CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2023-35080

    Last Modified: 7 Jan 2025

    A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, denial of service, or information disclosure.

    Published: 14 Nov 2023
    5.5
    Medium

    CVE-2023-38544

    Last Modified: 21 Nov 2024

    A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be exploited to compromise the integrity and security of the network on the affected system.

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-38043

    Last Modified: 21 Nov 2024

    A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases, resulting in a full compromise of the system.

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-38543

    Last Modified: 7 Jan 2025

    A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine.

    Published: 14 Nov 2023
    8.4
    High

    CVE-2023-31100

    Last Modified: 25 Sept 2025

    Improper Access Control in SMI handler vulnerability in Phoenix SecureCore™ Technology™ 4 allows SPI flash modification. This issue affects SecureCore™ Technology™ 4: * from 4.3.0.0 before 4.3.0.203 * from 4.3.1.0 before 4.3.1.163 * from 4.4.0.0 before 4.4.0.217 * from 4.5.0.0 before 4.5.0.138

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-43591

    Last Modified: 11 Jun 2025

    Improper privilege management in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access.

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-43590

    Last Modified: 21 Nov 2024

    Link following in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access.

    Published: 14 Nov 2023
    5.5
    Medium

    CVE-2023-43582

    Last Modified: 21 Nov 2024

    Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.

    Published: 14 Nov 2023
    3.5
    Low

    CVE-2023-43588

    Last Modified: 21 Nov 2024

    Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access.

    Published: 14 Nov 2023
    4.9
    Medium

    CVE-2023-39199

    Last Modified: 21 Nov 2024

    Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access.

    Published: 14 Nov 2023
    3.7
    Low

    CVE-2023-39206

    Last Modified: 21 Nov 2024

    Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

    Published: 14 Nov 2023
    4.3
    Medium

    CVE-2023-45627

    Last Modified: 21 Nov 2024

    An authenticated Denial-of-Service (DoS) vulnerability exists in the CLI service. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point.

    Published: 14 Nov 2023
    5.5
    Medium

    CVE-2023-45626

    Last Modified: 21 Nov 2024

    An authenticated vulnerability has been identified allowing an attacker to effectively establish highly privileged persistent arbitrary code execution across boot cycles.

    Published: 14 Nov 2023
    7.2
    High

    CVE-2023-45625

    Last Modified: 21 Nov 2024

    Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

    Published: 14 Nov 2023
    7.5
    High

    CVE-2023-45624

    Last Modified: 27 Feb 2025

    An unauthenticated Denial-of-Service (DoS) vulnerability exists in the soft ap daemon accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point.

    Published: 14 Nov 2023
    7.5
    High

    CVE-2023-45623

    Last Modified: 21 Nov 2024

    Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Wi-Fi Uplink service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.

    Published: 14 Nov 2023
    7.5
    High

    CVE-2023-45622

    Last Modified: 21 Nov 2024

    Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the BLE daemon service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.

    Published: 14 Nov 2023
    7.5
    High

    CVE-2023-45621

    Last Modified: 21 Nov 2024

    Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.

    Published: 14 Nov 2023
    7.5
    High

    CVE-2023-45620

    Last Modified: 21 Nov 2024

    Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.

    Published: 14 Nov 2023
    8.2
    High

    CVE-2023-45619

    Last Modified: 21 Nov 2024

    There is an arbitrary file deletion vulnerability in the RSSI service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point.

    Published: 14 Nov 2023
    8.2
    High

    CVE-2023-45618

    Last Modified: 21 Nov 2024

    There are arbitrary file deletion vulnerabilities in the AirWave client service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point.

    Published: 14 Nov 2023
    8.2
    High

    CVE-2023-45617

    Last Modified: 21 Nov 2024

    There are arbitrary file deletion vulnerabilities in the CLI service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point.

    Published: 14 Nov 2023
    9.8
    Critical

    CVE-2023-45616

    Last Modified: 21 Nov 2024

    There is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

    Published: 14 Nov 2023
    9.8
    Critical

    CVE-2023-45615

    Last Modified: 21 Nov 2024

    There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

    Published: 14 Nov 2023
    9.8
    Critical

    CVE-2023-45614

    Last Modified: 21 Nov 2024

    There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

    Published: 14 Nov 2023
    4.3
    Medium

    CVE-2023-39205

    Last Modified: 21 Nov 2024

    Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.

    Published: 14 Nov 2023
    4.3
    Medium

    CVE-2023-39204

    Last Modified: 21 Nov 2024

    Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

    Published: 14 Nov 2023
    4.3
    Medium

    CVE-2023-39203

    Last Modified: 21 Nov 2024

    Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disclosure of information via network access.

    Published: 14 Nov 2023
    3.1
    Low

    CVE-2023-39202

    Last Modified: 21 Nov 2024

    Untrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a denial of service via local access.

    Published: 14 Nov 2023
    7.1
    High

    CVE-2023-47517

    Last Modified: 28 Apr 2026

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in SendPress Newsletters plugin <= 1.23.11.6 versions.

    Published: 14 Nov 2023
    7.1
    High

    CVE-2023-47518

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Matthew Muro Restrict Categories plugin <= 2.6.4 versions.

    Published: 14 Nov 2023
    7.1
    High

    CVE-2023-47520

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Michael Uno (miunosoft) Responsive Column Widgets plugin <= 1.2.7 versions.

