Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-29901 5 Debian, Fedoraproject, Intel and 2 more 254 Debian Linux, Fedora, Core I3-6100 and 251 more 2023-02-23 1.9 LOW 6.5 MEDIUM
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.
CVE-2023-21822 1 Microsoft 13 Windows 10, Windows 10 1607, Windows 10 1809 and 10 more 2023-02-23 N/A 7.8 HIGH
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2023-21820 1 Microsoft 13 Windows 10, Windows 10 1607, Windows 10 1809 and 10 more 2023-02-23 N/A 7.4 HIGH
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
CVE-2023-21819 1 Microsoft 7 Windows 10 1809, Windows 10 20h2, Windows 10 21h2 and 4 more 2023-02-23 N/A 7.5 HIGH
Windows Secure Channel Denial of Service Vulnerability
CVE-2023-21818 1 Microsoft 12 Windows 10, Windows 10 1607, Windows 10 1809 and 9 more 2023-02-23 N/A 7.5 HIGH
Windows Secure Channel Denial of Service Vulnerability
CVE-2023-21817 1 Microsoft 13 Windows 10, Windows 10 1607, Windows 10 1809 and 10 more 2023-02-23 N/A 7.8 HIGH
Windows Kerberos Elevation of Privilege Vulnerability
CVE-2023-21816 1 Microsoft 13 Windows 10, Windows 10 1607, Windows 10 1809 and 10 more 2023-02-23 N/A 7.5 HIGH
Windows Active Directory Domain Services API Denial of Service Vulnerability
CVE-2023-21813 1 Microsoft 13 Windows 10, Windows 10 1607, Windows 10 1809 and 10 more 2023-02-23 N/A 7.5 HIGH
Windows Secure Channel Denial of Service Vulnerability
CVE-2023-22938 1 Splunk 2 Splunk, Splunk Cloud Platform 2023-02-23 N/A 4.3 MEDIUM
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘sendemail’ REST API endpoint lets any authenticated user send an email as the Splunk instance. The endpoint is now restricted to the ‘splunk-system-user’ account on the local instance.
CVE-2023-21812 1 Microsoft 13 Windows 10, Windows 10 1607, Windows 10 1809 and 10 more 2023-02-23 N/A 7.8 HIGH
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2023-21811 1 Microsoft 13 Windows 10, Windows 10 1607, Windows 10 1809 and 10 more 2023-02-23 N/A 7.5 HIGH
Windows iSCSI Service Denial of Service Vulnerability
CVE-2022-3564 3 Debian, Linux, Netapp 10 Debian Linux, Linux Kernel, H300s and 7 more 2023-02-23 N/A 7.1 HIGH
A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211087.
CVE-2022-4905 1 Udx 1 Stateless Media Plugin 2023-02-23 N/A 6.1 MEDIUM
A vulnerability was found in UDX Stateless Media Plugin 3.1.1. It has been declared as problematic. This vulnerability affects the function setup_wizard_interface of the file lib/classes/class-settings.php. The manipulation of the argument settings leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 3.2.0 is able to address this issue. The name of the patch is 6aee7ae0b0beeb2232ce6e1c82aa7e2041ae151a. It is recommended to upgrade the affected component. VDB-220750 is the identifier assigned to this vulnerability.
CVE-2022-3521 2 Debian, Linux 2 Debian Linux, Linux Kernel 2023-02-23 N/A 2.5 LOW
A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function kcm_tx_work of the file net/kcm/kcmsock.c of the component kcm. The manipulation leads to race condition. It is recommended to apply a patch to fix this issue. VDB-211018 is the identifier assigned to this vulnerability.
CVE-2023-22934 1 Splunk 2 Splunk, Splunk Cloud Platform 2023-02-23 N/A 8.0 HIGH
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘pivot’ search processing language (SPL) command lets a search bypass [SPL safeguards for risky commands](https://docs.splunk.com/Documentation/Splunk/latest/Security/SPLsafeguards) using a saved search job. The vulnerability requires an authenticated user to craft the saved job and a higher privileged user to initiate a request within their browser. The vulnerability affects instances with Splunk Web enabled.
CVE-2022-20369 2 Debian, Google 2 Debian Linux, Android 2023-02-23 N/A 6.7 MEDIUM
In v4l2_m2m_querybuf of v4l2-mem2mem.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-223375145References: Upstream kernel
CVE-2023-25161 1 Nextcloud 1 Nextcloud Server 2023-02-23 N/A 5.3 MEDIUM
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 25.0.1 24.0.8, and 23.0.12 missing rate limiting on password reset functionality. This could result in service slowdown, storage overflow, or cost impact when using external email services. Users should upgrade to Nextcloud Server 25.0.1, 24.0.8, or 23.0.12 or Nextcloud Enterprise Server 25.0.1, 24.0.8, or 23.0.12 to receive a patch. No known workarounds are available.
CVE-2023-21809 1 Microsoft 1 Defender Security Intelligence Updates 2023-02-23 N/A 7.8 HIGH
Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
CVE-2023-21807 1 Microsoft 1 Dynamics 365 2023-02-23 N/A 6.5 MEDIUM
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-21806 1 Microsoft 1 Power Bi Report Server 2023-02-23 N/A 8.2 HIGH
Power BI Report Server Spoofing Vulnerability