Reference material - not professional advice. Test in staging, back up first, verify against your specific version. Use your own judgment for your environment.
Showing 236 of 236 guides from 2023
CRITICAL⚠ KEVRCE

How to Fix Command Injection in Sophos Web Appliance

CVE-2023-1671 is an OS command injection in Sophos Web Appliance. Verified patched version, official vendor advisory, and how to confirm the

CVE-2023-1671 · OtherRead fix →
CRITICAL⚠ KEVPrivilege Escalation

How to Fix Cisco IOS XE Web UI Privilege Escalation

CVE-2023-20198 is the Cisco IOS XE web UI vulnerability that gave unauthenticated attackers full admin access. Affected versions, fix builds

CVE-2023-20198 · CiscoRead fix →
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution in Aria Operations for Networks (Formerly vRealize Network Insight)

CVE-2023-20887 is a remote code execution flaw in Aria Operations for Networks (Formerly vRealize Network Insight). Verified patched version

CVE-2023-20887 · VmwareRead fix →
CRITICAL⚠ KEV

How to Fix Integer Overflow in Chrome

CVE-2023-2136 is an integer overflow flaw in Chrome. Verified patched version and mitigations from the official advisory.

CVE-2023-2136 · GoogleRead fix →
CRITICAL⚠ KEV

How to Fix Confluence Data Center Broken Access Control

CVE-2023-22515 is the Confluence Data Center / Server zero-day that let attackers create admin accounts unauthenticated. Patched versions an

CVE-2023-22515 · AtlassianRead fix →
CRITICAL⚠ KEVAuth Bypass

How to Fix Atlassian Confluence Data Loss via Improper Authorization

CVE-2023-22518 lets an unauthenticated attacker reset Confluence and create new admin accounts. Affected versions, patched builds, recovery

CVE-2023-22518 · AtlassianRead fix →
CRITICAL⚠ KEVRCE

How to Fix Atlassian Confluence Template Injection RCE

CVE-2023-22527 is the Confluence Data Center / Server template injection that gives unauthenticated RCE. Affected versions, fixed versions,

CVE-2023-22527 · AtlassianRead fix →
CRITICAL⚠ KEV

How to Fix Improper Input Validation in Microsoft Office Ltsc 2021

CVE-2023-23397 is a improper input validation in Microsoft Office Ltsc 2021. Patched version, runnable upgrade commands, and how to verify t

CVE-2023-23397 · MicrosoftRead fix →
CRITICAL⚠ KEVRCE

How to Fix Citrix ShareFile Customer-Managed Storage Zone RCE

CVE-2023-24489 lets unauthenticated attackers compromise the Citrix ShareFile customer-managed Storage Zones Controller. Patched build and u

CVE-2023-24489 · CitrixRead fix →
CRITICAL⚠ KEVRCE

How to Fix Command Injection in DIR-820 Router

CVE-2023-25280 is a command injection flaw in DIR-820 Router. Verified patched version and mitigations from the official advisory.

CVE-2023-25280 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution in Ruckus Wireless Admin through

CVE-2023-25717 is a remote code execution flaw in Ruckus Wireless Admin through. Verified patched version and mitigations from the official

CVE-2023-25717 · OtherRead fix →
CRITICAL⚠ KEVDeserialization

How to Fix Adobe ColdFusion Deserialization (Sibling)

CVE-2023-26359 is the first in the 2023 Adobe ColdFusion deserialization series. Same Lockdown Guide hardening as CVE-2023-29300.

CVE-2023-26359 · AdobeRead fix →
CRITICAL⚠ KEV

How to Fix Access Control Bypass in NG

CVE-2023-27350 is an access control bypass in NG. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2023-27350 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix Command Injection in NAS326 firmware

CVE-2023-27992 is an OS command injection in NAS326 firmware. Verified patched version, official vendor advisory, and how to confirm the fix

CVE-2023-27992 · OtherRead fix →
CRITICAL⚠ KEVPath Traversal

How to Fix Path Traversal in FortiOS-6K7K

CVE-2023-27997 is a path traversal in FortiOS-6K7K. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2023-27997 · FortinetRead fix →
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution in AG/vxAG ArrayOS

CVE-2023-28461 is a remote code execution flaw in AG/vxAG ArrayOS. Verified patched version and mitigations from the official advisory.

CVE-2023-28461 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix Command Injection in Barracuda Email Security Gateway

CVE-2023-2868: an OS command injection in Barracuda Email Security Gateway. Patched version and vendor advisory inside.

CVE-2023-2868 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix Command Injection in ZyWALL/USG series firmware

CVE-2023-28771: an OS command injection in ZyWALL/USG series firmware. Patched version and vendor advisory inside.

CVE-2023-28771 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix Adobe ColdFusion Wddx Deserialization RCE

CVE-2023-29300 is the Adobe ColdFusion Wddx deserialization RCE. Affected versions, patched builds, and lockdown.html considerations.

CVE-2023-29300 · AdobeRead fix →
CRITICAL⚠ KEV

How to Fix Incorrect Implementation of Authentication Algorithm

CVE-2023-29357 incorrect implementation of authentication algorithm in Microsoft Sharepoint Server 2019. Runnable upgrade commands and verif

CVE-2023-29357 · MicrosoftRead fix →
CRITICAL⚠ KEV

How to Fix Security Vulnerability in Novi Survey

CVE-2023-29492 is a security vulnerability flaw in Novi Survey. Verified patched version and mitigations from the official advisory.

CVE-2023-29492 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Critical Vulnerability in ATP series firmware

CVE-2023-33009 is a vulnerability in ATP series firmware. Verified patched version, official vendor advisory, and how to confirm the fix lan

CVE-2023-33009 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Critical Vulnerability in ATP series firmware

CVE-2023-33010 is a vulnerability in ATP series firmware. Verified patched version, official vendor advisory, and how to confirm the fix lan

CVE-2023-33010 · OtherRead fix →
CRITICAL⚠ KEVBuffer Overflow

How to Fix VMware vCenter Server DCERPC Out-of-Bounds Write

CVE-2023-34048 is the vCenter DCERPC out-of-bounds write, UNC3886 used it as a zero-day for two years. Patched builds and Linux Service Cons

CVE-2023-34048 · VmwareRead fix →
CRITICAL⚠ KEV

How to Fix Security Vulnerability in Zimbra Collaboration Suite (ZCS)

CVE-2023-34192 is a security vulnerability flaw in Zimbra Collaboration Suite (ZCS). Verified patched version and mitigations from the offic

CVE-2023-34192 · OtherRead fix →
CRITICAL⚠ KEVSQLi

How to Fix SQL Injection in In Progress MOVEit Transfer

CVE-2023-34362 is a sql injection flaw in In Progress MOVEit Transfer. Verified patched version and mitigations from the official advisory.

