Latest CVE Feed
-
7.1
HIGHCVE-2023-26607
In the Linux kernel 6.0.8, there is an out-of-bounds read in ntfs_attr_find in fs/ntfs/attrib.c.... Read more
- EPSS Score: %0.06
- Published: Feb. 26, 2023
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2023-26606
In the Linux kernel 6.0.8, there is a use-after-free in ntfs_trim_fs in fs/ntfs3/bitmap.c.... Read more
Affected Products : linux_kernel- EPSS Score: %0.02
- Published: Feb. 26, 2023
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2023-26605
In the Linux kernel 6.0.8, there is a use-after-free in inode_cgwb_move_to_attached in fs/fs-writeback.c, related to __list_del_entry_valid.... Read more
Affected Products : linux_kernel- EPSS Score: %0.02
- Published: Feb. 26, 2023
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2023-26544
In the Linux kernel 6.0.8, there is a use-after-free in run_unpack in fs/ntfs3/run.c, related to a difference between NTFS sector size and media sector size.... Read more
Affected Products : linux_kernel- EPSS Score: %0.02
- Published: Feb. 25, 2023
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2023-26242
afu_mmio_region_get_by_offset in drivers/fpga/dfl-afu-region.c in the Linux kernel through 6.1.12 has an integer overflow.... Read more
Affected Products : linux_kernel- EPSS Score: %0.01
- Published: Feb. 21, 2023
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2023-26068
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).... Read more
Affected Products : cxtpc_firmware cstpc_firmware mxtct_firmware mxtpm_firmware cxtmm_firmware mslsg_firmware mxlsg_firmware mslbd_firmware mxlbd_firmware msngm_firmware +142 more products- EPSS Score: %75.87
- Published: Apr. 10, 2023
- Modified: May. 05, 2025
-
4.6
MEDIUMCVE-2023-25012
The Linux kernel through 6.1.9 has a Use-After-Free in bigben_remove in drivers/hid/hid-bigbenff.c via a crafted USB device because the LED controllers remain registered for too long.... Read more
Affected Products : linux_kernel- EPSS Score: %0.03
- Published: Feb. 02, 2023
- Modified: May. 05, 2025
-
7.5
HIGHCVE-2023-24678
A vulnerability in Centralite Pearl Thermostat 0x04075010 allows attackers to cause a Denial of Service (DoS) via a crafted Zigbee message.... Read more
- EPSS Score: %0.09
- Published: Mar. 17, 2023
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2023-23559
In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5, there is an integer overflow in an addition.... Read more
- EPSS Score: %0.02
- Published: Jan. 13, 2023
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2023-22995
In the Linux kernel before 5.17, an error path in dwc3_qcom_acpi_register_core in drivers/usb/dwc3/dwc3-qcom.c lacks certain platform_device_put and kfree calls.... Read more
Affected Products : linux_kernel- EPSS Score: %0.01
- Published: Feb. 28, 2023
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2023-22670
A heap-based buffer overflow exists in the DXF file reading procedure in Open Design Alliance Drawings SDK before 2023.6. The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of the length of user-... Read more
- EPSS Score: %0.06
- Published: Apr. 15, 2023
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2023-22669
Parsing of DWG files in Open Design Alliance Drawings SDK before 2023.6 lacks proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute cod... Read more
- EPSS Score: %0.05
- Published: Apr. 15, 2023
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2023-20873
In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x user... Read more
Affected Products : spring_boot- EPSS Score: %0.38
- Published: Apr. 20, 2023
- Modified: May. 05, 2025
-
6.1
MEDIUMCVE-2023-1806
The WP Inventory Manager WordPress plugin before 2.1.0.12 does not sanitise and escape the message parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admini... Read more
Affected Products : wp_inventory_manager- EPSS Score: %0.11
- Published: May. 08, 2023
- Modified: May. 05, 2025
-
8.8
HIGHCVE-2023-1530
Use after free in PDF in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- EPSS Score: %0.36
- Published: Mar. 21, 2023
- Modified: May. 05, 2025
-
6.1
MEDIUMCVE-2023-1465
The WP EasyPay WordPress plugin before 4.1 does not escape some generated URLs before outputting them back in pages, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as admin... Read more
Affected Products : wp_easypay- EPSS Score: %0.09
- Published: Aug. 16, 2023
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2023-1078
A flaw was found in the Linux Kernel in RDS (Reliable Datagram Sockets) protocol. The rds_rm_zerocopy_callback() uses list_entry() on the head of a list causing a type confusion. Local user can trigger this with rds_message_put(). Type confusion leads to ... Read more
Affected Products : linux_kernel- EPSS Score: %0.02
- Published: Mar. 27, 2023
- Modified: May. 05, 2025
-
8.8
HIGHCVE-2023-0933
Integer overflow in PDF in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)... Read more
- EPSS Score: %0.26
- Published: Feb. 22, 2023
- Modified: May. 05, 2025
-
8.8
HIGHCVE-2023-0767
An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.... Read more
- EPSS Score: %0.24
- Published: Jun. 02, 2023
- Modified: May. 05, 2025
-
7.5
HIGHCVE-2023-0705
Integer overflow in Core in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who had one a race condition to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)... Read more
- EPSS Score: %0.23
- Published: Feb. 07, 2023
- Modified: May. 05, 2025