Latest CVE Feed
-
9.8
CRITICALCVE-2023-38545
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that ho... Read more
Affected Products : fedora curl windows_server_2019 active_iq_unified_manager oncommand_insight oncommand_workflow_automation libcurl windows_10_1809 windows_10_21h2 windows_10_22h2 +4 more products- EPSS Score: %22.22
- Published: Oct. 18, 2023
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2024-5989
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.... Read more
- Published: Jun. 25, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-34039
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the ... Read more
Affected Products : aria_operations_for_networks- EPSS Score: %93.25
- Published: Aug. 29, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-32056
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability... Read more
- EPSS Score: %0.84
- Published: Jul. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-32015
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_21h2 +6 more products- EPSS Score: %2.72
- Published: Jun. 14, 2023
- Modified: Apr. 08, 2025
-
9.8
CRITICALCVE-2023-32002
The use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x... Read more
Affected Products : node.js- EPSS Score: %0.03
- Published: Aug. 21, 2023
- Modified: Jul. 02, 2025
-
9.8
CRITICALCVE-2023-45615
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successf... Read more
- EPSS Score: %0.87
- Published: Nov. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-30801
All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use t... Read more
Affected Products : qbittorrent- EPSS Score: %0.37
- Published: Oct. 10, 2023
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2023-29531
An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *This bug only affects Firefox and Thunderbird for macOS. Other operating systems are unaffected.* This vulne... Read more
- EPSS Score: %0.95
- Published: Jun. 19, 2023
- Modified: Dec. 11, 2024
-
9.8
CRITICALCVE-2023-29404
The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#... Read more
- EPSS Score: %0.08
- Published: Jun. 08, 2023
- Modified: Jan. 06, 2025
-
9.8
CRITICALCVE-2023-29300
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not re... Read more
Affected Products : coldfusion- Actively Exploited
- EPSS Score: %92.91
- Published: Jul. 12, 2023
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2023-28531
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.... Read more
- EPSS Score: %0.10
- Published: Mar. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28324
A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.... Read more
Affected Products : endpoint_manager- EPSS Score: %78.60
- Published: Jul. 01, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-25178
Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning. ... Read more
- EPSS Score: %0.89
- Published: Jul. 13, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-23363
A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating system. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors. We have already fixed the vulnerability in... Read more
Affected Products : qts- EPSS Score: %1.28
- Published: Sep. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-20894
The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading t... Read more
Affected Products : vcenter_server- EPSS Score: %49.09
- Published: Jun. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-20893
The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system tha... Read more
Affected Products : vcenter_server- EPSS Score: %2.92
- Published: Jun. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-48716
In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd938x: fix incorrect used of portid Mixer controls have the channel id in mixer->reg, which is not same as port id. port id should be derived from chan_info array. So fi... Read more
Affected Products : linux_kernel- Published: Jun. 20, 2024
- Modified: Apr. 01, 2025
-
9.8
CRITICALCVE-2022-46680
A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitive information, denial of service, or modification of data if an attacker is able to intercept network traffic. ... Read more
- EPSS Score: %0.12
- Published: May. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-45141
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the ... Read more
Affected Products : samba- EPSS Score: %0.35
- Published: Mar. 06, 2023
- Modified: Mar. 06, 2025