Common Vulnerabilities and Exposures (CVE) is a critical tool for maintaining software security, providing a standardized way to track and manage vulnerabilities across systems. Organizations should regularly monitor CVE databases, assess the impact of vulnerabilities, and apply patches promptly to reduce the risk of exploitation.
CVE (Common Vulnerabilities and Exposures) is a public database that provides a standardized method for identifying, tracking, and referencing publicly disclosed security vulnerabilities in software and hardware.
Each vulnerability receives a unique identifier called a CVE ID (e.g., CVE-2023-12345), making it easier to reference specific vulnerabilities across different tools and databases.
Total Search Results: 158437
CVE ID | Description | Severity | Published Date | Affected Vendor | Action |
---|---|---|---|---|---|
CVE-2023-21461 | Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21462 | The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related permission. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21463 | Improper access control vulnerability in MyFiles application prior to versions 12.2.09.0 in Android 11, 13.1.03.501 in Android 12 and 14.1.03.0 in Android 13 allows local attacker to get sensitive information of secret mode in Samsung Internet application with specific conditions. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21464 | Improper access control in Samsung Calendar prior to versions 12.4.02.9000 in Android 13 and 12.3.08.2000 in Android 12 allows local attacker to configure improper status. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21465 | Improper access control vulnerability in BixbyTouch prior to version 3.2.02.5 in China models allows untrusted applications access local files. | Unknown | N/A | Samsung Mobile | |
CVE-2023-2147 | A vulnerability was found in Campcodes Online Thesis Archiving System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/students/view_details.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226268. | Unknown | N/A | Campcodes | |
CVE-2023-2148 | A vulnerability classified as critical has been found in Campcodes Online Thesis Archiving System 1.0. This affects an unknown part of the file /admin/curriculum/view_curriculum.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-226269 was assigned to this vulnerability. | Unknown | N/A | Campcodes | |
CVE-2023-21484 | Improper access control vulnerability in AppLock prior to SMR May-2023 Release 1 allows local attackers without proper permission to execute a privileged operation. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21485 | Improper export of android application components vulnerability in VideoPreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21486 | Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21487 | Improper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows local attackers to change a call setting. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21488 | Improper access control vulnerablility in Tips prior to SMR May-2023 Release 1 allows local attackers to launch arbitrary activity in Tips. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21489 | Heap out-of-bounds write vulnerability in bootloader prior to SMR May-2023 Release 1 allows a physical attacker to execute arbitrary code. | Unknown | N/A | Samsung Mobile | |
CVE-2023-2149 | A vulnerability classified as critical was found in Campcodes Online Thesis Archiving System 1.0. This vulnerability affects unknown code of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-226270 is the identifier assigned to this vulnerability. | Unknown | N/A | Campcodes | |
CVE-2023-21490 | Improper access control in GearManagerStub prior to SMR May-2023 Release 1 allows a local attacker to delete applications installed by watchmanager. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21491 | Improper access control vulnerability in ThemeManager prior to SMR May-2023 Release 1 allows local attackers to write arbitrary files with system privilege. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21492 | Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21493 | Improper access control vulnerability in SemShareFileProvider prior to SMR May-2023 Release 1 allows local attackers to access protected data. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21494 | Potential buffer overflow vulnerability in auth api in mm_Authentication.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21495 | Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device admin is set. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21496 | Active Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows attacker to use debug function via setting debug level. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21497 | Use of externally-controlled format string vulnerability in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the memory address. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21498 | Improper input validation vulnerability in setPartnerTAInfo in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to overwrite the trustlet memory. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21499 | Out-of-bounds write vulnerability in TA_Communication_mpos_encrypt_pin in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to execute arbitrary code. | Unknown | N/A | Samsung Mobile | |
CVE-2023-2150 | A vulnerability, which was classified as critical, has been found in SourceCodester Task Reminder System 1.0. This issue affects some unknown processing of the file Master.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-226271. | Unknown | N/A | SourceCodester | |
CVE-2023-21500 | Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the trustlet memory. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21501 | Improper input validation vulnerability in mPOS fiserve trustlet prior to SMR May-2023 Release 1 allows local attackers to execute arbitrary code. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21502 | Improper input validation vulnerability in FactoryTest application prior to SMR May-2023 Release 1 allows local attackers to get privilege escalation via debugging commands. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21503 | Potential buffer overflow vulnerability in mm_LteInterRatManagement.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21504 | Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21505 | Improper access control in Samsung Core Service prior to version 2.1.00.36 allows attacker to write arbitrary file in sandbox. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21506 | Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21507 | Out-of-bounds Read vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21508 | Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21509 | Out-of-bounds Write vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code. | Unknown | N/A | Samsung Mobile | |
CVE-2023-2151 | A vulnerability, which was classified as critical, was found in SourceCodester Student Study Center Desk Management System 1.0. Affected is an unknown function of the file manage_student.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226272. | Unknown | N/A | SourceCodester | |
