Show filters
94,096 Total Results
Displaying 321-330 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Low

CVE-2023-41474

Disclosure Date: January 25, 2024 (last updated February 26, 2025)
Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component.
Attacker Value
Very High

CVE-2024-22729

Disclosure Date: January 25, 2024 (last updated February 26, 2025)
NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.
Attacker Value
Unknown

CVE-2023-6549

Disclosure Date: January 17, 2024 (last updated February 26, 2025)
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read
Attacker Value
Unknown

CVE-2023-6548

Disclosure Date: January 17, 2024 (last updated February 26, 2025)
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.
Attacker Value
Unknown

CVE-2024-0519

Disclosure Date: January 16, 2024 (last updated February 26, 2025)
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Attacker Value
Very High

CVE-2023-50919

Disclosure Date: January 12, 2024 (last updated February 26, 2025)
An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.
Attacker Value
Very Low

CVE-2023-41056

Disclosure Date: January 10, 2024 (last updated February 25, 2025)
Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.
Attacker Value
Unknown

CVE-2024-21307

Disclosure Date: January 09, 2024 (last updated February 25, 2025)
Remote Desktop Client Remote Code Execution Vulnerability
Attacker Value
Very High

CVE-2024-21650

Disclosure Date: January 08, 2024 (last updated February 25, 2025)
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code execution (RCE) attack through its user registration feature. This issue allows an attacker to execute arbitrary code by crafting malicious payloads in the "first name" or "last name" fields during user registration. This impacts all installations that have user registration enabled for guests. This vulnerability has been patched in XWiki 14.10.17, 15.5.3 and 15.8 RC1.
Attacker Value
High

CVE-2023-35636

Disclosure Date: December 12, 2023 (last updated February 25, 2025)
Microsoft Outlook Information Disclosure Vulnerability