Skip to content
VulniPulse

Complete feed

Exploited / KEV

Known exploitation or KEV-listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.8Atlassian Exploited CISA KEV

Critical [CVE-2023-22527] template injection vulnerability on older versions of Confluence Data Center and Server

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.

CVE-2023-22527
Confluence
Jan 16, 2024
Critical10.0GitLab Exploited CISA KEV

Critical [CVE-2023-7028] Weak Password Recovery Mechanism for Forgotten Password in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

CVE-2023-7028
Unclassified
Jan 12, 2024
High8.0QNAP Exploited CISA KEV

High [CVE-2023-47565] QVR: OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x.

An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QVR Firmware 5.0.0 and later

CVE-2023-47565
Surveillance (QVR)
Dec 8, 2023
CriticalCommvault Exploited CISA KEV

Critical [CVE-2023-46604] Remote Code Execution Vulnerability in Apache ActiveMQ

Remote Code Execution Vulnerability in Apache ActiveMQ

CVE-2023-46604
Unclassified
Nov 6, 2023
Critical9.8Atlassian Exploited CISA KEV

Critical [CVE-2023-22518] Confluence Data Center: All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.

All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

CVE-2023-22518
Confluence
Oct 31, 2023
Critical9.8F5 Exploited CISA KEV

Critical [CVE-2023-46747] Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP…

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2023-46747
BIG-IP
Oct 26, 2023
High8.8F5 Exploited CISA KEV

High [CVE-2023-46748] authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may

An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2023-46748
BIG-IP
Oct 26, 2023
Critical9.8Atlassian Exploited CISA KEV

Critical [CVE-2023-22515] Confluence Data Center: Atlassian has been made aware of an issue reported by a handful of customers where external attackers

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

CVE-2023-22515
Confluence
Oct 4, 2023
CriticalCommvault Exploited CISA KEV

Critical [CVE-2023-4863] Libwebp Vulnerability

CVE.Org link: CVE-2023-4863 Save as PDF

CVE-2023-4863
Unclassified
Oct 4, 2023
Medium5.0Cisco Exploited CISA KEV

Medium [CVE-2023-20269] vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or an authenticated, remote attacker to establish a clientless SSL VPN session with an unauthorized user

An unauthenticated remote attacker could exploit a flaw in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software to conduct a brute force attack in an attempt to identify valid username and password combinations or an authenticated, remote attacker to establish a clientless SSL VPN session with an unauthorized user. The flaw is caused by improper separation of authentication, authorization, and accounting (AAA) between the remote access VPN feature and the HTTPS management and site-to-site VPN features. Establish a clientless SSL VPN session (only when running Cisco ASA Software Release 9.16 or earlier). Affected products named by the advisory: Secure Firewall Adaptive Security Appliance (ASA) Software; ASA 5500-X Series Firewalls; 3000 Series Industrial Security Appliances (ISA); Firepower 9000 Series; and 4 more. Affected products named by the advisory: Firepower 4100 Series; Adaptive Security Virtual Appliance (ASAv); Firepower 2100 Series; Firepower 1000 Series.

CVE-2023-20269
FirewallASA / FirepowerASA 5500
Sep 6, 2023
Critical10.0Ivanti Exploited CISA KEV

Critical [CVE-2023-35078] Endpoint Manager Mobile: authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication. Affected products named by the advisory: Endpoint Manager Mobile; endpoint_manager_mobile.

CVE-2023-35078
Endpoint Manager
Jul 25, 2023
Critical9.8NetScaler Exploited CISA KEV

Critical [CVE-2023-3519] NetScaler ADC: Unauthenticated remote code execution

Unauthenticated remote code execution Affected products named by the advisory: NetScaler ADC; NetScaler Gateway.

CVE-2023-3519
NetScaler ADCNetScaler Gateway
Jul 19, 2023
High7.5MS Server Exploited CISA KEV

High [CVE-2023-36884] Windows Search Remote Code Execution Vulnerability

Windows Search Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2008 Service Pack 2; Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2 (Server Core installation); and 9 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 1 more.

CVE-2023-36884
Windows Server
Jul 11, 2023
Critical9.2Fortinet Exploited CISA KEV

Critical [CVE-2023-27997] FortiOS-6K7K: heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version…

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests. Affected products named by the advisory: FortiOS-6K7K.

CVE-2023-27997
FortiGateFirewallFortiOSFortiProxy
Jun 13, 2023
Critical9.8Sophos Exploited CISA KEV

Critical [CVE-2023-1671] pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4

A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.

CVE-2023-1671
Unclassified
Apr 4, 2023
High7.8MS Server Exploited CISA KEV

High [CVE-2023-21823] Windows Graphics Component Remote Code Execution Vulnerability

Windows Graphics Component Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2008 Service Pack 2; Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2 (Server Core installation); and 9 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 1 more.

CVE-2023-21823
Windows Server
Feb 14, 2023
High7.8MS Server Exploited CISA KEV

High [CVE-2023-23376] Windows Common Log File System Driver Elevation of Privilege Vulnerability

Windows Common Log File System Driver Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2019 (Server Core installation); Windows Server 2022; Windows Server 2016; and 9 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2008 Service Pack 2 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 R2 Service Pack 1 (Server Core installation); and 2 more.

CVE-2023-23376
Windows Server
Feb 14, 2023
High8.8MS Server Exploited CISA KEV

High [CVE-2023-21529] Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2013 Cumulative Update 23; Microsoft Exchange Server 2016 Cumulative Update 23; Microsoft Exchange Server 2019 Cumulative Update 11; Microsoft Exchange Server 2019 Cumulative Update 12.

CVE-2023-21529
Exchange Server
Feb 14, 2023
High7.8Check Point Exploited CISA KEV

High [CVE-2022-23748] mDNSResponder.exe is vulnerable to DLL Sideloading attack.

mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files.

CVE-2022-23748
Unclassified
Nov 17, 2022
High8.8MS Server Exploited CISA KEV

High [CVE-2022-41080] Microsoft Exchange Server Elevation of Privilege Vulnerability

Microsoft Exchange Server Elevation of Privilege Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2013 Cumulative Update 23; Microsoft Exchange Server 2016 Cumulative Update 22; Microsoft Exchange Server 2016 Cumulative Update 23; Microsoft Exchange Server 2019 Cumulative Update 11; and 1 more. Affected products named by the advisory: Microsoft Exchange Server 2019 Cumulative Update 12.

CVE-2022-41080
Exchange Server
Nov 9, 2022