CVE-2023-21510 | Out-of-bounds Read vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21511 | Out-of-bounds Read vulnerability while processing CMD_COLDWALLET_BTC_SET_PRV_UTXO in bc_core trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21512 | Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to read work profile notifications without proper access permission. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21513 | Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21514 | Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21515 | InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21516 | XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21517 | Heap out-of-bound write vulnerability in Exynos baseband prior to SMR Jun-2023 Release 1 allows remote attacker to execute arbitrary code. | Unknown | N/A | Samsung Mobile | |
CVE-2023-21518 | Improper access control vulnerability in SearchWidget prior to version 3.3 in China models allows untrusted applications to start arbitrary activity. | Unknown | N/A | Samsung Mobile | |
CVE-2023-2152 | A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument page leads to file inclusion. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-226273 was assigned to this vulnerability. | Unknown | N/A | SourceCodester | |
CVE-2023-21520 | A PII Enumeration via Credential Recovery in the Self Service (Credential Recovery) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially associate a list of contact details with an AtHoc IWS organization. | Unknown | N/A | BlackBerry | |
CVE-2023-21521 | An SQL Injection vulnerability in the Management Console (Operator Audit Trail) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database, recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system. | Unknown | N/A | BlackBerry | |
CVE-2023-21522 | A Reflected Cross-site Scripting (XSS) vulnerability in the Management Console (Reports) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially control a script that is executed in the victim's browser then they can execute script commands in the context of the affected user account. | Unknown | N/A | BlackBerry | |
CVE-2023-21523 | A Stored Cross-site Scripting (XSS) vulnerability in the Management Console (User Management and Alerts) of BlackBerry AtHoc version 7.15 could allow an attacker to execute script commands in the context of the affected user account. | Unknown | N/A | BlackBerry | |
CVE-2023-21524 | Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21525 | Remote Procedure Call Runtime Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21526 | Windows Netlogon Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21527 | Windows iSCSI Service Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21528 | Microsoft SQL Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21529 | Microsoft Exchange Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-2153 | A vulnerability was found in SourceCodester Complaint Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file admin/assets/plugins/DataTables/examples/examples_support/editable_ajax.php of the component POST Parameter Handler. The manipulation of the argument value with the input 1> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-226274 is the identifier assigned to this vulnerability. | Unknown | N/A | SourceCodester | |
CVE-2023-21531 | Azure Service Fabric Container Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21532 | Windows GDI Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21535 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21536 | Event Tracing for Windows Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21537 | Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21538 | .NET Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21539 | Windows Authentication Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-2154 | A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/?page=reminders/view_reminder. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-226275. | Unknown | N/A | SourceCodester | |
CVE-2023-21540 | Windows Cryptographic Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21541 | Windows Task Scheduler Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21542 | Windows Installer Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21543 | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21546 | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21547 | Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21548 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21549 | Windows SMB Witness Service Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-2155 | A vulnerability was found in SourceCodester Air Cargo Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file classes/Master.php?f=save_cargo_type. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226276. | Unknown | N/A | SourceCodester | |
CVE-2023-21550 | Windows Cryptographic Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21551 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21552 | Windows GDI Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21553 | Azure DevOps Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21554 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21555 | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21556 | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21557 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21558 | Windows Error Reporting Service Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21559 | Windows Cryptographic Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-2156 | A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the system. | Unknown | N/A | n/a | |
CVE-2023-21560 | Windows Boot Manager Security Feature Bypass Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21561 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21563 | BitLocker Security Feature Bypass Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21564 | Azure DevOps Server Cross-Site Scripting Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21565 | Azure DevOps Server Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21566 | Visual Studio Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21567 | Visual Studio Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21568 | Microsoft SQL Server Integration Service (VS extension) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21569 | Azure DevOps Server Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-2157 | A heap-based buffer overflow vulnerability was found in the ImageMagick package that can lead to the application crashing. | Unknown | N/A | n/a | |
CVE-2023-21570 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21571 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21572 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21573 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21574 | Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Unknown | N/A | Adobe |
vunerability-insight.com © 2023 - 2025. All Rights Reserved.
Vulnerability Data Repositories v