Common Vulnerabilities and Exposures (CVE) is a critical tool for maintaining software security, providing a standardized way to track and manage vulnerabilities across systems. Organizations should regularly monitor CVE databases, assess the impact of vulnerabilities, and apply patches promptly to reduce the risk of exploitation.
CVE (Common Vulnerabilities and Exposures) is a public database that provides a standardized method for identifying, tracking, and referencing publicly disclosed security vulnerabilities in software and hardware.
Each vulnerability receives a unique identifier called a CVE ID (e.g., CVE-2023-12345), making it easier to reference specific vulnerabilities across different tools and databases.
Total Search Results: 158437
CVE ID | Description | Severity | Published Date | Affected Vendor | Action |
---|---|---|---|---|---|
CVE-2023-28498 | Cross-Site Request Forgery (CSRF) vulnerability in MotoPress Hotel Booking Lite plugin <= 4.6.0 versions. | Unknown | N/A | MotoPress | |
CVE-2023-28499 | Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in simonpedge Slide Anything – Responsive Content / HTML Slider and Carousel plugin <= 2.4.9 versions. | Unknown | N/A | simonpedge | |
CVE-2023-2850 | NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user information to be extracted by attacker. | Unknown | N/A | NodeBB | |
CVE-2023-28500 | A Java insecure deserialization vulnerability in Adobe LiveCycle ES4 version 11.0 and earlier allows unauthenticated remote attackers to gain operating system code execution by submitting specially crafted Java serialized objects to a specific URL. Adobe LiveCycle ES4 version 11.0.1 and later may be vulnerable if the application is installed with Java environment 7u21 and earlier. Exploitation of the vulnerability depends on two factors: insecure deserialization methods used in the Adobe LiveCycle application, and the use of Java environments 7u21 and earlier. The code execution is performed in the context of the account that is running the Adobe LiveCycle application. If the account is privileged, exploitation provides privileged access to the operating system. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | Unknown | N/A | n/a | |
CVE-2023-28501 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based buffer overflow in the unirpcd daemon that, if successfully exploited, can lead to remote code execution as the root user. | Unknown | N/A | Rocket Software | |
CVE-2023-28502 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "udadmin" service that can lead to remote code execution as the root user. | Unknown | N/A | Rocket Software | |
CVE-2023-28503 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user. | Unknown | N/A | Rocket Software | |
CVE-2023-28504 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow that can lead to remote code execution as the root user. | Unknown | N/A | Rocket Software | |
CVE-2023-28505 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer overflow in an API function, where a string is copied into a caller-provided buffer without checking the length. This requires a valid login to exploit. | Unknown | N/A | Rocket Software | |
CVE-2023-28506 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow, where a string is copied into a buffer using a memcpy-like function and a user-provided length. This requires a valid login to exploit. | Unknown | N/A | Rocket Software | |
CVE-2023-28507 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a memory-exhaustion issue, where a decompression routine will allocate increasing amounts of memory until all system memory is exhausted and the forked process crashes. | Unknown | N/A | Rocket Software | |
CVE-2023-28508 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based overflow vulnerability, where certain input can corrupt the heap and crash the forked process. | Unknown | N/A | Rocket Software | |
CVE-2023-28509 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption for packet-level security and passwords transferred on the wire. | Unknown | N/A | Rocket Software | |
CVE-2023-2851 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AGT Tech Ceppatron allows Command Line Execution through SQL Injection, SQL Injection.This issue affects all versions of the sofware also EOS when CVE-ID assigned. | Unknown | N/A | AGT Tech | |
CVE-2023-28512 | IBM Watson CP4D Data Stores 4.6.0, 4.6.1, and 4.6.2 could allow an attacker with specific knowledge about the system to manipulate data due to improper input validation. IBM X-Force ID: 250396. | Unknown | N/A | IBM | |
CVE-2023-28513 | IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.3 CD and IBM MQ Appliance 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.2 LTS, under certain configurations, is vulnerable to a denial of service attack caused by an error processing messages. IBM X-Force ID: 250397. | Unknown | N/A | IBM | |
CVE-2023-28514 | IBM MQ 8.0, 9.0, and 9.1 could allow a local user to obtain sensitive credential information when a detailed technical error message is returned in a stack trace. IBM X-Force ID: 250398. | Unknown | N/A | IBM | |
CVE-2023-28517 | IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 250421. | Unknown | N/A | IBM | |
CVE-2023-2852 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Softmed SelfPatron allows SQL Injection.This issue affects SelfPatron : before 2.0. | Unknown | N/A | Softmed | |
CVE-2023-28520 | IBM Planning Analytics Local 2.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 250454. | Unknown | N/A | IBM | |
CVE-2023-28522 | IBM API Connect V10 could allow an authenticated user to perform actions that they should not have access to. IBM X-Force ID: 250585. | Unknown | N/A | IBM | |
CVE-2023-28523 | IBM Informix Dynamic Server 12.10 and 14.10 onsmsync is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 250753. | Unknown | N/A | IBM | |
