CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2023-42886

    Last Modified: 4 Nov 2025

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3, macOS Monterey 12.7.2. A user may be able to cause unexpected app termination or arbitrary code execution.

    Published: 12 Dec 2023
    2.4
    Low

    CVE-2023-42874

    Last Modified: 4 Nov 2025

    This issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.2. Secure text fields may be displayed via the Accessibility Keyboard when using a physical keyboard.

    Published: 12 Dec 2023
    —
    Unknown

    CVE-2023-42927

    Last Modified: 20 Dec 2023

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 12 Dec 2023
    4.6
    Medium

    CVE-2023-42897

    Last Modified: 4 Nov 2025

    The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker with physical access may be able to use Siri to access sensitive user data.

    Published: 12 Dec 2023
    7.8
    High

    CVE-2023-42907

    Last Modified: 4 Nov 2025

    Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

    Published: 12 Dec 2023
    7.8
    High

    CVE-2023-42911

    Last Modified: 4 Nov 2025

    Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

    Published: 12 Dec 2023
    8.8
    High

    CVE-2023-42910

    Last Modified: 4 Nov 2025

    Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

    Published: 12 Dec 2023
    7.8
    High

    CVE-2023-42906

    Last Modified: 4 Nov 2025

    Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

    Published: 12 Dec 2023
    7.8
    High

    CVE-2023-42926

    Last Modified: 4 Nov 2025

    Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

    Published: 12 Dec 2023
    7.8
    High

    CVE-2023-42909

    Last Modified: 4 Nov 2025

    Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

    Published: 12 Dec 2023
    7.8
    High

    CVE-2023-42899

    Last Modified: 4 Nov 2025

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, macOS Ventura 13.6.3, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Monterey 12.7.2. Processing an image may lead to arbitrary code execution.

    Published: 12 Dec 2023
    7.8
    High

    CVE-2023-42905

    Last Modified: 4 Nov 2025

    Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

    Published: 12 Dec 2023
    5.5
    Medium

    CVE-2023-42894

    Last Modified: 4 Nov 2025

    This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3, macOS Monterey 12.7.2. An app may be able to access information about a user's contacts.

    Published: 12 Dec 2023
    7.8
    High

    CVE-2023-42882

    Last Modified: 4 Nov 2025

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2. Processing an image may lead to arbitrary code execution.

    Published: 12 Dec 2023
    7.8
    High

    CVE-2023-42904

    Last Modified: 4 Nov 2025

    Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

    Published: 12 Dec 2023
    7.8
    High

    CVE-2023-42912

    Last Modified: 4 Nov 2025

    Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

    Published: 12 Dec 2023
    5.5
    Medium

    CVE-2023-42932

    Last Modified: 4 Nov 2025

    A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3, macOS Monterey 12.7.2. An app may be able to access protected user data.

    Published: 12 Dec 2023
    5.5
    Medium

    CVE-2023-42898

    Last Modified: 4 Nov 2025

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2. Processing an image may lead to arbitrary code execution.

    Published: 12 Dec 2023
    5.5
    Medium

    CVE-2023-42924

    Last Modified: 4 Nov 2025

    A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3. An app may be able to access sensitive user data.

    Published: 12 Dec 2023
    7.8
    High

    CVE-2023-42908

    Last Modified: 4 Nov 2025

    Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

    Published: 12 Dec 2023
    7.8
    High

    CVE-2023-42903

    Last Modified: 4 Nov 2025

    Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

    Published: 12 Dec 2023
    5.5
    Medium

    CVE-2023-42919

    Last Modified: 4 Nov 2025

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, macOS Ventura 13.6.3, iOS 16.7.3 and iPadOS 16.7.3, macOS Monterey 12.7.2. An app may be able to access sensitive user data.

    Published: 12 Dec 2023
    5.3
    Medium

    CVE-2023-42923

    Last Modified: 4 Nov 2025

    This issue was addressed through improved state management. This issue is fixed in iOS 17.2 and iPadOS 17.2. Private Browsing tabs may be accessed without authentication.

    Published: 12 Dec 2023
    5.5
    Medium

    CVE-2023-42922

    Last Modified: 4 Nov 2025

    This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, macOS Ventura 13.6.3, iOS 16.7.3 and iPadOS 16.7.3, macOS Monterey 12.7.2. An app may be able to read sensitive location information.

    Published: 12 Dec 2023
    5.5
    Medium

    CVE-2023-42884

    Last Modified: 4 Nov 2025

    This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, macOS Ventura 13.6.3, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. An app may be able to disclose kernel memory.

    Published: 12 Dec 2023
    7.8
    High

    CVE-2023-42902

    Last Modified: 4 Nov 2025

    Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

    Published: 12 Dec 2023
    6.3
    Medium

    CVE-2023-42914

    Last Modified: 4 Nov 2025

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, macOS Ventura 13.6.3, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Monterey 12.7.2. An app may be able to break out of its sandbox.

    Published: 12 Dec 2023
    5.5
    Medium

    CVE-2023-42883

    Last Modified: 13 Feb 2025

    The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. Processing an image may lead to a denial-of-service.

    Published: 12 Dec 2023
    7.5
    High

    CVE-2018-16153

    Last Modified: 27 May 2025

    An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts to arbitrary external services in some situations.

