Common Vulnerabilities and Exposures (CVE) is a critical tool for maintaining software security, providing a standardized way to track and manage vulnerabilities across systems. Organizations should regularly monitor CVE databases, assess the impact of vulnerabilities, and apply patches promptly to reduce the risk of exploitation.
CVE (Common Vulnerabilities and Exposures) is a public database that provides a standardized method for identifying, tracking, and referencing publicly disclosed security vulnerabilities in software and hardware.
Each vulnerability receives a unique identifier called a CVE ID (e.g., CVE-2023-12345), making it easier to reference specific vulnerabilities across different tools and databases.
Total Search Results: 158437
CVE ID | Description | Severity | Published Date | Affected Vendor | Action |
---|---|---|---|---|---|
CVE-2023-21675 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21676 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21677 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21678 | Windows Print Spooler Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21679 | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-2168 | The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Suggest Terms Title field in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | Unknown | N/A | stevejburge | |
CVE-2023-21680 | Windows Win32k Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21681 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21682 | Windows Point-to-Point Protocol (PPP) Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21683 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21684 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21685 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21686 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21687 | HTTP.sys Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21688 | NT OS Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21689 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-2169 | The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | Unknown | N/A | stevejburge | |
CVE-2023-21690 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21691 | Microsoft Protected Extensible Authentication Protocol (PEAP) Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21692 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21693 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21694 | Windows Fax Service Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21695 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21697 | Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21699 | Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-2170 | The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | Unknown | N/A | stevejburge | |
CVE-2023-21700 | Windows iSCSI Discovery Service Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21701 | Microsoft Protected Extensible Authentication Protocol (PEAP) Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21702 | Windows iSCSI Service Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21703 | Azure Data Box Gateway Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21704 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21705 | Microsoft SQL Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21706 | Microsoft Exchange Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21707 | Microsoft Exchange Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21708 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21709 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-2171 | The BadgeOS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.7.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | Unknown | N/A | learningtimes | |
CVE-2023-21710 | Microsoft Exchange Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21712 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21713 | Microsoft SQL Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21714 | Microsoft Office Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21715 | Microsoft Publisher Security Features Bypass Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21716 | Microsoft Word Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21717 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21718 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21719 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-2172 | The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7.1.6. This is due to improper validation and authorization checks within the badgeos_update_steps_ajax_handler, badgeos_update_award_steps_ajax_handler, badgeos_update_deduct_steps_ajax_handler, and badgeos_update_ranks_req_steps_ajax_handler functions. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to overwrite arbitrary post titles. | Unknown | N/A | learningtimes | |
CVE-2023-21720 | Microsoft Edge (Chromium-based) Tampering Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21721 | Microsoft OneNote Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21722 | .NET Framework Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21724 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21725 | Windows Malicious Software Removal Tool Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21726 | Windows Credential Manager User Interface Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21727 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21728 | Windows Netlogon Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21729 | Remote Procedure Call Runtime Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-2173 | The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7.1.6. This is due to improper validation and authorization checks within the badgeos_delete_step_ajax_handler, badgeos_delete_award_step_ajax_handler, badgeos_delete_deduct_step_ajax_handler, and badgeos_delete_rank_req_step_ajax_handler functions. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete arbitrary posts. | Unknown | N/A | learningtimes | |
CVE-2023-21730 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21732 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21733 | Windows Bind Filter Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21734 | Microsoft Office Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21735 | Microsoft Office Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21736 | Microsoft Office Visio Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21737 | Microsoft Office Visio Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21738 | Microsoft Office Visio Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21739 | Windows Bluetooth Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-2174 | The BadgeOS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_badgeos_log_entries function in versions up to, and including, 3.7.1.6. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete the plugin's log entries. | Unknown | N/A | learningtimes | |
CVE-2023-21740 | Windows Media Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21741 | Microsoft Office Visio Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21742 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21743 | Microsoft SharePoint Server Security Feature Bypass Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21744 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21745 | Microsoft Exchange Server Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21746 | Windows NTLM Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21747 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21748 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21749 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21750 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21751 | Azure DevOps Server Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21752 | Windows Backup Service Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21753 | Event Tracing for Windows Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21754 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21755 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21756 | Windows Win32k Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21757 | Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21758 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21759 | Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-2176 | A vulnerability was found in compare_netdev_and_ip in drivers/infiniband/core/cma.c in RDMA in the Linux Kernel. The improper cleanup results in out-of-boundary read, where a local user can utilize this problem to crash the system or escalation of privilege. | Unknown | N/A | n/a | |
CVE-2023-21760 | Windows Print Spooler Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21761 | Microsoft Exchange Server Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21762 | Microsoft Exchange Server Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21763 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21764 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21765 | Windows Print Spooler Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21766 | Windows Overlay Filter Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21767 | Windows Overlay Filter Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21768 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-21769 | Microsoft Message Queuing Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-2177 | A null pointer dereference issue was found in the sctp network protocol in net/sctp/stream_sched.c in Linux Kernel. If stream_in allocation is failed, stream_out is freed which would further be accessed. A local user could use this flaw to crash the system or potentially cause a denial of service. | Unknown | N/A | n/a | |
CVE-2023-21771 | Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft |
vunerability-insight.com © 2023 - 2025. All Rights Reserved.
Vulnerability Data Repositories v