Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-3622 1 Solarwinds 1 Solarwinds Platform 2023-12-28 N/A 4.3 MEDIUM
Access Control Bypass Vulnerability in the SolarWinds Platform that allows an underprivileged user to read arbitrary resource
CVE-2019-16892 3 Fedoraproject, Redhat, Rubyzip Project 3 Fedora, Cloudforms, Rubyzip 2023-12-28 7.1 HIGH 5.5 MEDIUM
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
CVE-2022-3587 1 Oretnom23 1 Simple Cold Storage Management System 2023-12-28 N/A 5.4 MEDIUM
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component My Account. The manipulation of the argument First Name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-211201 was assigned to this vulnerability.
CVE-2022-3585 1 Oretnom23 1 Simple Cold Storage Management System 2023-12-28 N/A 4.3 MEDIUM
A vulnerability classified as problematic has been found in SourceCodester Simple Cold Storage Management System 1.0. Affected is an unknown function of the file /csms/?page=contact_us of the component Contact Us. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-211194 is the identifier assigned to this vulnerability.
CVE-2022-3548 1 Oretnom23 1 Simple Cold Storage Management System 2023-12-28 N/A 4.8 MEDIUM
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the component Add New Storage Handler. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-211048.
CVE-2022-3546 1 Oretnom23 1 Simple Cold Storage Management System 2023-12-28 N/A 4.8 MEDIUM
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /csms/admin/?page=user/list of the component Create User Handler. The manipulation of the argument First Name/Last Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-211046 is the identifier assigned to this vulnerability.
CVE-2023-4527 4 Fedoraproject, Gnu, Netapp and 1 more 32 Fedora, Glibc, H300s and 29 more 2023-12-28 N/A 6.5 MEDIUM
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.
CVE-2021-43221 1 Microsoft 1 Edge Chromium 2023-12-28 4.0 MEDIUM 4.2 MEDIUM
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2021-43211 1 Microsoft 1 Windows 10 Update Assistant 2023-12-28 6.6 MEDIUM 5.5 MEDIUM
Windows 10 Update Assistant Elevation of Privilege Vulnerability
CVE-2021-42297 1 Microsoft 1 Windows 10 Update Assistant 2023-12-28 6.9 MEDIUM 5.0 MEDIUM
Windows 10 Update Assistant Elevation of Privilege Vulnerability
CVE-2021-42319 1 Microsoft 2 Visual Studio 2017, Visual Studio 2019 2023-12-28 2.1 LOW 4.7 MEDIUM
Visual Studio Elevation of Privilege Vulnerability
CVE-2021-42305 1 Microsoft 1 Exchange Server 2023-12-28 4.3 MEDIUM 6.5 MEDIUM
Microsoft Exchange Server Spoofing Vulnerability
CVE-2021-42304 1 Microsoft 1 Azure Real Time Operating System 2023-12-28 7.2 HIGH 6.6 MEDIUM
Azure RTOS Elevation of Privilege Vulnerability
CVE-2021-42303 1 Microsoft 1 Azure Real Time Operating System 2023-12-28 7.2 HIGH 6.6 MEDIUM
Azure RTOS Elevation of Privilege Vulnerability
CVE-2021-42302 1 Microsoft 1 Azure Real Time Operating System 2023-12-28 7.2 HIGH 6.6 MEDIUM
Azure RTOS Elevation of Privilege Vulnerability
CVE-2021-42300 1 Microsoft 1 Azure Sphere 2023-12-28 4.6 MEDIUM 6.0 MEDIUM
Azure Sphere Tampering Vulnerability
CVE-2021-42288 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2023-12-28 3.6 LOW 5.7 MEDIUM
Windows Hello Security Feature Bypass Vulnerability
CVE-2021-42284 1 Microsoft 8 Windows 10, Windows 11, Windows 8.1 and 5 more 2023-12-28 7.1 HIGH 6.8 MEDIUM
