CVE-2023-38606MedKEVJul 27, 2023
    risk 0.48cvss 5.5epss 0.03

    This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to modify sensitive kernel state.…

  • CVE-2023-37450HigKEVJul 27, 2023
    risk 0.71cvss 8.8epss 0.19

    The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been…

  • CVE-2023-35078CriKEVJul 25, 2023
    risk 0.90cvss 9.8epss 1.00

    An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.