24021 Total CVEs
23926 AI Analyzed
338 CISA KEV
5516 Critical
All Vendors
Showing 22801-22850 of 24021 CVEs Page 457 of 481
CVE-2023-49186
Analyzed
7.1
KlbTheme Machic Core

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in KlbTheme Machic Core allows DOM-Based XSS

2026-01-06
CVE-2023-49105
KEV Analyzed
9.5
Unknown ownCloud Core

An authentication bypass in ownCloud core allows unauthenticated attackers to access, modify, or delete files if the victim username is known and no s...

2026-08-28
CVE-2023-47799
Analyzed
7.5
Mahara

Mahara before 22

2025-08-25
CVE-2023-46453
Analyzed
9.8

Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both...

2026-05-09
CVE-2023-45796
Analyzed
8.1
Pilz PMI v8xx

A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1

2026-06-23
CVE-2023-45795
Analyzed
7.8
Pilz PMI v8xx

A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1

2026-06-23
CVE-2023-43692
Analyzed
7.5
Malwarebytes

An issue was discovered in Malwarebytes before 4

2025-08-15
CVE-2023-4346
KEV Analyzed
9.5
KNX Association KNX Protocol Connection Authorization Option 1

The KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that is currently being expl...

2026-07-16
CVE-2023-43010
Analyzed
8.8
Apple iOS and iPadOS

The issue was addressed with improved memory handling

2026-03-13
CVE-2023-43000
KEV Analyzed
8.8
Apple macOS

A use-after-free issue was addressed with improved memory management

2025-11-06
CVE-2023-41974
KEV Analyzed
9.5
Apple iOS and iPadOS

Apple iOS and iPadOS Use-After-Free Vulnerability - Active in CISA KEV catalog.

2026-03-06
CVE-2023-41532
Analyzed
8.8
Hospital

Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter in doctorsearch

2025-08-07
CVE-2023-41531
Analyzed
8.8
Hospital

Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3

2025-08-07
CVE-2023-41524
Analyzed
8.8
Student

Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username parameter at index

2025-08-08
CVE-2023-41523
Analyzed
8.8
Student

Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress parameter at createClassTeacher

2025-08-08
CVE-2023-41522
Analyzed
8.8
Student

Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStudents

2025-08-08
CVE-2023-41521
Analyzed
8.8
Student

Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createSessionTerm

2025-08-07
CVE-2023-41520
Analyzed
8.8
Student

Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createClassArms

2025-08-07
CVE-2023-41471
Analyzed
7.8
Unknown

Cross Site Scripting vulnerability in copyparty v

2025-08-29
CVE-2023-37524
Analyzed
7.7
HCLSoftware Traveler for Microsoft Outlook

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to

2026-06-28
CVE-2023-36525
Analyzed
8.6
WPJobBoard WPJobBoard

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPJobBoard allows Blind SQL Injection

2025-12-25
CVE-2023-36424
KEV Analyzed
9.5
Microsoft Windows 11 version 22H3

Microsoft Windows Out-of-Bounds Read Vulnerability - Active in CISA KEV catalog.

2026-04-14
CVE-2023-3634
Analyzed
8.8
Festo MSE6-C2M-5000-FB36-D-M-RG-BAR-M12L4-AGD

In products of the MSE6 product-family by Festo a remote authenticated, low privileged attacker could use functions of undocumented test mode which co...

2026-04-16
CVE-2023-36331
Analyzed
8.2
Unknown

Incorrect access control in the /member/orderList API of xmall v1

2026-01-13
CVE-2023-32256
Analyzed
7.5
Red Hat Red Hat Enterprise Linux 10

A flaw was found in the Linux kernel's ksmbd component

2025-08-01
CVE-2023-31325
Analyzed
7.2
AMD AMD Ryzen™ 8000 Series Desktop Processors

Improper isolation of shared resources on System-on-a-chip (SOC) could a privileged attacker to tamper with the contents of the PSP reserved DRAM regi...

2025-09-07
CVE-2023-31322
Analyzed
8.7
AMD

Type confusion in the ASP could allow an attacker to pass a malformed argument to the Reliability, Availability, and Serviceability trusted applicatio...

