KEV 2023
163 CISA Known Exploited Vulnerabilities from 2023
Critical 48
February 2025
January 2025
November 2024
September 2024
July 2024
May 2024
GitLab CE/EE — Password Reset to Unverified Email Enables Silent Account Takeover Without Victim Interaction; CVSS 10.0; Affects GitLab 1.0 to 16.7.1
CVSS 10NextGen Healthcare Mirth Connect — Unauthenticated Java Deserialization Achieves RCE on Healthcare Integration Engines; Follow-On to CVE-2023-37679; Ransomware Targeting Healthcare
CVSS 9.8March 2024
January 2024
Atlassian Confluence — Unauthenticated OGNL Template Injection Achieves Pre-Auth RCE; Affects All Confluence 8.x Before 8.5.4; Mass Exploitation Within 24 Hours; Ransomware
CVSS 9.8VMware vCenter Server DCERPC — Zero-Day OOB Write Enables Pre-Auth RCE; UNC3886 (China-Nexus) Exploited Before Patch; Silently Fixed October 2023
CVSS 9.8Ivanti EPMM / MobileIron Core — Unauthenticated API Access Affecting End-of-Life and Current Versions
CVSS 9.8Microsoft SharePoint Server — Spoofed JWT Token Bypasses Auth to Grant Admin Privileges; Chained with CVE-2023-24955 RCE for Full Exploit; STAR Labs Pwn2Own 2023
CVSS 9.8Adobe ColdFusion 2018/2021/2023 — Pre-Auth Java Deserialization RCE via APSB23-40; Patch Analysis Triggered Bypass Discovery (CVE-2023-38203); KEV January 2024
CVSS 9.8Adobe ColdFusion 2018/2021/2023 — Pre-Auth Java Deserialization RCE via APSB23-41; Exploited After Premature PoC Disclosure; Ransomware Targeting; KEV January 2024
CVSS 9.8December 2023
Unitronics Vision Series PLC/HMI — Default Password '1111' on PCOM Protocol Enables Remote ICS Command Execution; Iranian IRGC-Linked Attack on Pennsylvania Water Utility
CVSS 9.8Qlik Sense Enterprise for Windows — Low-Privilege HTTP Request Tunneling Reaches Backend Services; Cactus Ransomware Exploitation; Predecessor to CVE-2023-48365 Bypass
CVSS 9.6November 2023
ownCloud graphapi — Unauthenticated phpinfo() Exposure Leaks Admin Credentials and Database Passwords in Containerized Deployments; Rapid Mass Exploitation
CVSS 10Apache ActiveMQ — OpenWire ClassInfo Deserialization Allows Unauthenticated Remote Code Execution via Port 61616
CVSS 10Sophos Web Appliance — Pre-Auth Command Injection in warn-proceed Handler Enables RCE; EOL Product July 2023; KEV Added November 2023
CVSS 9.8Juniper Junos OS J-Web — PHPRC Environment Variable Injection Enables Pre-Auth RCE on EX Switches and SRX Firewalls; Chained with CVE-2023-36844; August 2023 Out-of-Cycle Patch
CVSS 9.8SysAid ITSM Server — Unauthenticated Path Traversal Enables JSP Web Shell Upload and RCE; Lace Tempest / Cl0p Ransomware Exploitation; Fixed in 23.3.36
CVSS 9.8Atlassian Confluence — Unauthenticated Data Destruction via Restore Endpoint Resets Instance; Cerber Ransomware Exploitation; Ransomware Encryption of Wiped Databases
CVSS 9.8Google Chrome / Chromium Skia Graphics Engine — Zero-Day Integer Overflow Enables Sandbox Escape; Chrome 119.0.6045.199 Emergency Patch; November 2023
CVSS 9.6October 2023
Cisco IOS XE Web UI — Zero-Day Creates Local Level-15 Admin Account Unauthenticated; 50,000+ Devices Compromised; 'BadCandy' Implant; 4-Day Emergency Deadline
CVSS 10Progress WS_FTP Server Ad Hoc Transfer — CVSS 10.0 Pre-Auth .NET Deserialization Achieves RCE as SYSTEM; Rapid7 PoC; Ransomware Exploitation; September 2023
CVSS 10F5 BIG-IP TMUI — Unauthenticated Request Smuggling Bypasses Auth to Enable RCE When Chained with CVE-2023-46748; Praetorian Discovery; Ransomware Exploitation
