CVE Feed

    Dashboard / CVE

    5.6
    Medium

    CVE-2023-25071

    Last Modified: 21 Nov 2024

    NULL pointer dereference in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows Drviers before version 31.0.101.4255 may allow authenticated user to potentially enable denial of service via local access.

    Published: 14 Nov 2023
    6.1
    Medium

    CVE-2022-42879

    Last Modified: 21 Nov 2024

    NULL pointer dereference in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 14 Nov 2023
    6.1
    Medium

    CVE-2023-25952

    Last Modified: 21 Nov 2024

    Out-of-bounds write in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 14 Nov 2023
    6.7
    Medium

    CVE-2023-27305

    Last Modified: 21 Nov 2024

    Incorrect default permissions in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    6.7
    Medium

    CVE-2023-29165

    Last Modified: 21 Nov 2024

    Unquoted search path or element in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    6.7
    Medium

    CVE-2023-34350

    Last Modified: 21 Nov 2024

    Uncontrolled search path element in some Intel(R) XTU software before version 7.12.0.15 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    6.7
    Medium

    CVE-2023-34314

    Last Modified: 21 Nov 2024

    Insecure inherited permissions in some Intel(R) Simics Simulator software before version 1.7.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    6.7
    Medium

    CVE-2023-32638

    Last Modified: 21 Nov 2024

    Incorrect default permissions in some Intel Arc RGB Controller software before version 1.06 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    6.7
    Medium

    CVE-2023-39230

    Last Modified: 21 Nov 2024

    Insecure inherited permissions in some Intel Rapid Storage Technology software before version 16.8.5.1014.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    9.8
    Critical

    CVE-2023-20596

    Last Modified: 21 Nov 2024

    Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leading to arbitrary code execution.

    Published: 14 Nov 2023
    8.1
    High

    CVE-2023-20571

    Last Modified: 21 Nov 2024

    A race condition in System Management Mode (SMM) code may allow an attacker using a compromised user space to leverage CVE-2018-8897 potentially resulting in privilege escalation.

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-20565

    Last Modified: 21 Nov 2024

    Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-20563

    Last Modified: 21 Nov 2024

    Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2023
    9.8
    Critical

    CVE-2022-23821

    Last Modified: 3 Dec 2024

    Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.

    Published: 14 Nov 2023
    6.1
    Medium

    CVE-2021-46758

    Last Modified: 21 Nov 2024

    Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapped beyond SPI flash resulting in a potential loss of availability and integrity.

    Published: 14 Nov 2023
    5.3
    Medium

    CVE-2023-20566

    Last Modified: 3 Dec 2024

    Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.

    Published: 14 Nov 2023
    3.3
    Low

    CVE-2023-20519

    Last Modified: 21 Nov 2024

    A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest integrity.

    Published: 14 Nov 2023
    1.9
    Low

    CVE-2022-23830

    Last Modified: 21 Nov 2024

    SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity.

    Published: 14 Nov 2023
    1.9
    Low

    CVE-2021-26345

    Last Modified: 21 Nov 2024

    Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service.

    Published: 14 Nov 2023
    5.9
    Medium

    CVE-2023-47653

    Last Modified: 7 Jan 2025

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Abu Bakar TWB Woocommerce Reviews plugin <= 1.7.5 versions.

    Published: 14 Nov 2023
    6.1
    Medium

    CVE-2023-20533

    Last Modified: 21 Nov 2024

    Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.

    Published: 14 Nov 2023
    1.9
    Low

    CVE-2023-20526

    Last Modified: 21 Nov 2024

    Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.

    Published: 14 Nov 2023
    3.3
    Low

    CVE-2023-20521

    Last Modified: 21 Nov 2024

    TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.

    Published: 14 Nov 2023
    7.5
    High

    CVE-2022-23820

    Last Modified: 21 Nov 2024

    Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.

    Published: 14 Nov 2023
    6.7
    Medium

    CVE-2021-46774

    Last Modified: 21 Nov 2024

    Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.

    Published: 14 Nov 2023
    2.5
    Low

    CVE-2021-46766

    Last Modified: 21 Nov 2024

    Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.

    Published: 14 Nov 2023
    7.5
    High

    CVE-2023-31320

    Last Modified: 21 Nov 2024

    Improper input validation in the AMD RadeonTM Graphics display driver may allow an attacker to corrupt the display potentially resulting in denial of service.

    Published: 14 Nov 2023
    6.7
    Medium

    CVE-2023-20568

    Last Modified: 13 Feb 2025

    Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch RadeonInstaller.exe without validating the file signature potentially leading to arbitrary code execution.

    Published: 14 Nov 2023
    6.7
    Medium

    CVE-2023-20567

    Last Modified: 13 Feb 2025

    Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareInstaller.exe without validating the file signature potentially leading to arbitrary code execution.

    Published: 14 Nov 2023
    5.5
    Medium

    CVE-2021-46748

    Last Modified: 13 Feb 2025

    Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds of what is permissible to a TA (Trusted Application) resulting in a potential denial of service.

    Published: 14 Nov 2023
    6.5
    Medium

    CVE-2023-47654

    Last Modified: 7 Jan 2025

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in livescore.Bz BZScore – Live Score plugin <= 1.03 versions.

    Published: 14 Nov 2023
    5.9
    Medium

    CVE-2023-47656

    Last Modified: 7 Jan 2025

    Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi ANAC XML Bandi di Gara plugin <= 7.5 versions.