    Published: 14 Nov 2023
    8.8
    High

    CVE-2023-48217

    Last Modified: 21 Nov 2024

    Statamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look like images may be uploaded regardless of mime type validation rules. This affects front-end forms using the "Forms" feature, and asset upload fields in the control panel. Malicious users could leverage this vulnerability to upload and execute code. This issue has been patched in versions 3.4.14 and 4.34.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 14 Nov 2023
    7.1
    High

    CVE-2023-47522

    Last Modified: 7 Jan 2025

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Photo Feed plugin <= 2.2.1 versions.

    Published: 14 Nov 2023
    8.2
    High

    CVE-2023-36038

    Last Modified: 9 Oct 2025

    ASP.NET Core Denial of Service Vulnerability

    Published: 14 Nov 2023
    5.8
    Medium

    CVE-2023-47524

    Last Modified: 7 Jan 2025

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability (requires PHP 8.x) in CodeBard CodeBard's Patron Button and Widgets for Patreon plugin <= 2.1.9 versions.

    Published: 14 Nov 2023
    7.5
    High

    CVE-2023-39537

    Last Modified: 21 Nov 2024

    AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper input validation via the local network. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity and availability.

    Published: 14 Nov 2023
    7.5
    High

    CVE-2023-39536

    Last Modified: 21 Nov 2024

    AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper input validation via the local network. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity and availability.

    Published: 14 Nov 2023
    7.5
    High

    CVE-2023-39535

    Last Modified: 21 Nov 2024

    AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper input validation via the local network. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity and availability.

    Published: 14 Nov 2023
    5.9
    Medium

    CVE-2023-47528

    Last Modified: 7 Jan 2025

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sajjad Hossain Sagor WP Edit Username plugin <= 1.0.5 versions.

    Published: 14 Nov 2023
    5.8
    Medium

    CVE-2023-47532

    Last Modified: 7 Jan 2025

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themeum WP Crowdfunding plugin <= 2.1.6 versions.

    Published: 14 Nov 2023
    5.9
    Medium

    CVE-2023-47533

    Last Modified: 7 Jan 2025

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Countdown and CountUp, WooCommerce Sales Timer plugin <= 1.8.2 versions.

    Published: 14 Nov 2023
    7.2
    High

    CVE-2023-47631

    Last Modified: 21 Nov 2024

    vantage6 is a framework to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). In affected versions a node does not check if an image is allowed to run if a `parent_id` is set. A malicious party that breaches the server may modify it to set a fake `parent_id` and send a task of a non-whitelisted algorithm. The node will then execute it because the `parent_id` that is set prevents checks from being run. This impacts all servers that are breached by an expert user. This vulnerability has been patched in version 4.1.2. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 14 Nov 2023
    7.1
    High

    CVE-2023-47544

    Last Modified: 18 Feb 2026

    Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Atarim Visual Website Collaboration, Feedback & Project Management – Atarim plugin <= 3.12 versions.

    Published: 14 Nov 2023
    7.1
    High

    CVE-2023-47630

    Last Modified: 27 Nov 2024

    Kyverno is a policy engine designed for Kubernetes. An issue was found in Kyverno that allowed an attacker to control the digest of images used by Kyverno users. The issue would require the attacker to compromise the registry that the Kyverno users fetch their images from. The attacker could then return an vulnerable image to the the user and leverage that to further escalate their position. As such, the attacker would need to know which images the Kyverno user consumes and know of one of multiple exploitable vulnerabilities in previous digests of the images. Alternatively, if the attacker has compromised the registry, they could craft a malicious image with a different digest with intentionally placed vulnerabilities and deliver the image to the user. Users pulling their images by digests and from trusted registries are not impacted by this vulnerability. There is no evidence of this being exploited in the wild. The issue has been patched in 1.10.5. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 14 Nov 2023
    5.9
    Medium

    CVE-2023-47545

    Last Modified: 7 Jan 2025

    Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Fatcat Apps Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin <= 2.5.4 versions.

    Published: 14 Nov 2023
    6.4
    Medium

    CVE-2023-47640

    Last Modified: 7 Jan 2025

    DataHub is an open-source metadata platform. The HMAC signature for DataHub Frontend sessions was being signed using a SHA-1 HMAC with the frontend secret key. SHA1 with a 10 byte key can be brute forced using sufficient resources (i.e. state level actors with large computational capabilities). DataHub Frontend was utilizing the Play LegacyCookiesModule with default settings which utilizes a SHA1 HMAC for signing. This is compounded by using a shorter key length than recommended by default for the signing key for the randomized secret value. An authenticated attacker (or attacker who has otherwise obtained a session token) could crack the signing key for DataHub and obtain escalated privileges by generating a privileged session cookie. Due to key length being a part of the risk, deployments should update to the latest helm chart and rotate their session signing secret. All deployments using the default helm chart configurations for generating the Play secret key used for signing are affected by this vulnerability. Version 0.11.1 resolves this vulnerability. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 14 Nov 2023
    5.9
    Medium

    CVE-2023-47546

    Last Modified: 7 Jan 2025

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Walter Pinem OneClick Chat to Order plugin <= 1.0.4.2 versions.

    Published: 14 Nov 2023
    5.3
    Medium

    CVE-2023-47627

    Last Modified: 3 Nov 2025

    aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt wheel). These bugs have been addressed in commit `d5c12ba89` which has been included in release version 3.8.6. Users are advised to upgrade. There are no known workarounds for these issues.

    Published: 14 Nov 2023
    7.1
    High

    CVE-2023-47547

    Last Modified: 7 Jan 2025

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory Products, Order & Customers Export for WooCommerce plugin <= 2.0.7 versions.

    Published: 14 Nov 2023