Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Angry Yack Logo
Total 34640 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-32025 1 Microsoft 2 Odbc Driver For Sql Server, Sql Server 2024-11-21 N/A 7.8 HIGH
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
CVE-2023-32024 1 Microsoft 1 Power Apps 2024-11-21 N/A 3.0 LOW
Microsoft Power Apps Spoofing Vulnerability
CVE-2023-32022 1 Microsoft 4 Windows Server 2012, Windows Server 2016, Windows Server 2019 and 1 more 2024-11-21 N/A 7.6 HIGH
Windows Server Service Security Feature Bypass Vulnerability
CVE-2023-32021 1 Microsoft 4 Windows Server 2012, Windows Server 2016, Windows Server 2019 and 1 more 2024-11-21 N/A 7.1 HIGH
Windows SMB Witness Service Security Feature Bypass Vulnerability
CVE-2023-32020 1 Microsoft 5 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 2 more 2024-11-21 N/A 5.6 MEDIUM
Windows DNS Spoofing Vulnerability
CVE-2023-32018 1 Microsoft 1 Windows 11 22h2 2024-11-21 N/A 7.8 HIGH
Windows Hello Remote Code Execution Vulnerability
CVE-2023-32013 1 Microsoft 7 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 4 more 2024-11-21 N/A 5.3 MEDIUM
Windows Hyper-V Denial of Service Vulnerability
CVE-2023-32012 1 Microsoft 4 Windows 10 21h2, Windows 10 22h2, Windows 11 21h2 and 1 more 2024-11-21 N/A 7.8 HIGH
Windows Container Manager Service Elevation of Privilege Vulnerability
CVE-2023-32010 1 Microsoft 1 Windows 11 22h2 2024-11-21 N/A 7.0 HIGH
Windows Bus Filter Driver Elevation of Privilege Vulnerability
CVE-2023-32009 1 Microsoft 9 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 6 more 2024-11-21 N/A 8.8 HIGH
Windows Collaborative Translation Framework Elevation of Privilege Vulnerability
CVE-2023-31824 1 Dericia 1 Delicia 2024-11-21 N/A 7.5 HIGH
An issue found in DERICIA Co. Ltd, DELICIA v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp DELICIA function.
CVE-2023-31655 1 Redis 1 Redis 2024-11-21 N/A 7.5 HIGH
redis v7.0.10 was discovered to contain a segmentation violation. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
CVE-2023-31490 3 Debian, Fedoraproject, Frrouting 3 Debian Linux, Fedora, Frrouting 2024-11-21 N/A 7.5 HIGH
An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.
CVE-2023-31489 2 Fedoraproject, Frrouting 2 Fedora, Frrouting 2024-11-21 N/A 5.5 MEDIUM
An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_capability_llgr() function.
CVE-2023-31488 1 Cisco 3 Ironport Email Security Appliance, Secure Email Gateway, Secure Email Gateway Firmware 2024-11-21 N/A 9.8 CRITICAL
Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, Cisco Secure Email Gateway, and various non-Cisco products, allow attackers to trigger a segmentation fault and execute arbitrary code via a crafted document.
CVE-2023-31465 1 Fsmlabs 1 Timekeeper 2024-11-21 N/A 9.8 CRITICAL
An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper streams, it is possible to find the getsamplebacklog call. Some query parameters are passed directly in the URL and named arg[x], with x an integer starting from 1; it is possible to modify arg[2] to insert Bash code that will be executed directly by the server.
CVE-2023-31462 1 Steelseries 1 Gg 2024-11-21 N/A 8.8 HIGH
An issue was discovered in SteelSeries GG 36.0.0. An attacker can change values in an unencrypted database that is writable for all users on the computer, in order to trigger code execution with higher privileges.
CVE-2023-31447 1 Draytek 4 Vigor2620, Vigor2620 Firmware, Vigor2625 and 1 more 2024-11-21 N/A 9.8 CRITICAL
user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers to send a crafted payload to modify the content of the code segment, insert shellcode, and execute arbitrary code.
CVE-2023-31416 1 Elastic 2 Apm Server, Elastic Cloud On Kubernetes 2024-11-21 N/A 5.3 MEDIUM
Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.
CVE-2023-31271 1 Intel 1 Virtual Raid On Cpu 2024-11-21 N/A 6.7 MEDIUM
Improper access control in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2023-31203 1 Intel 1 Openvino Model Server 2024-11-21 N/A 4.3 MEDIUM
Improper input validation in some OpenVINO Model Server software before version 2022.3 for Intel Distribution of OpenVINO toolkit may allow an unauthenticated user to potentially enable denial of service via network access.
CVE-2023-31191 1 Bluemark 2 Dronescout Ds230, Dronescout Ds230 Firmware 2024-11-21 N/A 9.3 CRITICAL
DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an information loss vulnerability through traffic injection. An attacker can exploit this vulnerability by injecting, on carefully selected channels, high power spoofed Open Drone ID (ODID) messages which force the DroneScout ds230 Remote ID receiver to drop real Remote ID (RID) information and, instead, generate and transmit JSON encoded MQTT messages containing crafted RID information. Consequently, the MQTT broker, ...