    Published: 14 Nov 2023
    5.9
    Medium

    CVE-2023-47658

    Last Modified: 7 Jan 2025

    Auth. (ShopManager+) Stored Cross-Site Scripting (XSS) vulnerability in actpro Extra Product Options for WooCommerce plugin <= 3.0.3 versions.

    Published: 14 Nov 2023
    7.1
    High

    CVE-2023-32701

    Last Modified: 9 Sept 2025

    Improper Input Validation in the Networking Stack of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially cause Information Disclosure or a Denial-of-Service condition.

    Published: 14 Nov 2023
    7.1
    High

    CVE-2022-40681

    Last Modified: 21 Nov 2024

    A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to cause denial of service via sending a crafted request to a specific named pipe.

    Published: 14 Nov 2023
    5.4
    Medium

    CVE-2023-25603

    Last Modified: 21 Nov 2024

    A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1 allow an unauthorized attacker to carry out privileged actions and retrieve sensitive information via crafted web requests.

    Published: 14 Nov 2023
    4.1
    Medium

    CVE-2023-40719

    Last Modified: 21 Nov 2024

    A use of hard-coded credentials vulnerability in Fortinet FortiAnalyzer and FortiManager 7.0.0 - 7.0.8, 7.2.0 - 7.2.3 and 7.4.0 allows an attacker to access Fortinet private testing data via the use of static credentials.

    Published: 14 Nov 2023
    6.7
    Medium

    CVE-2023-29177

    Last Modified: 21 Nov 2024

    Multiple buffer copy without checking size of input ('classic buffer overflow') vulnerabilities [CWE-120] in FortiADC version 7.2.0 and before 7.1.2 & FortiDDoS-F version 6.5.0 and before 6.4.1 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI requests.

    Published: 14 Nov 2023
    5.4
    Medium

    CVE-2023-36633

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests.

    Published: 14 Nov 2023
    9.8
    Critical

    CVE-2023-34991

    Last Modified: 16 Dec 2025

    A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.0 through 8.4.2 and 8.3.0 through 8.3.2 and 8.2.2 allows attacker to execute unauthorized code or commands via a crafted http request.

    Published: 14 Nov 2023
    4.4
    Medium

    CVE-2023-33304

    Last Modified: 21 Nov 2024

    A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an attacker to bypass system protections via the use of static credentials.

    Published: 14 Nov 2023
    4.4
    Medium

    CVE-2023-44248

    Last Modified: 14 Jan 2026

    An improper access control vulnerability [CWE-284] in FortiEDRCollectorWindows version 5.2.0.4549 and below, 5.0.3.1007 and below, 4.0 all may allow a local attacker to prevent the collector service to start in the next system reboot by tampering with some registry keys of the service.

    Published: 14 Nov 2023
    8.1
    High

    CVE-2023-26205

    Last Modified: 16 Dec 2025

    An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a specific crafted configuration of fabric automation CLI script.

    Published: 14 Nov 2023
    2.3
    Low

    CVE-2023-45585

    Last Modified: 21 Nov 2024

    An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0, version 6.7.6 and below, version 6.6.3 and below, version 6.5.1 and below, version 6.4.2 and below, version 6.3.3 and below, version 6.2.1 and below, version 6.1.2 and below, version 5.4.0, version 5.3.3 and below may allow an authenticated user to view an encrypted ElasticSearch password via debug log files generated when FortiSIEM is configured with ElasticSearch Event Storage.

    Published: 14 Nov 2023
    4.3
    Medium

    CVE-2023-41676

    Last Modified: 21 Nov 2024

    An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with access to windows agent logs to obtain the windows agent password via searching through the logs.

    Published: 14 Nov 2023
    5.6
    Medium

    CVE-2023-45582

    Last Modified: 21 Nov 2024

    An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to  perform a brute force attack on the affected endpoints via repeated login attempts.

    Published: 14 Nov 2023
    9.8
    Critical

    CVE-2023-36553

    Last Modified: 16 Dec 2025

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.3.3 and 5.2.5 through 5.2.8 and 5.2.1 through 5.2.2 and 5.1.0 through 5.1.3 and 5.0.0 through 5.0.1 and 4.10.0 and 4.9.0 and 4.7.2 allows attacker to execute unauthorized code or commands via crafted API requests.

    Published: 14 Nov 2023
    6.4
    Medium

    CVE-2023-28002

    Last Modified: 11 Jun 2025

    An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.12, 6.4 all versions, 6.2 all versions, 6.0 all versions and VMs may allow a local attacker with admin privileges to boot a malicious image on the device and bypass the filesystem integrity check in place.

    Published: 14 Nov 2023
    6.5
    Medium

    CVE-2023-36641

    Last Modified: 21 Nov 2024

    A numeric truncation error in Fortinet FortiProxy version 7.2.0 through 7.2.4, FortiProxy version 7.0.0 through 7.0.10, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1, all versions, FortiProxy 1.0 all versions, FortiOS version 7.4.0, FortiOS version 7.2.0 through 7.2.5, FortiOS version 7.0.0 through 7.0.12, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions allows attacker to denial of service via specifically crafted HTTP requests.

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-41840

    Last Modified: 16 Dec 2025

    A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to perform a DLL Hijack attack via a malicious OpenSSL engine library in the search path.

    Published: 14 Nov 2023