Common Vulnerabilities and Exposures (CVE) is a critical tool for maintaining software security, providing a standardized way to track and manage vulnerabilities across systems. Organizations should regularly monitor CVE databases, assess the impact of vulnerabilities, and apply patches promptly to reduce the risk of exploitation.
CVE (Common Vulnerabilities and Exposures) is a public database that provides a standardized method for identifying, tracking, and referencing publicly disclosed security vulnerabilities in software and hardware.
Each vulnerability receives a unique identifier called a CVE ID (e.g., CVE-2023-12345), making it easier to reference specific vulnerabilities across different tools and databases.
Total Search Results: 158437
CVE ID | Description | Severity | Published Date | Affected Vendor | Action |
---|---|---|---|---|---|
CVE-2023-35342 | Windows Image Acquisition Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35343 | Windows Geolocation Service Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35344 | Windows DNS Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35345 | Windows DNS Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35346 | Windows DNS Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35347 | Microsoft Install Service Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35348 | Active Directory Federation Service Security Feature Bypass Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35349 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-3535 | A vulnerability was found in SimplePHPscripts FAQ Script PHP 2.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-233287. | Unknown | N/A | SimplePHPscripts | |
CVE-2023-35350 | Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35351 | Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35352 | Windows Remote Desktop Security Feature Bypass Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35353 | Connected User Experiences and Telemetry Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35355 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35356 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35357 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35358 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35359 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-3536 | A vulnerability was found in SimplePHPscripts Funeral Script PHP 3.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-233288. | Unknown | N/A | SimplePHPscripts | |
CVE-2023-35360 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35361 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35362 | Windows Clip Service Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35363 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35364 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35365 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35366 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35367 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35368 | Microsoft Exchange Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-3537 | A vulnerability classified as problematic has been found in SimplePHPscripts News Script PHP Pro 2.4. This affects an unknown part of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-233289 was assigned to this vulnerability. | Unknown | N/A | SimplePHPscripts | |
CVE-2023-35371 | Microsoft Office Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35372 | Microsoft Office Visio Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35373 | Mono Authenticode Validation Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35374 | Paint 3D Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35376 | Microsoft Message Queuing Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35377 | Microsoft Message Queuing Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35378 | Windows Projected File System Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35379 | Reliability Analysis Metrics Calculation Engine (RACEng) Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-3538 | A vulnerability classified as problematic was found in SimplePHPscripts Photo Gallery PHP 2.0. This vulnerability affects unknown code of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. VDB-233290 is the identifier assigned to this vulnerability. | Unknown | N/A | SimplePHPscripts | |
CVE-2023-35380 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35381 | Windows Fax Service Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35382 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35383 | Microsoft Message Queuing Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35384 | Windows HTML Platforms Security Feature Bypass Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35385 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35386 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35387 | Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35388 | Microsoft Exchange Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35389 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-3539 | A vulnerability, which was classified as problematic, has been found in SimplePHPscripts Simple Forum PHP 2.7. This issue affects some unknown processing of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-233291. | Unknown | N/A | SimplePHPscripts | |
CVE-2023-35390 | .NET and Visual Studio Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35391 | ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35392 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35393 | Azure Apache Hive Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35394 | Azure HDInsight Jupyter Notebook Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-3540 | A vulnerability, which was classified as problematic, was found in SimplePHPscripts NewsLetter Script PHP 2.4. Affected is an unknown function of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-233292. | Unknown | N/A | SimplePHPscripts | |
CVE-2023-3541 | A vulnerability has been found in ThinuTech ThinuCMS 1.5 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /author_posts.php. The manipulation of the argument author with the input g6g12o8sdm leads to cross site scripting. The attack can be launched remotely. The identifier VDB-233293 was assigned to this vulnerability. | Unknown | N/A | ThinuTech | |
CVE-2023-3542 | A vulnerability was found in ThinuTech ThinuCMS 1.5 and classified as problematic. Affected by this issue is some unknown functionality of the file /contact.php. The manipulation of the argument name/body leads to cross site scripting. The attack may be launched remotely. VDB-233294 is the identifier assigned to this vulnerability. | Unknown | N/A | ThinuTech | |
CVE-2023-3543 | A vulnerability was found in GZ Scripts Availability Booking Calendar PHP 1.8. It has been classified as problematic. This affects an unknown part of the file load.php of the component HTTP POST Request Handler. The manipulation of the argument cid/first_name/second_name/address_1/country leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-233295. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Unknown | N/A | GZ Scripts | |