CVE-2023-34362 · MOVEitRead fix →
CRITICAL⚠ KEV

How to Fix Ivanti EPMM Remote Unauthenticated API Access

CVE-2023-35078 is the Ivanti EPMM zero-day used against Norwegian government ministries in 2023. Affected versions, patched builds, and IoC

CVE-2023-35078 · IvantiRead fix →
CRITICAL⚠ KEVAuth Bypass

How to Fix Ivanti EPMM / MobileIron Core Auth Bypass

CVE-2023-35082 lets unauthenticated attackers access restricted Ivanti EPMM 11.10 and earlier (and legacy MobileIron Core) APIs. Upgrade and

CVE-2023-35082 · IvantiRead fix →
CRITICAL⚠ KEVRCE

How to Fix Citrix NetScaler ADC and Gateway Unauthenticated RCE

CVE-2023-3519 is the Citrix NetScaler / ADC / Gateway zero-day used to compromise US critical infrastructure in 2023. Patched versions and I

CVE-2023-3519 · CitrixRead fix →
CRITICAL⚠ KEV

How to Fix Arbitrary File Read in Junos OS

CVE-2023-36845 is an arbitrary file read in Junos OS. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2023-36845 · JuniperRead fix →
CRITICAL⚠ KEVDeserialization

How to Fix Adobe ColdFusion Deserialization (Sibling)

CVE-2023-38203 is one of the ColdFusion 2018u17 / 2021u7 deserialization siblings. Same patch as CVE-2023-29300.

CVE-2023-38203 · AdobeRead fix →
CRITICAL⚠ KEVRCE

How to Fix Deserialization RCE in WS_FTP Server

CVE-2023-40044 is an unsafe deserialization in WS_FTP Server. Verified patched version, official vendor advisory, and how to confirm the fix

CVE-2023-40044 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Critical Vulnerability in n/a

CVE-2023-41265 is a vulnerability in n/a. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2023-41265 · OtherRead fix →
CRITICAL⚠ KEVAuth Bypass

How to Fix Authentication Bypass in TeamCity

CVE-2023-42793 is an authentication bypass in TeamCity. Verified patched version, official vendor advisory, and how to confirm the fix lande

CVE-2023-42793 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution in NextGen Healthcare Mirth Connect

CVE-2023-43208 is a remote code execution flaw in NextGen Healthcare Mirth Connect. Verified patched version and mitigations from the offici

CVE-2023-43208 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Default Credentials in Acronis Cyber Infrastructure

CVE-2023-45249: a default credentials in Acronis Cyber Infrastructure. Patched version and vendor advisory inside.

CVE-2023-45249 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix Apache ActiveMQ OpenWire Deserialization RCE

CVE-2023-46604 lets a remote attacker run code on Apache ActiveMQ via the OpenWire protocol. Patched versions, upgrade steps, and Kinsing/ra

CVE-2023-46604 · ApacheRead fix →
CRITICAL⚠ KEVAuth Bypass

How to Fix F5 BIG-IP Configuration Utility Authentication Bypass

CVE-2023-46747 lets unauthenticated attackers bypass the F5 BIG-IP Configuration Utility (TMUI). Patched builds and TMUI lockdown procedure.

CVE-2023-46747 · F5Read fix →
CRITICAL⚠ KEVPath Traversal

How to Fix Path Traversal in In SysAid On-Premise

CVE-2023-47246 is a path traversal flaw in In SysAid On-Premise. Verified patched version and mitigations from the official advisory.

CVE-2023-47246 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Critical Vulnerability in n/a

CVE-2023-48365 is a vulnerability in n/a. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2023-48365 · OtherRead fix →
CRITICAL⚠ KEVSQLi

How to Fix SQL Injection in FortiClientEMS

CVE-2023-48788 is a SQL injection in FortiClientEMS. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2023-48788 · FortinetRead fix →
CRITICAL⚠ KEV

How to Fix Critical Vulnerability in n/a

CVE-2023-49103 is a vulnerability in n/a. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2023-49103 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Memory Corruption in NetScaler ADC

CVE-2023-4966 is a memory corruption in NetScaler ADC. Verified patched version, official vendor advisory, and how to confirm the fix landed

CVE-2023-4966 · CitrixRead fix →
CRITICAL⚠ KEV

How to Fix Insecure Default Config in VisiLogic

CVE-2023-6448 is an insecure default configuration in VisiLogic. Verified patched version, official vendor advisory, and how to confirm the

CVE-2023-6448 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix GitLab Account Takeover via Password Reset

CVE-2023-7028 lets an attacker hijack any GitLab account by sending the password reset email to their own address. Patch and audit steps for

CVE-2023-7028 · GitlabRead fix →
HIGH⚠ KEVUse After Free

How to Fix Use-After-Free in Linux Kernel

CVE-2023-0266 is an use-after-free in Linux Kernel. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2023-0266 · LinuxRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in Kernel

CVE-2023-0386 is a security vulnerability flaw in Kernel. Verified patched version and mitigations from the official advisory.

CVE-2023-0386 · LinuxRead fix →
HIGH⚠ KEVDeserialization

How to Fix Insecure Deserialization in Goanywhere MFT

CVE-2023-0669 is an insecure deserialization flaw in Goanywhere MFT. Verified patched version and mitigations from the official advisory.

CVE-2023-0669 · GoRead fix →
HIGH⚠ KEVRCE

How to Fix Command Injection in TP-Link Archer AX21 (AX1800)

CVE-2023-1389 is a command injection flaw in TP-Link Archer AX21 (AX1800). Verified patched version and mitigations from the official adviso

CVE-2023-1389 · Tp-LinkRead fix →
HIGH⚠ KEVRCE

How to Fix Command Injection in Cisco IOS XE Software

CVE-2023-20273 is an OS command injection in Cisco IOS XE Software. Verified patched version, official vendor advisory, and how to confirm t

CVE-2023-20273 · CiscoRead fix →
HIGH⚠ KEV

How to Fix Type Confusion in Chrome

CVE-2023-2033 is a type confusion flaw in Chrome. Verified patched version and mitigations from the official advisory.

CVE-2023-2033 · GoogleRead fix →
HIGH⚠ KEVRCE

How to Fix Remote Code Execution in Android

CVE-2023-20963 is a remote code execution flaw in Android. Verified patched version and mitigations from the official advisory.

CVE-2023-20963 · AndroidRead fix →
HIGH⚠ KEVDeserialization

How to Fix Insecure Deserialization in Microsoft Exchange Server 2019 Cumulative Update 12

CVE-2023-21529 - Insecure Deserialization in Microsoft Exchange Server 2019 Cumulative Update 12. Runnable patch commands and verification o

CVE-2023-21529 · MicrosoftRead fix →
HIGH⚠ KEVUse After Free

How to Fix Use-After-Free in Acrobat Reader

CVE-2023-21608 is an use-after-free in Acrobat Reader. Verified patched version, official vendor advisory, and how to confirm the fix landed

CVE-2023-21608 · AdobeRead fix →
HIGH⚠ KEVUse After Free

How to Fix Use After Free in Windows 10 Version 1809

CVE-2023-21674 is a use after free in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the fix landed.

CVE-2023-21674 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Incorrect Authorization in Microsoft 365 Apps For Enterprise

CVE-2023-21715 incorrect authorization in Microsoft 365 Apps For Enterprise. Runnable upgrade commands and verification steps for sysadmins.

CVE-2023-21715 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Integer Overflow or Wraparound in Microsoft Office For Android

CVE-2023-21823 integer overflow or wraparound in Microsoft Office For Android. Runnable upgrade commands and verification steps for sysadmin

CVE-2023-21823 · MicrosoftRead fix →
HIGH⚠ KEVAuth Bypass

How to Fix Missing Authentication for Critical Function in Weblogic Server

CVE-2023-21839 missing authentication for critical function in Weblogic Server. Runnable upgrade commands and verification steps for sysadmi

CVE-2023-21839 · OracleRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in In SugarCRM

CVE-2023-22952 is a security vulnerability flaw in In SugarCRM. Verified patched version and mitigations from the official advisory.

