Search
32,636 CVEs · Critical severity
CVEs (32,636, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 32,636 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29519 | CRITICAL | Patched | 9.0 | 2023-04-19 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A registered user can perform remote code execution leading to priv… |
| CVE-2023-29213 | CRITICAL | Patched | 9.0 | 2023-04-17 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of `org.xwiki.platform:xwiki-platform-logging-… |
| CVE-2023-29206 | CRITICAL | Patched | 9.0 | 2023-04-15 | XWiki Commons are technical libraries common to several other top level XWiki projects. There was no check in the author of a JavaScript xobject or StyleSheet xobject added… |
| CVE-2023-29201 | CRITICAL | Patched | 9.0 | 2023-04-15 | XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milest… |
| CVE-2023-29202 | CRITICAL | Patched | 9.0 | 2023-04-15 | XWiki Commons are technical libraries common to several other top level XWiki projects. The RSS macro that is bundled in XWiki included the content of the feed items withou… |
| CVE-2023-27830 | CRITICAL | Patched | 9.0 | 2023-04-12 | TightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate files with crafted files when executing a file transfe… |
| CVE-2023-27267 | CRITICAL | 9.0 | 2023-04-11 | Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with deep knowledge of the … | |
| CVE-2023-0432 | CRITICAL | Patched | 9.0 | 2023-03-31 | The web configuration service of the affected device contains an authenticated command injection vulnerability. It can be used to execute system commands on the operating … |
| CVE-2023-26482 | CRITICAL | Patched | 9.0 | 2023-03-30 | Nextcloud server is an open source home cloud implementation. In affected versions a missing scope validation allowed users to create workflows which are designed to be onl… |
| CVE-2023-21456 | CRITICAL | 9.0 | 2023-03-16 | Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid. | |
| CVE-2023-25617 | CRITICAL | 9.0 | 2023-03-14 | SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, when program objects execution is enabled, to authenti… | |
| CVE-2023-1287 | CRITICAL | Patched | 9.0 | 2023-03-09 | An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution. |
| CVE-2021-33351 | CRITICAL | Patched | 9.0 | 2023-03-08 | Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allows attackers to escalte privileges via a crafted pay… |
| CVE-2021-42761 | CRITICAL | Patched | 9.0 | 2023-02-16 | A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 t… |
| CVE-2023-0740 | CRITICAL | Patched | 9.0 | 2023-02-08 | Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4. |
| CVE-2023-0741 | CRITICAL | Patched | 9.0 | 2023-02-08 | Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4. |
| CVE-2023-0742 | CRITICAL | Patched | 9.0 | 2023-02-08 | Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4. |
| CVE-2023-0743 | CRITICAL | Patched | 9.0 | 2023-02-08 | Cross-site Scripting (XSS) - Generic in GitHub repository answerdev/answer prior to 1.0.4. |
| CVE-2022-48311 | CRITICAL | 9.0 | 2023-02-06 | **UNSUPPORTED WHEN ASSIGNED** Cross Site Scripting (XSS) in HP Deskjet 2540 series printer Firmware Version CEP1FN1418BR and Product Model Number A9U23B allows authenticate… | |
| CVE-2023-22482 | CRITICAL | Patched | 9.0 | 2023-01-26 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions of Argo CD starting with v1.8.2 and prior to 2.3.13, 2.4.19, 2.5.6, and 2.6.0-rc-3 are v… |
| CVE-2023-20025 | CRITICAL | Patched | 9.0 | 2023-01-20 | A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers could allow an unauthenticated, remote attacker to byp… |
| CVE-2022-41989 | CRITICAL | Patched | 9.0 | 2023-01-18 | Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 does not validate the length of RTLS report payloads during communication. T… |
| CVE-2022-36760 | CRITICAL | Patched | 9.0 | 2023-01-17 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the A… |
| CVE-2023-0014 | CRITICAL | 9.0 | 2023-01-10 | SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.… | |
| CVE-2023-22457 | CRITICAL | Patched | 9.0 | 2023-01-04 | CKEditor Integration UI adds support for editing wiki pages using CKEditor. Prior to versions 1.64.3,t he `CKEditor.HTMLConverter` document lacked a protection against Cros… |