Common Vulnerabilities and Exposures (CVE) is a critical tool for maintaining software security, providing a standardized way to track and manage vulnerabilities across systems. Organizations should regularly monitor CVE databases, assess the impact of vulnerabilities, and apply patches promptly to reduce the risk of exploitation.
CVE (Common Vulnerabilities and Exposures) is a public database that provides a standardized method for identifying, tracking, and referencing publicly disclosed security vulnerabilities in software and hardware.
Each vulnerability receives a unique identifier called a CVE ID (e.g., CVE-2023-12345), making it easier to reference specific vulnerabilities across different tools and databases.
Total Search Results: 158437
CVE ID | Description | Severity | Published Date | Affected Vendor | Action |
---|---|---|---|---|---|
CVE-2023-2337 | The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | Unknown | N/A | Unknown | |
CVE-2023-23370 | An insufficiently protected credentials vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated administrators to gain access to user accounts and access sensitive data used by the user account via unspecified vectors. We have already fixed the vulnerability in the following version: QVPN Windows 2.1.0.0518 and later | Unknown | N/A | QNAP Systems Inc. | |
CVE-2023-23371 | A cleartext transmission of sensitive information vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated administrators to read sensitive data via unspecified vectors. We have already fixed the vulnerability in the following version: QVPN Windows 2.2.0.0823 and later | Unknown | N/A | QNAP Systems Inc. | |
CVE-2023-23372 | A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444 build 20230629 and later QTS 4.5.4.2467 build 20230718 and later QuTS hero h5.1.0.2424 build 20230609 and later QuTS hero h5.0.1.2515 build 20230907 and later QuTS hero h4.5.4.2476 build 20230728 and later | Unknown | N/A | QNAP Systems Inc. | |
CVE-2023-23373 | An OS command injection vulnerability has been reported to affect QUSBCam2. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following version: QUSBCam2 2.0.3 ( 2023/06/15 ) and later | Unknown | N/A | QNAP Systems Inc. | |
CVE-2023-23374 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23375 | Microsoft ODBC and OLE DB Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23376 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23377 | 3D Builder Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23378 | Print 3D Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23379 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-2338 | SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.21. | Unknown | N/A | pimcore | |
CVE-2023-23381 | Visual Studio Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23382 | Azure Machine Learning Compute Instance Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23383 | Service Fabric Explorer Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23384 | Microsoft SQL Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23385 | Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23388 | Windows Bluetooth Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23389 | Microsoft Defender Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-2339 | Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21. | Unknown | N/A | pimcore | |
CVE-2023-23390 | 3D Builder Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23391 | Office for Android Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23392 | HTTP Protocol Stack Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23393 | Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23394 | Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23395 | Microsoft SharePoint Server Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23396 | Microsoft Excel Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23397 | Microsoft Outlook Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23398 | Microsoft Excel Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23399 | Microsoft Excel Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-2340 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21. | Unknown | N/A | pimcore | |
CVE-2023-23400 | Windows DNS Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23401 | Windows Media Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23402 | Windows Media Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23403 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23404 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23405 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23406 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23407 | Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23408 | Azure Apache Ambari Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23409 | Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-2341 | Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21. | Unknown | N/A | pimcore | |
CVE-2023-23410 | Windows HTTP.sys Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23411 | Windows Hyper-V Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23412 | Windows Accounts Picture Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23413 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23414 | Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23415 | Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23416 | Windows Cryptographic Services Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23417 | Windows Partition Management Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23418 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23419 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-2342 | Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21. | Unknown | N/A | pimcore | |
CVE-2023-23420 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23421 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23422 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23423 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-23424 | Some Honor products are affected by file writing vulnerability, successful exploitation could cause code execution | Unknown | N/A | Honor | |
CVE-2023-23426 | Some Honor products are affected by file writing vulnerability, successful exploitation could cause information disclosure. | Unknown | N/A | Honor | |
CVE-2023-23427 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions. | Unknown | N/A | Honor | |
CVE-2023-23428 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions. | Unknown | N/A | Honor | |