CVE-2023-22952 · OtherRead fix →
HIGH⚠ KEVBuffer Overflow

How to Fix Heap-based Buffer Overflow in Windows 10 Version 1809

CVE-2023-23376 is a heap-based buffer overflow in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the

CVE-2023-23376 · MicrosoftRead fix →
HIGH⚠ KEVRCE

How to Fix Remote Code Execution in Safari, iOS and iPadOS, macOS

CVE-2023-23529 is a remote code execution flaw in Safari, iOS and iPadOS, macOS. Verified patched version and mitigations from the official

CVE-2023-23529 · AppleRead fix →
HIGH⚠ KEV

How to Fix Improper Control of Generation of Code ('Code Injection')

CVE-2023-24955 improper control of generation of code ('code injection') in Microsoft Sharepoint Enterprise Server 2016. Runnable upgrade co

CVE-2023-24955 · MicrosoftRead fix →
HIGH⚠ KEVCSRF

How to Fix Cross-Site Request Forgery in Papercut PaperCut NG/MF

CVE-2023-2533 is a Cross-Site Request Forgery flaw in Papercut PaperCut NG/MF. Actively exploited per CISA KEV. Verified patched builds and

CVE-2023-2533 · OtherRead fix →
HIGH⚠ KEV

How to Fix Access Control Bypass in ColdFusion

CVE-2023-26360 is an access control bypass in ColdFusion. Verified patched version, official vendor advisory, and how to confirm the fix lan

CVE-2023-26360 · AdobeRead fix →
HIGH⚠ KEVRCE

How to Fix Command Injection in Acrobat Reader

CVE-2023-26369 is an OS command injection in Acrobat Reader. Verified patched version, official vendor advisory, and how to confirm the fix

CVE-2023-26369 · AdobeRead fix →
HIGH⚠ KEVAuth Bypass

How to Fix Authentication Bypass in Papercut NG

CVE-2023-27351 is a Authentication Bypass flaw in Papercut NG. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-27351 · OtherRead fix →
HIGH⚠ KEV

How to Fix Insecure Default Config in Apache Superset

CVE-2023-27524: an insecure default configuration in Apache Superset. Patched version and vendor advisory inside.

CVE-2023-27524 · ApacheRead fix →
HIGH⚠ KEVAuth Bypass

How to Fix Missing Authentication in Veeam Backup & Replication

CVE-2023-27532 is a missing authentication flaw in Veeam Backup & Replication. Verified patched version and mitigations from the official ad

CVE-2023-27532 · OtherRead fix →
HIGH⚠ KEVRCE

How to Fix Remote Code Execution in Safari, iOS and iPadOS, macOS

CVE-2023-28205 is a remote code execution flaw in Safari, iOS and iPadOS, macOS. Verified patched version and mitigations from the official

CVE-2023-28205 · AppleRead fix →
HIGH⚠ KEVDoS

How to Fix Denial of Service in iOS and iPadOS, macOS

CVE-2023-28206 is a denial of service flaw in iOS and iPadOS, macOS. Verified patched version and mitigations from the official advisory.

CVE-2023-28206 · AppleRead fix →
HIGH⚠ KEV

How to Fix Sensitive Data Storage in Improperly Locked Memory in Windows 10 Version 1809

CVE-2023-28229 sensitive data storage in improperly locked memory in Windows 10 Version 1809. Runnable upgrade commands and verification ste

CVE-2023-28229 · MicrosoftRead fix →
HIGH⚠ KEVBuffer Overflow

How to Fix Heap-based Buffer Overflow in Windows 10 Version 1809

CVE-2023-28252 is a heap-based buffer overflow in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the

CVE-2023-28252 · MicrosoftRead fix →
HIGH⚠ KEVInfo Disclosure

How to Fix Information Disclosure in Minio minio

CVE-2023-28432 is a Information Disclosure flaw in Minio minio. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-28432 · OtherRead fix →
HIGH⚠ KEV

How to Fix Critical Vulnerability in minio

CVE-2023-28434 is a vulnerability in minio. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2023-28434 · OtherRead fix →
HIGH⚠ KEV

How to Fix Access Control Bypass in ColdFusion

CVE-2023-29298 is an access control bypass in ColdFusion. Verified patched version, official vendor advisory, and how to confirm the fix lan

CVE-2023-29298 · AdobeRead fix →
HIGH⚠ KEVUse After Free

How to Fix Use After Free in Windows 10 Version 1507

CVE-2023-29336 is a use after free in Windows 10 Version 1507. Patched version, runnable upgrade commands, and how to verify the fix landed.

CVE-2023-29336 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Untrusted Pointer Dereference in Windows 10 Version 1809

CVE-2023-29360 is a untrusted pointer dereference in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify

CVE-2023-29360 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in Service Location Protocol (SLP)

CVE-2023-29552 is a security vulnerability flaw in Service Location Protocol (SLP). Verified patched version and mitigations from the offici

CVE-2023-29552 · OtherRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in Windows 10 Version 1809

CVE-2023-32046 is a security vulnerability in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the fix

CVE-2023-32046 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in Windows 10 Version 1809

CVE-2023-32049 is a security vulnerability in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the fix

CVE-2023-32049 · MicrosoftRead fix →
HIGH⚠ KEVPath Traversal

How to Fix Path Traversal in Igniterealtime Openfire

CVE-2023-32315 is a Path Traversal flaw in Igniterealtime Openfire. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-32315 · OtherRead fix →
HIGH⚠ KEVUse After Free

How to Fix Qualcomm, Inc. Snapdragon (Bundle Sibling)

CVE-2023-33063 is a Use-After-Free flaw in Qualcomm, Inc. Snapdragon. Actively exploited per CISA KEV. Verified patched builds and fix steps

CVE-2023-33063 · GoRead fix →
HIGH⚠ KEV

How to Fix Use of Out-of-range Pointer Offset in Qualcomm, Inc. Snapdragon

CVE-2023-33106: Use of Out-of-range Pointer Offset in Qualcomm, Inc. Snapdragon. Patched builds and fix steps.

CVE-2023-33106 · GoRead fix →
HIGH⚠ KEV

How to Fix Qualcomm, Inc. Snapdragon (Bundle Sibling)

CVE-2023-33107 is a Integer Overflow flaw in Qualcomm, Inc. Snapdragon. Actively exploited per CISA KEV. Verified patched builds and fix ste

CVE-2023-33107 · GoRead fix →
HIGH⚠ KEVRCE

How to Fix Command Injection in TP-Link TL-WR940N

CVE-2023-33538 is a command injection flaw in TP-Link TL-WR940N. Verified patched version and mitigations from the official advisory.

