CVE Feed

    Dashboard / CVE

    7.3
    High

    CVE-2023-35624

    Last Modified: 1 Jan 2025

    Azure Connected Machine Agent Elevation of Privilege Vulnerability

    Published: 12 Dec 2023
    7.5
    High

    CVE-2023-35622

    Last Modified: 22 May 2025

    Windows DNS Spoofing Vulnerability

    Published: 12 Dec 2023
    7.5
    High

    CVE-2023-35621

    Last Modified: 1 Jan 2025

    Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability

    Published: 12 Dec 2023
    5.3
    Medium

    CVE-2023-35619

    Last Modified: 1 Jan 2025

    Microsoft Outlook for Mac Spoofing Vulnerability

    Published: 12 Dec 2023
    6.5
    Medium

    CVE-2023-35636

    Last Modified: 1 Jan 2025

    Microsoft Outlook Information Disclosure Vulnerability

    Published: 12 Dec 2023
    5.5
    Medium

    CVE-2023-35635

    Last Modified: 22 May 2025

    Windows Kernel Denial of Service Vulnerability

    Published: 12 Dec 2023
    8
    High

    CVE-2023-35634

    Last Modified: 1 Jan 2025

    Windows Bluetooth Driver Remote Code Execution Vulnerability

    Published: 12 Dec 2023
    7.8
    High

    CVE-2023-35633

    Last Modified: 1 Jan 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 12 Dec 2023
    7.8
    High

    CVE-2023-35632

    Last Modified: 1 Jan 2025

    Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

    Published: 12 Dec 2023
    7.8
    High

    CVE-2023-35631

    Last Modified: 1 Jan 2025

    Win32k Elevation of Privilege Vulnerability

    Published: 12 Dec 2023
    8.8
    High

    CVE-2023-35630

    Last Modified: 1 Jan 2025

    Internet Connection Sharing (ICS) Remote Code Execution Vulnerability

    Published: 12 Dec 2023
    6.8
    Medium

    CVE-2023-35629

    Last Modified: 1 Jan 2025

    Microsoft USBHUB 3.0 Device Driver Remote Code Execution Vulnerability

    Published: 12 Dec 2023
    8.1
    High

    CVE-2023-35628

    Last Modified: 1 Jan 2025

    Windows MSHTML Platform Remote Code Execution Vulnerability

    Published: 12 Dec 2023
    7.8
    High

    CVE-2023-35644

    Last Modified: 1 Jan 2025

    Windows Sysmain Service Elevation of Privilege Vulnerability

    Published: 12 Dec 2023
    7.5
    High

    CVE-2023-35643

    Last Modified: 1 Jan 2025

    DHCP Server Service Information Disclosure Vulnerability

    Published: 12 Dec 2023
    6.5
    Medium

    CVE-2023-35642

    Last Modified: 1 Jan 2025

    Internet Connection Sharing (ICS) Denial of Service Vulnerability

    Published: 12 Dec 2023
    8.8
    High

    CVE-2023-35641

    Last Modified: 1 Jan 2025

    Internet Connection Sharing (ICS) Remote Code Execution Vulnerability

    Published: 12 Dec 2023
    8.8
    High

    CVE-2023-35639

    Last Modified: 1 Jan 2025

    Microsoft ODBC Driver Remote Code Execution Vulnerability

    Published: 12 Dec 2023
    7.5
    High

    CVE-2023-35638

    Last Modified: 1 Jan 2025

    DHCP Server Service Denial of Service Vulnerability

    Published: 12 Dec 2023
    8.8
    High

    CVE-2023-36006

    Last Modified: 1 Jan 2025

    Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

    Published: 12 Dec 2023
    7.5
    High

    CVE-2023-36005

    Last Modified: 1 Jan 2025

    Windows Telephony Server Elevation of Privilege Vulnerability

    Published: 12 Dec 2023
    7.5
    High

    CVE-2023-36004

    Last Modified: 1 Jan 2025

    Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability

    Published: 12 Dec 2023
    6.7
    Medium

    CVE-2023-36003

    Last Modified: 1 Jan 2025

    XAML Diagnostics Elevation of Privilege Vulnerability

    Published: 12 Dec 2023
    5.3
    Medium

    CVE-2023-36012

    Last Modified: 1 Jan 2025

    DHCP Server Service Information Disclosure Vulnerability

    Published: 12 Dec 2023
    7.5
    High

    CVE-2023-36010

    Last Modified: 1 Jan 2025

    Microsoft Defender Denial of Service Vulnerability

    Published: 12 Dec 2023
    9.6
    Critical

    CVE-2023-36019

    Last Modified: 1 Jan 2025

    Microsoft Power Platform Connector Spoofing Vulnerability

    Published: 12 Dec 2023
    7.8
    High

    CVE-2023-21740

    Last Modified: 1 Jan 2025

    Windows Media Remote Code Execution Vulnerability

    Published: 12 Dec 2023
    4.7
    Medium

    CVE-2023-35625

    Last Modified: 1 Jan 2025

    Azure Machine Learning Compute Instance for SDK Users Information Disclosure Vulnerability