CVE-2023-28525 | IBM Engineering Requirements Management 9.7.2.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 251052. | Unknown | N/A | IBM | |
CVE-2023-28526 | IBM Informix Dynamic Server 12.10 and 14.10 archecker is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a local user to cause a segmentation fault. IBM X-Force ID: 251204. | Unknown | N/A | IBM | |
CVE-2023-28527 | IBM Informix Dynamic Server 12.10 and 14.10 cdr is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a local user to cause a segmentation fault. IBM X-Force ID: 251206. | Unknown | N/A | IBM | |
CVE-2023-28528 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 251207. | Unknown | N/A | IBM | |
CVE-2023-28529 | IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 251213. | Unknown | N/A | IBM | |
CVE-2023-2853 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Softmed SelfPatron allows Reflected XSS.This issue affects SelfPatron : before 2.0. | Unknown | N/A | Softmed | |
CVE-2023-28530 | IBM Cognos Analytics 11.1 and 11.2 is vulnerable to stored cross-site scripting, caused by improper validation of SVG Files in Custom Visualizations. A remote attacker could exploit this vulnerability to execute scripts in a victim's Web browser within the security context of the hosting Web site. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. IBM X-Force ID: 251214. | Unknown | N/A | IBM | |
CVE-2023-28531 | ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9. | Unknown | N/A | n/a | |
CVE-2023-28533 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in M Williams Cab Grid plugin <= 1.5.15 versions. | Unknown | N/A | M Williams | |
CVE-2023-28534 | Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in WP Job Portal WP Job Portal – A Complete Job Board plugin <= 2.0.0 versions. | Unknown | N/A | WP Job Portal | |
CVE-2023-28535 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Paytm Paytm Payment Donation plugin <= 2.2.0 versions. | Unknown | N/A | Paytm | |
CVE-2023-28537 | Memory corruption while allocating memory in COmxApeDec module in Audio. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28538 | Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28539 | Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-2854 | BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file | Unknown | N/A | Wireshark Foundation | |
CVE-2023-28540 | Cryptographic issue in Data Modem due to improper authentication during TLS handshake. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28541 | Memory Corruption in Data Modem while processing DMA buffer release event about CFR data. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28542 | Memory Corruption in WLAN HOST while fetching TX status information. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28543 | A malformed DLC can trigger Memory Corruption in SNPE library due to out of bounds read, such as by loading an untrusted model (e.g. from a remote source). | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28544 | Memory corruption in WLAN while sending transmit command from HLOS to UTF handlers. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28545 | Memory corruption in TZ Secure OS while loading an app ELF. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28546 | Memory Corruption in SPS Application while exporting public key in sorter TA. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28547 | Memory corruption in SPS Application while requesting for public key in sorter TA. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28548 | Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28549 | Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-2855 | Candump log parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file | Unknown | N/A | Wireshark Foundation | |
CVE-2023-28550 | Memory corruption in MPP performance while accessing DSM watermark using external memory address. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28551 | Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28553 | Information Disclosure in WLAN Host when processing WMI event command. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28554 | Information Disclosure in Qualcomm IPC while reading values from shared memory in VM. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28555 | Transient DOS in Audio while remapping channel buffer in media codec decoding. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28556 | Cryptographic issue in HLOS during key management. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28557 | Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28558 | Memory corruption in WLAN handler while processing PhyID in Tx status handler. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28559 | Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-2856 | VMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file | Unknown | N/A | Wireshark Foundation | |
CVE-2023-28560 | Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28561 | Memory corruption in QESL while processing payload from external ESL device to firmware. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28562 | Memory corruption while handling payloads from remote ESL. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28563 | Information disclosure in IOE Firmware while handling WMI command. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28564 | Memory corruption in WLAN HAL while passing command parameters through WMI interfaces. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28565 | Memory corruption in WLAN HAL while handling command streams through WMI interfaces. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28566 | Information disclosure in WLAN HAL while handling the WMI state info command. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28567 | Memory corruption in WLAN HAL while handling command through WMI interfaces. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28568 | Information disclosure in WLAN HAL when reception status handler is called. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28569 | Information disclosure in WLAN HAL while handling command through WMI interfaces. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-2857 | BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file | Unknown | N/A | Wireshark Foundation | |