CVE-2023-33538 · Tp-LinkRead fix →
HIGH⚠ KEVPath Traversal

How to Fix Path Traversal in EPMM

CVE-2023-35081 is a path traversal in EPMM. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2023-35081 · IvantiRead fix →
HIGH⚠ KEV

How to Fix Time-of-check Time-of-use (TOCTOU) Race Condition

CVE-2023-35311 time-of-check time-of-use (toctou) race condition in Microsoft 365 Apps For Enterprise. Runnable upgrade commands and verific

CVE-2023-35311 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in Windows 10 Version 1809

CVE-2023-36025 is a security vulnerability in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the fix

CVE-2023-36025 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Untrusted Pointer Dereference in Windows 10 Version 1809

CVE-2023-36033 is a untrusted pointer dereference in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify

CVE-2023-36033 · MicrosoftRead fix →
HIGH⚠ KEVBuffer Overflow

How to Fix Heap-based Buffer Overflow in Windows 10 Version 1809

CVE-2023-36036 is a heap-based buffer overflow in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the

CVE-2023-36036 · MicrosoftRead fix →
HIGH⚠ KEVBuffer Overflow

How to Fix Out-of-Bounds Read in Windows 11 version 22H3

CVE-2023-36424 - Out-of-Bounds Read in Windows 11 version 22H3. Runnable patch commands, mitigation snippets, and verification steps on this

CVE-2023-36424 · MicrosoftRead fix →
HIGH⚠ KEVUse After Free

How to Fix Use After Free in Windows 10 Version 1809

CVE-2023-36802 is a use after free in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the fix landed.

CVE-2023-36802 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Improper Link Resolution Before File Access ('Link Following')

CVE-2023-36874 improper link resolution before file access ('link following') in Windows 10 Version 1809. Runnable upgrade commands and veri

CVE-2023-36874 · MicrosoftRead fix →
HIGH⚠ KEVRCE

How to Fix Concurrent Execution using Shared Resource with Improper Synchronization ('Race

CVE-2023-36884 concurrent execution using shared resource with improper synchronization ('race in Windows 10 Version 1809. Runnable upgrade

CVE-2023-36884 · MicrosoftRead fix →
HIGH⚠ KEVRCE

How to Fix Uncontrolled Resource Consumption in Asp.Net Core 2.1

CVE-2023-38180 is a uncontrolled resource consumption in Asp.Net Core 2.1. Patched version, runnable upgrade commands, and how to verify the

CVE-2023-38180 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Access Control Bypass in ColdFusion

CVE-2023-38205 is an access control bypass in ColdFusion. Verified patched version, official vendor advisory, and how to confirm the fix lan

CVE-2023-38205 · AdobeRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in RARLAB WinRAR

CVE-2023-38831 is a security vulnerability flaw in RARLAB WinRAR. Verified patched version and mitigations from the official advisory.

CVE-2023-38831 · OtherRead fix →
HIGH⚠ KEVPath Traversal

How to Fix Path Traversal in BioTime

CVE-2023-38950 is a path traversal flaw in BioTime. Verified patched version and mitigations from the official advisory.

CVE-2023-38950 · OtherRead fix →
HIGH⚠ KEVRCE

How to Fix Command Injection in RT-AX55

CVE-2023-39780 is an OS command injection in RT-AX55. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2023-39780 · OtherRead fix →
HIGH⚠ KEVPath Traversal

How to Fix Path Traversal in N/a n/a

CVE-2023-41266 is a Path Traversal flaw in N/a n/a. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-41266 · OtherRead fix →
HIGH⚠ KEVRCE

How to Fix Remote Code Execution in HTTP/2

CVE-2023-44487 is a remote code execution flaw in HTTP/2. Verified patched version and mitigations from the official advisory.

CVE-2023-44487 · OtherRead fix →
HIGH⚠ KEVXXE

How to Fix XXE Injection in Proself Enterprise/Standard Edition, Proself Gateway Edition, Proself Mail Sanitize Edition

CVE-2023-45727 is a xxe injection flaw in Proself Enterprise/Standard Edition, Proself Gateway Edition, Proself Mail Sanitize Edition. Verif

CVE-2023-45727 · OtherRead fix →
HIGH⚠ KEVSQLi

How to Fix SQL Injection in BIG-IP

CVE-2023-46748 is a SQL injection in BIG-IP. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2023-46748 · F5Read fix →
HIGH⚠ KEV

How to Fix Critical Vulnerability in ICS

CVE-2023-46805 is a vulnerability in ICS. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2023-46805 · IvantiRead fix →
HIGH⚠ KEVRCE

How to Fix OS Command Injection in QNAP Systems Inc. VioStor NVR

CVE-2023-47565 is a OS Command Injection flaw in QNAP Systems Inc. VioStor NVR. Actively exploited per CISA KEV. Verified patched builds and

CVE-2023-47565 · QnapRead fix →
HIGH⚠ KEVBuffer Overflow

How to Fix Heap Buffer Overflow in Red Hat Red Hat Enterprise Linux 6

CVE-2023-4911 is a Heap Buffer Overflow flaw in Red Hat Red Hat Enterprise Linux 6. Actively exploited per CISA KEV. Verified patched builds

CVE-2023-4911 · LinuxRead fix →
HIGH⚠ KEVRCE

How to Fix Command Injection in AE1021, AE1021PE

CVE-2023-49897 is a command injection flaw in AE1021, AE1021PE. Verified patched version and mitigations from the official advisory.

CVE-2023-49897 · OtherRead fix →
HIGH⚠ KEVRCE

How to Fix Command Injection in Digiever DS-2105 Pro

CVE-2023-52163 is a command injection flaw in Digiever DS-2105 Pro. Verified patched version and mitigations from the official advisory.

CVE-2023-52163 · OtherRead fix →
HIGH⚠ KEV

How to Fix Memory Corruption in Cloud Software Group NetScaler ADC

CVE-2023-6549 is a Memory Corruption flaw in Cloud Software Group NetScaler ADC. Actively exploited per CISA KEV. Verified patched builds an

CVE-2023-6549 · OtherRead fix →
HIGH⚠ KEV

How to Fix Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injec in Spreadsheet::ParseExcel

CVE-2023-7101 is an improper neutralization of directives in dynamically evaluated code ('eval injec flaw in Spreadsheet::ParseExcel. Verifi

CVE-2023-7101 · OtherRead fix →
MEDIUM⚠ KEVRCE

How to Fix Command Injection in IOS

CVE-2023-20109 is an OS command injection in IOS. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2023-20109 · CiscoRead fix →
MEDIUM⚠ KEVRCE

How to Fix Command Injection in Cisco Small Business RV Series Router Firmware

CVE-2023-20118: an OS command injection in Cisco Small Business RV Series Router Fi. Patched version and vendor advisory inside.

CVE-2023-20118 · CiscoRead fix →
MEDIUM⚠ KEVAuth Bypass

How to Fix Authentication Bypass in Cisco Cisco Adaptive Security Appliance (ASA) Software

CVE-2023-20269: Authentication Bypass in Cisco Cisco Adaptive Security Appliance (ASA) Software. Patched builds and fix steps.

CVE-2023-20269 · CiscoRead fix →
MEDIUM⚠ KEVInfo Disclosure

How to Fix Information Disclosure in Android

CVE-2023-21237 is an information disclosure flaw in Android. Verified patched version and mitigations from the official advisory.

CVE-2023-21237 · AndroidRead fix →
MEDIUM⚠ KEV

How to Fix Samsung Mobile Samsung Mobile Devices (Bundle Sibling)

CVE-2023-21492: Insertion of Sensitive Information into Log File in Samsung Mobile Samsung Mobile Devices. Patched builds and fix steps.