CVE-2023-23429 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions. | Unknown | N/A | Honor | |
CVE-2023-2343 | Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21. | Unknown | N/A | pimcore | |
CVE-2023-23430 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions. | Unknown | N/A | Honor | |
CVE-2023-23431 | Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file. | Unknown | N/A | Honor | |
CVE-2023-23432 | Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file. | Unknown | N/A | Honor | |
CVE-2023-23433 | Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file. | Unknown | N/A | Honor | |
CVE-2023-23434 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | Unknown | N/A | Honor | |
CVE-2023-23435 | Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file | Unknown | N/A | Honor | |
CVE-2023-23436 | Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file | Unknown | N/A | Honor | |
CVE-2023-23437 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak | Unknown | N/A | Honor | |
CVE-2023-23438 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions | Unknown | N/A | Honor | |
CVE-2023-23439 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | Unknown | N/A | Honor | |
CVE-2023-2344 | A vulnerability has been found in SourceCodester Service Provider Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=save_service of the component HTTP POST Request Handler. The manipulation of the argument name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227587. | Unknown | N/A | SourceCodester | |
CVE-2023-23440 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | Unknown | N/A | Honor | |
CVE-2023-23441 | Some Honor products are affected by out of bounds read vulnerability, successful exploitation could cause information leak. | Unknown | N/A | Honor | |
CVE-2023-23442 | Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak. | Unknown | N/A | Honor | |
CVE-2023-23443 | Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak. | Unknown | N/A | Honor | |
CVE-2023-23444 | Missing Authentication for Critical Function in SICK Flexi Classic and Flexi Soft Gateways with Partnumbers 1042193, 1042964, 1044078, 1044072, 1044073, 1044074, 1099830, 1099832, 1127717, 1069070, 1112296, 1051432, 1102420, 1127487, 1121596, 1121597 allows an unauthenticated remote attacker to influence the availability of the device by changing the IP settings of the device via broadcasted UDP packets. | Unknown | N/A | SICK AG | |
CVE-2023-23445 | Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by using a therefore unpriviledged account via the REST interface. | Unknown | N/A | SICK AG | |
CVE-2023-23446 | Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviledged account via the REST interface. | Unknown | N/A | SICK AG | |
CVE-2023-23447 | Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to influence the availability of the webserver by invocing several open file requests via the REST interface. | Unknown | N/A | SICK AG | |
CVE-2023-23448 | Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code. | Unknown | N/A | SICK AG | |
CVE-2023-23449 | Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames by analyzing challenge responses from the server via the REST interface. | Unknown | N/A | SICK AG | |
CVE-2023-2345 | A vulnerability was found in SourceCodester Service Provider Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=delete_inquiry. The manipulation leads to improper authorization. The attack may be launched remotely. The identifier of this vulnerability is VDB-227588. | Unknown | N/A | SourceCodester | |
CVE-2023-23450 | Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to use a password hash instead of an actual password to login to a valid user account via the REST interface. | Unknown | N/A | SICK AG | |
CVE-2023-23451 | The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN1 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN3S04 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN4 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK FX0-GENT00000 FLEXISOFT EIP GATEW. with serial number <=2311xxxx with Firmware <=V2.11.0, SICK FX0-GMOD00000 FLEXISOFT MOD GATEW. with serial number <=2311xxxx with Firmware <=V2.11.0, SICK FX0-GPNT00000 FLEXISOFT PNET GATEW. with serial number <=2311xxxx with Firmware <=V2.12.0, SICK FX0-GENT00030 FLEXISOFT EIP GATEW.V2 with serial number <=2311xxxx all Firmware versions, SICK FX0-GPNT00030 FLEXISOFT PNET GATEW.V2 with serial number <=2311xxxx all Firmware versions and SICK FX0-GMOD00010 FLEXISOFT MOD GW with serial number <=2311xxxx with Firmware <=V2.11.0 all have Telnet enabled by factory default. No password is set in the default configuration. | Unknown | N/A | N/A | |
CVE-2023-23452 | Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000. | Unknown | N/A | n/a | |
CVE-2023-23453 | Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000. | Unknown | N/A | n/a | |
CVE-2023-23454 | cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results). | Unknown | N/A | n/a | |
CVE-2023-23455 | atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results). | Unknown | N/A | n/a | |
CVE-2023-23456 | A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file. | Unknown | N/A | Unknown | |
CVE-2023-23457 | A Segmentation fault was found in UPX in PackLinuxElf64::invert_pt_dynamic() in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service. | Unknown | N/A | Unknown | |
CVE-2023-23458 | Sunell DVR, latest version, CWE-200: Exposure of Sensitive Information to an Unauthorized Actor through an unspecified request. | Unknown | N/A | Sunell | |
CVE-2023-23459 | Priority Windows may allow Command Execution via SQL Injection using an unspecified method. | Unknown | N/A | Priority | |
CVE-2023-2346 | A vulnerability was found in SourceCodester Service Provider Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/inquiries/view_inquiry.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227589 was assigned to this vulnerability. | Unknown | N/A | SourceCodester | |
CVE-2023-23460 | Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass. | Unknown | N/A | Priority | |
CVE-2023-23461 | Libpeconv – access violation, before commit b076013 (30/11/2022). | Unknown | N/A | Hasherezade (github) | |
CVE-2023-23462 | Libpeconv – integer overflow, before commit 75b1565 (30/11/2022). | Unknown | N/A | Hasherezade (github) | |
CVE-2023-23463 | Sunell DVR, latest version, Insufficiently Protected Credentials (CWE-522) may be exposed through an unspecified request. | Unknown | N/A | Sunell |
vunerability-insight.com © 2023 - 2025. All Rights Reserved.
Vulnerability Data Repositories v