Total
34640 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-21548 | 1 Microsoft | 15 Windows 10 1607, Windows 10 1809, Windows 10 20h2 and 12 more | 2024-11-21 | N/A | 8.1 HIGH |
|
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
|
|||||
| CVE-2023-21543 | 1 Microsoft | 15 Windows 10 1607, Windows 10 1809, Windows 10 20h2 and 12 more | 2024-11-21 | N/A | 8.1 HIGH |
|
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
|
|||||
| CVE-2023-21541 | 1 Microsoft | 15 Windows 10 1607, Windows 10 1809, Windows 10 20h2 and 12 more | 2024-11-21 | N/A | 7.8 HIGH |
|
Windows Task Scheduler Elevation of Privilege Vulnerability
|
|||||
| CVE-2023-21540 | 1 Microsoft | 8 Windows 10 1809, Windows 10 20h2, Windows 10 21h2 and 5 more | 2024-11-21 | N/A | 5.5 MEDIUM |
|
Windows Cryptographic Information Disclosure Vulnerability
|
|||||
| CVE-2023-21539 | 1 Microsoft | 6 Windows 10 20h2, Windows 10 21h2, Windows 10 22h2 and 3 more | 2024-11-21 | N/A | 7.5 HIGH |
|
Windows Authentication Remote Code Execution Vulnerability
|
|||||
| CVE-2023-21538 | 2 Fedoraproject, Microsoft | 3 Fedora, .net, Powershell | 2024-11-21 | N/A | 7.5 HIGH |
|
.NET Denial of Service Vulnerability
|
|||||
| CVE-2023-21537 | 1 Microsoft | 15 Windows 10 1607, Windows 10 1809, Windows 10 20h2 and 12 more | 2024-11-21 | N/A | 7.8 HIGH |
|
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
|
|||||
| CVE-2023-21535 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows 10 20h2 and 11 more | 2024-11-21 | N/A | 8.1 HIGH |
|
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
|
|||||
| CVE-2023-21532 | 1 Microsoft | 15 Windows 10 1607, Windows 10 1809, Windows 10 20h2 and 12 more | 2024-11-21 | N/A | 7.0 HIGH |
|
Windows GDI Elevation of Privilege Vulnerability
|
|||||
| CVE-2023-21529 | 1 Microsoft | 1 Exchange Server | 2024-11-21 | N/A | 8.8 HIGH |
|
Microsoft Exchange Server Remote Code Execution Vulnerability
|
|||||
| CVE-2023-21528 | 1 Microsoft | 1 Sql Server | 2024-11-21 | N/A | 7.8 HIGH |
|
Microsoft SQL Server Remote Code Execution Vulnerability
|
|||||
| CVE-2023-21527 | 1 Microsoft | 15 Windows 10 1607, Windows 10 1809, Windows 10 20h2 and 12 more | 2024-11-21 | N/A | 7.5 HIGH |
|
Windows iSCSI Service Denial of Service Vulnerability
|
|||||
| CVE-2023-21526 | 1 Microsoft | 12 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 9 more | 2024-11-21 | N/A | 7.4 HIGH |
|
Windows Netlogon Information Disclosure Vulnerability
|
|||||
| CVE-2023-21525 | 1 Microsoft | 15 Windows 10 1607, Windows 10 1809, Windows 10 20h2 and 12 more | 2024-11-21 | N/A | 5.3 MEDIUM |
|
Remote Procedure Call Runtime Denial of Service Vulnerability
|
|||||
| CVE-2023-21524 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 20h2 and 9 more | 2024-11-21 | N/A | 7.8 HIGH |
|
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
|
|||||
| CVE-2023-21520 | 1 Blackberry | 1 Athoc | 2024-11-21 | N/A | 5.3 MEDIUM |
|
A PII Enumeration via Credential Recovery in the Self Service (Credential Recovery) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially associate a list of contact details with an AtHoc IWS organization.
|
|||||
| CVE-2023-21515 | 1 Samsung | 1 Galaxy Store | 2024-11-21 | N/A | 7.5 HIGH |
|
InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
|
|||||
| CVE-2023-21495 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 4.0 MEDIUM |
|
Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device admin is set.
|
|||||
| CVE-2023-21493 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 6.8 MEDIUM |
|
Improper access control vulnerability in SemShareFileProvider prior to SMR May-2023 Release 1 allows local attackers to access protected data.
|
|||||
| CVE-2023-21491 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 8.5 HIGH |
|
Improper access control vulnerability in ThemeManager prior to SMR May-2023 Release 1 allows local attackers to write arbitrary files with system privilege.