CVE-2023-21492 · OtherRead fix →
MEDIUM⚠ KEV

How to Fix Incorrect Authorization in Windows 10 Version 1809

CVE-2023-24880 is a incorrect authorization in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the fi

CVE-2023-24880 · MicrosoftRead fix →
MEDIUM⚠ KEV

How to Fix Improper Input Validation in Windows 10 Version 1809

CVE-2023-36563 is a improper input validation in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the

CVE-2023-36563 · MicrosoftRead fix →
MEDIUM⚠ KEV

How to Fix Security Vulnerability in Windows 10 Version 1809

CVE-2023-36584 is a security vulnerability in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the fix

CVE-2023-36584 · MicrosoftRead fix →
MEDIUM⚠ KEV

How to Fix Improper Input Validation in Microsoft Office 2019

CVE-2023-36761 is a improper input validation in Microsoft Office 2019. Patched version, runnable upgrade commands, and how to verify the fi

CVE-2023-36761 · MicrosoftRead fix →
MEDIUM⚠ KEV

How to Fix PHP External Variable Modification in Juniper Networks Junos OS

CVE-2023-36844: PHP External Variable Modification in Juniper Networks Junos OS. Patched builds and fix steps.

CVE-2023-36844 · JuniperRead fix →
MEDIUM⚠ KEVAuth Bypass

How to Fix Juniper Networks Junos OS (Bundle Sibling)

CVE-2023-36846: Missing Authentication for Critical Function in Juniper Networks Junos OS. Patched builds and fix steps.

CVE-2023-36846 · JuniperRead fix →
MEDIUM⚠ KEVAuth Bypass

How to Fix Juniper Networks Junos OS (Bundle Sibling)

CVE-2023-36847: Missing Authentication for Critical Function in Juniper Networks Junos OS. Patched builds and fix steps.

CVE-2023-36847 · JuniperRead fix →
MEDIUM⚠ KEVAuth Bypass

How to Fix Juniper Networks Junos OS (Bundle Sibling)

CVE-2023-36851: Missing Authentication for Critical Function in Juniper Networks Junos OS. Patched builds and fix steps.

CVE-2023-36851 · JuniperRead fix →
MEDIUM⚠ KEVXSS

How to Fix Cross-Site Scripting in Zimbra Collaboration Suite (ZCS)

CVE-2023-37580 is a cross-site scripting flaw in Zimbra Collaboration Suite (ZCS). Verified patched version and mitigations from the officia

CVE-2023-37580 · OtherRead fix →
MEDIUM⚠ KEVSSRF

How to Fix Server-Side Request Forgery (SSRF) in Skype For Business Server 2015 Cu13

CVE-2023-41763 server-side request forgery (ssrf) in Skype For Business Server 2015 Cu13. Runnable upgrade commands and verification steps f

CVE-2023-41763 · MicrosoftRead fix →
MEDIUM⚠ KEVUse After Free

How to Fix Use-After-Free in Arm 5th Gen GPU Architecture Kernel Driver, Bifrost GPU Kernel Driver, Midgard GPU Kernel Driver, Valhall GPU Kernel Dr

CVE-2023-4211 is an use-after-free flaw in Arm 5th Gen GPU Architecture Kernel Driver, Bifrost GPU Kernel Driver, Midgard GPU Kernel Driver,

CVE-2023-4211 · OtherRead fix →
MEDIUM⚠ KEVXSS

How to Fix Cross-Site Scripting in Roundcube

CVE-2023-43770 is a cross-site scripting flaw in Roundcube. Verified patched version and mitigations from the official advisory.

CVE-2023-43770 · OtherRead fix →
MEDIUM⚠ KEVAuth Bypass

How to Fix Authentication Bypass by Spoofing in Tp-link TL-WR841N

CVE-2023-50224 is a Authentication Bypass by Spoofing flaw in Tp-link TL-WR841N. Actively exploited per CISA KEV. Verified patched builds an

CVE-2023-50224 · Tp-LinkRead fix →
MEDIUM⚠ KEVXSS

How to Fix Cross-Site Scripting in Roundcube Roundcubemail

CVE-2023-5631 is a Cross-Site Scripting flaw in Roundcube Roundcubemail. Actively exploited per CISA KEV. Verified patched builds and fix st

CVE-2023-5631 · OtherRead fix →
MEDIUM⚠ KEV

How to Fix Code Injection in Cloud Software Group NetScaler ADC

CVE-2023-6548 is a Code Injection flaw in Cloud Software Group NetScaler ADC. Actively exploited per CISA KEV. Verified patched builds and f

CVE-2023-6548 · OtherRead fix →
LOW⚠ KEVAuth Bypass

How to Fix Authentication Bypass in VMWARE VMware Tools

CVE-2023-20867 is a Authentication Bypass flaw in VMWARE VMware Tools. Actively exploited per CISA KEV. Verified patched builds and fix step

CVE-2023-20867 · VmwareRead fix →
LOW⚠ KEV

How to Fix Security Vulnerability in Mali Graphics Processing Unit (GPU)

CVE-2023-26083 is a security vulnerability flaw in Mali Graphics Processing Unit (GPU). Verified patched version and mitigations from the of

CVE-2023-26083 · OtherRead fix →
NOT VERIFIED⚠ KEV

How to Fix Security Vulnerability in Joomla! Project Joomla! CMS

CVE-2023-23752 is a Security Vulnerability flaw in Joomla! Project Joomla! CMS. Actively exploited per CISA KEV. Verified patched builds and

CVE-2023-23752 · JoomlaRead fix →
NOT VERIFIED⚠ KEVBuffer Overflow

How to Fix Out-of-Bounds Memory Access in Apple Safari

CVE-2023-28204 is a Out-of-Bounds Memory Access flaw in Apple Safari. Actively exploited per CISA KEV. Verified patched builds and fix steps

CVE-2023-28204 · AppleRead fix →
NOT VERIFIED⚠ KEV

How to Fix Security Vulnerability in Google Chrome

CVE-2023-3079 is a Security Vulnerability flaw in Google Chrome. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-3079 · GoogleRead fix →
NOT VERIFIED⚠ KEVUse After Free

How to Fix Apple Safari (Bundle Sibling)

CVE-2023-32373 is a Use-After-Free flaw in Apple Safari. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-32373 · AppleRead fix →
NOT VERIFIED⚠ KEVDoS

How to Fix Apple Safari (Bundle Sibling)

CVE-2023-32409 is a Denial of Service flaw in Apple Safari. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-32409 · AppleRead fix →
NOT VERIFIED⚠ KEVDoS

How to Fix Denial of Service in Apple iOS and iPadOS

CVE-2023-32434 is a Denial of Service flaw in Apple iOS and iPadOS. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-32434 · AppleRead fix →
NOT VERIFIED⚠ KEVDoS

How to Fix Denial of Service in Apple Safari

CVE-2023-32435 is a Denial of Service flaw in Apple Safari. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-32435 · AppleRead fix →
NOT VERIFIED⚠ KEVDoS

How to Fix Denial of Service in Apple Safari

CVE-2023-32439 is a Denial of Service flaw in Apple Safari. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-32439 · AppleRead fix →
NOT VERIFIED⚠ KEV

How to Fix Code Injection in Apache Software Foundation Apache RocketMQ

CVE-2023-33246: Code Injection in Apache Software Foundation Apache RocketMQ. Patched builds and fix steps.

