Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-22043 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-08-08 7.2 HIGH 7.8 HIGH
Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
CVE-2022-23176 1 Watchguard 1 Fireware 2023-08-08 9.0 HIGH 8.8 HIGH
WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. This vulnerability impacts Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U3, and 12.2.x through 12.5.x before 12.5.7_U3.
CVE-2022-30224 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-08-08 6.9 MEDIUM 7.0 HIGH
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
CVE-2022-30181 1 Microsoft 1 Azure Site Recovery 2023-08-08 5.5 MEDIUM 6.5 MEDIUM
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-27773 1 Ivanti 1 Endpoint Manager 2023-08-08 N/A 9.8 CRITICAL
A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elevated privileges.
CVE-2022-44710 1 Microsoft 1 Windows 11 2023-08-08 N/A 7.8 HIGH
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2022-37905 1 Arubanetworks 12 7005, 7008, 7010 and 9 more 2023-08-08 N/A 8.8 HIGH
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.
CVE-2022-23259 1 Microsoft 1 Dynamics 365 2023-08-08 9.0 HIGH 8.8 HIGH
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
CVE-2022-22572 1 Ivanti 1 Incapptic Connect 2023-08-08 6.5 MEDIUM 8.8 HIGH
A non-admin user with user management permission can escalate his privilege to admin user via password reset functionality. The vulnerability affects Incapptic Connect version < 1.40.1.
CVE-2022-23272 1 Microsoft 1 Dynamics Gp 2023-08-08 9.0 HIGH 8.1 HIGH
Microsoft Dynamics GP Elevation Of Privilege Vulnerability
CVE-2022-44699 1 Microsoft 1 Azure Network Watcher Agent 2023-08-08 N/A 5.5 MEDIUM
Azure Network Watcher Agent Security Feature Bypass Vulnerability
CVE-2022-35766 1 Microsoft 5 Windows 10, Windows 11, Windows Server 2016 and 2 more 2023-08-08 N/A 8.1 HIGH
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVE-2023-1208 1 Riverside 1 Http Headers 2023-08-08 N/A 7.2 HIGH
This HTTP Headers WordPress plugin before 1.18.11 allows arbitrary data to be written to arbitrary files, leading to a Remote Code Execution vulnerability.
CVE-2022-45937 1 Siemens 18 Pxc00-e96.a, Pxc00-e96.a Firmware, Pxc100-e96.a and 15 more 2023-08-08 N/A 6.5 MEDIUM
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), TALON TC Compact (BACnet) (All versions < V3.5.5), TALON TC Modular (BACnet) (All versions < V3.5.5). A low privilege authenticated attacker with network access to the integrated web server could download sensitive information from the device containing user account credentials.
CVE-2023-37550 1 Codesys 16 Control For Beaglebone Sl, Control For Empc-a\/imx6 Sl, Control For Iot2000 Sl and 13 more 2023-08-07 N/A 6.5 MEDIUM
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546, CVE-2023-37547, CVE-2023-37548 and CVE-2023-37549.
CVE-2023-37546 1 Codesys 16 Control For Beaglebone Sl, Control For Empc-a\/imx6 Sl, Control For Iot2000 Sl and 13 more 2023-08-07 N/A 6.5 MEDIUM
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37547, CVE-2023-37548, CVE-2023-37549 and CVE-2023-37550
CVE-2023-37548 1 Codesys 16 Control For Beaglebone Sl, Control For Empc-a\/imx6 Sl, Control For Iot2000 Sl and 13 more 2023-08-07 N/A 6.5 MEDIUM
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546, CVE-2023-37547, CVE-2023-37549 and CVE-2023-37550
CVE-2023-37545 1 Codesys 16 Control For Beaglebone Sl, Control For Empc-a\/imx6 Sl, Control For Iot2000 Sl and 13 more 2023-08-07 N/A 6.5 MEDIUM
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37546, CVE-2023-37547, CVE-2023-37548, CVE-2023-37549, CVE-2023-37550
CVE-2023-37547 1 Codesys 16 Control For Beaglebone Sl, Control For Empc-a\/imx6 Sl, Control For Iot2000 Sl and 13 more 2023-08-07 N/A 6.5 MEDIUM
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546, CVE-2023-37548, CVE-2023-37549 and CVE-2023-37550
CVE-2023-37549 1 Codesys 16 Control For Beaglebone Sl, Control For Empc-a\/imx6 Sl, Control For Iot2000 Sl and 13 more 2023-08-07 N/A 6.5 MEDIUM
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546, CVE-2023-37547, CVE-2023-37548 and CVE-2023-37550
CVE-2023-4008 1 Gitlab 1 Gitlab 2023-08-07 N/A 9.8 CRITICAL
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to takeover GitLab Pages with unique domain URLs if the random string added was known.
CVE-2023-21411 1 Axis 1 License Plate Verifier 2023-08-07 N/A 8.8 HIGH
User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for arbitrary code execution.
CVE-2023-21410 1 Axis 1 License Plate Verifier 2023-08-07 N/A 8.8 HIGH
User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for arbitrary code execution.
CVE-2023-38556 1 Epson 24 Ep-801a, Ep-801a Firmware, Ep-802a and 21 more 2023-08-07 N/A 7.5 HIGH
Improper input validation vulnerability in SEIKO EPSON printer Web Config allows a remote attacker to turned off the printer. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers via a web browser. Web Config is pre-installed in some printers provided by SEIKO EPSON CORPORATION. For the details of the affected product names/model numbers, refer to the information provided by the vendor.