|
|||||
| CVE-2023-21490 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 4.7 MEDIUM |
|
Improper access control in GearManagerStub prior to SMR May-2023 Release 1 allows a local attacker to delete applications installed by watchmanager.
|
|||||
| CVE-2023-21488 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 4.4 MEDIUM |
|
Improper access control vulnerablility in Tips prior to SMR May-2023 Release 1 allows local attackers to launch arbitrary activity in Tips.
|
|||||
| CVE-2023-21465 | 1 Samsung | 1 Bixbytouch | 2024-11-21 | N/A | 5.5 MEDIUM |
|
Improper access control vulnerability in BixbyTouch prior to version 3.2.02.5 in China models allows untrusted applications access local files.
|
|||||
| CVE-2023-21462 | 2 Google, Samsung | 2 Android, Quick Share | 2024-11-21 | N/A | 4.2 MEDIUM |
|
The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related permission.
|
|||||
| CVE-2023-21442 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 4.0 MEDIUM |
|
Improper access control vulnerability in Runestone application prior to version 2.9.09.003 in Android R(11) and 3.2.01.007 in Android S(12) allows local attackers to get device location information.
|
|||||
| CVE-2023-21436 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 3.3 LOW |
|
Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID.
|
|||||
| CVE-2023-21432 | 1 Samsung | 1 Smart Things | 2024-11-21 | N/A | 4.2 MEDIUM |
|
Improper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without authorization of the owner.
|
|||||
| CVE-2023-21429 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 4.0 MEDIUM |
|
Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID.
|
|||||
| CVE-2023-21427 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Improper access control vulnerability in NfcTile prior to SMR Jan-2023 Release 1 allows to attacker to use NFC without user recognition.
|
|||||
| CVE-2023-21419 | 1 Google | 1 Android | 2024-11-21 | N/A | 4.3 MEDIUM |
|
An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container remain unlocked under certain condition.
|
|||||
| CVE-2023-21416 | 1 Axis | 2 Axis Os, Axis Os 2022 | 2024-11-21 | N/A | 7.1 HIGH |
|
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi was vulnerable to a Denial-of-Service attack allowing for an attacker to block access to the overlay configuration page in the web interface of the Axis device. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account however the impact is equal. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Ax ...
Show More |
|||||
| CVE-2023-21414 | 1 Axis | 35 A8207-ve Mk Ii, Axis Os, M3215 and 32 more | 2024-11-21 | N/A | 7.1 HIGH |
|
NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
|
|||||
| CVE-2023-21411 | 1 Axis | 1 License Plate Verifier | 2024-11-21 | N/A | 7.2 HIGH |
|
User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for
arbitrary code execution.
|
|||||
| CVE-2023-21410 | 1 Axis | 1 License Plate Verifier | 2024-11-21 | N/A | 7.2 HIGH |
|
User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for
arbitrary code execution.
|
|||||
| CVE-2023-21405 | 1 Axis | 11 A1001, A1001 Firmware, A1210 \(-b\) and 8 more | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network
Intercoms when communicating over OSDP, highlighting that the OSDP message parser crashes
the pacsiod process, causing a temporary unavailability of the door-controlling functionalities
meaning that doors cannot be opened or closed. No sensitive or customer data can be extracted
as the Axis device is not further compromised. Please refer to the Axis security advisory for more information, mitigation and ...
Show More |
|||||
| CVE-2023-21403 | 1 Google | 1 Android | 2024-11-21 | N/A | 9.8 CRITICAL |
|
In RGXDestroyZSBufferKM of rgxta3d.c, there is a possible arbitrary code execution due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
|
|||||
| CVE-2023-21402 | 1 Google | 1 Android | 2024-11-21 | N/A | 9.8 CRITICAL |
|
In MMU_UnmapPages of mmu_common.c, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
|
|||||
| CVE-2023-21401 | 1 Google | 1 Android | 2024-11-21 | N/A | 9.8 CRITICAL |
|
In DevmemIntChangeSparse of devicemem_server.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
|
|||||
| CVE-2023-21398 | 1 Google | 1 Android | 2024-11-21 | N/A | 7.8 HIGH |
|
In sdksandbox, there is a possible strandhogg style overlay attack due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
|
|||||
| CVE-2023-21397 | 1 Google | 1 Android | 2024-11-21 | N/A | 7.8 HIGH |
|
In Setup Wizard, there is a possible way to save a WiFi network due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
|
|||||