CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2023-47549

    Last Modified: 7 Jan 2025

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability on 302 response page in spider-themes EazyDocs plugin <= 2.3.3 versions.

    Published: 14 Nov 2023
    8.1
    High

    CVE-2023-47130

    Last Modified: 21 Nov 2024

    Yii is an open source PHP web framework. yiisoft/yii before version 1.1.29 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. An attacker may leverage this vulnerability to compromise the host system. A fix has been developed for the 1.1.29 release. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 14 Nov 2023
    7.1
    High

    CVE-2023-46132

    Last Modified: 21 Nov 2024

    Hyperledger Fabric is an open source permissioned distributed ledger framework. Combining two molecules to one another, called "cross-linking" results in a molecule with a chemical formula that is composed of all atoms of the original two molecules. In Fabric, one can take a block of transactions and cross-link the transactions in a way that alters the way the peers parse the transactions. If a first peer receives a block B and a second peer receives a block identical to B but with the transactions being cross-linked, the second peer will parse transactions in a different way and thus its world state will deviate from the first peer. Orderers or peers cannot detect that a block has its transactions cross-linked, because there is a vulnerability in the way Fabric hashes the transactions of blocks. It simply and naively concatenates them, which is insecure and lets an adversary craft a "cross-linked block" (block with cross-linked transactions) which alters the way peers process transactions. For example, it is possible to select a transaction and manipulate a peer to completely avoid processing it, without changing the computed hash of the block. Additional validations have been added in v2.2.14 and v2.5.5 to detect potential cross-linking issues before processing blocks. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 14 Nov 2023
    9.8
    Critical

    CVE-2023-34060

    Last Modified: 16 Dec 2025

    VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance was upgraded to 10.5 from an older version. On an upgraded version of VMware Cloud Director Appliance 10.5, a malicious actor with network access to the appliance can bypass login restrictions when authenticating on port 22 (ssh) or port 5480 (appliance management console) . This bypass is not present on port 443 (VCD provider and tenant login). On a new installation of VMware Cloud Director Appliance 10.5, the bypass is not present. VMware Cloud Director Appliance is impacted since it uses an affected version of sssd from the underlying Photon OS. The sssd issue is no longer present in versions of Photon OS that ship with sssd-2.8.1-11 or higher (Photon OS 3) or sssd-2.8.2-9 or higher (Photon OS 4 and 5).

    Published: 14 Nov 2023
    7.6
    High

    CVE-2023-36007

    Last Modified: 8 Oct 2025

    Microsoft Send Customer Voice survey from Dynamics 365 Spoofing Vulnerability

    Published: 14 Nov 2023
    8.8
    High

    CVE-2023-36437

    Last Modified: 8 Oct 2025

    Azure DevOps Server Remote Code Execution Vulnerability

    Published: 14 Nov 2023
    4.7
    Medium

    CVE-2023-47125

    Last Modified: 21 Nov 2024

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions DOM processing instructions are not handled correctly. This allows bypassing the cross-site scripting mechanism of typo3/html-sanitizer. This vulnerability has been addressed in versions 1.5.3 and 2.1.4. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 14 Nov 2023
    7.1
    High

    CVE-2023-47550

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in RedNao Donations Made Easy – Smart Donations allows Stored XSS.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12.

    Published: 14 Nov 2023
    3.7
    Low

    CVE-2023-47126

    Last Modified: 21 Nov 2024

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions the login screen of the standalone install tool discloses the full path of the transient data directory (e.g. /var/www/html/var/transient/). This applies to composer-based scenarios only - “classic” non-composer installations are not affected. This issue has been addressed in version 12.4.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 14 Nov 2023
    5.9
    Medium

    CVE-2023-47554

    Last Modified: 7 Jan 2025

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DenK BV Actueel Financieel Nieuws – Denk Internet Solutions plugin <= 5.1.0 versions.

    Published: 14 Nov 2023
    5.9
    Medium

    CVE-2023-47646

    Last Modified: 7 Jan 2025

    Auth. (Shop Manager+) Stored Cross-Site Scripting (XSS) vulnerability in CedCommerce Recently viewed and most viewed products plugin <= 1.1.1 versions.