CVE-2023-33246 · ApacheRead fix →
NOT VERIFIED⚠ KEV

How to Fix Security Vulnerability in Google Android

CVE-2023-35674 is a Security Vulnerability flaw in Google Android. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-35674 · GoogleRead fix →
NOT VERIFIED⚠ KEVDoS

How to Fix Denial of Service in Apple Safari

CVE-2023-37450 is a Denial of Service flaw in Apple Safari. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-37450 · AppleRead fix →
NOT VERIFIED⚠ KEV

How to Fix Security Vulnerability in Ivanti MobileIron Sentry

CVE-2023-38035 is a Security Vulnerability flaw in Ivanti MobileIron Sentry. Actively exploited per CISA KEV. Verified patched builds and fi

CVE-2023-38035 · IvantiRead fix →
NOT VERIFIED⚠ KEVDoS

How to Fix Denial of Service in Apple iOS and iPadOS

CVE-2023-38606 is a Denial of Service flaw in Apple iOS and iPadOS. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-38606 · AppleRead fix →
NOT VERIFIED⚠ KEVDoS

How to Fix Denial of Service in Apple iOS and iPadOS

CVE-2023-41061 is a Denial of Service flaw in Apple iOS and iPadOS. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-41061 · AppleRead fix →
NOT VERIFIED⚠ KEVDoS

How to Fix Buffer Overflow in Apple iOS and iPadOS

CVE-2023-41064 is a Buffer Overflow flaw in Apple iOS and iPadOS. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-41064 · AppleRead fix →
NOT VERIFIED⚠ KEV

How to Fix Security Vulnerability in Trend Micro, Inc. Trend Micro Apex One

CVE-2023-41179: Security Vulnerability in Trend Micro, Inc. Trend Micro Apex One. Patched builds and fix steps.

CVE-2023-41179 · Trend MicroRead fix →
NOT VERIFIED⚠ KEVDoS

How to Fix Use-After-Free in Apple iOS and iPadOS

CVE-2023-41974 is a Use-After-Free flaw in Apple iOS and iPadOS. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-41974 · AppleRead fix →
NOT VERIFIED⚠ KEVDoS

How to Fix Denial of Service in Apple iOS and iPadOS

CVE-2023-41990 is a Denial of Service flaw in Apple iOS and iPadOS. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-41990 · AppleRead fix →
NOT VERIFIED⚠ KEVDoS

How to Fix Denial of Service in Apple iOS and iPadOS

CVE-2023-41991 is a Denial of Service flaw in Apple iOS and iPadOS. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-41991 · AppleRead fix →
NOT VERIFIED⚠ KEVDoS

How to Fix Denial of Service in Apple iOS and iPadOS

CVE-2023-41992 is a Denial of Service flaw in Apple iOS and iPadOS. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-41992 · AppleRead fix →
NOT VERIFIED⚠ KEV

How to Fix Security Vulnerability in Apple macOS

CVE-2023-41993 is a Security Vulnerability flaw in Apple macOS. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-41993 · AppleRead fix →
NOT VERIFIED⚠ KEVDoS

How to Fix Denial of Service in Apple iOS and iPadOS

CVE-2023-42824 is a Denial of Service flaw in Apple iOS and iPadOS. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-42824 · AppleRead fix →
NOT VERIFIED⚠ KEVBuffer Overflow

How to Fix Out-of-Bounds Memory Access in Apple Safari

CVE-2023-42916 is a Out-of-Bounds Memory Access flaw in Apple Safari. Actively exploited per CISA KEV. Verified patched builds and fix steps

CVE-2023-42916 · AppleRead fix →
NOT VERIFIED⚠ KEVDoS

How to Fix Denial of Service in Apple Safari

CVE-2023-42917 is a Denial of Service flaw in Apple Safari. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-42917 · AppleRead fix →
NOT VERIFIED⚠ KEVUse After Free

How to Fix Use-After-Free in Apple Safari

CVE-2023-43000 is a Use-After-Free flaw in Apple Safari. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-43000 · AppleRead fix →
NOT VERIFIED⚠ KEVRCE

How to Fix OS Command Injection in Sonicwall SMA100

CVE-2023-44221 is a OS Command Injection flaw in Sonicwall SMA100. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-44221 · SonicwallRead fix →
NOT VERIFIED⚠ KEV

How to Fix Security Vulnerability in Google Chrome

CVE-2023-4762 is a Security Vulnerability flaw in Google Chrome. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-4762 · GoogleRead fix →
NOT VERIFIED⚠ KEVBuffer Overflow

How to Fix Buffer Overflow in Google Chrome

CVE-2023-4863 is a Buffer Overflow flaw in Google Chrome. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-4863 · GoogleRead fix →
NOT VERIFIED⚠ KEVBuffer Overflow

How to Fix Buffer Overflow in Google Chrome

CVE-2023-5217 is a Buffer Overflow flaw in Google Chrome. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-5217 · GoogleRead fix →
NOT VERIFIED⚠ KEV

How to Fix Security Vulnerability in Google Chrome

CVE-2023-6345 is a Security Vulnerability flaw in Google Chrome. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-6345 · GoogleRead fix →
NOT VERIFIED⚠ KEVBuffer Overflow

How to Fix Buffer Overflow in Google Chrome

CVE-2023-7024 is a Buffer Overflow flaw in Google Chrome. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2023-7024 · GoogleRead fix →
CRITICALSQLi

How to Fix SQL Injection in SAP BPC MS 10.0

SQL Injection in SAP BPC MS 10.0. Critical severity. Verified patched versions and remediation steps.

CVE-2023-0016 · SapRead fix →
CRITICALXSS

How to Fix Cross-Site Scripting in BusinessObjects Business Intelligence Platform (Central management console)

Cross-Site Scripting in BusinessObjects Business Intelligence Platform (Central management console) (Sap). Critical severity. Verified patch

CVE-2023-0018 · SapRead fix →
CRITICAL

How to Fix Improper Control of Generation of Code ('Code Injection' in BusinessObjects Business Intelligence platform (Analysis edition for OLAP)

Improper Control of Generation of Code ('Code Injection' in BusinessObjects Business Intelligence platform (Analysis edition for OLAP) (Sap)

CVE-2023-0022 · SapRead fix →
CRITICAL

How to Fix CWE-190 Integer Overflow or Wraparound in ThingWorx Edge C-SDK

CVE-2023-0754 is a vulnerability in PTC ThingWorx Edge C-SDK. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-0754 · OtherRead fix →
CRITICAL

How to Fix CWE-129 Improper Validation of Array Index in ThingWorx Edge C-SDK

CVE-2023-0755 is a vulnerability in PTC ThingWorx Edge C-SDK. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-0755 · OtherRead fix →
CRITICAL

How to Fix CWE-266 Incorrect Privilege Assignment in minikube

CVE-2023-1174 is a vulnerability in Kubernetes minikube. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-1174 · KubernetesRead fix →
CRITICAL

How to Fix Buffer Copy without Checking Size of Input in Cisco Secure Web Appliance

CVE-2023-20032 is a vulnerability in Cisco Secure Web Appliance. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-20032 · CiscoRead fix →
CRITICAL

How to Fix CWE-78 in Cisco Industrial Network Director

CWE-78 in Cisco Industrial Network Director. Critical severity. Verified patched versions and remediation steps.

CVE-2023-20036 · CiscoRead fix →
CRITICAL

How to Fix Improper Privilege Management in Cisco Firepower Management Center

Improper Privilege Management in Cisco Firepower Management Center. Critical severity. Verified patched versions and remediation steps.

