Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,635 CVEs · Low severity

CVEs (15,635, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 451–475 of 15,635 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2023-2434 LOW Patched 3.8 2023-05-31 The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions up to, and including,…
CVE-2023-29128 LOW 3.8 2023-05-09 A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The filenam&hellip;
CVE-2023-27892 LOW Patched 3.8 2023-05-02 Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.7.0 allow a global buffer overflow via crafted messages. Flaws in cf_confirmExecTx() &hellip;
CVE-2022-23721 LOW Patched 3.8 2023-04-25 PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can lead to a username collision when two people with the same username are pro&hellip;
CVE-2023-21988 LOW Patched 3.8 2023-04-18 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8.&hellip;
CVE-2022-43772 LOW Patched 3.8 2023-04-03 Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Data Plugin expose the username and password of cluster&hellip;
CVE-2023-23677 LOW Patched 3.8 2023-03-30 Reflected Cross-Site Scripting (XSS) vulnerability in GTmetrix GTmetrix for WordPress plugin <= 0.4.5 versions.
CVE-2023-1541 LOW Patched 3.8 2023-03-21 Business Logic Errors in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1367 LOW Patched 3.8 2023-03-13 Code Injection in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
CVE-2023-1045 LOW 3.8 2023-02-26 A vulnerability was found in MuYuCMS 2.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin.php/accessory/filesdel.h&hellip;
CVE-2022-38056 LOW Patched 3.8 2023-02-16 Improper neutralization in the Intel(R) EMA software before version 1.8.1.0 may allow a privileged user to potentially enable escalation of privilege via network access.
CVE-2023-23854 LOW 3.8 2023-02-14 SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks for an authen&hellip;
CVE-2023-21885 LOW Patched 3.8 2023-01-18 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.42 and prior to 7.0.6.&hellip;
CVE-2023-21889 LOW Patched 3.8 2023-01-18 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.42 and prior to 7.0.6.&hellip;
CVE-2023-0091 LOW 3.8 2023-01-13 A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or&hellip;
CVE-2022-37911 LOW Patched 3.8 2022-12-12 Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated atta&hellip;
CVE-2022-4031 LOW Patched 3.8 2022-11-29 The Simple:Press plugin for WordPress is vulnerable to arbitrary file modifications in versions up to, and including, 6.8 via the 'file' parameter which does not properly r&hellip;
CVE-2022-45194 LOW Patched 3.8 2022-11-12 CBRN-Analysis before 22 allows XXE attacks via am mws XML document, leading to NTLMv2-SSP hash disclosure.
CVE-2022-30297 LOW Patched 3.8 2022-11-11 Cross-site scripting in the Intel(R) EMA software before version 1.8.0 may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2022-39394 LOW Patched 3.8 2022-11-10 Wasmtime is a standalone runtime for WebAssembly. Prior to version 2.0.2, there is a bug in Wasmtime's C API implementation where the definition of the `wasmtime_trap_code`&hellip;
CVE-2022-20962 LOW 3.8 2022-11-04 A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make unauthorized changes to th&hellip;
CVE-2022-33747 LOW 3.8 2022-10-11 Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e.g. removing pages from a guest's P2M (Physical-to-Machine) mapping. When large pages a&hellip;
CVE-2021-36865 LOW Patched 3.8 2022-09-30 Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz.
CVE-2022-2256 LOW 3.8 2022-09-01 A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This flaw allows a privileged attacker to execute malicious &hellip;
CVE-2022-2469 LOW Patched 3.8 2022-07-19 GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client