    Published: 14 Nov 2023
    8.7
    High

    CVE-2023-26222

    Last Modified: 21 Nov 2024

    The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.22 and below, versions 6.0.13 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 5.0.0 and below.

    Published: 14 Nov 2023
    4.2
    Medium

    CVE-2023-47127

    Last Modified: 21 Nov 2024

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. In typo3 installations there are always at least two different sites. Eg. first.example.org and second.example.com. In affected versions a session cookie generated for the first site can be reused on the second site without requiring additional authentication. This vulnerability has been addressed in versions 8.7.55, 9.5.44, 10.4.41, 11.5.33, and 12.4.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 14 Nov 2023
    7.9
    High

    CVE-2023-28741

    Last Modified: 21 Nov 2024

    Buffer overflow in some Intel(R) QAT drivers for Windows - HW Version 1.0 before version 1.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    2.3
    Low

    CVE-2023-22313

    Last Modified: 21 Nov 2024

    Improper buffer restrictions in some Intel(R) QAT Library software before version 22.07.1 may allow a privileged user to potentially enable information disclosure via local access.

    Published: 14 Nov 2023
    6.7
    Medium

    CVE-2023-28740

    Last Modified: 21 Nov 2024

    Uncontrolled search path element in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    6.7
    Medium

    CVE-2023-28378

    Last Modified: 21 Nov 2024

    Improper authorization in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    6.7
    Medium

    CVE-2023-28388

    Last Modified: 11 Jun 2025

    Uncontrolled search path element in some Intel(R) Chipset Device Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    6.7
    Medium

    CVE-2023-29504

    Last Modified: 21 Nov 2024

    Uncontrolled search path element in some Intel(R) RealSense(TM) Dynamic Calibration software before version 2.13.1.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    6.7
    Medium

    CVE-2023-27513

    Last Modified: 11 Jun 2025

    Uncontrolled search path element in some Intel(R) Server Information Retrieval Utility software before version 16.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    7.5
    High

    CVE-2022-29510

    Last Modified: 21 Nov 2024

    Improper buffer restrictions in some Intel(R) Server Board M10JNP2SB BIOS firmware before version 7.219 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    7.5
    High

    CVE-2022-24379

    Last Modified: 21 Nov 2024

    Improper input validation in some Intel(R) Server System M70KLP Family BIOS firmware before version 01.04.0029 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    7.9
    High

    CVE-2022-29262

    Last Modified: 21 Nov 2024

    Improper buffer restrictions in some Intel(R) Server Board BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    8.2
    High

    CVE-2022-33945

    Last Modified: 21 Nov 2024

    Improper input validation in some Intel(R) Server board and Intel(R) Server System BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    8.2
    High

    CVE-2023-34431

    Last Modified: 21 Nov 2024

    Improper input validation in some Intel(R) Server Board BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access

    Published: 14 Nov 2023
    2.6
    Low

    CVE-2023-22329

    Last Modified: 13 Feb 2025

    Improper input validation in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via adjacent access.

    Published: 14 Nov 2023
    4.6
    Medium

    CVE-2023-25756

    Last Modified: 13 Feb 2025

    Out-of-bounds read in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 14 Nov 2023
    4.1
    Medium

    CVE-2023-40540

    Last Modified: 21 Nov 2024

    Non-Transparent Sharing of Microarchitectural Resources in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.

    Published: 14 Nov 2023
    5.3
    Medium

    CVE-2023-40220

    Last Modified: 21 Nov 2024

    Improper buffer restrictions in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.

    Published: 14 Nov 2023
    6.8
    Medium

    CVE-2023-27383

    Last Modified: 21 Nov 2024

    Protection mechanism failure in some Intel(R) oneAPI HPC Toolkit 2023.1 and Intel(R)MPI Library software before version 2021.9 may allow a privileged user to potentially enable escalation of privilege via adjacent access.