CVSS 9.8Atlassian Confluence — Zero-Day Unauthenticated Admin Account Creation via Setup Endpoint; Storm-0062 (China-Nexus) Exploited as Zero-Day; 8-Day Emergency Deadline
CVSS 9.8JetBrains TeamCity On-Premises — Unauthenticated Auth Bypass Creates Admin Token for RCE; APT29 and North Korean Actors Exploit CI/CD Supply Chain Access; Fixed 2023.05.4
CVSS 9.8Citrix NetScaler 'CitrixBleed' — Session Token Memory Leak Enables Unauthenticated Session Hijacking on Gateway and AAA Endpoints
CVSS 9.4September 2023
August 2023
Ivanti Sentry — Pre-Auth RCE via Unauthenticated Hessian RPC on MICS Admin Portal
CVSS 9.8Adobe ColdFusion 2018/2021 — Pre-Auth Java Deserialization RCE via APSB23-25; First of Three ColdFusion Deserialization CVEs in 2023; KEV August 2023
CVSS 9.8Citrix ShareFile Storage Zones Controller — AES-ECB Cryptographic Flaw Enables Unauthenticated Admin Access; Assetnote Discovery; Active Exploitation August 2023
CVSS 9.8July 2023
Ivanti EPMM — Unauthenticated Remote API Access via Missing Authentication Control
CVSS 9.8Citrix NetScaler ADC/Gateway — Zero-Day Pre-Auth Code Injection Installs Web Shells; 2,000+ Compromised Appliances; Mass Exploitation by Multiple Threat Actors; Ransomware
CVSS 9.8June 2023
Zyxel NAS326/NAS540/NAS542 — Pre-Auth OS Command Injection via Crafted HTTP Request; 4-Day KEV Turnaround; Fixed June 2023
CVSS 9.8VMware Aria Operations for Networks (vRealize Network Insight) — Unauthenticated Command Injection via Thrift RPC; Rapid Mass Exploitation After PoC Publication; June 2023
CVSS 9.8Fortinet FortiOS/FortiProxy SSL-VPN — 'XORtigate' Pre-Auth Heap Overflow Enables RCE on Fortinet VPN Gateways; Lexfo Discovery; Ransomware and Nation-State Exploitation
CVSS 9.8Zyxel ATP/USG FLEX/VPN Firewalls — Pre-Auth Buffer Overflow in Notification Function Enables RCE or DoS; Paired with CVE-2023-33010; Rapid KEV Addition May 2023
CVSS 9.8Zyxel ATP/USG FLEX/VPN Firewalls — Pre-Auth Buffer Overflow in ID Processing Function; Companion to CVE-2023-33009; Same Firmware Advisory; KEV June 2023
CVSS 9.8Progress MOVEit Transfer — Unauthenticated SQL Injection Enables Data Exfiltration and Webshell Deployment; Cl0p Mass Exploitation Campaign
CVSS 9.8May 2023
Zyxel ATP/USG FLEX/VPN Firewalls — Pre-Auth Command Injection via Improper IKE Error Message Handling; Mirai Botnet and Nation-State Exploitation; Patched April 2023
CVSS 9.8Ruckus ZoneDirector/SmartZone/Solo APs — Web Services RCE Enables Unauthenticated Remote Code Execution; AndorianBot Exploitation; Fixed February 2023
CVSS 9.8Barracuda ESG — Zero-Day TAR Filename OS Command Injection; UNC4841 (China-Nexus) Operated Undetected 8+ Months; Barracuda Recommended Full Appliance Replacement
CVSS 9.4April 2023
PaperCut MF/NG — Unauthenticated Access to SetupCompleted Handler Enables RCE as SYSTEM; Clop and LockBit Ransomware Mass Exploitation; Same-Day KEV April 2023
CVSS 9.8Novi Survey Web Application — Pre-Auth .NET Deserialization Enables RCE in Service Account Context; Rapid KEV Addition April 2023
CVSS 9.8Google Chrome Skia 2D Graphics — Zero-Day Integer Overflow Enables Renderer-to-OS Sandbox Escape; Chrome 112 Emergency Patch; April 2023
CVSS 9.6March 2023
High 88
April 2026
Microsoft Exchange Server — Authenticated RCE via PowerShell SOAP Deserialization
CVSS 8.8Windows CLFS Driver — Kernel Pool Corruption via BLF File Parsing Leading to Privilege Escalation
CVSS 7.8PaperCut NG/MF — Pre-Auth Authentication Bypass via SecurityRequestFilter Enabling Information Disclosure
