Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-47579 1 Relyum 2 Rely-pcie, Rely-pcie Firmware 2023-12-18 N/A 7.5 HIGH
Relyum RELY-PCIe 22.2.1 devices suffer from a system group misconfiguration, allowing read access to the central password hash file of the operating system.
CVE-2023-36019 1 Microsoft 2 Azure Logic Apps, Power Platform 2023-12-18 N/A 7.4 HIGH
Microsoft Power Platform Connector Spoofing Vulnerability
CVE-2023-36012 1 Microsoft 5 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 2 more 2023-12-18 N/A 5.3 MEDIUM
DHCP Server Service Information Disclosure Vulnerability
CVE-2023-36011 1 Microsoft 12 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 9 more 2023-12-18 N/A 7.8 HIGH
Win32k Elevation of Privilege Vulnerability
CVE-2023-4304 1 Froxlor 1 Froxlor 2023-12-18 N/A 2.7 LOW
Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.22,2.1.0.
CVE-2023-42890 1 Apple 6 Ipados, Iphone Os, Macos and 3 more 2023-12-18 N/A 8.8 HIGH
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2. Processing web content may lead to arbitrary code execution.
CVE-2023-23583 3 Debian, Intel, Netapp 443 Debian Linux, Core I3-1005g1, Core I3-1005g1 Firmware and 440 more 2023-12-16 N/A 7.8 HIGH
Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.
CVE-2023-48634 3 Adobe, Apple, Microsoft 3 After Effects, Macos, Windows 2023-12-16 N/A 7.8 HIGH
Adobe After Effects versions 24.0.3 (and earlier) and 23.6.0 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2023-5058 1 Phoenix 1 Securecore Technology 2023-12-16 N/A 7.8 HIGH
Improper Input Validation in the processing of user-supplied splash screen during system boot in Phoenix SecureCore™ Technology™ 4 potentially allows denial-of-service attacks or arbitrary code execution.
CVE-2023-36403 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2023-12-15 N/A 7.0 HIGH
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-36404 1 Microsoft 11 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 8 more 2023-12-15 N/A 5.5 MEDIUM
Windows Kernel Information Disclosure Vulnerability
CVE-2023-36406 1 Microsoft 5 Windows 11 21h2, Windows 11 22h2, Windows 11 23h2 and 2 more 2023-12-15 N/A 5.5 MEDIUM
Windows Hyper-V Information Disclosure Vulnerability
CVE-2023-36405 1 Microsoft 11 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 8 more 2023-12-15 N/A 7.0 HIGH
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-36407 1 Microsoft 5 Windows 11 21h2, Windows 11 22h2, Windows 11 23h2 and 2 more 2023-12-15 N/A 7.8 HIGH
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2023-36408 1 Microsoft 11 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 8 more 2023-12-15 N/A 7.8 HIGH
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2023-36424 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2023-12-15 N/A 7.8 HIGH
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2023-36425 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2023-12-15 N/A 8.0 HIGH
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
CVE-2023-36427 1 Microsoft 9 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 6 more 2023-12-15 N/A 7.0 HIGH
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2023-36428 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2023-12-15 N/A 5.5 MEDIUM
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
CVE-2023-36705 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2023-12-15 N/A 7.8 HIGH
Windows Installer Elevation of Privilege Vulnerability
CVE-2023-35621 1 Microsoft 1 Dynamics 365 2023-12-15 N/A 7.5 HIGH
Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability
CVE-2023-21740 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2023-12-15 N/A 7.8 HIGH
Windows Media Remote Code Execution Vulnerability
CVE-2008-2160 1 Microsoft 1 Windows Embedded Compact 2023-12-15 9.3 HIGH N/A
Multiple unspecified vulnerabilities in the JPEG (GDI+) and GIF image processing in Microsoft Windows CE 5.0 allow remote attackers to execute arbitrary code via crafted (1) JPEG and (2) GIF images.
CVE-2023-24934 1 Microsoft 1 Malware Protection Platform 2023-12-15 N/A 5.5 MEDIUM
Microsoft Defender Security Feature Bypass Vulnerability
CVE-2023-6759 1 Thecosy 1 Icecms 2023-12-15 N/A 7.5 HIGH
A vulnerability classified as problematic has been found in Thecosy IceCMS 2.0.1. This affects an unknown part of the file /WebResource/resource of the component Love Handler. The manipulation leads to improper enforcement of a single, unique action. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-247887.
CVE-2023-20275 1 Cisco 2 Adaptive Security Appliance Software, Firepower Threat Defense 2023-12-15 N/A 4.3 MEDIUM
A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to send packets with another VPN user's source IP address. This vulnerability is due to improper validation of the packet's inner source IP address after decryption. An attacker could exploit this vulnerability by sending crafted packets through the tunnel. A successful exploit could allow the attacker to send a packet impersonating another VPN user's IP address. It is not possible for the attacker to receive return packets.