2025-09-07
CVE-2023-31313
Analyzed
7.2
AMD AMD Instinct™ MI210

An unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a privileged attacker to send malformed messages to the sy...

2026-02-14
CVE-2023-28815
Analyzed
9.8
Hikvision iSecure Center

Some versions of Hikvision's iSecure Center Product contain insufficient parameter validation, resulting in a command injection vulnerability. Attacke...

2025-10-17
CVE-2023-28814
Analyzed
9.8
Hikvision iSecure Center

Some versions of Hikvision's iSecure Center Product have an improper file upload control vulnerability. Due to the improper verification of file to be...

2025-10-17
CVE-2023-28760
Analyzed
7.5

TP-Link AX1800 WiFi 6 Router (Archer AX21) devices allow unauthenticated attackers (on the LAN) to execute arbitrary code as root via the db_dir field...

2025-10-02
CVE-2023-27573
Analyzed
9
netbox-community netbox-docker

NetBox-docker versions before 2.5.0 contain a superuser account with default credentials and a static API token, potentially allowing unauthorized adm...

2026-03-11
CVE-2023-27351
KEV Analyzed
9.5
PaperCut NG

PaperCut NG/MF Improper Authentication Vulnerability - Active in CISA KEV catalog.

2026-04-21
CVE-2023-25446
Analyzed
7.7
HappyFiles HappyFiles Pro

Missing Authorization vulnerability in HappyFiles HappyFiles Pro happyfiles-pro allows Exploiting Incorrectly Configured Access Control Security Level...

2025-12-21
CVE-2023-2533
KEV
9.5
PaperCut PaperCut NG/MF

PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability - Active in CISA KEV catalog.

2025-07-28
CVE-2023-21529
KEV Analyzed
9.5
Microsoft Exchange Server

Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.

2026-04-14
CVE-2023-21480
Analyzed
8.5
Samsung Mobile Samsung Mobile Devices

Improper input validation vulnerability in CertByte prior to SMR Apr-2023 Release 1 allows local attackers to launch privileged activities

2025-09-03
CVE-2023-21477
Analyzed
7.9
Samsung Mobile Samsung Mobile Devices

Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protec...

2025-09-03
CVE-2023-21476
Analyzed
8
Samsung Mobile Samsung Mobile Devices

Out-of-bounds Write vulnerability in libaudiosaplus_sec

2025-09-03
CVE-2023-21475
Analyzed
8
Samsung Mobile Samsung Mobile Devices

Out-of-bounds Write vulnerability in libaudiosaplus_sec

2025-09-03
CVE-2023-21125
Analyzed
8
Google Android

In btif_hh_hsdata_rpt_copy_cb of bta_hh

2025-08-27
CVE-2023-1462
Analyzed
8.8
Vadi Corporate Information Systems DIGIKENT

Authorization Bypass Through User-Controlled Key vulnerability in Vadi Corporate Information Systems DigiKent allows Authentication Bypass, Authentica...

2026-06-02
CVE-2023-0882
Analyzed
8.8
Kron Tech Single Connect

Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Kron Tech Single Connect on Windows allows Privilege Abus...

2026-06-02
CVE-2022-51017
Analyzed
7.5
pmmp PocketMine-MP

PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to excee...

2026-09-08
CVE-2022-51009
Analyzed
7.5
pmmp PocketMine-MP

PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can s...

2026-09-07
CVE-2022-51000
Analyzed
9.8
sparklemotion nokogiri

The nokogiri gem contains outdated libxml2 and libxslt libraries, exposing applications to denial of service, memory disclosure, or remote code execut...

2026-08-26
CVE-2022-50999
Analyzed
8.6
sparklemotion nokogiri

Nokogiri versions before 1

2026-08-26
CVE-2022-50994
Analyzed
8.1
DrayTek Vigor 2960

DrayTek Vigor 2960 firmware versions prior to 1

2026-05-09
CVE-2022-50993
Analyzed
9.8
Weaver Network E-office

Weaver E-office is vulnerable to unauthenticated arbitrary file upload via OfficeServer.php, allowing remote attackers to execute code via webshells.

2026-05-01
CVE-2022-50992
Analyzed
7.5
Weaver Network E-cology

Weaver (Fanwei) E-cology 9

2026-05-01