Show More

CVE-2023-31185 1 Rozcom 1 Rozcom Client 2024-11-21 N/A 7.5 HIGH
ROZCOM server framework - Misconfiguration may allow information disclosure via an unspecified request.
CVE-2023-31178 1 Agilepoint 1 Agilepoint Nx 2024-11-21 N/A 8.1 HIGH
AgilePoint NX v8.0 SU2.2 & SU2.3 – Arbitrary File Delete Vulnerability allows arbitrary file deletion, by an unspecified request.
CVE-2023-31133 1 Ghost 1 Ghost 2024-11-21 N/A 7.5 HIGH
Ghost is an app for new-media creators with tools to build a website, publish content, send newsletters, and offer paid subscriptions to members. Prior to version 5.46.1, due to a lack of validation when filtering on the public API endpoints, it is possible to reveal private fields via a brute force attack. Ghost(Pro) has already been patched. Maintainers can find no evidence that the issue was exploited on Ghost(Pro) prior to the patch being added. Self-hosters are impacted if running Ghost a ...

Show More

CVE-2023-31042 1 Purestorage 1 Purity 2024-11-21 N/A 7.7 HIGH
A flaw exists in FlashBlade Purity whereby an authenticated user with access to FlashBlade’s object store protocol can impact the availability of the system’s data access and replication protocols.
CVE-2023-31035 1 Nvidia 2 Dgx A100, Dgx A100 Firmware 2024-11-21 N/A 7.5 HIGH
NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that could be used to execute arbitrary code at the SMM level. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, and information disclosure.
CVE-2023-31027 2 Microsoft, Nvidia 2 Windows, Virtual Gpu 2024-11-21 N/A 8.2 HIGH
NVIDIA GPU Display Driver for Windows contains a vulnerability that allows Windows users with low levels of privilege to escalate privileges when an administrator is updating GPU drivers, which may lead to escalation of privileges.
CVE-2023-30991 4 Ibm, Linux, Microsoft and 1 more 4 Db2, Linux Kernel, Windows and 1 more 2024-11-21 N/A 7.5 HIGH
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to denial of service with a specially crafted query. IBM X-Force ID: 254037.
CVE-2023-30989 1 Ibm 1 I 2024-11-21 N/A 8.4 HIGH
IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain all object access to the host operating system. IBM X-Force ID: 254017.
CVE-2023-30988 1 Ibm 1 I 2024-11-21 N/A 8.4 HIGH
The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system. IBM X-Force ID: 254016.
CVE-2023-30987 4 Ibm, Linux, Microsoft and 1 more 4 Db2, Linux Kernel, Windows and 1 more 2024-11-21 N/A 5.3 MEDIUM
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain databases. IBM X-Force ID: 253440.
CVE-2023-30956 1 Palantir 1 Foundry Comments 2024-11-21 N/A 5.3 MEDIUM
A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of the target attachment. This defect was resolved with the release of Foundry Comments 2.267.0.
CVE-2023-30912 1 Hpe 1 Oneview 2024-11-21 N/A 7.2 HIGH
A remote code execution issue exists in HPE OneView.
CVE-2023-30911 1 Hpe 77 Alletra 4110, Alletra 4120, Alletra 4140 and 74 more 2024-11-21 N/A 6.8 MEDIUM
HPE Integrated Lights-Out 5, and Integrated Lights-Out 6 using iLOrest may cause denial of service.
CVE-2023-30909 1 Hp 1 Oneview 2024-11-21 N/A 9.8 CRITICAL
A remote authentication bypass issue exists in some OneView APIs.
CVE-2023-30908 1 Hp 1 Oneview 2024-11-21 N/A 9.8 CRITICAL
A remote authentication bypass issue exists in a OneView API.
CVE-2023-30906 1 Hpe 1 Intelligent Provisioning 2024-11-21 N/A 7.5 HIGH
The vulnerability could be locally exploited to allow escalation of privilege.
CVE-2023-30859 1 Triton Project 1 Triton 2024-11-21 N/A 7.2 HIGH
Triton is a Minecraft plugin for Spigot and BungeeCord that helps you translate your Minecraft server. The CustomPayload packet allows you to execute commands on the spigot/bukkit console. When you enable bungee mode in the config it will enable the bungee bridge and the server will begin to broadcast the 'triton:main' plugin channel. Using this plugin channel you are able to send a payload packet containing a byte (2) and a string (any spigot command). This could be used to make yourself a serv ...

Show More

CVE-2023-30851 1 Cilium 1 Cilium 2024-11-21 N/A 2.6 LOW
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. This issue only impacts users who have a HTTP policy that applies to multiple `toEndpoints` AND have an allow-all rule in place that affects only one of those endpoints. In such cases, a wildcard rule will be appended to the set of HTTP rules, which could cause bypass of HTTP policies. This issue has been patched in Cilium 1.11.16, 1.12.9, and 1.13.2.