CVE-2020-12612 1 Beyondtrust 1 Privilege Management For Windows 2023-12-15 N/A 7.8 HIGH
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When specifying a program to elevate, it can typically be found within the Program Files (x86) folder and therefore uses the %ProgramFiles(x86)% environment variable. However, when this same policy gets pushed to a 32bit machine, this environment variable does not exist. Therefore, since the standard user can create a user level environment variable, they can repoint this variable to any folder the user has full control of. Then, the folder structure can be created in such a way that a rule matches and arbitrary code runs elevated.
CVE-2020-12615 1 Beyondtrust 1 Privilege Management For Windows 2023-12-15 N/A 7.8 HIGH
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding the Add Admin token to a process, and specifying that it runs at medium integrity with the user owning the process, this security token can be stolen and applied to arbitrary processes.
CVE-2023-35644 1 Microsoft 8 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 5 more 2023-12-15 N/A 7.8 HIGH
Windows Sysmain Service Elevation of Privilege
CVE-2023-35643 1 Microsoft 4 Windows Server 2012, Windows Server 2016, Windows Server 2019 and 1 more 2023-12-15 N/A 7.5 HIGH
DHCP Server Service Information Disclosure Vulnerability
CVE-2023-35642 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2023-12-15 N/A 6.5 MEDIUM
Internet Connection Sharing (ICS) Denial of Service Vulnerability
CVE-2023-35641 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2023-12-15 N/A 8.8 HIGH
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
CVE-2023-35639 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2023-12-15 N/A 8.8 HIGH
Microsoft ODBC Driver Remote Code Execution Vulnerability
CVE-2023-6727 1 Mattermost 1 Mattermost Server 2023-12-15 N/A 4.3 MEDIUM
Mattermost fails to perform correct authorization checks when creating a playbook action, allowing users without access to the playbook to create playbook actions. If the playbook action created is to post a message in a channel based on specific keywords in a post, some playbook information, like the name, can be leaked. 
CVE-2023-49578 1 Sap 1 Cloud Connector 2023-12-15 N/A 3.5 LOW
SAP Cloud Connector - version 2.0, allows an authenticated user with low privilege to perform Denial of service attack from adjacent UI by sending a malicious request which leads to low impact on the availability and no impact on confidentiality or Integrity  of the application.
CVE-2023-6757 1 Thecosy 1 Icecms 2023-12-15 N/A 6.5 MEDIUM
A vulnerability was found in Thecosy IceCMS 2.0.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /adplanet/PlanetUser of the component API. The manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247885 was assigned to this vulnerability.
CVE-2023-4886 2 Redhat, Theforeman 2 Satellite, Foreman 2023-12-14 N/A 4.4 MEDIUM
A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable.
CVE-2023-36391 1 Microsoft 1 Windows 11 23h2 2023-12-14 N/A 7.8 HIGH
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
CVE-2023-35638 1 Microsoft 4 Windows Server 2012, Windows Server 2016, Windows Server 2019 and 1 more 2023-12-14 N/A 7.5 HIGH
DHCP Server Service Denial of Service Vulnerability
CVE-2023-35625 1 Microsoft 1 Azure Machine Learning Software Development Kit 2023-12-14 N/A 4.7 MEDIUM
Azure Machine Learning Compute Instance for SDK Users Information Disclosure Vulnerability
CVE-2023-35622 1 Microsoft 6 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 3 more 2023-12-14 N/A 7.5 HIGH
Windows DNS Spoofing Vulnerability
CVE-2023-35624 1 Microsoft 1 Azure Connected Machine Agent 2023-12-14 N/A 7.3 HIGH
Azure Connected Machine Agent Elevation of Privilege Vulnerability
CVE-2023-35628 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2023-12-14 N/A 8.1 HIGH
Windows MSHTML Platform Remote Code Execution Vulnerability
CVE-2023-35629 1 Microsoft 3 Windows 10 1507, Windows Server 2008, Windows Server 2012 2023-12-14 N/A 6.8 MEDIUM
Microsoft USBHUB 3.0 Device Driver Remote Code Execution Vulnerability
CVE-2023-36696 1 Microsoft 9 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 6 more 2023-12-14 N/A 7.8 HIGH
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2023-35630 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2023-12-14 N/A 8.8 HIGH
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
CVE-2023-35631 1 Microsoft 4 Windows 11 21h2, Windows 11 22h2, Windows 11 23h2 and 1 more 2023-12-14 N/A 7.8 HIGH
Win32k Elevation of Privilege Vulnerability
CVE-2023-35632 1 Microsoft 9 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 6 more 2023-12-14 N/A 7.8 HIGH
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2023-35634 1 Microsoft 3 Windows 11 21h2, Windows 11 22h2, Windows 11 23h2 2023-12-14 N/A 8.8 HIGH
Windows Bluetooth Driver Remote Code Execution Vulnerability
CVE-2023-35636 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2023-12-14 N/A 6.5 MEDIUM
Microsoft Outlook Information Disclosure Vulnerability