CVSS 7.5March 2026
Apple WebKit — Use-After-Free in Maliciously Crafted Web Content Leads to Code Execution; Fixed iOS 16.6 (July 2023); NVD Registration Delayed 2 Years; Exploited in Coruna Exploit Kit Targeting Legacy iPhones
CVSS 8.8Apple iOS/iPadOS — Local Use-After-Free in Kernel Enables App-to-Kernel Privilege Escalation; Patched in iOS 17; KEV Added March 2026
CVSS 7.8December 2025
July 2025
June 2025
TP-Link TL-WR Series — Authenticated Command Injection via WlanNetworkRpm; Likely EoL Devices
CVSS 8.8ASUS RT-AX55 — Authenticated OS Command Injection via Router Management Interface
CVSS 8.8Linux Kernel OverlayFS — FUSE setuid File Copy Bypasses nosuid; Local Root Privilege Escalation; KEV Added June 2025 Reflecting Ongoing Exploitation
CVSS 7.8May 2025
ZKTeco BioTime — Unauthenticated Path Traversal in iclock API Enabling Arbitrary File Read
CVSS 7.5SonicWall SMA100 SSL VPN — Admin-Auth Command Injection Executes as 'nobody'; Chained with CVE-2021-20035 in Active 2025 Exploitation Campaign; KEV May 2025
CVSS 7.2December 2024
March 2024
February 2024
Chromium V8 — Type Confusion in JavaScript Engine Enabling Remote Code Execution via Crafted Web Page
CVSS 8.8Windows Streaming Service — No-Auth Local Privilege Escalation via Untrusted Pointer Dereference; Used by Lazarus Group
CVSS 8.4January 2024
Apache Superset — Well-Known Default SECRET_KEY Allows Session Cookie Forgery and Admin Takeover; ~3,000 Exposed Instances
CVSS 8.9Google Chrome WebRTC — Zero-Day Heap Buffer Overflow Enables RCE via Crafted HTML; Chrome 120 Emergency Patch; Eighth Chrome Zero-Day of 2023
CVSS 8.8Citrix NetScaler ADC/Gateway — Pre-Auth Buffer Overflow Causes DoS When Configured as Gateway or AAA Server; Companion to CVE-2023-6548; January 2024 Emergency KEV
CVSS 8.2Ivanti Connect Secure/Policy Secure — Zero-Day Auth Bypass Chains with CVE-2024-21887 for Pre-Auth RCE; UNC5221 (China-Nexus) Mass Exploitation; CISA Emergency Directive ED-24-01
CVSS 8.2Apple iOS/macOS — Font Parser Code Execution via Undocumented CPU Feature, Used in Operation Triangulation
CVSS 7.8Spreadsheet::ParseExcel Perl Library — Eval Injection via Malicious Number Format Strings in XLS Files; UNC4841 (China-Nexus) Exploited via Barracuda ESG; KEV January 2024
CVSS 7.8December 2023
FXC AE1021/AE1021PE Wall-Outlet WiFi APs — Authenticated Command Injection via Management Interface; InfectedSlurs Mirai Botnet Zero-Day; JPCERT/CC Disclosure
CVSS 8.8Apple WebKit — Memory Corruption Enables RCE via Malicious Web Content; Zero-Day Chained with CVE-2023-42916 for Full Exploit; iOS 17.1.2 / macOS Sonoma 14.1.2
CVSS 8.8Qualcomm GPU Driver — Out-of-Range Pointer Offset in GPU AUX Command IOCTL Enables Kernel Privilege Escalation on Android; Limited Targeted Exploitation Acknowledged
CVSS 8.4Qualcomm GPU Driver — Integer Overflow During Shared Virtual Memory IOCTL Assignment Enables Kernel Privilege Escalation on Android; Limited Targeted Exploitation Acknowledged
CVSS 8.4Qlik Sense Enterprise — Unauthenticated Path Traversal Enabling Anonymous Session Creation, Exploited by Cactus Ransomware
CVSS 8.2QNAP VioStor NVR — Adjacent-Network Command Injection via Low-Privilege Auth; InfectedSlurs Mirai Botnet Exploitation; Fixed in QVR 5.x Firmware
CVSS 8Qualcomm DSP Services — Use-After-Free During HLOS-to-DSP Remote Call Enables Kernel Privilege Escalation on Android; Limited Targeted Exploitation Acknowledged
CVSS 7.8November 2023