    Published: 12 Dec 2023
    7.8
    High

    CVE-2023-36011

    Last Modified: 22 May 2025

    Win32k Elevation of Privilege Vulnerability

    Published: 12 Dec 2023
    5.5
    Medium

    CVE-2023-36009

    Last Modified: 19 May 2026

    Microsoft Word Information Disclosure Vulnerability

    Published: 12 Dec 2023
    7.6
    High

    CVE-2023-36020

    Last Modified: 1 Jan 2025

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

    Published: 12 Dec 2023
    7.8
    High

    CVE-2023-36391

    Last Modified: 1 Jan 2025

    Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

    Published: 12 Dec 2023
    7.8
    High

    CVE-2023-36696

    Last Modified: 1 Jan 2025

    Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

    Published: 12 Dec 2023
    4.1
    Medium

    CVE-2023-20275

    Last Modified: 11 Aug 2026

    A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to send packets with another VPN user's source IP address. This vulnerability is due to improper validation of the packet's inner source IP address after decryption. An attacker could exploit this vulnerability by sending crafted packets through the tunnel. A successful exploit could allow the attacker to send a packet impersonating another VPN user's IP address. It is not possible for the attacker to receive return packets.

    Published: 12 Dec 2023
    6.8
    Medium

    CVE-2023-49923

    Last Modified: 24 May 2025

    An issue was discovered by Elastic whereby the Documents API of App Search logged the raw contents of indexed documents at INFO log level. Depending on the contents of such documents, this could lead to the insertion of sensitive or private information in the App Search logs. Elastic has released 8.11.2 and 7.17.16 that resolves this issue by changing the log level at which these are logged to DEBUG, which is disabled by default.

    Published: 12 Dec 2023
    4.3
    Medium

    CVE-2023-48313

    Last Modified: 21 Nov 2024

    Umbraco is an ASP.NET content management system (CMS). Starting in 10.0.0 and prior to versions 10.8.1 and 12.3.4, Umbraco contains a cross-site scripting (XSS) vulnerability enabling attackers to bring malicious content into a website or application. Versions 10.8.1 and 12.3.4 contain a patch for this issue.

    Published: 12 Dec 2023
    4.3
    Medium

    CVE-2023-48227

    Last Modified: 21 Nov 2024

    Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, and 12.3.0, Backoffice users with send for approval permission but not publish permission are able to publish in some scenarios. Versions 8.18.10, 10.7.0, and 12.3.0 contains a patch for this issue. No known workarounds are available.

    Published: 12 Dec 2023
    3.5
    Low

    CVE-2023-38694

    Last Modified: 21 Nov 2024

    Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, and 12.1.0, a user with access to a specific part of the backoffice is able to inject HTML code into a form where it is not intended. Versions 8.18.10, 10.7.0, and 12.1.0 contain a patch for this issue.

    Published: 12 Dec 2023
    —
    Unknown

    CVE-2023-6734

    Last Modified: 5 Jun 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-33679. Reason: This candidate is a reservation duplicate of CVE-2024-33679. Notes: All CVE users should reference CVE-2024-33679 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 12 Dec 2023
    9.8
    Critical

    CVE-2023-6593

    Last Modified: 21 Nov 2024

    Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to the application to execute entries in a SQL data source without restriction.

    Published: 12 Dec 2023
    5.3
    Medium

    CVE-2023-6193

    Last Modified: 21 Nov 2024

    quiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which could lead to excessive resource consumption. QUIC path validation (RFC 9000 Section 8.2) requires that the recipient of a PATH_CHALLENGE frame responds by sending a PATH_RESPONSE. An unauthenticated remote attacker can exploit the vulnerability by sending PATH_CHALLENGE frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that PATH_RESPONSE frames can only be sent at the slower rate than they are received; leading to storage of path validation data in an unbounded queue. Quiche versions greater than 0.19.0 address this problem.

