Search
32,642 CVEs · Critical severity
CVEs (32,642, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 32,642 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-34192 | CRITICAL | 9.0 | 2023-07-06 | Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function. | |
| CVE-2023-30320 | CRITICAL | 9.0 | 2023-07-06 | Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/chatWindow.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allo… | |
| CVE-2023-30321 | CRITICAL | 9.0 | 2023-07-06 | Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, al… | |
| CVE-2023-31997 | CRITICAL | 9.0 | 2023-07-01 | UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud Keys that are both (1)… | |
| CVE-2023-36477 | CRITICAL | Patched | 9.0 | 2023-06-30 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights can edit all pages in the `CKEditor' spac… |
| CVE-2023-36471 | CRITICAL | Patched | 9.0 | 2023-06-29 | Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki since version 14.6RC1 allowed form and input HTML t… |
| CVE-2023-2625 | CRITICAL | Patched | 9.0 | 2023-06-28 | A vulnerability exists that can be exploited by an authenticated client that is connected to the same network segment as the CoreTec 4, having any level of access VIEWER to… |
| CVE-2023-35169 | CRITICAL | Patched | 9.0 | 2023-06-23 | PHP-IMAP is a wrapper for common IMAP communication without the need to have the php-imap module installed / enabled. Prior to version 5.3.0, an unsanitized attachment file… |
| CVE-2023-35153 | CRITICAL | Patched | 9.0 | 2023-06-23 | XWiki Platform is a generic wiki platform. Starting in version 5.4.4 and prior to versions 14.4.8, 14.10.4, and 15.0, a stored cross-site scripting vulnerability can be exp… |
| CVE-2023-34464 | CRITICAL | Patched | 9.0 | 2023-06-23 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.2.1 until versions 14.4.8, 14.10.5, and 15.1R… |
| CVE-2023-22582 | CRITICAL | Patched | 9.0 | 2023-06-11 | The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting. |
| CVE-2023-22585 | CRITICAL | Patched | 9.0 | 2023-06-11 | The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting in the title parameter. |
| CVE-2021-4356 | CRITICAL | Patched | 9.0 | 2023-06-07 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up to, and including, 18.2. This is due to lacking aut… |
| CVE-2023-32217 | CRITICAL | 9.0 | 2023-06-05 | IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, Iden… | |
| CVE-2023-3086 | CRITICAL | Patched | 9.0 | 2023-06-03 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. |
| CVE-2022-45938 | CRITICAL | Patched | 9.0 | 2023-06-02 | An issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can inject a stored XSS payload in the Device ID field under Inventory Managem… |
| CVE-2023-2586 | CRITICAL | 9.0 | 2023-05-22 | Teltonika’s Remote Management System versions 4.14.0 is vulnerable to an unauthorized attacker registering previously unregistered devices through the RMS platform. If the… | |
| CVE-2023-31703 | CRITICAL | 9.0 | 2023-05-17 | Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the … | |
| CVE-2023-32080 | CRITICAL | Patched | 9.0 | 2023-05-10 | Wings is the server control plane for Pterodactyl Panel. A vulnerability affecting versions prior to 1.7.5 and versions 1.11.0 prior to 1.11.6 impacts anyone running the af… |
| CVE-2023-32070 | CRITICAL | Patched | 9.0 | 2023-05-10 | XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site script… |
| CVE-2023-32071 | CRITICAL | Patched | 9.0 | 2023-05-09 | XWiki Platform is a generic wiki platform. Starting in versions 2.2-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, it's possible to execute javascript wi… |
| CVE-2023-31126 | CRITICAL | Patched | 9.0 | 2023-05-09 | `org.xwiki.commons:xwiki-commons-xml` is an XML library used by the open-source wiki platform XWiki. The HTML sanitizer, introduced in version 14.6-rc-1, allows the injecti… |
| CVE-2023-31127 | CRITICAL | Patched | 9.0 | 2023-05-08 | libspdm is a sample implementation that follows the DMTF SPDM specifications. A vulnerability has been identified in SPDM session establishment in libspdm prior to version … |
| CVE-2023-30627 | CRITICAL | Patched | 9.0 | 2023-04-24 | jellyfin-web is the web client for Jellyfin, a free-software media system. Starting in version 10.1.0 and prior to version 10.8.10, a stored cross-site scripting vulnerabil… |
| CVE-2023-29528 | CRITICAL | Patched | 9.0 | 2023-04-20 | XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milest… |