Latest CVE Feed
-
9.6
CRITICALCVE-2023-27905
Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hostin... Read more
Affected Products : update-center2- EPSS Score: %1.07
- Published: Mar. 10, 2023
- Modified: Feb. 28, 2025
-
9.6
CRITICALCVE-2023-27500
An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-write system files. In this attack, no data can be read but potentially critical OS files can be over-written making the system unavailab... Read more
Affected Products : netweaver_application_server_abap- EPSS Score: %0.42
- Published: Mar. 14, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2018-3679
Escalation of privilege in Reference UI in Intel Data Center Manager SDK 5.0 and before may allow an unauthorized remote unauthenticated user to potentially execute code via administrator privileges.... Read more
Affected Products : data_center_manager- EPSS Score: %0.38
- Published: Sep. 12, 2018
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-26034
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are affected by a SQL Injection vulnerability. The (blind) SQL Injection vulnerabil... Read more
Affected Products : zoneminder- EPSS Score: %0.51
- Published: Feb. 25, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-6505
Use after free in speech in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.... Read more
Affected Products : chrome- EPSS Score: %0.62
- Published: Jul. 22, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-20105
A vulnerability in the change password functionality of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with Read-only credentials to elevate privileges to Administrator on an a... Read more
- EPSS Score: %0.10
- Published: Jun. 28, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-35618
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability... Read more
Affected Products : edge_chromium- EPSS Score: %0.48
- Published: Dec. 07, 2023
- Modified: Jan. 01, 2025
-
9.6
CRITICALCVE-2023-35162
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the previewactions template to... Read more
Affected Products : xwiki- EPSS Score: %3.38
- Published: Jun. 23, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-35161
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the DeleteApplication page to ... Read more
Affected Products : xwiki- EPSS Score: %3.38
- Published: Jun. 23, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-35159
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the deletespace template to pe... Read more
Affected Products : xwiki- EPSS Score: %3.38
- Published: Jun. 23, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-29095
Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior) contain a cross-site scripting vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnera... Read more
- EPSS Score: %0.72
- Published: Jun. 10, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-32725
The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.... Read more
- EPSS Score: %0.20
- Published: Dec. 18, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-32722
The zabbix/src/libs/zbxjson module is vulnerable to a buffer overflow when parsing JSON files via zbx_json_open.... Read more
Affected Products : zabbix- EPSS Score: %0.27
- Published: Oct. 12, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-32680
Metabase is an open source business analytics engine. To edit SQL Snippets, Metabase should have required people to be in at least one group with native query editing permissions to a database–but affected versions of Metabase didn't enforce that requirem... Read more
Affected Products : metabase- EPSS Score: %0.14
- Published: May. 18, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-31403
SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any malicious user can read and write to the SMB shared folder. Additionally, the files in the folder can be ... Read more
Affected Products : business_one- EPSS Score: %0.10
- Published: Nov. 14, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-32797
JupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affected versions untrusted notebook can execute code on load. In particular JupyterLab doesn’t sanitize the action attribute of html `<form>... Read more
Affected Products : jupyterlab- EPSS Score: %1.14
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-31126
`org.xwiki.commons:xwiki-commons-xml` is an XML library used by the open-source wiki platform XWiki. The HTML sanitizer, introduced in version 14.6-rc-1, allows the injection of arbitrary HTML code and thus cross-site scripting via invalid data attributes... Read more
Affected Products : xwiki- EPSS Score: %3.27
- Published: May. 09, 2023
- Modified: Jan. 28, 2025
-
9.6
CRITICALCVE-2021-21481
The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This might allow an unauthorized attacker to access configuration objects, including such that grant administr... Read more
Affected Products : netweaver- EPSS Score: %0.16
- Published: Mar. 09, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-2746
The Rockwell Automation Enhanced HIM software contains an API that the application uses that is not protected sufficiently and uses incorrect Cross-Origin Resource Sharing (CORS) settings and, as a result, is vulnerable to a Cross Site Request Forgery (... Read more
Affected Products : enhanced_him- EPSS Score: %0.18
- Published: Jul. 11, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-2478
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2. Under certain conditions, a malicious unauthorized GitL... Read more
Affected Products : gitlab- EPSS Score: %0.47
- Published: May. 08, 2023
- Modified: Jan. 29, 2025