CVE-Datenbank
Archiv bekannter Schwachstellen (CVEs) mit CVSS-Wert, Schweregrad, betroffenen Produkten und Herstellern. Nach Jahr und Schweregrad filterbar.
- CVE-2023-20887Kritisch9.8
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.
- CVE-2023-33538Hoch8.8
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm .
- CVE-2023-3079Hoch8.8
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-34362Kritisch9.8
In Progress MOVEit Transfer vor 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5) und 2023.0.1 (15.0.1) wurde in der MOVEit Transfer-Webanwendung eine SQL-Injection-Schwachstelle gefunden, die es einem nicht authentifizierten Angreifer ermöglichen könnte, Zugriff auf die Datenbank von MOVEit Transfer zu erlangen. Je nach verwendeter Datenbank-Engine (MySQL, Microsoft SQL Server oder Azure SQL) kann ein Angreifer möglicherweise Informationen über die Struktur und die Inhalte der Datenbank ableiten und SQL-Anweisungen ausführen, die Datenbankelemente ändern oder löschen. HINWEIS: Dies wird im Mai und Juni 2023 in freier Wildbahn ausgenutzt; die Ausnutzung ungepatchter Systeme kann über HTTP oder HTTPS erfolgen. Alle Versionen (z. B. 2020.0 und 2019x) vor den fünf ausdrücklich genannten Versionen sind betroffen, einschließlich älterer nicht unterstützter Versionen.
- CVE-2023-32315Hoch8.6
Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an already configured Openfire environment to access restricted pages in the Openfire Admin Console reserved for administrative users. This vulnerability affects all versions of Openfire that have been released since April 2015, starting with version 3.10.0. The problem has been patched in Openfire release 4.7.5 and 4.6.8, and further improvements will be included in the yet-to-be released first version on the 4.8 branch (which is expected to be version 4.8.0). Users are advised to upgrade. If an Openfire upgrade isn’t available for a specific release, or isn’t quickly actionable, users may see the linked github advisory (GHSA-gw42-f939-fhvm) for mitigation advice.
- CVE-2023-2825Kritisch10.0
In GitLab CE/EE wurde ein Problem entdeckt, das nur Version 16.0.0 betrifft. Ein nicht authentifizierter böswilliger Benutzer kann eine Path-Traversal-Schwachstelle nutzen, um beliebige Dateien auf dem Server zu lesen, wenn ein Anhang in einem öffentlichen Projekt vorhanden ist, das in mindestens fünf Gruppen verschachtelt ist.
- CVE-2023-2868Kritisch9.4
A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format these file names in a particular manner that will result in remotely executing a system command through Perl's qx operator with the privileges of the Email Security Gateway product. This issue was fixed as part of BNSF-36456 patch. This patch was automatically applied to all customer appliances.
- CVE-2023-33246Kritisch9.8
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content. To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using RocketMQ 5.x or 4.9.6 or above for using RocketMQ 4.x .
- CVE-2023-33010Kritisch9.8
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
- CVE-2023-33009Kritisch9.8
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
- CVE-2023-29336Hoch7.8
Win32k Elevation of Privilege Vulnerability
- CVE-2023-24955Hoch7.2
Microsoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2023-21492Mittel4.4
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.
- CVE-2023-29552Hoch7.5
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
- CVE-2023-28771Kritisch9.8
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.
- CVE-2023-27524Hoch8.9
Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config. All superset installations should always set a unique secure random SECRET_KEY. Your SECRET_KEY is used to securely sign all session cookies and encrypting sensitive information on the database. Add a strong SECRET_KEY to your `superset_config.py` file like: SECRET_KEY = <YOUR_OWN_RANDOM_GENERATED_SECRET_KEY> Alternatively you can set it with `SUPERSET_SECRET_KEY` environment variable.
- CVE-2023-27351Hoch7.5
Diese Schwachstelle ermöglicht es entfernten Angreifern, die Authentifizierung auf betroffenen Installationen von PaperCut NG 22.0.5 (Build 63914) zu umgehen. Zur Ausnutzung dieser Schwachstelle ist keine Authentifizierung erforderlich. Der spezifische Fehler befindet sich in der Klasse SecurityRequestFilter. Das Problem resultiert aus einer fehlerhaften Implementierung des Authentifizierungsalgorithmus. Ein Angreifer kann diese Schwachstelle ausnutzen, um die Authentifizierung auf dem System zu umgehen. War ZDI-CAN-19226.
- CVE-2023-27350Kritisch9.8
Diese Schwachstelle ermöglicht es Remote-Angreifern, die Authentifizierung auf betroffenen Installationen von PaperCut NG 22.0.5 (Build 63914) zu umgehen. Zur Ausnutzung dieser Schwachstelle ist keine Authentifizierung erforderlich. Der spezifische Fehler befindet sich innerhalb der SetupCompleted-Klasse. Das Problem resultiert aus einer fehlerhaften Zugriffskontrolle. Ein Angreifer kann diese Schwachstelle ausnutzen, um die Authentifizierung zu umgehen und beliebigen Code im Kontext von SYSTEM auszuführen. War ZDI-CAN-18987.
- CVE-2023-2136Kritisch9.6
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-2033Hoch8.8
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
This product uses the NVD API but is not endorsed or certified by the NVD.