Windows Hyper-V Denial of Service Vulnerability
CVE-2021-42280 1 Microsoft 5 Windows 10, Windows 11, Windows Server 2016 and 2 more 2023-12-28 4.6 MEDIUM 5.5 MEDIUM
Windows Feedback Hub Elevation of Privilege Vulnerability
CVE-2021-42279 1 Microsoft 5 Windows 10, Windows 11, Windows Server 2016 and 2 more 2023-12-28 5.1 MEDIUM 4.2 MEDIUM
Chakra Scripting Engine Memory Corruption Vulnerability
CVE-2021-42277 1 Microsoft 8 Visual Studio, Visual Studio 2017, Visual Studio 2019 and 5 more 2023-12-28 4.6 MEDIUM 5.5 MEDIUM
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
CVE-2021-42274 1 Microsoft 5 Windows 10, Windows 11, Windows Server 2016 and 2 more 2023-12-28 2.1 LOW 6.8 MEDIUM
Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability
CVE-2021-41379 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-12-28 4.6 MEDIUM 5.5 MEDIUM
Windows Installer Elevation of Privilege Vulnerability
CVE-2021-41375 1 Microsoft 1 Azure Sphere 2023-12-28 2.1 LOW 4.4 MEDIUM
Azure Sphere Information Disclosure Vulnerability
CVE-2021-41374 1 Microsoft 1 Azure Sphere 2023-12-28 2.1 LOW 6.7 MEDIUM
Azure Sphere Information Disclosure Vulnerability
CVE-2021-41373 1 Microsoft 1 Fslogix 2023-12-28 2.1 LOW 5.5 MEDIUM
FSLogix Information Disclosure Vulnerability
CVE-2021-41371 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-12-28 2.1 LOW 4.4 MEDIUM
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2021-41368 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2023-12-28 6.8 MEDIUM 6.1 MEDIUM
Microsoft Access Remote Code Execution Vulnerability
CVE-2021-41351 1 Microsoft 4 Edge, Windows 10, Windows 11 and 1 more 2023-12-28 4.3 MEDIUM 4.3 MEDIUM
Microsoft Edge (Chrome based) Spoofing on IE Mode
CVE-2021-41349 1 Microsoft 1 Exchange Server 2023-12-28 4.3 MEDIUM 6.5 MEDIUM
Microsoft Exchange Server Spoofing Vulnerability
CVE-2021-38631 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-12-28 2.1 LOW 4.4 MEDIUM
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2021-41363 1 Microsoft 1 Intune Management Extension 2023-12-28 4.4 MEDIUM 4.2 MEDIUM
Intune Management Extension Security Feature Bypass Vulnerability
CVE-2023-42627 1 Liferay 2 Digital Experience Platform, Liferay Portal 2023-12-28 N/A 5.4 MEDIUM
Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal 7.3.5 through 7.4.3.91, and Liferay DXP 7.3 update 33 and earlier, and 7.4 before update 92 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a (1) Shipping Name, (2) Shipping Phone Number, (3) Shipping Address, (4) Shipping Address 2, (5) Shipping Address 3, (6) Shipping Zip, (7) Shipping City, (8) Shipping Region (9), Shipping Country, (10) Billing Name, (11) Billing Phone Number, (12) Billing Address, (13) Billing Address 2, (14) Billing Address 3, (15) Billing Zip, (16) Billing City, (17) Billing Region, (18) Billing Country, or (19) Region Code.
CVE-2023-42628 1 Liferay 2 Digital Experience Platform, Liferay Portal 2023-12-28 N/A 5.4 MEDIUM
Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay DXP 7.0 fix pack 83 through 102, 7.1 fix pack 28 and earlier, 7.2 fix pack 20 and earlier, 7.3 update 33 and earlier, and 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML into a parent wiki page via a crafted payload injected into a wiki page's ‘Content’ text field.
CVE-2023-42629 1 Liferay 2 Digital Experience Platform, Liferay Portal 2023-12-28 N/A 5.4 MEDIUM
Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Vocabulary's 'description' text field.