CVE-2023-28570 | Memory corruption while processing audio effects. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28571 | Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28572 | Memory corruption in WLAN HOST while processing the WLAN scan descriptor list. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28573 | Memory corruption in WLAN HAL while parsing WMI command parameters. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28574 | Memory corruption in core services when Diag handler receives a command to configure event listeners. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28575 | The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28576 | The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), causing checks (e.g. size checks) in kernel code to be invalid. This may lead to out-of-bounds read/write issues. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28577 | In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEASE_BUF to unmap the kernel va which cause UAF of the kernel address. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28578 | Memory corruption in Core Services while executing the command for removing a single event listener. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28579 | Memory Corruption in WLAN Host while deserializing the input PMK bytes without checking the input PMK length. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-2858 | NetScaler file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file | Unknown | N/A | Wireshark Foundation | |
CVE-2023-28580 | Memory corruption in WLAN Host while setting the PMK length in PMK length in internal cache. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28581 | Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28582 | Memory corruption in Data Modem while verifying hello-verify message during the DTLS handshake. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28583 | Memory corruption when IPv6 prefix timer object`s lifetime expires which are created while Netmgr daemon gets an IPv6 address. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28584 | Transient DOS in WLAN Host when a mobile station receives invalid channel in CSA IE while doing channel switch announcement (CSA). | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28585 | Memory corruption while loading an ELF segment in TEE Kernel. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28586 | Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28587 | Memory corruption in BT controller while parsing debug commands with specific sub-opcodes at HCI interface level. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-28588 | Transient DOS in Bluetooth Host while rfc slot allocation. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2023-2859 | Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | Unknown | N/A | nilsteampassnet | |
CVE-2023-28596 | Zoom Client for IT Admin macOS installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain during the installation process to escalate their privileges to privileges to root. | Unknown | N/A | Zoom Video Communications Inc | |
CVE-2023-28597 | Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond to client requests, causing the client to execute attacker controlled executables. This could result in an attacker gaining access to a user's device and data, and remote code execution. | Unknown | N/A | Zoom Video Communications Inc | |
CVE-2023-28598 | Zoom for Linux clients prior to 5.13.10 contain an HTML injection vulnerability. If a victim starts a chat with a malicious user it could result in a Zoom application crash. | Unknown | N/A | Zoom Video Communications, Inc. | |
CVE-2023-28599 | Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victim to a malicious website during meeting creation. | Unknown | N/A | Zoom Video Communications, Inc. | |
CVE-2023-2860 | An out-of-bounds read vulnerability was found in the SR-IPv6 implementation in the Linux kernel. The flaw exists within the processing of seg6 attributes. The issue results from the improper validation of user-supplied data, which can result in a read past the end of an allocated buffer. This flaw allows a privileged local user to disclose sensitive information on affected installations of the Linux kernel. | Unknown | N/A | n/a | |
CVE-2023-28600 | Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to delete/replace Zoom Client files potentially causing a loss of integrity and availability to the Zoom Client. | Unknown | N/A | Zoom Video Communications, Inc. | |
CVE-2023-28601 | Zoom for Windows clients prior to 5.14.0 contain an improper restriction of operations within the bounds of a memory buffer vulnerability. A malicious user may alter protected Zoom Client memory buffer potentially causing integrity issues within the Zoom Client. | Unknown | N/A | Zoom Video Communications, Inc. | |
CVE-2023-28602 | Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially downgrade Zoom Client components to previous versions. | Unknown | N/A | Zoom Video Communications, Inc. | |
CVE-2023-28603 | Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may potentially delete local files without proper permissions. | Unknown | N/A | Zoom Video Communications, Inc. | |
CVE-2023-28604 | The fluid_components (aka Fluid Components) extension before 3.5.0 for TYPO3 allows XSS via a component argument parameter, for certain {content} use cases that may be edge cases. | Unknown | N/A | n/a |
vunerability-insight.com © 2023 - 2025. All Rights Reserved.
Vulnerability Data Repositories v