Search
32,642 CVEs · Critical severity
CVEs (32,642, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 32,642 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-37502 | CRITICAL | Patched | 9.0 | 2023-10-18 | HCL Compass is vulnerable to lack of file upload security. An attacker could upload files containing active code that can be executed by the server or by a user's web browser. |
| CVE-2023-45146 | CRITICAL | Patched | 9.0 | 2023-10-18 | XXL-RPC is a high performance, distributed RPC framework. With it, a TCP server can be set up using the Netty framework and the Hessian serialization mechanism. When such a… |
| CVE-2023-42628 | CRITICAL | Patched | 9.0 | 2023-10-17 | Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay DXP 7.0 fix pack 83 through 102, 7.1 fix pack 28 an… |
| CVE-2023-44310 | CRITICAL | Patched | 9.0 | 2023-10-17 | Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP 7.3 fix pack 1 through update 23, and 7.4 before up… |
| CVE-2023-42629 | CRITICAL | Patched | 9.0 | 2023-10-17 | Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before update 88 allows remote a… |
| CVE-2023-44309 | CRITICAL | Patched | 9.0 | 2023-10-17 | Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 through 7.4.3.53, and Liferay DXP 7.4 before update 54 allow r… |
| CVE-2023-27395 | CRITICAL | 9.0 | 2023-10-12 | A heap-based buffer overflow vulnerability exists in the vpnserver WpcParsePacket() functionality of SoftEther VPN 4.41-9782-beta, 5.01.9674 and 5.02. A specially crafted n… | |
| CVE-2023-32670 | CRITICAL | 9.0 | 2023-10-03 | Cross-Site Scripting vulnerability in BuddyBoss 2.2.9 version , which could allow a local attacker with basic privileges to execute a malicious payload through the "[nam… | |
| CVE-2023-43632 | CRITICAL | Patched | 9.0 | 2023-09-21 | As noted in the “VTPM.md” file in the eve documentation, “VTPM is a server listening on port 8877 in EVE, exposing limited functionality of the TPM to the clients. VTPM a… |
| CVE-2023-39612 | CRITICAL | Patched | 9.0 | 2023-09-16 | A cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 allows an authenticated attacker to escalate privileges to Administrator via user interaction with … |
| CVE-2017-9453 | CRITICAL | Patched | 9.0 | 2023-09-05 | BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass. |
| CVE-2023-4299 | CRITICAL | Patched | 9.0 | 2023-08-31 | Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment. |
| CVE-2023-40572 | CRITICAL | Patched | 9.0 | 2023-08-24 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The create action is vulnerable to a CSRF attack, allowing script a… |
| CVE-2023-40573 | CRITICAL | Patched | 9.0 | 2023-08-24 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki supports scheduled jobs that contain Groovy scripts. Currentl… |
| CVE-2023-41028 | CRITICAL | Patched | 9.0 | 2023-08-23 | A stack-based buffer overflow exists in Juplink RX4-1500, a WiFi router, in versions 1.0.2 through 1.0.5. An authenticated attacker can exploit this vulnerability to achiev… |
| CVE-2023-40176 | CRITICAL | Patched | 9.0 | 2023-08-23 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can exploit a stored XSS through their user pro… |
| CVE-2023-39969 | CRITICAL | Patched | 9.0 | 2023-08-09 | uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Version 1.0.9 of uthenticode hashed the entire file rather than hashi… |
| CVE-2023-4203 | CRITICAL | Patched | 9.0 | 2023-08-08 | Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in th… |
| CVE-2023-4202 | CRITICAL | Patched | 9.0 | 2023-08-08 | Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in th… |
| CVE-2023-36217 | CRITICAL | 9.0 | 2023-08-03 | Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function. | |
| CVE-2023-32478 | CRITICAL | Patched | 9.0 | 2023-07-21 | Dell PowerStore versions prior to 3.5.0.1 contain an insertion of sensitive information into log file vulnerability. A high privileged malicious user could potentially exp… |
| CVE-2023-21974 | CRITICAL | Patched | 9.0 | 2023-07-18 | Vulnerability in the Application Express Team Calendar Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are App… |
| CVE-2023-21975 | CRITICAL | Patched | 9.0 | 2023-07-18 | Vulnerability in the Application Express Customers Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Applica… |
| CVE-2023-34142 | CRITICAL | Patched | 9.0 | 2023-07-18 | Cleartext Transmission of Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Server, Device Manager Agent, Host Data Collector … |
| CVE-2023-32250 | CRITICAL | Patched | 9.0 | 2023-07-10 | A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP commands. The is… |