ABCDEFGHIJKLMNOPQRSTUVWX
1
CVE IDVendorSoftwareCVSSv3CISA Date AddedMemory CorruptionRoot CauseRoot Cause CategoryExploited As 0-DaySoftware TypeNotesRerences
2
CVE-2023-22527AtlassianConfluence Data Center and Server1001/24/2024FALSEOGNL Injection via Insecure Exposed FunctionInsecure Exposed FunctionFALSEEnterprise Softwarehttps://blog.projectdiscovery.io/atlassian-confluence-ssti-remote-code-execution/
4
CVE-2023-34048VMwarevCenter Server9.801/22/2024TRUEMemory CorruptionMemory CorruptionTRUEApplianceNo POC, evidence of 2021https://www.mandiant.com/resources/blog/chinese-vmware-exploitation-since-2021
5
CVE-2023-35082IvantiEndpoint Manager Mobile (EPMM) and MobileIron Core1001/18/2024FALSEAuthorization Bypass via Routing / Path AbuseRouting / Path AbuseFALSEAppliancehttps://www.rapid7.com/blog/post/2023/08/02/cve-2023-35082-mobileiron-core-unauthenticated-api-access-vulnerability/
11
CVE-2024-21887IvantiConnect Secure and Policy Secure9.101/10/2024FALSEAuthorization Bypass via Routing / Path AbuseRouting / Path AbuseTRUEAppliancehttps://attackerkb.com/topics/AdUh6by52K/cve-2023-46805/rapid7-analysis
12
CVE-2023-29357MicrosoftSharePoint Server9.801/10/2024FALSEAuthorization Bypass via Insecure Exposed FunctionInsecure Exposed FunctionFALSEEnterprise Softwarealg none
https://testbnull.medium.com/p2o-vancouver-2023-v%C3%A0i-d%C3%B2ng-v%E1%BB%81-sharepoint-pre-auth-rce-chain-cve-2023-29357-cve-2023-24955-ed
13
CVE-2023-27524ApacheSuperset9.801/08/2024FALSEAuthorization Bypass via Default SecretDefault SecretFALSEEnterprise Middlewarehttps://www.horizon3.ai/cve-2023-27524-insecure-default-configuration-in-apache-superset-leads-to-remote-code-execution/
15
CVE-2023-38203AdobeColdFusion9.801/08/2024FALSEDeserialization via Insecure Exposed FunctionInsecure Exposed FunctionFALSEEnterprise Middlewarehttps://blog.projectdiscovery.io/adobe-coldfusion-rce/
18
CVE-2023-29300AdobeColdFusion9.801/08/2024FALSEDeserialization via Insecure Exposed FunctionInsecure Exposed FunctionFALSEEnterprise Middlewarehttps://www.rapid7.com/blog/post/2023/07/17/etr-active-exploitation-of-multiple-adobe-coldfusion-vulnerabilities/
23
CVE-2023-6448UnitronicsVision PLC and HMI9.812/11/2023FALSEAuthorization Bypass via Default SecretDefault SecretTRUEPLCNo POC - 1111https://www.cisa.gov/news-events/alerts/2023/11/28/exploitation-unitronics-plcs-used-water-and-wastewater-systems
24
CVE-2023-41265QlikSense9.912/07/2023FALSEAuthorization Bypass via Request SmugglingRequest SmugglingFALSEEnterprise Softwarehttps://www.praetorian.com/blog/qlik-sense-technical-exploit/
32
CVE-2023-6345GoogleSkia9.611/30/2023TRUEMemory CorruptionMemory CorruptionTRUEEmbedded Libraryhttps://chromereleases.googleblog.com/2023/11/stable-channel-update-for-desktop_28.html
36
CVE-2023-1671SophosWeb Appliance9.811/16/2023FALSECommand Injection via Insecure Exposed FunctionInsecure Exposed FunctionFALSEAppliancehttps://vulncheck.com/blog/cve-2023-1671-analysis
41
CVE-2023-36845JuniperJunos OS9.811/13/2023FALSEFile Write via Insecure Exposed FunctionInsecure Exposed FunctionFALSEAppliancePHP Magichttps://vulncheck.com/blog/juniper-cve-2023-36845
