Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

32,642 CVEs · Critical severity

CVEs (32,642, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 376–400 of 32,642 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2023-34192 CRITICAL 9.0 2023-07-06 Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.
CVE-2023-30320 CRITICAL 9.0 2023-07-06 Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/chatWindow.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allo…
CVE-2023-30321 CRITICAL 9.0 2023-07-06 Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, al…
CVE-2023-31997 CRITICAL 9.0 2023-07-01 UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud Keys that are both (1)…
CVE-2023-36477 CRITICAL Patched 9.0 2023-06-30 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights can edit all pages in the `CKEditor' spac…
CVE-2023-36471 CRITICAL Patched 9.0 2023-06-29 Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki since version 14.6RC1 allowed form and input HTML t…
CVE-2023-2625 CRITICAL Patched 9.0 2023-06-28 A vulnerability exists that can be exploited by an authenticated client that is connected to the same network segment as the CoreTec 4, having any level of access VIEWER to…
CVE-2023-35169 CRITICAL Patched 9.0 2023-06-23 PHP-IMAP is a wrapper for common IMAP communication without the need to have the php-imap module installed / enabled. Prior to version 5.3.0, an unsanitized attachment file…
CVE-2023-35153 CRITICAL Patched 9.0 2023-06-23 XWiki Platform is a generic wiki platform. Starting in version 5.4.4 and prior to versions 14.4.8, 14.10.4, and 15.0, a stored cross-site scripting vulnerability can be exp…
CVE-2023-34464 CRITICAL Patched 9.0 2023-06-23 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.2.1 until versions 14.4.8, 14.10.5, and 15.1R…
CVE-2023-22582 CRITICAL Patched 9.0 2023-06-11 The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting.
CVE-2023-22585 CRITICAL Patched 9.0 2023-06-11 The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting in the title parameter.
CVE-2021-4356 CRITICAL Patched 9.0 2023-06-07 The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up to, and including, 18.2. This is due to lacking aut…
CVE-2023-32217 CRITICAL 9.0 2023-06-05 IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, Iden…
CVE-2023-3086 CRITICAL Patched 9.0 2023-06-03 Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
CVE-2022-45938 CRITICAL Patched 9.0 2023-06-02 An issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can inject a stored XSS payload in the Device ID field under Inventory Managem…
CVE-2023-2586 CRITICAL 9.0 2023-05-22 Teltonika’s Remote Management System versions 4.14.0 is vulnerable to an unauthorized attacker registering previously unregistered devices through the RMS platform. If the…
CVE-2023-31703 CRITICAL 9.0 2023-05-17 Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the …
CVE-2023-32080 CRITICAL Patched 9.0 2023-05-10 Wings is the server control plane for Pterodactyl Panel. A vulnerability affecting versions prior to 1.7.5 and versions 1.11.0 prior to 1.11.6 impacts anyone running the af…
CVE-2023-32070 CRITICAL Patched 9.0 2023-05-10 XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site script…
CVE-2023-32071 CRITICAL Patched 9.0 2023-05-09 XWiki Platform is a generic wiki platform. Starting in versions 2.2-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, it's possible to execute javascript wi…
CVE-2023-31126 CRITICAL Patched 9.0 2023-05-09 `org.xwiki.commons:xwiki-commons-xml` is an XML library used by the open-source wiki platform XWiki. The HTML sanitizer, introduced in version 14.6-rc-1, allows the injecti…
CVE-2023-31127 CRITICAL Patched 9.0 2023-05-08 libspdm is a sample implementation that follows the DMTF SPDM specifications. A vulnerability has been identified in SPDM session establishment in libspdm prior to version …
CVE-2023-30627 CRITICAL Patched 9.0 2023-04-24 jellyfin-web is the web client for Jellyfin, a free-software media system. Starting in version 10.1.0 and prior to version 10.8.10, a stored cross-site scripting vulnerabil…
CVE-2023-29528 CRITICAL Patched 9.0 2023-04-20 XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milest…