    Published: 12 Dec 2023
    7.2
    High

    CVE-2023-49692

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V7.2.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V7.2.2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions < V7.2.2), SCALANCE M812-1 ADSL-Router (6GK5812-1BA00-2AA2) (All versions < V7.2.2), SCALANCE M816-1 ADSL-Router (6GK5816-1AA00-2AA2) (All versions < V7.2.2), SCALANCE M816-1 ADSL-Router (6GK5816-1BA00-2AA2) (All versions < V7.2.2), SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2) (All versions < V7.2.2), SCALANCE M874-2 (6GK5874-2AA00-2AA2) (All versions < V7.2.2), SCALANCE M874-3 (6GK5874-3AA00-2AA2) (All versions < V7.2.2), SCALANCE M876-3 (6GK5876-3AA02-2BA2) (All versions < V7.2.2), SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2) (All versions < V7.2.2), SCALANCE M876-4 (6GK5876-4AA10-2BA2) (All versions < V7.2.2), SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2) (All versions < V7.2.2), SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2) (All versions < V7.2.2), SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1) (All versions < V7.2.2), SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1) (All versions < V7.2.2), SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1) (All versions < V7.2.2), SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2) (All versions < V7.2.2), SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2) (All versions < V7.2.2). An Improper Neutralization of Special Elements used in an OS Command with root privileges vulnerability exists in the parsing of the IPSEC configuration. This could allow malicious local administrators to issue commands on system level after a new connection is established.

    Published: 12 Dec 2023
    7.2
    High

    CVE-2023-49691

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.0), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.0), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions < V8.0), SCALANCE M812-1 ADSL-Router (6GK5812-1BA00-2AA2) (All versions < V8.0), SCALANCE M816-1 ADSL-Router (6GK5816-1AA00-2AA2) (All versions < V8.0), SCALANCE M816-1 ADSL-Router (6GK5816-1BA00-2AA2) (All versions < V8.0), SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2) (All versions < V8.0), SCALANCE M874-2 (6GK5874-2AA00-2AA2) (All versions < V8.0), SCALANCE M874-3 (6GK5874-3AA00-2AA2) (All versions < V8.0), SCALANCE M876-3 (6GK5876-3AA02-2BA2) (All versions < V8.0), SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2) (All versions < V8.0), SCALANCE M876-4 (6GK5876-4AA10-2BA2) (All versions < V8.0), SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2) (All versions < V8.0), SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2) (All versions < V8.0), SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1) (All versions < V8.0), SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1) (All versions < V8.0), SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1) (All versions < V8.0), SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2) (All versions < V8.0), SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2) (All versions < V8.0). An Improper Neutralization of Special Elements used in an OS Command with root privileges vulnerability exists in the handling of the DDNS configuration. This could allow malicious local administrators to issue commands on system level after a successful IP address update.

    Published: 12 Dec 2023
    6.8
    Medium

    CVE-2023-48431

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected software does not correctly validate the response received by an UMC server. An attacker can use this to crash the affected software by providing and configuring a malicious UMC server or by manipulating the traffic from a legitimate UMC server (i.e. leveraging CVE-2023-48427).

    Published: 12 Dec 2023
    2.7
    Low

    CVE-2023-48430

    Last Modified: 25 Feb 2026

    A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The REST API of affected devices does not check the length of parameters in certain conditions. This allows a malicious admin to crash the server by sending a crafted request to the API. The server will automatically restart.

    Published: 12 Dec 2023
    2.7
    Low

    CVE-2023-48429

    Last Modified: 25 Feb 2026

    A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The Web UI of affected devices does not check the length of parameters in certain conditions. This allows a malicious admin to crash the server by sending a crafted request to the server. The server will automatically restart.

    Published: 12 Dec 2023
    7.2
    High

    CVE-2023-48428

    Last Modified: 25 Feb 2026

    A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The radius configuration mechanism of affected products does not correctly check uploaded certificates. A malicious admin could upload a crafted certificate resulting in a denial-of-service condition or potentially issue commands on system level.

    Published: 12 Dec 2023
    8.1
    High

    CVE-2023-48427

    Last Modified: 25 Nov 2024

    A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the UMC server as well as to manipulate responses, potentially allowing an attacker to escalate privileges.

    Published: 12 Dec 2023
    7.5
    High

    CVE-2023-46285

    Last Modified: 24 May 2025

    A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 8), Totally Integrated Automation Portal (TIA Portal) V18 (All versions < V18 Update 3). The affected application contains an improper input validation vulnerability that could allow an attacker to bring the service into a Denial-of-Service state by sending a specifically crafted message to 4004/tcp. The corresponding service is auto-restarted after the crash is detected by a watchdog.

    Published: 12 Dec 2023
    7.5
    High

    CVE-2023-46284

    Last Modified: 25 Feb 2026

    A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 8), Totally Integrated Automation Portal (TIA Portal) V18 (All versions < V18 Update 3). The affected application contains an out of bounds write past the end of an allocated buffer when handling specific requests on port 4002/tcp and 4004/tcp. This could allow an attacker to crash the application. The corresponding service is auto-restarted after the crash.

    Published: 12 Dec 2023