43
CVE-2023-47246SysAidSysAid Server9.811/13/2023FALSEFile Write via Insecure Exposed FunctionInsecure Exposed FunctionTRUEEnterprise Softwarehttps://www.huntress.com/blog/critical-vulnerability-sysaid-cve-2023-47246
48
CVE-2023-22518AtlassianConfluence Data Center and Server1011/07/2023FALSEAuthorization Bypass via Insecure Exposed FunctionInsecure Exposed FunctionFALSEEnterprise SoftwareSetup Abusehttps://github.com/ForceFledgling/CVE-2023-22518
49
CVE-2023-46604ApacheActiveMQ9.811/02/2023FALSEDeserialization via Insecure Exposed FunctionInsecure Exposed FunctionFALSEEnterprise Middlewarehttps://exp10it.io/2023/10/apache-activemq-%E7%89%88%E6%9C%AC-5.18.3-rce-%E5%88%86%E6%9E%90/
51
CVE-2023-46747F5BIG-IP Configuration Utility9.810/31/2023FALSEAuthorization Bypass via Request SmugglingRequest SmugglingFALSEApplianceOut-of-date dependencyhttps://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/?ref=blog.projectdiscovery.io
56
CVE-2023-20198CiscoIOS XE Web UI1010/16/2023FALSEAuthorization Bypass via Routing / Path AbuseRouting / Path AbuseTRUEAppliancePath Normalizationhttps://www.horizon3.ai/cisco-ios-xe-cve-2023-20198-deep-dive-and-poc/
63
CVE-2023-22515AtlassianConfluence Data Center and Server1010/05/2023FALSEAuthorization Bypass via Insecure Exposed FunctionInsecure Exposed FunctionTRUEEnterprise SoftwareSetup Abusehttps://attackerkb.com/topics/Q5f0ItSzw5/cve-2023-22515/rapid7-analysis
65
CVE-2023-42793JetBrainsTeamCity9.810/04/2023FALSEAuthorization Bypass via Routing / Path AbuseRouting / Path AbuseFALSEEnterprise Softwarehttps://www.sonarsource.com/blog/teamcity-vulnerability/
70
CVE-2023-41993AppleMultiple Products9.809/25/2023TRUEMemory CorruptionMemory CorruptionTRUECell Phonehttps://github.com/po6ix/POC-for-CVE-2023-41993
84
CVE-2023-20269Cisco
Adaptive Security Appliance and Firepower Threat Defense
9.109/13/2023FALSECredential Brute Force via Routing / Path AbuseRouting / Path AbuseTRUEApplianceNo POChttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC
91
CVE-2023-33246ApacheRocketMQ9.809/06/2023FALSECommand Injection via Insecure Exposed FunctionInsecure Exposed FunctionEnterprise Middlewarehttps://attackerkb.com/topics/YBI7e7fY0a/cve-2023-33246
94
CVE-2023-38035IvantiSentry9.808/22/2023FALSEAuthorization Bypass via Insecure Exposed FunctionInsecure Exposed FunctionAppliancehttps://www.horizon3.ai/ivanti-sentry-authentication-bypass-cve-2023-38035-deep-dive/
96
CVE-2023-26359AdobeColdFusion9.808/21/2023FALSEDeserialization via Insecure Exposed FunctionInsecure Exposed FunctionEnterprise Middlewarehttps://attackerkb.com/topics/F36ClHTTIQ/cve-2023-26360/rapid7-analysis
97
CVE-2023-24489CitrixContent Collaboration9.808/16/2023FALSEAuthorization Bypass via Weak EncryptionWeak EncryptionAppliancehttps://blog.assetnote.io/2023/07/04/citrix-sharefile-rce/
103
CVE-2023-35078IvantiEndpoint Manager Mobile (EPMM)1007/25/2023FALSEAuthorization Bypass via Routing / Path AbuseRouting / Path AbuseAppliancehttps://attackerkb.com/topics/8vqyuSfHRq/cve-2023-35078