CVE-2022-2346 1 Octopus 1 Octopus Server 2023-08-07 N/A 4.3 MEDIUM
In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoints.
CVE-2020-11732 1 Davidlingren 1 Media Library Assistant 2023-08-07 5.0 MEDIUM 7.5 HIGH
The Media Library Assistant plugin before 2.82 for Wordpress suffers from a Local File Inclusion vulnerability in mla_gallery link=download.
CVE-2020-11928 1 Davidlingren 1 Media Library Assistant 2023-08-07 7.5 HIGH 9.8 CRITICAL
In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin.
CVE-2023-31927 1 Broadcom 1 Brocade Fabric Operating System 2023-08-07 N/A 5.3 MEDIUM
An information disclosure in the web interface of Brocade Fabric OS versions before Brocade Fabric OS v9.2.0 and v9.1.1c, could allow a remote unauthenticated attacker to get technical details about the web interface.
CVE-2023-4054 2 Microsoft, Mozilla 3 Windows, Firefox, Firefox Esr 2023-08-07 N/A 5.5 MEDIUM
When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 102.14, Firefox ESR < 115.1, Thunderbird < 102.14, and Thunderbird < 115.1.
CVE-2023-36141 1 Phpjabbers 1 Cleaning Business Software 2023-08-07 N/A 5.3 MEDIUM
User enumeration is found in in PHPJabbers Cleaning Business Software 1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
CVE-2023-38990 1 Jeesite 1 Jeesite 2023-08-05 N/A 4.3 MEDIUM
An issue in the delete function in the MenuController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete menus created by the Administrator.
CVE-2023-4011 1 Gitlab 1 Gitlab 2023-08-04 N/A 7.5 HIGH
An issue has been discovered in GitLab EE affecting all versions from 15.11 prior to 16.2.2 which allows an attacker to spike the resource consumption resulting in DoS.
CVE-2023-3993 1 Gitlab 1 Gitlab 2023-08-04 N/A 7.5 HIGH
An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. Access tokens may have been logged when a query was made to a specific endpoint.
CVE-2023-3900 1 Gitlab 1 Gitlab 2023-08-04 N/A 7.5 HIGH
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.
CVE-2023-1210 1 Gitlab 1 Gitlab 2023-08-04 N/A 4.3 MEDIUM
An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to leak a user's email via an error message for groups that restrict membership by email domain.
CVE-2023-4051 1 Mozilla 1 Firefox 2023-08-04 N/A 7.5 HIGH
A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116.
CVE-2023-33561 1 Phpjabbers 1 Time Slots Booking Calendar 2023-08-04 N/A 9.8 CRITICAL
Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure passwords.
CVE-2023-33562 1 Phpjabbers 1 Time Slots Booking Calendar 2023-08-04 N/A 9.8 CRITICAL
User enumeration is found in in PHP Jabbers Time Slots Booking Calendar v3.3. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
CVE-2023-37478 1 Pnpm 1 Pnpm 2023-08-04 N/A 9.8 CRITICAL
pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar archives. This can result in a package that appears safe on the npm registry or when installed via npm being replaced with a compromised or malicious version when installed via pnpm. This issue has been patched in version(s) 7.33.4 and 8.6.8.
CVE-2023-38750 1 Zimbra 1 Zimbra 2023-08-04 N/A 7.5 HIGH
In Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41, 9 before 9.0.0 Patch 34, and 10 before 10.0.2, internal JSP and XML files can be exposed.
CVE-2023-36983 1 Lavalite 1 Lavalite 2023-08-04 N/A 7.5 HIGH
LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure.
CVE-2023-36984 1 Lavalite 1 Lavalite 2023-08-04 N/A 7.5 HIGH
LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure.
CVE-2022-43831 1 Ibm 1 Spectrum Scale Container Native Storage Access 2023-08-03 N/A 7.8 HIGH
IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.6.1 could allow a local user to obtain escalated privileges on a host without proper security context settings configured. IBM X-Force ID: 238941.
CVE-2023-37216 1 Anasystem 2 Sensmini M4, Sensmini M4 Firmware 2023-08-03 N/A 6.5 MEDIUM
AnaSystem SensMini M4 – Using the configuration tool, an authenticated user can cause Denial of Service for the device
CVE-2023-38988 1 Jeesite 1 Jeesite 2023-08-03 N/A 4.3 MEDIUM
An issue in the delete function in the OaNotifyController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete notifications created by Administrators.
CVE-2023-37754 1 Powerjob 1 Powerjob 2023-08-03 N/A 9.8 CRITICAL
PowerJob v4.3.3 was discovered to contain a remote command execution (RCE) vulnerability via the instanceId parameter at /instance/detail.
CVE-2023-38685 1 Discourse 1 Discourse 2023-08-03 N/A 4.3 MEDIUM
Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, information about restricted-visibility topic tags could be obtained by unauthorized users. The issue is patched in version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches.
CVE-2023-38602 1 Apple 1 Macos 2023-08-03 N/A 5.5 MEDIUM
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.6.8, macOS Ventura 13.5, macOS Big Sur 11.7.9. An app may be able to modify protected parts of the file system.
CVE-2023-38593 1 Apple 5 Ipados, Iphone Os, Macos and 2 more 2023-08-02 N/A 5.5 MEDIUM
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.8, iOS 16.6 and iPadOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to cause a denial-of-service.
CVE-2023-38603 1 Apple 3 Ipados, Iphone Os, Macos 2023-08-02 N/A 7.5 HIGH
The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. A remote user may be able to cause a denial-of-service.