    Published: 12 Dec 2023
    7.8
    High

    CVE-2020-12612

    Last Modified: 21 Nov 2024

    An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When specifying a program to elevate, it can typically be found within the Program Files (x86) folder and therefore uses the %ProgramFiles(x86)% environment variable. However, when this same policy gets pushed to a 32bit machine, this environment variable does not exist. Therefore, since the standard user can create a user level environment variable, they can repoint this variable to any folder the user has full control of. Then, the folder structure can be created in such a way that a rule matches and arbitrary code runs elevated.

    Published: 12 Dec 2023
    7.8
    High

    CVE-2020-12614

    Last Modified: 21 Nov 2024

    An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. If the publisher criteria is selected, it defines the name of a publisher that must be present in the certificate (and also requires that the certificate is valid). If an Add Admin token is protected by this criteria, it can be leveraged by a malicious actor to achieve Elevation of Privileges from standard user to administrator.

    Published: 12 Dec 2023
    5.3
    Medium

    CVE-2024-4067

    Last Modified: 4 Aug 2025

    The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged fix but further testing shows the issue persists. This issue should be mitigated by using a safe pattern that won't start backtracking the regular expression due to greedy matching. This issue was fixed in version 4.0.8.

    Published: 12 Dec 2023
    5.5
    Medium

    CVE-2015-2179

    Last Modified: 21 Nov 2024

    The xaviershay-dm-rails gem 0.10.3.8 for Ruby allows local users to discover MySQL credentials by listing a process and its arguments.

    Published: 12 Dec 2023
    9.8
    Critical

    CVE-2013-2513

    Last Modified: 21 Nov 2024

    The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file.

    Published: 12 Dec 2023
    8.8
    High

    CVE-2020-10676

    Last Modified: 21 Nov 2024

    In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace to move that namespace to a different project.

    Published: 12 Dec 2023
    7.8
    High

    CVE-2020-12615

    Last Modified: 21 Nov 2024

    An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding the Add Admin token to a process, and specifying that it runs at medium integrity with the user owning the process, this security token can be stolen and applied to arbitrary processes.

    Published: 12 Dec 2023
    7.8
    High

    CVE-2020-28369

    Last Modified: 21 Nov 2024

    In BeyondTrust Privilege Management for Windows (aka PMfW) through 5.7, a SYSTEM installation causes Cryptbase.dll to be loaded from the user-writable location %WINDIR%\Temp.

    Published: 12 Dec 2023
    7.5
    High

    CVE-2023-46455

    Last Modified: 21 Nov 2024

    In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality.

    Published: 12 Dec 2023
    7.5
    High

    CVE-2015-8314

    Last Modified: 27 May 2025

    The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.

    Published: 12 Dec 2023
    5.3
    Medium

    CVE-2022-44543

    Last Modified: 21 Nov 2024

    The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users in restricted groups (if there is a usergroup field on the registration form). This occurs because the usergroup.inList protection mechanism is mishandled.

    Published: 12 Dec 2023
    7.5
    High

    CVE-2023-36647

    Last Modified: 26 Nov 2024

    A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via crafted JWT tokens.

    Published: 12 Dec 2023
    8.2
    High

    CVE-2023-36648

    Last Modified: 21 Nov 2024

    Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticated users to read potentially sensitive information and deny service to users by directly reading and writing data in Apache Kafka (as consumer and producer).

    Published: 12 Dec 2023
    9.1
    Critical

    CVE-2023-36649

    Last Modified: 21 Nov 2024

    Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management and the REST API by reading JWT tokens from logs (as a Granafa authenticated user) or from the Loki REST API without authentication.

    Published: 12 Dec 2023
    7.2
    High

    CVE-2023-36650

    Last Modified: 21 Nov 2024

    A missing integrity check in the update system in ProLion CryptoSpike 3.0.15P2 allows attackers to execute OS commands as the root Linux user on the host system via forged update packages.

    Published: 12 Dec 2023
    7.2
    High

    CVE-2023-36651

    Last Modified: 21 Nov 2024

    Hidden and hard-coded credentials in ProLion CryptoSpike 3.0.15P2 allow remote attackers to login to web management as super-admin and consume the most privileged REST API endpoints via these credentials.

    Published: 12 Dec 2023
    4.3
    Medium

    CVE-2023-36652

    Last Modified: 27 May 2025

    A SQL Injection in the users searching REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to read database data via SQL commands injected in the search parameter.

    Published: 12 Dec 2023
    6.5
    Medium

    CVE-2023-36654

    Last Modified: 21 Nov 2024

    Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to download host server SSH private keys (associated with a Linux root user) by injecting paths inside REST API endpoint parameters.

    Published: 12 Dec 2023
    6.5
    Medium

    CVE-2023-26920

    Last Modified: 21 Nov 2024

    fast-xml-parser before 4.1.2 allows __proto__ for Prototype Pollution.

    Published: 12 Dec 2023
    6.1
    Medium

    CVE-2023-28604

    Last Modified: 21 Nov 2024

    The fluid_components (aka Fluid Components) extension before 3.5.0 for TYPO3 allows XSS via a component argument parameter, for certain {content} use cases that may be edge cases.

    Published: 12 Dec 2023
    5.3
    Medium

    CVE-2023-31048

    Last Modified: 21 Nov 2024

    The OPC UA .NET Standard Reference Server before 1.4.371.86. places sensitive information into an error message that may be seen remotely.

    Published: 12 Dec 2023