CVE-2023-20048 · CiscoRead fix →
CRITICALBuffer Overflow

How to Fix Stack-based Buffer Overflow in Cisco IP Phones with Multiplatform Firmware

CVE-2023-20078 is a vulnerability in Cisco IP Phones with Multiplatform Firmware. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-20078 · CiscoRead fix →
CRITICALBuffer Overflow

How to Fix Stack-based Buffer Overflow in Cisco IP Phones with Multiplatform Firmware

CVE-2023-20079 is a vulnerability in Cisco IP Phones with Multiplatform Firmware. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-20079 · CiscoRead fix →
CRITICAL

How to Fix Use of Hard-coded Credentials in Cisco Emergency Responder

CVE-2023-20101 is a vulnerability in Cisco Emergency Responder. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-20101 · CiscoRead fix →
CRITICALAuth Bypass

How to Fix Missing Authentication in Cisco Small Business IP Phones

CVE-2023-20126 is a vulnerability in Cisco Small Business IP Phones. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-20126 · CiscoRead fix →
CRITICALAuth Bypass

How to Fix Improper Authentication in Cisco BroadWorks

Improper Authentication in Cisco BroadWorks. Critical severity. Verified patched versions and remediation steps.

CVE-2023-20238 · CiscoRead fix →
CRITICALAuth Bypass

How to Fix Missing Authorization in Cisco SD-WAN vManage

CVE-2023-20252 is a vulnerability in Cisco SD-WAN vManage. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-20252 · CiscoRead fix →
CRITICALPrivilege Escalation

How to Fix Privilege Escalation in Linux Kernel

Privilege Escalation in Linux Kernel. Critical severity. Verified patched versions and remediation steps.

CVE-2023-2163 · LinuxRead fix →
CRITICALRCE

How to Fix RCE in Assets Discovery Cloud

CVE-2023-22523 is a vulnerability in Atlassian Assets Discovery Cloud. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-22523 · AtlassianRead fix →
CRITICALAuth Bypass

How to Fix Authentication Bypass in My Cloud OS 5

Authentication Bypass in My Cloud OS 5 (Western Digital). Critical severity. Verified patched versions and remediation steps.

CVE-2023-22814 · OtherRead fix →
CRITICALAuth Bypass

How to Fix Improper Authentication in NetWeaver AS for Java

Improper Authentication in NetWeaver AS for Java (Sap). Critical severity. Verified patched versions and remediation steps.

CVE-2023-23857 · SapRead fix →
CRITICAL

How to Fix CWE-74 in Business Objects Business Intelligence Platform (CMC)

CWE-74 in Business Objects Business Intelligence Platform (CMC) (Sap). Critical severity. Verified patched versions and remediation steps.

CVE-2023-25616 · SapRead fix →
CRITICALAuth Bypass

How to Fix Missing Authentication for Critical Function in Diagnostics Agent (EventLogServiceCollector)

Missing Authentication for Critical Function in Diagnostics Agent (EventLogServiceCollector) (Sap). Critical severity. Verified patched vers

CVE-2023-27497 · SapRead fix →
CRITICALXXE

How to Fix Improper Restriction of XML External Entity Reference in Aspera Faspex

Improper Restriction of XML External Entity Reference in Aspera Faspex (Ibm). Critical severity. Verified patched versions and remediation s

CVE-2023-27874 · IbmRead fix →
CRITICALPath Traversal

How to Fix Path Traversal in GitLab

Path Traversal in GitLab. Critical severity. Verified patched versions and remediation steps.

CVE-2023-2825 · GitlabRead fix →
CRITICAL

How to Fix CWE-863 Incorrect Authorization in FANTSY

CVE-2023-28698 is a vulnerability in Wade Digital Design Co, Ltd. FANTSY. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-28698 · OtherRead fix →
CRITICAL

How to Fix CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in BusinessObjects Business Intelligence Platform (Promotion Management)

CVE-2023-28765: SAP BusinessObjects Business Intelligence Platform (Promotion Management) flaw. CVSS 9.8 Critical. Verified patch and mitiga

CVE-2023-28765 · SapRead fix →
CRITICAL

How to Fix CWE-94 Improper Control of Generation of Code in Zabbix

CVE-2023-29453 is a vulnerability in Zabbix Zabbix. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-29453 · OtherRead fix →
CRITICAL

How to Fix CWE-78: Improper Neutralization of Special Elements used in an OS Command in Gipsy

CVE-2023-30621 is a vulnerability in Curiosity-org Gipsy. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-30621 · IosRead fix →
CRITICALAuth Bypass

How to Fix CWE-287 Improper Authentication in Easy Digital Downloads

CVE-2023-30869 is a vulnerability in Easy Digital Downloads Easy Digital Downloads. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-30869 · OtherRead fix →
CRITICAL

How to Fix Execute unauthorized code or commands in FortiProxy

CVE-2023-33308 is a vulnerability in Fortinet FortiProxy. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-33308 · FortinetRead fix →
CRITICAL

How to Fix CWE-89 Improper Neutralization of Special Elements used in an SQL Command in Zekiweb

CVE-2023-3376 is a vulnerability in Digital Strategy Zekiweb. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-3376 · OtherRead fix →
CRITICALFile Upload

How to Fix Arbitrary File Upload in MailHunter Ultimate

Arbitrary File Upload in MailHunter Ultimate (Easyuse Digital Technology). Critical severity. Verified patched versions and remediation step

CVE-2023-34207 · OtherRead fix →
CRITICAL

How to Fix Execute unauthorized code or commands in FortiSIEM

CVE-2023-34992 is a vulnerability in Fortinet FortiSIEM. CVSS 9.7 Critical. Verified patch steps and mitigations.

CVE-2023-34992 · FortinetRead fix →
CRITICAL

How to Fix CWE-78 in Security Guardium

CWE-78 in Security Guardium (Ibm). Critical severity. Verified patched versions and remediation steps.

CVE-2023-35893 · IbmRead fix →
CRITICALRCE

How to Fix CWE-89 Improper Neutralization of Special Elements used in an SQL Command in E-Commerce Software

CVE-2023-3651 is a vulnerability in Digital Ant E-Commerce Software. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-3651 · OtherRead fix →
CRITICALAuth Bypass

How to Fix CWE-306: Missing Authentication for Critical Function in SAP PowerDesigner

CVE-2023-37483 is a vulnerability in SAP Se SAP PowerDesigner. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-37483 · SapRead fix →
CRITICALDeserialization

How to Fix Deserialization of Untrusted Data in ColdFusion

CVE-2023-38204 is a vulnerability in Adobe ColdFusion. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-38204 · AdobeRead fix →
CRITICALRCE

How to Fix Remote Code Execution in One

Remote Code Execution in One (Veeam). Critical severity. Verified patched versions and remediation steps.

CVE-2023-38547 · OtherRead fix →
CRITICAL

How to Fix A vulnerability in Veeam ONE allows an unprivileged user who has access to th... in One

CVE-2023-38548 is a vulnerability in Veeam One. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-38548 · OtherRead fix →
CRITICAL

How to Fix CWE-863: Incorrect Authorization in SAP CommonCryptoLib

CVE-2023-40309 is a vulnerability in SAP Se SAP CommonCryptoLib. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-40309 · SapRead fix →
CRITICAL

How to Fix CWE-89 Improper Neutralization of Special Elements used in an SQL Command in Smartrise Document Management System

CVE-2023-4034: Digita Information Technology Smartrise Document Management System flaw. CVSS 9.8 Critical. Verified patch and mitigation ste

CVE-2023-4034 · OtherRead fix →
CRITICALRCE

How to Fix Incorrect Permission Assignment for Critical Resource in SAP BusinessObjects Business Intelligence Platform (Promotion Management)

Incorrect Permission Assignment for Critical Resource in SAP BusinessObjects Business Intelligence Platform (Promotion Management) (Sap_Se).

