Search
32,642 CVEs · Critical severity
CVEs (32,642, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 326–350 of 32,642 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-52139 | CRITICAL | Patched | 9.0 | 2023-12-29 | Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endpoints or Websocket APIs that are incorrectly specifi… |
| CVE-2023-51412 | CRITICAL | Patched | 9.0 | 2023-12-29 | Unrestricted Upload of File with Dangerous Type vulnerability in Piotnet Piotnet Forms.This issue affects Piotnet Forms: from n/a through 1.0.25. |
| CVE-2023-6879 | CRITICAL | Patched | 9.0 | 2023-12-27 | Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc(). |
| CVE-2023-45603 | CRITICAL | Patched | 9.0 | 2023-12-20 | Unrestricted Upload of File with Dangerous Type vulnerability in Jeff Starr User Submitted Posts – Enable Users to Submit Posts from the Front End.This issue affects User S… |
| CVE-2023-4020 | CRITICAL | Patched | 9.0 | 2023-12-15 | An unvalidated input in a library function responsible for communicating between secure and non-secure memory in Silicon Labs TrustZone implementation allows reading/writin… |
| CVE-2023-48692 | CRITICAL | Patched | 9.0 | 2023-12-05 | Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to m… |
| CVE-2023-48240 | CRITICAL | Patched | 9.0 | 2023-11-20 | XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents and not display a difference for an actually unchange… |
| CVE-2023-31247 | CRITICAL | 9.0 | 2023-11-14 | A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can le… | |
| CVE-2023-27882 | CRITICAL | 9.0 | 2023-11-14 | A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can… | |
| CVE-2023-28379 | CRITICAL | 9.0 | 2023-11-14 | A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to … | |
| CVE-2023-28391 | CRITICAL | 9.0 | 2023-11-14 | A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to … | |
| CVE-2023-25181 | CRITICAL | 9.0 | 2023-11-14 | A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead … | |
| CVE-2023-45849 | CRITICAL | Patched | 9.0 | 2023-11-08 | An arbitrary code execution which results in privilege escalation was discovered in Helix Core versions prior to 2023.2. Reported by Jason Geffner. |
| CVE-2023-28574 | CRITICAL | 9.0 | 2023-11-07 | Memory corruption in core services when Diag handler receives a command to configure event listeners. | |
| CVE-2023-23369 | CRITICAL | 9.0 | 2023-11-03 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute comma… | |
| CVE-2023-1715 | CRITICAL | 9.0 | 2023-11-01 | A logic error when using mb_strpos() to check for potential XSS payload in Bitrix24 22.0.300 allows attackers to bypass XSS sanitisation via placing HTML tags at the begin… | |
| CVE-2023-1716 | CRITICAL | 9.0 | 2023-11-01 | Cross-site scripting (XSS) vulnerability in Invoice Edit Page in Bitrix24 22.0.300 allows attackers to execute arbitrary JavaScript code in the victim's browser, and possi… | |
| CVE-2023-46248 | CRITICAL | Patched | 9.0 | 2023-10-31 | Cody is an artificial intelligence (AI) coding assistant. The Cody AI VSCode extension versions 0.10.0 through 0.14.0 are vulnerable to Remote Code Execution under certain … |
| CVE-2023-5843 | CRITICAL | Patched | 9.0 | 2023-10-30 | The Ads by datafeedr.com plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.1.3 via the 'dfads_ajax_load_ads' function. This al… |
| CVE-2023-45869 | CRITICAL | 9.0 | 2023-10-26 | ILIAS 7.25 (2023-09-12) allows any authenticated user to execute arbitrary operating system commands remotely, when a highly privileged account accesses an XSS payload. The… | |
| CVE-2023-31422 | CRITICAL | 9.0 | 2023-10-26 | An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. The issue impacts only Kibana version 8.10.0 when logg… | |
| CVE-2023-45137 | CRITICAL | Patched | 9.0 | 2023-10-25 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. `org.xwiki.platform:xwiki-platform-web` starting in version 3.1-mil… |
| CVE-2023-45134 | CRITICAL | Patched | 9.0 | 2023-10-25 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. `org.xwiki.platform:xwiki-platform-web` starting in version 3.1-mil… |
| CVE-2023-45135 | CRITICAL | Patched | 9.0 | 2023-10-25 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In `org.xwiki.platform:xwiki-platform-web` versions 7.2-milestone-2… |
| CVE-2023-37908 | CRITICAL | Patched | 9.0 | 2023-10-25 | XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. The cleaning of attributes during XHTML rendering, introduc… |