    Published: 14 Nov 2023
    7.3
    High

    CVE-2023-24592

    Last Modified: 21 Nov 2024

    Path traversal in the some Intel(R) oneAPI Toolkits and Component software before version 2023.1 may allow authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    6.7
    Medium

    CVE-2022-38786

    Last Modified: 21 Nov 2024

    Improper access control in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    6.7
    Medium

    CVE-2023-32662

    Last Modified: 21 Nov 2024

    Improper authorization in some Intel Battery Life Diagnostic Tool installation software before version 2.2.1 may allow a privilaged user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    6.7
    Medium

    CVE-2023-34430

    Last Modified: 21 Nov 2024

    Uncontrolled search path in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    3.9
    Low

    CVE-2023-38411

    Last Modified: 21 Nov 2024

    Improper access control in the Intel Smart Campus android application before version 9.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    6.7
    Medium

    CVE-2023-29161

    Last Modified: 21 Nov 2024

    Uncontrolled search path in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    8.4
    High

    CVE-2023-29157

    Last Modified: 21 Nov 2024

    Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    8.8
    High

    CVE-2023-32204

    Last Modified: 21 Nov 2024

    Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    4.3
    Medium

    CVE-2023-31203

    Last Modified: 21 Nov 2024

    Improper input validation in some OpenVINO Model Server software before version 2022.3 for Intel Distribution of OpenVINO toolkit may allow an unauthenticated user to potentially enable denial of service via network access.

    Published: 14 Nov 2023
    5.3
    Medium

    CVE-2023-25080

    Last Modified: 21 Nov 2024

    Protection mechanism failure in some Intel(R) Distribution of OpenVINO toolkit software before version 2023.0.0 may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 14 Nov 2023
    10
    Critical

    CVE-2023-31273

    Last Modified: 21 Nov 2024

    Protection mechanism failure in some Intel DCM software before version 5.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

    Published: 14 Nov 2023
    5.5
    Medium

    CVE-2023-33872

    Last Modified: 21 Nov 2024

    Improper access control in the Intel Support android application all verions may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 14 Nov 2023
    5.9
    Medium

    CVE-2023-24588

    Last Modified: 21 Nov 2024

    Exposure of sensitive information to an unauthorized actor in firmware for some Intel(R) Optane(TM) SSD products may allow an unauthenticated user to potentially enable information disclosure via physical access.

    Published: 14 Nov 2023
    6.5
    Medium

    CVE-2023-27306

    Last Modified: 21 Nov 2024

    Improper Initialization in firmware for some Intel(R) Optane(TM) SSD products may allow an authenticated user to potentially enable denial of service via local access.

    Published: 14 Nov 2023
    6.8
    Medium

    CVE-2023-27879

    Last Modified: 21 Nov 2024

    Improper access control in firmware for some Intel(R) Optane(TM) SSD products may allow an unauthenticated user to potentially enable information disclosure via physical access.

    Published: 14 Nov 2023
    6.9
    Medium

    CVE-2023-27519

    Last Modified: 11 Jun 2025

    Improper input validation in firmware for some Intel(R) Optane(TM) SSD products may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    6.9
    Medium

    CVE-2023-24587

    Last Modified: 21 Nov 2024

    Insufficient control flow management in firmware for some Intel(R) Optane(TM) SSD products may allow a privileged user to potentially enable denial of service via local access.

    Published: 14 Nov 2023
    6.5
    Medium

    CVE-2023-28376

    Last Modified: 13 Feb 2025

    Out-of-bounds read in the firmware for some Intel(R) E810 Ethernet Controllers and Adapters before version 1.7.1 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 14 Nov 2023
    7.3
    High

    CVE-2023-32641

    Last Modified: 21 Nov 2024

    Improper input validation in firmware for Intel(R) QAT before version QAT20.L.1.0.40-00004 may allow escalation of privilege and denial of service via adjacent access.

    Published: 14 Nov 2023
    6
    Medium

    CVE-2023-22327

    Last Modified: 21 Nov 2024

    Out-of-bounds write in firmware for some Intel(R) FPGA products before version 2.8.1 may allow a privileged user to potentially enable information disclosure via local access.

    Published: 14 Nov 2023