VYPR

CVEs

1,665 total · page 12 of 34

  • CVE-2023-38203CriKEVJul 20, 2023
    risk 0.89cvss 9.8epss 0.97

    Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

  • CVE-2023-3519CriKEVJul 19, 2023
    risk 0.93cvss 9.8epss 1.00

    Unauthenticated remote code execution

  • CVE-2023-29300CriKEVJul 12, 2023
    risk 0.90cvss 9.8epss 1.00

    Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

  • CVE-2023-29298HigKEVJul 12, 2023
    risk 0.69cvss 7.5epss 1.00

    Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the…

  • CVE-2023-36884HigKEVJul 11, 2023
    risk 0.75cvss 7.5epss 0.99

    Windows Search Remote Code Execution Vulnerability

  • CVE-2023-36874HigKEVJul 11, 2023
    risk 0.68cvss 7.8epss 0.43

    Windows Error Reporting Service Elevation of Privilege Vulnerability

  • CVE-2023-35311HigKEVJul 11, 2023
    risk 0.70cvss 8.8epss 0.16

    Microsoft Outlook Security Feature Bypass Vulnerability

  • CVE-2023-32049HigKEVJul 11, 2023
    risk 0.70cvss 8.8epss 0.04

    Windows SmartScreen Security Feature Bypass Vulnerability

  • CVE-2023-32046HigKEVJul 11, 2023
    risk 0.63cvss 7.8epss 0.10

    Windows MSHTML Platform Elevation of Privilege Vulnerability

  • CVE-2023-24489CriKEVJul 10, 2023
    risk 0.83cvss 9.8epss 0.95

    A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.

  • CVE-2023-34192CriKEVJul 6, 2023
    risk 0.77cvss 9.0epss 0.77

    Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.

  • CVE-2023-21237MedKEVJun 28, 2023
    risk 0.48cvss 5.5epss 0.00

    In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2023-32439HigKEVJun 23, 2023
    risk 0.71cvss 8.8epss 0.24

    A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a…

  • CVE-2023-32435HigKEVJun 23, 2023
    risk 0.71cvss 8.8epss 0.23

    A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.7 and iPadOS 15.7.7. Processing web content may lead to arbitrary code execution. Apple is aware of a report that…

  • CVE-2023-32434HigKEVJun 23, 2023
    risk 0.67cvss 7.8epss 0.52

    An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute…

  • CVE-2023-32409HigKEVJun 23, 2023
    risk 0.69cvss 8.6epss 0.17

    The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8, Safari 16.5, iOS 16.5 and iPadOS 16.5. A remote attacker may be able to break out of Web Content sandbox. Apple is aware of a…

  • CVE-2023-32373HigKEVJun 23, 2023
    risk 0.70cvss 8.8epss 0.12

    A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing maliciously crafted web content may lead to arbitrary code…

  • CVE-2023-28204MedKEVJun 23, 2023
    risk 0.55cvss 6.5epss 0.14

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information. Apple is aware…

  • CVE-2023-2533HigKEVJun 20, 2023
    risk 0.69cvss 8.4epss 0.29

    A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. This could be exploited if the target is an admin with a current…

  • CVE-2023-27992CriKEVJun 19, 2023
    risk 0.82cvss 9.8epss 0.84

    The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to…

  • CVE-2023-29360HigKEVJun 14, 2023
    risk 0.68cvss 8.4epss 0.22

    Microsoft Streaming Service Elevation of Privilege Vulnerability

  • CVE-2023-29357CriKEVJun 14, 2023
    risk 0.93cvss 9.8epss 1.00

    Microsoft SharePoint Server Elevation of Privilege Vulnerability

  • CVE-2023-20867LowKEVJun 13, 2023
    risk 0.38cvss 3.9epss 0.14

    A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.

  • CVE-2023-27997CriKEVJun 13, 2023
    risk 0.89cvss 9.8epss 0.86

    A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all…

  • CVE-2023-20887CriKEVJun 7, 2023
    risk 0.87cvss 9.8epss 0.98

    Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.

  • CVE-2023-33538HigKEVJun 7, 2023
    risk 0.73cvss 8.8epss 0.42

    TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm .

  • CVE-2023-3079HigKEVJun 5, 2023
    risk 0.72cvss 8.8epss 0.32

    Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-34362CriKEVJun 2, 2023
    risk 0.93cvss 9.8epss 1.00

    In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access…

  • CVE-2023-32315HigKEVMay 26, 2023
    risk 0.72cvss 8.6epss 1.00

    Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the…

  • CVE-2023-2868CriKEVMay 24, 2023
    risk 0.83cvss 9.4epss 0.87

    A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape…

  • CVE-2023-33246CriKEVMay 24, 2023
    risk 0.79cvss 9.8epss 0.97

    For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit…

  • CVE-2023-33010CriKEVMay 24, 2023
    risk 0.78cvss 9.8epss 0.29

    A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions…

  • CVE-2023-33009CriKEVMay 24, 2023
    risk 0.78cvss 9.8epss 0.28

    A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions…

  • CVE-2023-29336HigKEVMay 9, 2023
    risk 0.69cvss 7.8epss 0.41

    Win32k Elevation of Privilege Vulnerability

  • CVE-2023-24955HigKEVMay 9, 2023
    risk 0.75cvss 7.2epss 0.85

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2023-21492MedKEVMay 4, 2023
    risk 0.41cvss 4.4epss 0.03

    Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.

  • CVE-2023-29552HigKEVApr 25, 2023
    risk 0.66cvss 7.5epss 0.66

    The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.

  • CVE-2023-28771CriKEVApr 25, 2023
    risk 0.87cvss 9.8epss 0.99

    Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an…

  • CVE-2023-27524HigKEVApr 24, 2023
    risk 0.74cvss 8.9epss 0.97

    Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not…

  • CVE-2023-27351HigKEVApr 20, 2023
    risk 0.73cvss 7.5epss 0.77

    This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results…

  • CVE-2023-27350CriKEVApr 20, 2023
    risk 0.93cvss 9.8epss 1.00

    This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from…

  • CVE-2023-2136CriKEVApr 19, 2023
    risk 0.75cvss 9.6epss 0.06

    Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-2033HigKEVApr 14, 2023
    risk 0.72cvss 8.8epss 0.41

    Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-20118MedKEVApr 13, 2023
    risk 0.59cvss 6.5epss 0.54

    A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to improper…

  • CVE-2023-28252HigKEVApr 11, 2023
    risk 0.76cvss 7.8epss 0.49

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

  • CVE-2023-28229HigKEVApr 11, 2023
    risk 0.58cvss 7.0epss 0.02

    Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

  • CVE-2023-29492CriKEVApr 11, 2023
    risk 0.76cvss 9.8epss 0.03

    Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.

  • CVE-2023-28206HigKEVApr 10, 2023
    risk 0.70cvss 8.6epss 0.25

    An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1, iOS 15.7.5 and iPadOS 15.7.5, macOS Big Sur 11.7.6. An app may be able to execute arbitrary code with…

  • CVE-2023-28205HigKEVApr 10, 2023
    risk 0.71cvss 8.8epss 0.27

    A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 and iPadOS 15.7.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is…

  • CVE-2023-26083LowKEVApr 6, 2023
    risk 0.34cvss 3.3epss 0.01

    Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from…