Total
34640 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-23935 | 1 Discourse | 1 Discourse | 2024-11-21 | N/A | 3.5 LOW |
|
Discourse is an open-source messaging platform. In versions 3.0.1 and prior on the `stable` branch and versions 3.1.0.beta2 and prior on the `beta` and `tests-passed` branches, the count of personal messages displayed for a tag is a count of all personal messages regardless of whether the personal message is visible to a given user. As a result, any users can technically poll a sensitive tag to determine if a new personal message is created even if the user does not have access to the personal m ...
Show More |
|||||
| CVE-2023-23934 | 1 Palletsprojects | 1 Werkzeug | 2024-11-21 | N/A | 2.6 LOW |
|
Werkzeug is a comprehensive WSGI web application library. Browsers may allow "nameless" cookies that look like `=value` instead of `key=value`. A vulnerable browser may allow a compromised application on an adjacent subdomain to exploit this to set a cookie like `=__Host-test=bad` for another subdomain. Werkzeug prior to 2.2.3 will parse the cookie `=__Host-test=bad` as __Host-test=bad`. If a Werkzeug application is running next to a vulnerable or malicious subdomain which sets such a cookie usi ...
Show More |
|||||
| CVE-2023-23932 | 1 Objectcomputing | 1 Opendds | 2024-11-21 | N/A | 5.3 MEDIUM |
|
OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). OpenDDS applications that are exposed to untrusted RTPS network traffic may crash when parsing badly-formed input. This issue has been patched in version 3.23.1.
|
|||||
| CVE-2023-23923 | 1 Moodle | 1 Moodle | 2024-11-21 | N/A | 8.2 HIGH |
|
The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
|
|||||
| CVE-2023-23908 | 3 Debian, Fedoraproject, Intel | 275 Debian Linux, Fedora, Microcode and 272 more | 2024-11-21 | N/A | 6.0 MEDIUM |
|
Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access.
|
|||||
| CVE-2023-23903 | 1 Nozominetworks | 2 Cmc, Guardian | 2024-11-21 | N/A | 4.9 MEDIUM |
|
An authenticated administrator can upload a SAML configuration file with the wrong format, with the application not checking the correct file format. Every subsequent application request will return an error.
The whole application in rendered unusable until a console intervention.
|
|||||
| CVE-2023-23839 | 1 Solarwinds | 1 Solarwinds Platform | 2024-11-21 | N/A | 6.5 MEDIUM |
|
The SolarWinds Platform was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users to access Orion.WebCommunityStrings SWIS schema object and obtain sensitive information.
|
|||||
| CVE-2023-23622 | 1 Discourse | 1 Discourse | 2024-11-21 | N/A | 4.3 MEDIUM |
|
Discourse is an open-source discussion platform. Prior to version 3.0.1 of the `stable` branch and version 3.1.0.beta2 of the `beta` and `tests-passed` branches, the count of topics displayed for a tag is a count of all regular topics regardless of whether the topic is in a read restricted category or not. As a result, any users can technically poll a sensitive tag to determine if a new topic is created in a category which the user does not have excess to.
In version 3.0.1 of the `stable` bran ...
Show More |
|||||
| CVE-2023-23611 | 1 Openedx | 1 Xblock-lti-consumer | 2024-11-21 | N/A | 5.4 MEDIUM |
|
LTI Consumer XBlock implements the consumer side of the LTI specification enabling integration of third-party LTI provider tools. Versions 7.0.0 and above, prior to 7.2.2, are vulnerable to Missing Authorization. Any LTI tool that is integrated with on the Open edX platform can post a grade back for any LTI XBlock so long as it knows or can guess the block location for that XBlock. An LTI tool submits scores to the edX platform for line items. The code that uploads that score to the LMS grade t ...
Show More |
|||||
| CVE-2023-23573 | 1 Intel | 1 Unite | 2024-11-21 | N/A | 4.4 MEDIUM |
|
Improper access control in the Intel(R) Unite(R) android application before Release 17 may allow a privileged user to potentially enable information disclosure via local access.
|
|||||
| CVE-2023-23549 | 1 Checkmk | 1 Checkmk | 2024-11-21 | N/A | 2.7 LOW |
|
Improper Input Validation in Checkmk <2.2.0p15, <2.1.0p37, <=2.0.0p39 allows priviledged attackers to cause partial denial of service of the UI via too long hostnames.
|
|||||
| CVE-2023-23512 | 1 Apple | 5 Ipados, Iphone Os, Macos and 2 more | 2024-11-21 | N/A | 6.5 MEDIUM |
|
The issue was addressed with improved handling of caches. This issue is fixed in watchOS 9.3, tvOS 16.3, macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. Visiting a website may lead to an app denial-of-service.
|
|||||
| CVE-2023-23498 | 1 Apple | 3 Ipados, Iphone Os, Macos | 2024-11-21 | N/A | 3.3 LOW |
|
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.7.3 and iPadOS 15.7.3, macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. The quoted original message may be selected from the wrong email when forwarding an email from an Exchange account.
|
|||||
| CVE-2023-23482 | 2 Ibm, Linux | 2 Sterling Partner Engagement Manager, Linux Kernel | 2024-11-21 | N/A | 5.4 MEDIUM |
|
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 245891.
