CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2023-25174

    Last Modified: 12 May 2025

    Improper access control in some Intel(R) Chipset Driver Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-28739

    Last Modified: 7 Jan 2025

    Incorrect default permissions in some Intel(R) Chipset Driver Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-25945

    Last Modified: 21 Nov 2024

    Protection mechanism failure in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    5.2
    Medium

    CVE-2023-31189

    Last Modified: 14 Jan 2026

    Improper authentication in some Intel(R) Server Product OpenBMC firmware before version egs-1.09 may allow an authenticated user to enable escalation of privilege via local access.

    Published: 14 Feb 2024
    5.3
    Medium

    CVE-2023-32280

    Last Modified: 14 Jan 2026

    Insufficiently protected credentials in some Intel(R) Server Product OpenBMC firmware before versions egs-1.05 may allow an unauthenticated user to enable information disclosure via network access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-41231

    Last Modified: 21 Nov 2024

    Incorrect default permissions in some ACAT software maintained by Intel(R) before version 2.0.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    5.5
    Medium

    CVE-2023-30767

    Last Modified: 14 Jan 2026

    Improper buffer restrictions in Intel(R) Optimization for TensorFlow before version 2.13.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.1
    Medium

    CVE-2023-28396

    Last Modified: 14 Jan 2026

    Improper access control in firmware for some Intel(R) Thunderbol(TM) Controllers versions before 41 may allow a privileged user to enable denial of service via local access.

    Published: 14 Feb 2024
    2
    Low

    CVE-2023-26591

    Last Modified: 21 Nov 2024

    Unchecked return value in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an unauthenticated user to potentially enable denial of service via physical access.

    Published: 14 Feb 2024
    2.5
    Low

    CVE-2023-26596

    Last Modified: 21 Nov 2024

    Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 14 Feb 2024
    3.8
    Low

    CVE-2023-27303

    Last Modified: 21 Nov 2024

    Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 14 Feb 2024
    3.8
    Low

    CVE-2023-26592

    Last Modified: 21 Nov 2024

    Deserialization of untrusted data in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable a denial of service via local access.

    Published: 14 Feb 2024
    3.8
    Low

    CVE-2023-27300

    Last Modified: 21 Nov 2024

    Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 14 Feb 2024
    3.8
    Low

    CVE-2023-27307

    Last Modified: 21 Nov 2024

    Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 14 Feb 2024
    4.2
    Medium

    CVE-2023-27301

    Last Modified: 21 Nov 2024

    Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    4.3
    Medium

    CVE-2023-24463

    Last Modified: 21 Nov 2024

    Improper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.

    Published: 14 Feb 2024
    4.6
    Medium

    CVE-2023-27308

    Last Modified: 21 Nov 2024

    Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    5
    Medium

    CVE-2023-26585

    Last Modified: 21 Nov 2024

    Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 14 Feb 2024
    5.5
    Medium

    CVE-2023-25769

    Last Modified: 21 Nov 2024

    Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 14 Feb 2024
    5.5
    Medium

    CVE-2023-22848

    Last Modified: 21 Nov 2024

    Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 14 Feb 2024
    6.1
    Medium

    CVE-2023-24589

    Last Modified: 12 May 2025

    Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.3
    Medium

    CVE-2023-24481

    Last Modified: 8 May 2025

    Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.5
    Medium

    CVE-2023-22390

    Last Modified: 21 Nov 2024

    Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-24542

    Last Modified: 12 May 2025

    Unquoted search path or element in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    6.7
    Medium

    CVE-2023-25779

    Last Modified: 21 Nov 2024

    Uncontrolled search path element in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    7.7
    High

    CVE-2023-22342

    Last Modified: 12 May 2025

    Improper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    7.9
    High

    CVE-2023-25777

    Last Modified: 21 Nov 2024

    Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    8.2
    High

    CVE-2023-22293

    Last Modified: 12 May 2025

    Improper access control in the Intel(R) Thunderbolt(TM) DCH drivers for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Feb 2024
    4.3
    Medium

    CVE-2024-0011

    Last Modified: 9 Dec 2024

    A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of an authenticated Captive Portal user’s browser) if a user clicks on a malicious link, allowing phishing attacks that could lead to credential theft.

    Published: 14 Feb 2024
    4.3
    Medium

    CVE-2024-0010

    Last Modified: 24 Apr 2025

    A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of a user’s browser) if a user clicks on a malicious link, allowing phishing attacks that could lead to credential theft.

    Published: 14 Feb 2024
    6.3
    Medium

    CVE-2024-0009

    Last Modified: 9 Dec 2024

    An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address.

    Published: 14 Feb 2024
    6.6
    Medium

    CVE-2024-0008

    Last Modified: 24 Mar 2025

    Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.

