CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2023-5122

    Last Modified: 13 Feb 2025

    Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing CSV data from a remote endpoint configured by an administrator. If this plugin was configured to send requests to a bare host with no path (e.g. https://www.example.com/ https://www.example.com/` ), requests to an endpoint other than the one configured by the administrator could be triggered by a specially crafted request from any user, resulting in an SSRF vector. AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator

    Published: 14 Feb 2024
    8
    High

    CVE-2023-5123

    Last Modified: 6 Jan 2026

    The JSON datasource plugin ( https://grafana.com/grafana/plugins/marcusolsson-json-datasource/ ) is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing JSON data from a remote endpoint (including a specific sub-path) configured by an administrator. Due to inadequate sanitization of the dashboard-supplied path parameter, it was possible to include path traversal characters (../) in the path parameter and send requests to paths on the configured endpoint outside the configured sub-path. This means that if the datasource was configured by an administrator to point at some sub-path of a domain (e.g. https://example.com/api/some_safe_api/ ), it was possible for an editor to create a dashboard referencing the datasource which issues queries containing path traversal characters, which would in turn cause the datasource to instead query arbitrary subpaths on the configured domain (e.g. https://example.com/api/admin_api/) . In the rare case that this plugin is configured by an administrator to point back at the Grafana instance itself, this vulnerability becomes considerably more severe, as an administrator browsing a maliciously configured panel could be compelled to make requests to Grafana administrative API endpoints with their credentials, resulting in the potential for privilege escalation, hence the high score for this vulnerability.

    Published: 14 Feb 2024
    5.3
    Medium

    CVE-2023-46186

    Last Modified: 8 May 2025

    IBM Jazz for Service Management 1.1.3.20 could allow an unauthorized user to obtain sensitive file information using forced browsing due to improper access controls. IBM X-Force ID: 269929.

    Published: 14 Feb 2024
    3.8
    Low

    CVE-2023-42776

    Last Modified: 21 Nov 2024

    Improper input validation in some Intel(R) SGX DCAP software for Windows before version 1.19.100.3 may allow an authenticateed user to potentially enable information disclosure via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-40156

    Last Modified: 21 Nov 2024

    Uncontrolled search path element in some Intel(R) SSU software before version 3.0.0.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-41091

    Last Modified: 21 Nov 2024

    Uncontrolled search path for some Intel(R) MPI Library Software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-39932

    Last Modified: 21 Nov 2024

    Uncontrolled search path in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow a privillaged user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-40154

    Last Modified: 21 Nov 2024

    Incorrect default permissions in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow privillaged user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    4.9
    Medium

    CVE-2023-29153

    Last Modified: 14 Jan 2026

    Uncontrolled resource consumption for some Intel(R) SPS firmware before version SPS_E5_06.01.04.002.0 may allow a privileged user to potentially enable denial of service via network access.

    Published: 14 Feb 2024
    6.5
    Medium

    CVE-2023-41252

    Last Modified: 21 Nov 2024

    Out-of-bounds read in some Intel(R) QAT software drivers for Windows before version QAT1.7-W-1.11.0 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 14 Feb 2024
    7.1
    High

    CVE-2023-39941

    Last Modified: 21 Nov 2024

    Improper access control in some Intel(R) SUR software before version 2.4.10587 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-38566

    Last Modified: 21 Nov 2024

    Uncontrolled search path in some Intel(R) ISPC software before version 1.21.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-33870

    Last Modified: 21 Nov 2024

    Insecure inherited permissions in some Intel(R) Ethernet tools and driver install software may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-39432

    Last Modified: 21 Nov 2024

    Improper access control element in some Intel(R) Ethernet tools and driver install software, before versions 28.2, may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-36493

    Last Modified: 21 Nov 2024

    Uncontrolled search path in some Intel(R) SDK for OpenCL(TM) Applications software may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6
    Medium

    CVE-2023-29162

    Last Modified: 14 Jan 2026

    Improper buffer restrictions the Intel(R) C++ Compiler Classic before version 2021.8 for Intel(R) oneAPI Toolkits before version 2022.3.1 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    7.8
    High

    CVE-2023-35121

    Last Modified: 14 Jan 2026

    Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-35060

    Last Modified: 21 Nov 2024

    Uncontrolled search path in some Intel(R) Battery Life Diagnostic Tool software before version 2.3.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.6
    Medium