CVE-2022-24599 3 Audio File Library Project, Debian, Fedoraproject 3 Audio File Library, Debian Linux, Fedora 2023-12-28 4.3 MEDIUM 6.5 MEDIUM
In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.
CVE-2019-13147 2 Audio File Library Project, Debian 2 Audio File Library, Debian Linux 2023-12-28 4.3 MEDIUM 6.5 MEDIUM
In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial of service via a crafted file.
CVE-2022-4393 1 Avirtum 1 Imagelinks 2023-12-28 N/A 5.4 MEDIUM
The ImageLinks Interactive Image Builder for WordPress plugin through 1.5.3 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2023-50825 1 Jacksonwhelan 1 Iframe Shortcode 2023-12-28 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terrier Tenacity iframe Shortcode allows Stored XSS.This issue affects iframe Shortcode: from n/a through 2.0.
CVE-2009-4895 3 Canonical, Debian, Linux 3 Ubuntu Linux, Debian Linux, Linux Kernel 2023-12-28 4.7 MEDIUM 4.7 MEDIUM
Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via unknown vectors, related to the put_tty_queue and __f_setown functions. NOTE: the vulnerability was addressed in a different way in 2.6.32.9.
CVE-2023-4522 1 Gitlab 1 Gitlab 2023-12-28 N/A 5.3 MEDIUM
An issue has been discovered in GitLab affecting all versions before 16.2.0. Committing directories containing LF character results in 500 errors when viewing the commit.
CVE-2022-46705 1 Apple 6 Ipados, Iphone Os, Macos and 3 more 2023-12-28 N/A 4.3 MEDIUM
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, Safari 16.2. Visiting a malicious website may lead to address bar spoofing.
CVE-2023-0563 1 Phpgurukul 1 Bank Locker Management System 2023-12-28 N/A 4.8 MEDIUM
A vulnerability classified as problematic has been found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown part of the file add-locker-form.php of the component Assign Locker. The manipulation of the argument ahname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-219717 was assigned to this vulnerability.
CVE-2023-33951 2 Linux, Redhat 4 Linux Kernel, Enterprise Linux, Enterprise Linux For Real Time and 1 more 2023-12-28 N/A 5.3 MEDIUM
A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. The issue results from improper locking when performing operations on an object. This flaw allows a local privileged user to disclose information in the context of the kernel.
CVE-2023-34968 4 Debian, Fedoraproject, Redhat and 1 more 5 Debian Linux, Fedora, Enterprise Linux and 2 more 2023-12-28 N/A 5.3 MEDIUM
A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path.
CVE-2023-4132 4 Debian, Fedoraproject, Linux and 1 more 6 Debian Linux, Fedora, Linux Kernel and 3 more 2023-12-28 N/A 5.5 MEDIUM
A use-after-free vulnerability was found in the siano smsusb module in the Linux kernel. The bug occurs during device initialization when the siano device is plugged in. This flaw allows a local user to crash the system, causing a denial of service condition.
CVE-2023-36942 1 Phpgurukul 1 Online Fire Reporting System 2023-12-28 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the website title field.
CVE-2023-7059 1 Remyandrade 1 School Visitor Log E-book 2023-12-28 N/A 5.4 MEDIUM
A vulnerability was found in SourceCodester School Visitor Log e-Book 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file log-book.php. The manipulation of the argument Full Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248750 is the identifier assigned to this vulnerability.
CVE-2023-7057 1 Carmelogarcia 1 Faculty Management System 2023-12-28 N/A 6.1 MEDIUM
A vulnerability, which was classified as problematic, has been found in code-projects Faculty Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/pages/yearlevel.php. The manipulation of the argument Year Level/Section leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-248744.
CVE-2023-7056 1 Carmelogarcia 1 Faculty Management System 2023-12-28 N/A 5.4 MEDIUM
A vulnerability classified as problematic was found in code-projects Faculty Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/pages/subjects.php. The manipulation of the argument Description/Units leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248743.