    Published: 14 Feb 2024
    6.8
    Medium

    CVE-2024-0007

    Last Modified: 17 Dec 2024

    A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances. This enables the impersonation of another authenticated administrator.

    Published: 14 Feb 2024
    9.8
    Critical

    CVE-2023-6441

    Last Modified: 20 May 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UNI-PA University Marketing & Computer Internet Trade Inc. University Information System allows SQL Injection. This issue affects University Information System: before 12.12.2023.

    Published: 14 Feb 2024
    8.8
    High

    CVE-2024-0568

    Last Modified: 8 May 2025

    CWE-287: Improper Authentication vulnerability exists that could cause unauthorized tampering of device configuration over NFC communication.

    Published: 14 Feb 2024
    6.5
    Medium

    CVE-2024-23952

    Last Modified: 13 Feb 2025

    This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.   This vulnerability exists in Apache Superset versions up to and including 2.1.2 and versions 3.0.0, 3.0.1.

    Published: 14 Feb 2024
    8.8
    High

    CVE-2024-23789

    Last Modified: 23 Dec 2025

    Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary OS command on the affected product.

    Published: 14 Feb 2024
    8.1
    High

    CVE-2024-23788

    Last Modified: 19 Mar 2025

    Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to send an arbitrary HTTP request (GET) from the affected product.

    Published: 14 Feb 2024
    6.5
    Medium

    CVE-2024-23787

    Last Modified: 25 Nov 2024

    Path traversal vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to obtain an arbitrary file in the affected product.

    Published: 14 Feb 2024
    9.3
    Critical

    CVE-2024-23786

    Last Modified: 18 Mar 2025

    Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the management page of the affected product.

    Published: 14 Feb 2024
    6.5
    Medium

    CVE-2024-23785

    Last Modified: 21 Nov 2024

    Cross-site request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a remote unauthenticated attacker to change the product settings.

    Published: 14 Feb 2024
    6.5
    Medium

    CVE-2024-23784

    Last Modified: 25 Mar 2025

    Improper access control vulnerability exists in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier, which may allow a network-adjacent unauthenticated attacker to obtain a username and its hashed password displayed on the management page of the affected product.

    Published: 14 Feb 2024
    8.8
    High

    CVE-2024-23783

    Last Modified: 25 Mar 2025

    Improper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to access the affected product without authentication.

    Published: 14 Feb 2024
    —
    Unknown

    CVE-2024-26014

    Last Modified: 18 Apr 2025

    Not used

    Published: 14 Feb 2024
    5.4
    Medium

    CVE-2023-44294

    Last Modified: 21 Nov 2024

    In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of Collection Rest API. This issue may potentially lead to unintentional information disclosure from the product database.

    Published: 14 Feb 2024
    5.4
    Medium

    CVE-2023-44293

    Last Modified: 21 Nov 2024

    In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of IP Range Rest API. This issue may potentially lead to unintentional information disclosure from the product database.

    Published: 14 Feb 2024
    7.8
    High

    CVE-2023-44283

    Last Modified: 21 Nov 2024

    In Dell SupportAssist for Home PCs (between v3.0 and v3.14.1) and SupportAssist for Business PCs (between v3.0 and v3.4.1), a security concern has been identified, impacting locally authenticated users on their respective PCs. This issue may potentially enable privilege escalation and the execution of arbitrary code, in the Windows system context, and confined to that specific local PC.

    Published: 14 Feb 2024
    6.3
    Medium

    CVE-2023-39249

    Last Modified: 21 Nov 2024

    Dell SupportAssist for Business PCs version 3.4.0 contains a local Authentication Bypass vulnerability that allows locally authenticated non-admin users to gain temporary privilege within the SupportAssist User Interface on their respective PC. The Run as Admin temporary privilege feature enables IT/System Administrators to perform driver scans and Dell-recommended driver installations without requiring them to log out of the local non-admin user session. However, the granted privilege is limited solely to the SupportAssist User Interface and automatically expires after 15 minutes.

    Published: 14 Feb 2024
    7.2
    High

    CVE-2023-25535

    Last Modified: 21 Nov 2024

    Dell SupportAssist for Home PCs Installer Executable file version prior to 3.13.2.19 used for initial installation has a high vulnerability that can result in local privilege escalation (LPE). This vulnerability only affects first-time installations done prior to 8th March 2023

    Published: 14 Feb 2024
    4.4
    Medium

    CVE-2024-22455

    Last Modified: 21 Nov 2024

    Dell Mobility - E-Lab Navigator, version(s) 3.1.9, 3.2.0, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Launch of phishing attacks.

    Published: 14 Feb 2024