CVE-2023-40622 · SapRead fix →
CRITICAL

How to Fix FortiSIEM (Bundle Sibling)

CVE-2023-40714 is a vulnerability in Fortinet FortiSIEM. CVSS 9.7 Critical. Verified patch steps and mitigations.

CVE-2023-40714 · FortinetRead fix →
CRITICAL

How to Fix An attacker sending specially crafted data packets to the Mobile Device Serve... in Wavelink

CVE-2023-41727 is a vulnerability in Ivanti Wavelink. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-41727 · IvantiRead fix →
CRITICALAuth Bypass

How to Fix Improper Authentication in Adobe Framemaker Publishing Server

CVE-2023-44324 is a vulnerability in Adobe Framemaker Publishing Server. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-44324 · AdobeRead fix →
CRITICAL

How to Fix ColdFusion (Bundle Sibling)

CVE-2023-44350 is a vulnerability in Adobe ColdFusion. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-44350 · AdobeRead fix →
CRITICAL

How to Fix ColdFusion (Bundle Sibling)

CVE-2023-44351 is a vulnerability in Adobe ColdFusion. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-44351 · AdobeRead fix →
CRITICAL

How to Fix ColdFusion (Bundle Sibling)

CVE-2023-44353 is a vulnerability in Adobe ColdFusion. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-44353 · AdobeRead fix →
CRITICAL

How to Fix Wavelink (Bundle Sibling)

CVE-2023-46216 is a vulnerability in Ivanti Wavelink. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-46216 · IvantiRead fix →
CRITICAL

How to Fix Wavelink (Bundle Sibling)

CVE-2023-46217 is a vulnerability in Ivanti Wavelink. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-46217 · IvantiRead fix →
CRITICAL

How to Fix An attacker sending specially crafted data packets to the Mobile Device Serve... in Avalanche

CVE-2023-46220 is a vulnerability in Ivanti Avalanche. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-46220 · IvantiRead fix →
CRITICAL

How to Fix Avalanche (Bundle Sibling)

CVE-2023-46221 is a vulnerability in Ivanti Avalanche. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-46221 · IvantiRead fix →
CRITICAL

How to Fix Avalanche (Bundle Sibling)

CVE-2023-46222 is a vulnerability in Ivanti Avalanche. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-46222 · IvantiRead fix →
CRITICAL

How to Fix Avalanche (Bundle Sibling)

CVE-2023-46223 is a vulnerability in Ivanti Avalanche. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-46223 · IvantiRead fix →
CRITICAL

How to Fix Avalanche (Bundle Sibling)

CVE-2023-46224 is a vulnerability in Ivanti Avalanche. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-46224 · IvantiRead fix →
CRITICAL

How to Fix Avalanche (Bundle Sibling)

CVE-2023-46225 is a vulnerability in Ivanti Avalanche. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-46225 · IvantiRead fix →
CRITICAL

How to Fix Avalanche (Bundle Sibling)

CVE-2023-46257 is a vulnerability in Ivanti Avalanche. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-46257 · IvantiRead fix →
CRITICAL

How to Fix Avalanche (Bundle Sibling)

CVE-2023-46258 is a vulnerability in Ivanti Avalanche. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-46258 · IvantiRead fix →
CRITICAL

How to Fix Avalanche (Bundle Sibling)

CVE-2023-46259 is a vulnerability in Ivanti Avalanche. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-46259 · IvantiRead fix →
CRITICAL

How to Fix Avalanche (Bundle Sibling)

CVE-2023-46261 is a vulnerability in Ivanti Avalanche. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-46261 · IvantiRead fix →
CRITICAL

How to Fix CWE-89 Improper Neutralization of Special Elements used in an SQL Command in Saphira Connect

CVE-2023-4661 is a vulnerability in Saphira Saphira Connect. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-4661 · SapRead fix →
CRITICAL

How to Fix CWE-250 Execution with Unnecessary Privileges in Saphira Connect

CVE-2023-4662 is a vulnerability in Saphira Saphira Connect. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-4662 · SapRead fix →
CRITICALFile Upload

How to Fix Arbitrary File Upload in ITSM

Arbitrary File Upload in ITSM (Ivanti). Critical severity. Verified patched versions and remediation steps.

CVE-2023-46808 · IvantiRead fix →
CRITICALXSS

How to Fix Cross-Site Scripting in Tivoli Application Dependency Discovery Manager

Cross-Site Scripting in Tivoli Application Dependency Discovery Manager (Ibm). Critical severity. Verified patched versions and remediation

CVE-2023-47143 · IbmRead fix →
CRITICALBuffer Overflow

How to Fix CWE-787: Out-of-bounds Write in netxduo

CVE-2023-48316 is a vulnerability in Azure-rtos netxduo. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-48316 · OtherRead fix →
CRITICAL

How to Fix Improper Privilege Management in Pixel Watch

Improper Privilege Management in Pixel Watch (Google). Critical severity. Verified patched versions and remediation steps.

CVE-2023-48418 · GoogleRead fix →
CRITICAL

How to Fix Improper Privilege Management in Google Nest Mini

Improper Privilege Management in Google Nest Mini. Critical severity. Verified patched versions and remediation steps.

CVE-2023-48419 · GoogleRead fix →
CRITICAL

How to Fix Security Vulnerability in Chromecast

Security Vulnerability in Chromecast (Google). Critical severity. Verified patched versions and remediation steps.

CVE-2023-48426 · GoogleRead fix →
CRITICAL

How to Fix CWE-22 Improper Limitation of a Pathname to a Restricted Directory in go-git

CVE-2023-49569 is a vulnerability in Go-git go-git. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-49569 · GoRead fix →
CRITICALDeserialization

How to Fix CWE-502 Deserialization of Untrusted Data in Transformation Extender Advanced

CVE-2023-49886 is a vulnerability in IBM Transformation Extender Advanced. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-49886 · IbmRead fix →
CRITICALFile Upload

How to Fix Arbitrary File Upload in WP MLM SOFTWARE PLUGIN

Arbitrary File Upload in WP MLM SOFTWARE PLUGIN (Ioss). Critical severity. Verified patched versions and remediation steps.

CVE-2023-51475 · IosRead fix →
CRITICAL

How to Fix CWE-269 Improper Privilege Management in WP MLM Unilevel

CVE-2023-51476 is a vulnerability in Ioss WP MLM Unilevel. CVSS 9.8 Critical. Verified patch steps and mitigations.

CVE-2023-51476 · IosRead fix →
CRITICALAuth Bypass

How to Fix Improper Authentication in Syrus4 IoT Telematics Gateway

Improper Authentication in Syrus4 IoT Telematics Gateway (Digital Communications Technologies). Critical severity. Verified patched versions

CVE-2023-6248 · OtherRead fix →
CRITICAL

How to Fix Missing Encryption of Sensitive Data in Wifi Pro

Missing Encryption of Sensitive Data in Wifi Pro (Google). Critical severity. Verified patched versions and remediation steps.

CVE-2023-6339 · GoogleRead fix →