CVE-2023-3544 | A vulnerability was found in GZ Scripts Time Slot Booking Calendar PHP 1.8. It has been declared as problematic. This vulnerability affects unknown code of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-233296. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Unknown | N/A | GZ Scripts | |
CVE-2023-3545 | Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of `.htaccess` file. This vulnerability may be exploited by privileged attackers or chained with unauthenticated arbitrary file write vulnerabilities, such as CVE-2023-3533, to achieve remote code execution. | Unknown | N/A | Chamilo | |
CVE-2023-3547 | The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly check nonce values in several actions, allowing an attacker to perform CSRF attacks. | Unknown | N/A | Unknown | |
CVE-2023-3548 | An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack. | Unknown | N/A | Johnson Controls | |
CVE-2023-3550 | Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attacker with a low-privileged user account can use this exploit to become an administrator by sending a malicious link to the instance administrator. | Unknown | N/A | MediaWiki | |
CVE-2023-3551 | Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10. | Unknown | N/A | nilsteampassnet | |
CVE-2023-3552 | Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.10. | Unknown | N/A | nilsteampassnet | |
CVE-2023-3553 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository nilsteampassnet/teampass prior to 3.0.10. | Unknown | N/A | nilsteampassnet | |
CVE-2023-3554 | A vulnerability was found in GZ Scripts GZ Forum Script 1.8 and classified as problematic. Affected by this issue is some unknown functionality of the file /preview.php. The manipulation of the argument catid/topicid/topic/topic_message/free_name leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-233348. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Unknown | N/A | GZ Scripts | |
CVE-2023-3555 | A vulnerability was found in GZ Scripts PHP Vacation Rental Script 1.8. It has been classified as problematic. This affects an unknown part of the file /preview.php. The manipulation of the argument page/layout/sort_by/property_id leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-233349 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Unknown | N/A | GZ Scripts | |
CVE-2023-3556 | A vulnerability was found in GZ Scripts Car Listing Script PHP 1.8. It has been declared as problematic. This vulnerability affects unknown code of the file /preview.php. The manipulation of the argument page/sort_by leads to cross site scripting. The attack can be initiated remotely. VDB-233350 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Unknown | N/A | GZ Scripts | |
CVE-2023-3557 | A vulnerability was found in GZ Scripts Property Listing Script 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /preview.php. The manipulation of the argument page/layout/sort_by leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-233351. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Unknown | N/A | GZ Scripts | |
CVE-2023-3558 | A vulnerability classified as problematic has been found in GZ Scripts Event Booking Calendar 1.8. Affected is an unknown function of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-233352. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Unknown | N/A | GZ Scripts | |
CVE-2023-3559 | A vulnerability classified as problematic was found in GZ Scripts PHP GZ Appointment Scheduling Script 1.8. Affected by this vulnerability is an unknown functionality of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. The attack can be launched remotely. The identifier VDB-233353 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Unknown | N/A | GZ Scripts | |
CVE-2023-3560 | A vulnerability, which was classified as problematic, has been found in GZ Scripts Ticket Booking Script 1.8. Affected by this issue is some unknown functionality of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. The attack may be launched remotely. VDB-233354 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Unknown | N/A | GZ Scripts | |
CVE-2023-3561 | A vulnerability, which was classified as problematic, was found in GZ Scripts PHP GZ Hotel Booking Script 1.8. This affects an unknown part of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-233355. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Unknown | N/A | GZ Scripts | |
CVE-2023-35618 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35619 | Microsoft Outlook for Mac Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-3562 | A vulnerability has been found in GZ Scripts PHP CRM Platform 1.8 and classified as problematic. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument action leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-233356. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Unknown | N/A | GZ Scripts | |
CVE-2023-35621 | Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35622 | Windows DNS Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35624 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35625 | Azure Machine Learning Compute Instance for SDK Users Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35628 | Windows MSHTML Platform Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35629 | Microsoft USBHUB 3.0 Device Driver Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-3563 | A vulnerability was found in GZ Scripts GZ E Learning Platform 1.8 and classified as problematic. This issue affects some unknown processing of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-233357 was assigned to this vulnerability. | Unknown | N/A | GZ Scripts | |
CVE-2023-35630 | Internet Connection Sharing (ICS) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35631 | Win32k Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35632 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35633 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35634 | Windows Bluetooth Driver Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35635 | Windows Kernel Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35636 | Microsoft Outlook Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35638 | DHCP Server Service Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35639 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-3564 | A vulnerability was found in GZ Scripts GZ Multi Hotel Booking System 1.8. It has been classified as problematic. Affected is an unknown function of the file /index.php. The manipulation of the argument adults/children/cal_id leads to cross site scripting. It is possible to launch the attack remotely. VDB-233358 is the identifier assigned to this vulnerability. | Unknown | N/A | GZ Scripts | |
CVE-2023-35641 | Internet Connection Sharing (ICS) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35642 | Internet Connection Sharing (ICS) Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35643 | DHCP Server Service Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2023-35644 | Windows Sysmain Service Elevation of Privilege | Unknown | N/A | Microsoft | |
CVE-2023-35645 | In tbd of tbd, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | Unknown | N/A | ||
CVE-2023-35646 | In TBD of TBD, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | Unknown | N/A |
vunerability-insight.com © 2023 - 2025. All Rights Reserved.
Vulnerability Data Repositories v