Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

32,642 CVEs · Critical severity

CVEs (32,642, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 351–375 of 32,642 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2023-37502 CRITICAL Patched 9.0 2023-10-18 HCL Compass is vulnerable to lack of file upload security.  An attacker could upload files containing active code that can be executed by the server or by a user's web browser.
CVE-2023-45146 CRITICAL Patched 9.0 2023-10-18 XXL-RPC is a high performance, distributed RPC framework. With it, a TCP server can be set up using the Netty framework and the Hessian serialization mechanism. When such a…
CVE-2023-42628 CRITICAL Patched 9.0 2023-10-17 Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay DXP 7.0 fix pack 83 through 102, 7.1 fix pack 28 an…
CVE-2023-44310 CRITICAL Patched 9.0 2023-10-17 Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP 7.3 fix pack 1 through update 23, and 7.4 before up…
CVE-2023-42629 CRITICAL Patched 9.0 2023-10-17 Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before update 88 allows remote a…
CVE-2023-44309 CRITICAL Patched 9.0 2023-10-17 Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 through 7.4.3.53, and Liferay DXP 7.4 before update 54 allow r…
CVE-2023-27395 CRITICAL 9.0 2023-10-12 A heap-based buffer overflow vulnerability exists in the vpnserver WpcParsePacket() functionality of SoftEther VPN 4.41-9782-beta, 5.01.9674 and 5.02. A specially crafted n…
CVE-2023-32670 CRITICAL 9.0 2023-10-03 Cross-Site Scripting vulnerability in BuddyBoss 2.2.9 version , which could allow a local attacker with basic privileges to execute a malicious payload through the "[nam…
CVE-2023-43632 CRITICAL Patched 9.0 2023-09-21 As noted in the “VTPM.md” file in the eve documentation, “VTPM is a server listening on port 8877 in EVE, exposing limited functionality of the TPM to the clients. VTPM a…
CVE-2023-39612 CRITICAL Patched 9.0 2023-09-16 A cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 allows an authenticated attacker to escalate privileges to Administrator via user interaction with …
CVE-2017-9453 CRITICAL Patched 9.0 2023-09-05 BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.
CVE-2023-4299 CRITICAL Patched 9.0 2023-08-31 Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment.
CVE-2023-40572 CRITICAL Patched 9.0 2023-08-24 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The create action is vulnerable to a CSRF attack, allowing script a…
CVE-2023-40573 CRITICAL Patched 9.0 2023-08-24 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki supports scheduled jobs that contain Groovy scripts. Currentl…
CVE-2023-41028 CRITICAL Patched 9.0 2023-08-23 A stack-based buffer overflow exists in Juplink RX4-1500, a WiFi router, in versions 1.0.2 through 1.0.5. An authenticated attacker can exploit this vulnerability to achiev…
CVE-2023-40176 CRITICAL Patched 9.0 2023-08-23 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can exploit a stored XSS through their user pro…
CVE-2023-39969 CRITICAL Patched 9.0 2023-08-09 uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Version 1.0.9 of uthenticode hashed the entire file rather than hashi…
CVE-2023-4203 CRITICAL Patched 9.0 2023-08-08 Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in th…
CVE-2023-4202 CRITICAL Patched 9.0 2023-08-08 Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in th…
CVE-2023-36217 CRITICAL 9.0 2023-08-03 Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function.
CVE-2023-32478 CRITICAL Patched 9.0 2023-07-21 Dell PowerStore versions prior to 3.5.0.1 contain an insertion of sensitive information into log file vulnerability. A high privileged malicious user could potentially exp…
CVE-2023-21974 CRITICAL Patched 9.0 2023-07-18 Vulnerability in the Application Express Team Calendar Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are App…
CVE-2023-21975 CRITICAL Patched 9.0 2023-07-18 Vulnerability in the Application Express Customers Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Applica…
CVE-2023-34142 CRITICAL Patched 9.0 2023-07-18 Cleartext Transmission of Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Server, Device Manager Agent, Host Data Collector …
CVE-2023-32250 CRITICAL Patched 9.0 2023-07-10 A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP commands. The is…