106
CVE-2023-3519CitrixNetScaler ADC and NetScaler Gateway9.807/19/2023TRUEMemory CorruptionMemory CorruptionAppliancehttps://bishopfox.com/blog/analysis-exploitation-cve-2023-3519
128
CVE-2023-27992ZyxelMultiple Network-Attached Storage (NAS) Devices9.806/23/2023FALSECommand Injection via Insecure Exposed FunctionInsecure Exposed FunctionAppliancehttps://securityintelligence.com/x-force/ibm-identifies-zero-day-vulnerability-zyxel-nas-devices/
130
CVE-2023-20887VMwareAria Operations for Networks9.806/22/2023FALSEAuthorization Bypass via Routing / Path AbuseRouting / Path AbuseAppliancehttps://github.com/sinsinology/CVE-2023-20887
135
CVE-2023-27997FortinetFortiOS and FortiProxy SSL-VPN9.806/13/2023TRUEMemory CorruptionMemory CorruptionTRUEAppliance
https://blog.lexfo.fr/xortigate-cve-2023-27997.html, https://www.fortinet.com/blog/psirt-blogs/analysis-of-cve-2023-27997-and-clarifications-on-volt-typhoon-campaign
137
CVE-2023-33010ZyxelMultiple Firewalls9.806/05/2023TRUEMemory CorruptionMemory CorruptionFALSEAppliance
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewalls
138
CVE-2023-33009ZyxelMultiple Firewalls9.806/05/2023TRUEMemory CorruptionMemory CorruptionFALSEAppliance
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewalls
139
CVE-2023-34362ProgressMOVEit Transfer9.806/02/2023FALSESQL Injection via Routing / Path AbuseRouting / Path AbuseEnterprise Softwarehttps://www.horizon3.ai/moveit-transfer-cve-2023-34362-deep-dive-and-indicators-of-compromise/
140
CVE-2023-28771ZyxelMultiple Firewalls9.805/31/2023FALSECommand Injection via Insecure Exposed FunctionInsecure Exposed FunctionAppliancehttps://attackerkb.com/topics/N3i8dxpFKS/cve-2023-28771/rapid7-analysis
141
CVE-2023-2868Barracuda NetworksEmail Security Gateway (ESG) Appliance9.805/26/2023FALSECommand Injection via Insecure Exposed FunctionInsecure Exposed FunctionAppliancehttps://attackerkb.com/topics/2Z0CWopGPX/cve-2023-2868/rapid7-analysis
154
CVE-2023-25717Ruckus WirelessMultiple Products9.805/12/2023FALSECommand Injection via Insecure Exposed FunctionInsecure Exposed FunctionAppliancehttps://cybir.com/2023/cve/proof-of-concept-ruckus-wireless-admin-10-4-unauthenticated-remote-code-execution-csrf-ssrf/
159
CVE-2023-2136GoogleChrome9.604/21/2023TRUEMemory CorruptionMemory CorruptionTRUEBrowserhttps://bugs.chromium.org/p/chromium/issues/detail?id=1432603
161
CVE-2023-27350PaperCutMF/NG9.804/21/2023FALSEAuthentication Bypass via Insecure Exposed FunctionInsecure Exposed FunctionEnterprise SoftwareSetup Abusehttps://www.horizon3.ai/papercut-cve-2023-27350-deep-dive-and-indicators-of-compromise/
166
CVE-2023-29492Novi SurveyNovi Survey9.804/13/2023FALSEDeserialization via Insecure Exposed FunctionInsecure Exposed FunctionEnterprise SoftwareNo POChttps://nvd.nist.gov/vuln/detail/CVE-2023-29492
187
CVE-2023-23397MicrosoftOffice9.803/14/2023FALSEAuthorization Bypass via Insecure Exposed FunctionInsecure Exposed FunctionEnterprise SoftwareUNC Pathhttps://unit42.paloaltonetworks.com/threat-brief-cve-2023-23397/
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270