    CVE-2023-40161

    Last Modified: 21 Nov 2024

    Improper access control in some Intel Unite(R) Client software before version 4.2.35041 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-28745

    Last Modified: 14 Jan 2026

    Uncontrolled search path in Intel(R) QSFP+ Configuration Utility software, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-24591

    Last Modified: 24 Apr 2025

    Uncontrolled search path in some Intel(R) Binary Configuration Tool software before version 3.4.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    5.5
    Medium

    CVE-2023-25073

    Last Modified: 12 May 2025

    Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 14 Feb 2024
    6.3
    Medium

    CVE-2023-35062

    Last Modified: 21 Nov 2024

    Improper access control in some Intel(R) DSA software before version 23.4.33 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    8.8
    High

    CVE-2023-39425

    Last Modified: 21 Nov 2024

    Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    1.8
    Low

    CVE-2023-41090

    Last Modified: 21 Nov 2024

    Race condition in some Intel(R) MAS software before version 2.3 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    5
    Medium

    CVE-2023-36490

    Last Modified: 21 Nov 2024

    Improper initialization in some Intel(R) MAS software before version 2.3 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-35769

    Last Modified: 21 Nov 2024

    Uncontrolled search path in some Intel(R) CIP software before version 2.4.10577 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-38135

    Last Modified: 21 Nov 2024

    Improper authorization in some Intel(R) PM software may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    5
    Medium

    CVE-2023-28715

    Last Modified: 21 Nov 2024

    Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.2 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-32618

    Last Modified: 21 Nov 2024

    Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    5.5
    Medium

    CVE-2023-38561

    Last Modified: 21 Nov 2024

    Improper access control in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-28407

    Last Modified: 21 Nov 2024

    Uncontrolled search path in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.8
    Medium

    CVE-2023-32647

    Last Modified: 21 Nov 2024

    Improper access control in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    7.5
    High

    CVE-2023-34351

    Last Modified: 21 Nov 2024

    Buffer underflow in some Intel(R) PCM software before version 202307 may allow an unauthenticated user to potentially enable denial of service via network access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-35003

    Last Modified: 21 Nov 2024

    Path transversal in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-34315

    Last Modified: 21 Nov 2024

    Incorrect default permissions in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-32646

    Last Modified: 21 Nov 2024

    Uncontrolled search path element in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-31271

    Last Modified: 21 Nov 2024

    Improper access control in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.6
    Medium

    CVE-2023-27517

    Last Modified: 20 Feb 2025

    Improper access control in some Intel(R) Optane(TM) PMem software before versions 01.00.00.3547, 02.00.00.3915, 03.00.00.0483 may allow an athenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-22311

    Last Modified: 12 May 2025

    Improper access control in some Intel(R) Optane(TM) PMem 100 Series Management Software before version 01.00.00.3547 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    4.3
    Medium

    CVE-2023-26586

    Last Modified: 21 Nov 2024

    Uncaught exception for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 14 Feb 2024
    4.3
    Medium

    CVE-2023-32644

    Last Modified: 21 Nov 2024

    Protection mechanism failure for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 14 Feb 2024
    4.3
    Medium

    CVE-2023-32651

    Last Modified: 21 Nov 2024

    Improper validation of specified type of input for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 14 Feb 2024
    2.3
    Low

    CVE-2023-35061

    Last Modified: 15 Apr 2026

    Improper initialization for the Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.

    Published: 14 Feb 2024
    4.3
    Medium

    CVE-2023-34983

    Last Modified: 21 Nov 2024

    Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 14 Feb 2024
    4.3
    Medium

    CVE-2023-32642

    Last Modified: 21 Nov 2024

    Insufficient adherence to expected conventions for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 14 Feb 2024
    6
    Medium

    CVE-2023-25951

    Last Modified: 21 Nov 2024

    Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.1
    Medium

    CVE-2023-28720

    Last Modified: 21 Nov 2024

    Improper initialization for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access..

    Published: 14 Feb 2024
    6.1
    Medium

    CVE-2023-28374

    Last Modified: 21 Nov 2024

    Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 14 Feb 2024
    7.1
    High

    CVE-2023-33875

    Last Modified: 21 Nov 2024

    Improper access control for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via local access..

    Published: 14 Feb 2024