Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-27477 1 Bytecodealliance 2 Cranelift-codegen, Wasmtime 2023-03-15 N/A 4.3 MEDIUM
wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's code generation backend, Cranelift, has a bug on x86_64 platforms for the WebAssembly `i8x16.select` instruction which will produce the wrong results when the same operand is provided to the instruction and some of the selected indices are greater than 16. There is an off-by-one error in the calculation of the mask to the `pshufb` instruction which causes incorrect results to be returned if lanes are selected from the second vector. This codegen bug has been fixed in Wasmtiem 6.0.1, 5.0.1, and 4.0.1. Users are recommended to upgrade to these updated versions. If upgrading is not an option for you at this time, you can avoid this miscompilation by disabling the Wasm simd proposal. Additionally the bug is only present on x86_64 hosts. Other platforms such as AArch64 and s390x are not affected.
CVE-2023-1287 1 3ds 1 Enovia Live Collaboration 2023-03-15 N/A 9.8 CRITICAL
An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution.
CVE-2022-47471 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-03-15 N/A 5.5 MEDIUM
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVE-2022-47456 2 Google, Unisoc 27 Android, S8000, S8000 Firmware and 24 more 2023-03-15 N/A 5.5 MEDIUM
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
CVE-2022-47461 2 Google, Unisoc 27 Android, S8000, S8000 Firmware and 24 more 2023-03-15 N/A 6.7 MEDIUM
In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.
CVE-2022-47460 2 Google, Unisoc 27 Android, S8000, S8000 Firmware and 24 more 2023-03-15 N/A 5.5 MEDIUM
In gpu device, there is a memory corruption due to a use after free. This could lead to local denial of service in kernel.
CVE-2022-47481 2 Google, Unisoc 27 Android, S8000, S8000 Firmware and 24 more 2023-03-15 N/A 5.5 MEDIUM
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.
CVE-2022-47480 2 Google, Unisoc 27 Android, S8000, S8000 Firmware and 24 more 2023-03-15 N/A 5.5 MEDIUM
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.
CVE-2022-47462 2 Google, Unisoc 27 Android, S8000, S8000 Firmware and 24 more 2023-03-15 N/A 6.7 MEDIUM
In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.
CVE-2023-27164 1 Halo 1 Halo 2023-03-15 N/A 4.8 MEDIUM
An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md file.
CVE-2022-3381 1 Gitlab 1 Gitlab 2023-03-15 N/A 6.1 MEDIUM
An issue has been discovered in GitLab affecting all versions starting from 10.0 to 15.7.8, 15.8 prior to 15.8.4 and 15.9 prior to 15.9.2. A crafted URL could be used to redirect users to arbitrary sites
CVE-2023-27119 1 Webassembly 1 Webassembly 2023-03-15 N/A 5.5 MEDIUM
WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::Decompiler::WrapChild.
CVE-2023-1303 1 Ucms Project 1 Ucms 2023-03-15 N/A 9.8 CRITICAL
A vulnerability was found in UCMS 1.6 and classified as critical. This issue affects some unknown processing of the file sadmin/fileedit.php of the component System File Management Module. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-222683.
CVE-2022-3767 1 Gitlab 1 Dynamic Application Security Testing Analyzer 2023-03-15 N/A 6.5 MEDIUM
Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.
CVE-2022-3758 1 Gitlab 1 Gitlab 2023-03-15 N/A 5.4 MEDIUM
An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Due to improper permissions checks an unauthorised user was able to read, add or edit a users private snippet.
CVE-2023-0483 1 Gitlab 1 Gitlab 2023-03-15 N/A 3.8 LOW
An issue has been discovered in GitLab affecting all versions starting from 12.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible for a project maintainer to extract a Datadog integration API key by modifying the site.
CVE-2022-4462 1 Gitlab 1 Gitlab 2023-03-15 N/A 4.3 MEDIUM
An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. This vulnerability could allow a user to unmask the Discord Webhook URL through viewing the raw API response.
CVE-2022-4317 1 Gitlab 1 Dynamic Application Security Testing Analyzer 2023-03-15 N/A 6.1 MEDIUM
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 1.47 before 3.0.51, which sends custom request headers in redirects.
CVE-2023-25814 1 Metersphere 1 Metersphere 2023-03-15 N/A 6.5 MEDIUM
metersphere is an open source continuous testing platform. In versions prior to 2.7.1 a user who has permission to create a resource file through UI operations is able to append a path to their submission query which will be read by the system and displayed to the user. This allows a users of the system to read arbitrary files on the filesystem of the server so long as the server process itself has permission to read the requested files. This issue has been addressed in version 2.7.1. All users are advised to upgrade. There are no known workarounds for this issue.
CVE-2023-25573 1 Metersphere 1 Metersphere 2023-03-15 N/A 7.5 HIGH
metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability exists in `/api/jmeter/download/files`, which allows any user to download any file without authentication. This issue may expose all files available to the running process. This issue has been addressed in version 1.20.20 lts and 2.7.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.