Windows SmartScreen — Zero-Day .url Shortcut Bypass Silently Skips SmartScreen Prompts; Phemedrone Stealer Delivery; November 2023 Patch Tuesday
CVSS 8.8glibc ld.so — 'Looney Tunables' GLIBC_TUNABLES Heap Buffer Overflow for Local Root
CVSS 7.8Windows DWM Core Library — Zero-Day LPE via Uninitialized Memory in dwm.exe Escalates to SYSTEM; Exploited Alongside CVE-2023-36025; November 2023 Patch Tuesday
CVSS 7.8Windows Cloud Files Mini Filter Driver — Heap Buffer Overflow for SYSTEM Privilege Escalation
CVSS 7.8IETF Service Location Protocol (SLP) — Up to 2,200x UDP Reflection Amplification; Affects Enterprise Printers, ESXi, and Hundreds of Other Products
CVSS 7.5October 2023
F5 BIG-IP — Authenticated SQL Injection Chained with CVE-2023-46747 for Unauthenticated RCE
CVSS 8.8Chromium libvpx — VP8 Encoding Heap Overflow Exploited by Commercial Spyware Operators
CVSS 8.8Adobe Acrobat and Reader — Use-After-Free in PDF Parser → Code Execution; APSB23-01 January 2023 Patch; KEV Added October 2023
CVSS 7.8Apple iOS/iPadOS — XNU Kernel Local Privilege Escalation Exploited in the Wild
CVSS 7.8HTTP/2 Protocol — Protocol-Level Denial of Service
CVSS 7.5Cisco IOS XE — Web UI Command Injection Chained with CVE-2023-20198 to Deploy Persistent Implant
CVSS 7.2Windows CNG Key Isolation Service — Sensitive Data Exposure Enabling Limited SYSTEM Privilege Escalation; High Complexity; KEV October 2023
CVSS 7September 2023
Apple WebKit — Zero-Click iMessage Code Execution via PassKit Attachment in BLASTPASS Pegasus Chain
CVSS 8.8MinIO — Authenticated Bucket Name Bypass via PostPolicyBucket; Chained with CVE-2023-28432 Credential Leak for Unauthenticated Admin Object Write
CVSS 8.8libwebp — Critical WebP Image Heap Overflow Affecting Chrome, Firefox, Safari, Android, and Electron Apps
CVSS 8.8Apple iOS/iPadOS/macOS/watchOS — Kernel LPE in BLASTPASS Chain, Attributed to NSO Group Pegasus
CVSS 7.8Adobe Acrobat/Reader — Out-of-Bounds Write in Document Parsing Enabling Code Execution via Malicious PDF
CVSS 7.8Android Framework — Local Privilege Escalation Zero-Day in September 2023 Security Bulletin
CVSS 7.8Microsoft Streaming Service Proxy — Use-After-Free Kernel Zero-Day Exploited for SYSTEM Privilege Escalation
CVSS 7.8Apple Wallet — Validation Flaw Used as Second Stage in BLASTPASS Zero-Click Pegasus Chain
CVSS 7.8Apple ImageIO — Buffer Overflow Triggered by PassKit Image Attachment; BLASTPASS Zero-Click Entry Point
CVSS 7.8Trend Micro Apex One — Admin-Accessible Third-Party AV Uninstaller Executes Arbitrary Attacker-Specified Binary on Managed Endpoints; Zero-Day KEV Addition 48 Hours After Advisory
CVSS 7.2August 2023
Openfire XMPP Server — Unauthenticated Path Traversal to Admin Console; Exploited to Deploy Web Shells
CVSS 8.6WinRAR — ZIP Archive Spoofing Triggers Executable When User Views Apparently Benign File; Exploited Since April 2023
CVSS 7.8Veeam Backup & Replication — Unauthenticated Credential Extraction from Backup Database; Exploited by FIN7 and Akira Ransomware for Backup Infrastructure Takeover
CVSS 7.5Microsoft .NET Core / ASP.NET Core — Unauthenticated DoS in Kestrel Web Server via Crafted HTTP Requests
CVSS 7.5July 2023
Apple WebKit — Actively Exploited Zero-Day Patched via Rapid Security Response in July 2023
CVSS 8.8Windows SmartScreen — Security Warning Bypass Enabling Drive-by Download Without User Prompt
CVSS 8.8Microsoft Outlook — Security Notice Bypass via Crafted URL; Zero-Day in July 2023 Patch Tuesday
CVSS 8.8Windows MSHTML — Privilege Escalation via Crafted File; July 2023 Patch Tuesday Zero-Day
