CVE-2023-27538
- EPSS 0.01%
- Published 30.03.2023 20:15:07
- Last modified 09.06.2025 15:15:29
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previous...
CVE-2023-28486
- EPSS 0.1%
- Published 16.03.2023 01:15:47
- Last modified 21.11.2024 07:55:12
Sudo before 1.9.13 does not escape control characters in log messages.
CVE-2023-28487
- EPSS 0.1%
- Published 16.03.2023 01:15:47
- Last modified 21.11.2024 07:55:12
Sudo before 1.9.13 does not escape control characters in sudoreplay output.
CVE-2022-23240
- EPSS 0.06%
- Published 28.02.2023 23:15:11
- Last modified 18.03.2025 15:15:40
Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors.
CVE-2022-23239
- EPSS 0.06%
- Published 28.02.2023 23:15:10
- Last modified 21.11.2024 06:48:14
Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows administrative users to perform a Stored Cross-Site Scripting (XSS) attack.
CVE-2023-23914
- EPSS 0.18%
- Published 23.02.2023 20:15:13
- Last modified 12.03.2025 19:15:35
A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan...
CVE-2023-23915
- EPSS 0.05%
- Published 23.02.2023 20:15:13
- Last modified 21.11.2024 07:47:05
A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTP...
CVE-2023-0482
- EPSS 0.04%
- Published 17.02.2023 22:15:11
- Last modified 18.03.2025 16:15:15
In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.
CVE-2023-24329
- EPSS 1.22%
- Published 17.02.2023 15:15:12
- Last modified 18.03.2025 17:15:41
An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
CVE-2023-0361
- EPSS 1.2%
- Published 15.02.2023 18:15:11
- Last modified 19.03.2025 18:15:18
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a s...