|
|||||
| CVE-2023-23468 | 2 Ibm, Redhat | 2 Robotic Process Automation, Openshift | 2024-11-21 | N/A | 5.1 MEDIUM |
|
IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to insufficient security configuration which may allow creation of namespaces within a cluster. IBM X-Force ID: 244500.
|
|||||
| CVE-2023-23440 | 1 Hihonor | 2 Lge-an00, Lge-an00 Firmware | 2024-11-21 | N/A | 3.3 LOW |
|
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
|
|||||
| CVE-2023-23439 | 1 Hihonor | 2 Lge-an00, Lge-an00 Firmware | 2024-11-21 | N/A | 4.0 MEDIUM |
|
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
|
|||||
| CVE-2023-23437 | 1 Hihonor | 1 Vmall | 2024-11-21 | N/A | 3.3 LOW |
|
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak
|
|||||
| CVE-2023-23434 | 1 Hihonor | 1 Honorboardapp | 2024-11-21 | N/A | 4.0 MEDIUM |
|
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
|
|||||
| CVE-2023-23426 | 1 Hihonor | 2 Fri-an00, Fri-an00 Firmware | 2024-11-21 | N/A | 6.6 MEDIUM |
|
Some Honor products are affected by file writing vulnerability, successful exploitation could cause information disclosure.
|
|||||
| CVE-2023-23424 | 1 Hihonor | 2 Nth-an00, Nth-an00 Firmware | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Some Honor products are affected by file writing vulnerability, successful exploitation could cause code execution
|
|||||
| CVE-2023-23423 | 1 Microsoft | 13 Windows 10, Windows 10 1607, Windows 10 1809 and 10 more | 2024-11-21 | N/A | 7.8 HIGH |
|
Windows Kernel Elevation of Privilege Vulnerability
|
|||||
| CVE-2023-23422 | 1 Microsoft | 13 Windows 10, Windows 10 1607, Windows 10 1809 and 10 more | 2024-11-21 | N/A | 7.8 HIGH |
|
Windows Kernel Elevation of Privilege Vulnerability
|
|||||
| CVE-2023-23421 | 1 Microsoft | 13 Windows 10, Windows 10 1607, Windows 10 1809 and 10 more | 2024-11-21 | N/A | 7.8 HIGH |
|
Windows Kernel Elevation of Privilege Vulnerability
|
|||||
| CVE-2023-23420 | 1 Microsoft | 13 Windows 10, Windows 10 1607, Windows 10 1809 and 10 more | 2024-11-21 | N/A | 7.8 HIGH |
|
Windows Kernel Elevation of Privilege Vulnerability
|
|||||
| CVE-2023-23419 | 1 Microsoft | 1 Windows 11 22h2 | 2024-11-21 | N/A | 7.8 HIGH |
|
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
|
|||||
| CVE-2023-23418 | 1 Microsoft | 1 Windows 11 22h2 | 2024-11-21 | N/A | 7.8 HIGH |
|
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
|
|||||
| CVE-2023-23417 | 1 Microsoft | 10 Windows 10 1607, Windows 10 1809, Windows 10 20h2 and 7 more | 2024-11-21 | N/A | 7.8 HIGH |
|
Windows Partition Management Driver Elevation of Privilege Vulnerability
|
|||||
| CVE-2023-23416 | 1 Microsoft | 12 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 9 more | 2024-11-21 | N/A | 7.8 HIGH |
|
Windows Cryptographic Services Remote Code Execution Vulnerability
|
|||||
| CVE-2023-23415 | 1 Microsoft | 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability
|
|||||
| CVE-2023-23414 | 1 Microsoft | 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more | 2024-11-21 | N/A | 7.1 HIGH |
|
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
|
|||||
| CVE-2023-23413 | 1 Microsoft | 12 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 9 more | 2024-11-21 | N/A | 8.8 HIGH |
|
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
|
|||||
| CVE-2023-23412 | 1 Microsoft | 10 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 7 more | 2024-11-21 | N/A | 7.8 HIGH |
|
Windows Accounts Picture Elevation of Privilege Vulnerability
|
|||||
| CVE-2023-23410 | 1 Microsoft | 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more | 2024-11-21 | N/A | 7.8 HIGH |
|
Windows HTTP.sys Elevation of Privilege Vulnerability
|
|||||
| CVE-2023-23406 | 1 Microsoft | 12 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 9 more | 2024-11-21 | N/A | 8.8 HIGH |
|
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
|
|||||
| CVE-2023-23405 | 1 Microsoft | 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more | 2024-11-21 | N/A | 8.1 HIGH |
|
Remote Procedure Call Runtime Remote Code Execution Vulnerability
|
|||||
| CVE-2023-23403 | 1 Microsoft | 12 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 9 more | 2024-11-21 | N/A | 8.8 HIGH |
|
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
|
|||||
| CVE-2023-23402 | 1 Microsoft | 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more | 2024-11-21 | N/A | 7.8 HIGH |
|
Windows Media Remote Code Execution Vulnerability
|
|||||
| CVE-2023-23401 | 1 Microsoft | 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more | 2024-11-21 | N/A | 7.8 HIGH |
|
Windows Media Remote Code Execution Vulnerability
|
|||||
| CVE-2023-23400 | 1 Microsoft | 4 Windows Server 2012, Windows Server 2016, Windows Server 2019 and 1 more | 2024-11-21 | N/A | 7.2 HIGH |
|
Windows DNS Server Remote Code Execution Vulnerability
|
|||||