CVSS 7.8Windows Error Reporting — Symlink Attack Enabling Local Privilege Escalation to SYSTEM
CVSS 7.8Adobe ColdFusion — URL Filter Bypass Allowing Unauthenticated Admin Panel Access; Patch Later Bypassed by CVE-2023-38205
CVSS 7.5Adobe ColdFusion — Authentication Bypass Patch Bypass Enabling Unauthenticated Admin Panel Access
CVSS 7.5Office/Windows HTML — MOTW Bypass and RCE via Malicious Office Document; Used by Storm-0978 at NATO Summit
CVSS 7.5Ivanti EPMM — Authenticated Arbitrary File Write via Path Traversal, Enabling Webshell Deployment
CVSS 7.2June 2023
Apple WebKit — Memory Corruption Enabling Code Execution; Component of Operation Triangulation Chain
CVSS 8.8Apple WebKit — Type Confusion Enabling Code Execution via Malicious Web Content; June 2023 Rapid Security Response
CVSS 8.8Chromium V8 — First Chrome Zero-Day of 2023; Type Confusion Enabling Heap Corruption via Crafted Web Page
CVSS 8.8Apple Kernel — Integer Overflow Enabling Kernel Code Execution; Component of Operation Triangulation Chain
CVSS 7.8May 2023
Apple WebKit — Use-After-Free Enabling Code Execution via Malicious Web Content; May 2023 Rapid Security Response Zero-Day
CVSS 8.8TP-Link Archer AX21 — Unauthenticated Command Injection in Locale API; Pwn2Own Toronto Discovery; Exploited by Mirai Botnet Variants
CVSS 8.8Apple WebKit — Sandbox Escape Enabling Breakout from Web Content Process; Chained with CVE-2023-32373
CVSS 8.6Windows Win32k — Use-After-Free SYSTEM Privilege Escalation; May 2023 Patch Tuesday Zero-Day; Discovered by Avast
CVSS 7.8Oracle WebLogic Server — Unauthenticated Deserialization via T3/IIOP → Sensitive Data Disclosure; January 2023 Critical Patch Update
CVSS 7.5April 2023
Chromium V8 — First Chrome Zero-Day of 2023; Type Confusion via Crafted HTML Page; Discovered by Google TAG
CVSS 8.8Apple iOS/iPadOS/macOS/Safari WebKit — Use-After-Free for Code Execution; April 2023 Zero-Day; Chained with CVE-2023-28206 for Full Device Compromise
CVSS 8.8Apple IOSurfaceAccelerator — Out-of-Bounds Write → Kernel Code Execution; April 2023 Zero-Day; Chained with CVE-2023-28205 WebKit for Full Device Compromise
CVSS 8.6Android Framework — WorkSource Privilege Escalation via Target SDK Update; Exploited by Pinduoduo Malicious App to Gain Persistent Device Access
CVSS 7.8Windows CLFS — Heap Buffer Overflow → SYSTEM; April 2023 Zero-Day Exploited by Nokoyawa Ransomware; Third CLFS Zero-Day in Six Months
CVSS 7.8MinIO — Unauthenticated Endpoint Returns All Environment Variables Including Admin Credentials; Chained with CVE-2023-28434 for Full Admin Takeover
CVSS 7.5March 2023
Adobe ColdFusion — Unauthenticated Improper Access Control Enabling Server-Side Code Execution; Emergency Out-of-Band Patch; KEV Added Before NVD Publication
CVSS 8.6Linux Kernel ALSA — Use-After-Free in snd_ctl_elem_read → Ring0 Privilege Escalation via Race Condition; Adjacent Network Vector
CVSS 7.9February 2023
Apple iOS/iPadOS/macOS/Safari WebKit — Type Confusion for Code Execution via Malicious Web Content; February 2023 Zero-Day; KEV Added Before NVD Publication
CVSS 8.8SugarCRM Multiple Products — PHP Code Injection via EmailTemplates Module → Authenticated RCE; SA-2023-001; February 2023 KEV
CVSS 8.8Windows Graphics Component — Integer Overflow → SYSTEM Privilege Escalation; February 2023 Zero-Day; Patched on Same Day as CLFS LPE CVE-2023-23376
CVSS 7.8Windows CLFS — Heap Buffer Overflow → SYSTEM; February 2023 Zero-Day; Ransomware Exploitation; Second in a Series of CLFS Zero-Days
