Database CVE
Archivio delle vulnerabilità note (CVE) con punteggio CVSS, gravità, prodotti e vendor coinvolti. Filtra per anno e severità, collegato ai nostri articoli.
- CVE-2023-34192Critica9.0
Vulnerabilità di Cross Site Scripting in Zimbra ZCS v.8.8.15 consente a un attaccante remoto autenticato di eseguire codice arbitrario tramite uno script appositamente creato alla funzione /h/autoSaveDraft.
- CVE-2023-21237Media5.5
In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251586912
- CVE-2023-32439Alta8.8
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
- CVE-2023-32435Alta8.8
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.7 and iPadOS 15.7.7. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.
- CVE-2023-32434Alta7.8
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.
- CVE-2023-32409Alta8.6
The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8, Safari 16.5, iOS 16.5 and iPadOS 16.5. A remote attacker may be able to break out of Web Content sandbox. Apple is aware of a report that this issue may have been actively exploited.
- CVE-2023-32373Alta8.8
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
- CVE-2023-28204Media6.5
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been actively exploited.
- CVE-2023-2533Alta8.4
È stata identificata una vulnerabilità di Cross-Site Request Forgery (CSRF) in PaperCut NG/MF, che, in condizioni specifiche, potrebbe potenzialmente consentire a un attaccante di alterare le impostazioni di sicurezza o eseguire codice arbitrario. Ciò potrebbe essere sfruttato se l'obiettivo è un admin con una sessione di login in corso. Lo sfruttamento implicherebbe tipicamente la possibilità di ingannare un admin inducendolo a fare clic su un link dannoso appositamente creato, portando potenzialmente a modifiche non autorizzate.
- CVE-2023-27992Critica9.8
The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands remotely by sending a crafted HTTP request.
- CVE-2023-29360Alta8.4
Microsoft Streaming Service Elevation of Privilege Vulnerability
- CVE-2023-29357Critica9.8
Microsoft SharePoint Server Elevation of Privilege Vulnerability
- CVE-2023-20867Bassa3.9
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.
- CVE-2023-27997Critica9.8
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.
- CVE-2023-20887Critica9.8
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.
- CVE-2023-33538Alta8.8
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm .
- CVE-2023-3079Alta8.8
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-34362Critica9.8
In Progress MOVEit Transfer prima di 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5) e 2023.0.1 (15.0.1), è stata trovata una vulnerabilità SQL injection nell'applicazione web MOVEit Transfer che potrebbe consentire a un attaccante non autenticato di ottenere l'accesso al database di MOVEit Transfer. A seconda del motore di database utilizzato (MySQL, Microsoft SQL Server o Azure SQL), un attaccante potrebbe essere in grado di dedurre informazioni sulla struttura e sul contenuto del database ed eseguire istruzioni SQL che alterano o eliminano elementi del database. NOTA: questa è sfruttata in the wild a maggio e giugno 2023; lo sfruttamento dei sistemi non aggiornati può avvenire tramite HTTP o HTTPS. Tutte le versioni (ad es. 2020.0 e 2019x) precedenti alle cinque versioni esplicitamente menzionate sono interessate, comprese le versioni precedenti non supportate.
- CVE-2023-32315Alta8.6
Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an already configured Openfire environment to access restricted pages in the Openfire Admin Console reserved for administrative users. This vulnerability affects all versions of Openfire that have been released since April 2015, starting with version 3.10.0. The problem has been patched in Openfire release 4.7.5 and 4.6.8, and further improvements will be included in the yet-to-be released first version on the 4.8 branch (which is expected to be version 4.8.0). Users are advised to upgrade. If an Openfire upgrade isn’t available for a specific release, or isn’t quickly actionable, users may see the linked github advisory (GHSA-gw42-f939-fhvm) for mitigation advice.
- CVE-2023-2825Critica10.0
È stato scoperto un problema in GitLab CE/EE che interessa solo la versione 16.0.0. Un utente malevolo non autenticato può utilizzare una vulnerabilità di path traversal per leggere file arbitrari sul server quando esiste un allegato in un progetto pubblico annidato all'interno di almeno cinque gruppi.
This product uses the NVD API but is not endorsed or certified by the NVD.