CVSS 7.8Microsoft Office Publisher — Macro Policy Bypass Allowing VBA Execution Despite Office Macro Restrictions; February 2023 Zero-Day
CVSS 7.3Fortra GoAnywhere MFT — Pre-Auth Deserialization RCE in License Response Servlet; Cl0p Ransomware Mass-Exploited 130+ Organizations
CVSS 7.2January 2023
Medium 25
September 2025
March 2025
March 2024
February 2024
January 2024
Citrix NetScaler ADC/Gateway — Authenticated Code Injection on Management Interface → RCE; January 2024 Zero-Day; CTX584986
CVSS 5.5Joomla! — Unauthenticated Access to Webservice API Endpoints Exposes Database Credentials and Configuration Data; Fixed in 4.2.8; KEV January 2024
CVSS 5.3December 2023
November 2023
Windows Mark of the Web — Security Feature Bypass Allows Internet-Downloaded Files to Bypass SmartScreen and Protected View; November 2023 KEV
CVSS 5.4Juniper Junos OS EX Series J-Web — PHP External Variable Modification Enables Pre-Auth RCE When Chained with File Upload CVEs; August 2023 Out-of-Cycle Bulletin
CVSS 5.3Juniper Junos OS SRX J-Web — Unauthenticated File Upload via user.php; Chained with CVE-2023-36844 for Pre-Auth RCE; August 2023 Out-of-Cycle Bulletin
CVSS 5.3Juniper Junos OS EX J-Web — Unauthenticated File Upload via installAppPackage.php; Chained with CVE-2023-36844 for Pre-Auth RCE; August 2023 Out-of-Cycle Bulletin
CVSS 5.3Juniper Junos OS SRX J-Web — Unauthenticated File Upload via webauth_operation.php; Chained with CVE-2023-36844 for Pre-Auth RCE; August 2023 Out-of-Cycle Bulletin
CVSS 5.3October 2023
Cisco IOS/IOS XE GET VPN — Out-of-Bounds Write via Crafted GDOI Messages → Code Execution; Requires Key Server or Group Member Compromise; October 2023 KEV
CVSS 6.6Microsoft WordPad — Opening Malicious Document Leaks NTLM Hash to Attacker Server; October 2023 Zero-Day; Credential Relay Risk
CVSS 6.5Roundcube Webmail — Stored XSS via Malicious Email Executes Attacker JavaScript in Victim's Browser; Exploited by Winter Vivern APT Against European Government Webmail
CVSS 6.1Arm Mali GPU Kernel Driver — Use-After-Free in GPU Memory Management Leaks Kernel Memory; Discovered by Google TAG; Android Exploitation; October 2023 KEV
CVSS 5.5Microsoft Skype for Business Server — Unauthenticated SSRF Allows Internal Network Probing and IP Address Disclosure; October 2023 Zero-Day
CVSS 5.3September 2023
Microsoft Word — Opening Malicious Document Leaks NTLM Hash to Attacker Server; September 2023 Zero-Day; Credential Relay Risk
CVSS 6.5Apple Security Framework — Improper Certificate Validation Allows Malicious App to Bypass Signature Verification; BLASTPASS Chain Stage (Sep 21 2023); Citizen Lab/Google TAG Discovery
CVSS 5.5Cisco ASA/FTD — VPN Authentication Weakness Enables Credential Brute Force and Unauthorized SSL VPN Sessions; Akira and LockBit Ransomware Initial Access Vector
CVSS 5July 2023
Zimbra ZCS 8.8.x — Reflected XSS via Unescaped URL Parameter Exploited by Four Nation-State Groups as Zero-Day
CVSS 6.1Apple XNU Kernel — Hardware MMIO Register Bypass Allows App to Modify Protected Kernel State; Operation Triangulation Component; July 2023 Zero-Day
CVSS 5.5May 2023
Apple WebKit — Out-of-Bounds Read Leaks Memory Layout via Malicious Web Content; May 2023 Zero-Day; KEV Added 32 Days Before NVD Publication; Apple RSR Delivery
CVSS 6.5Samsung Mobile Devices — Kernel Pointer Addresses Written to Log Files Enable ASLR Bypass; Android 11/12/13; May 2023 Samsung Security Update
CVSS 4.4