CVE-2023-45133
Last Modified: 13 Feb 2025Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the `path.evaluate()`or `path.evaluateTruthy()` internal Babel methods. Known affected plugins are `@babel/plugin-transform-runtime`; `@babel/preset-env` when using its `useBuiltIns` option; and any "polyfill provider" plugin that depends on `@babel/helper-define-polyfill-provider`, such as `babel-plugin-polyfill-corejs3`, `babel-plugin-polyfill-corejs2`, `babel-plugin-polyfill-es-shims`, `babel-plugin-polyfill-regenerator`. No other plugins under the `@babel/` namespace are impacted, but third-party plugins might be. Users that only compile trusted code are not impacted. The vulnerability has been fixed in `@babel/[email protected]` and `@babel/[email protected]`. Those who cannot upgrade `@babel/traverse` and are using one of the affected packages mentioned above should upgrade them to their latest version to avoid triggering the vulnerable code path in affected `@babel/traverse` versions: `@babel/plugin-transform-runtime` v7.23.2, `@babel/preset-env` v7.23.2, `@babel/helper-define-polyfill-provider` v0.4.3, `babel-plugin-polyfill-corejs2` v0.4.6, `babel-plugin-polyfill-corejs3` v0.8.5, `babel-plugin-polyfill-es-shims` v0.10.0, `babel-plugin-polyfill-regenerator` v0.5.3.
CVE-2023-5510
Last Modified: 11 Feb 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-26220
Last Modified: 21 Nov 2024The Spotfire Library component of TIBCO Software Inc.'s Spotfire Analyst and Spotfire Server contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s Spotfire Analyst: versions 11.4.7 and below, versions 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4, versions 12.1.0 and 12.1.1 and Spotfire Server: versions 11.4.11 and below, versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.0.4, and 12.0.5, versions 12.1.0 and 12.1.1.
CVE-2023-5508
Last Modified: 11 Feb 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-5497
Last Modified: 21 Nov 2024A vulnerability classified as critical has been found in Tongda OA 2017 11.10. Affected is an unknown function of the file general/hr/salary/welfare_manage/delete.php. The manipulation of the argument WELFARE_ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-241650 is the identifier assigned to this vulnerability.
CVE-2023-4309
Last Modified: 21 Nov 2024Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. These vulnerabilities allow an unauthenticated, remote attacker to read or modify data for any elections that share the same backend database. ESC deactivated older and unused elections and enabled web application firewall (WAF) protection for current and future elections on or around 2023-08-12.
CVE-2023-36414
Last Modified: 14 Apr 2025Azure Identity SDK Remote Code Execution Vulnerability
CVE-2023-36415
Last Modified: 14 Apr 2025Azure Identity SDK Remote Code Execution Vulnerability
CVE-2023-36416
Last Modified: 14 Apr 2025Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-36418
Last Modified: 14 Apr 2025Azure RTOS GUIX Studio Remote Code Execution Vulnerability
CVE-2023-36436
Last Modified: 14 Apr 2025Windows MSHTML Platform Remote Code Execution Vulnerability
CVE-2023-36565
Last Modified: 22 May 2026Microsoft Office Graphics Elevation of Privilege Vulnerability
CVE-2023-36566
Last Modified: 14 Apr 2025Microsoft Common Data Model SDK Denial of Service Vulnerability
CVE-2023-36743
Last Modified: 14 Apr 2025Win32k Elevation of Privilege Vulnerability
CVE-2023-36776
Last Modified: 14 Apr 2025Win32k Elevation of Privilege Vulnerability
CVE-2023-36778
Last Modified: 14 Apr 2025Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-36780
Last Modified: 14 Apr 2025Skype for Business Remote Code Execution Vulnerability
CVE-2023-36785
Last Modified: 14 Apr 2025Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
CVE-2023-36786
Last Modified: 14 Apr 2025Skype for Business Remote Code Execution Vulnerability
CVE-2023-36789
Last Modified: 14 Apr 2025Skype for Business Remote Code Execution Vulnerability
CVE-2023-36790
Last Modified: 14 Apr 2025Windows RDP Encoder Mirror Driver Elevation of Privilege Vulnerability
CVE-2023-38159
Last Modified: 14 Apr 2025Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2023-38166
Last Modified: 14 Apr 2025Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
CVE-2023-29348
Last Modified: 14 Apr 2025Windows Remote Desktop Gateway (RD Gateway) Information Disclosure Vulnerability
CVE-2023-36417
Last Modified: 14 Apr 2025Microsoft SQL OLE DB Remote Code Execution Vulnerability
CVE-2023-36419
Last Modified: 11 Feb 2026Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability
CVE-2023-36420
Last Modified: 14 Apr 2025Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
CVE-2023-36429
Last Modified: 14 Apr 2025Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2023-36431
Last Modified: 14 Apr 2025Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVE-2023-36433
Last Modified: 14 Apr 2025Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2023-36434
Last Modified: 14 Apr 2025Windows IIS Server Elevation of Privilege Vulnerability
CVE-2023-36438
Last Modified: 14 Apr 2025Windows TCP/IP Information Disclosure Vulnerability
CVE-2023-36557
Last Modified: 14 Apr 2025PrintHTML API Remote Code Execution Vulnerability
CVE-2023-36561
Last Modified: 14 Apr 2025Azure DevOps Server Elevation of Privilege Vulnerability
CVE-2023-36563
Last Modified: 28 Oct 2025Microsoft WordPad Information Disclosure Vulnerability
CVE-2023-36564
Last Modified: 14 Apr 2025Windows Search Security Feature Bypass Vulnerability
CVE-2023-36567
Last Modified: 14 Apr 2025Windows Deployment Services Information Disclosure Vulnerability
CVE-2023-36568
Last Modified: 14 Apr 2025Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
CVE-2023-36569
Last Modified: 14 Apr 2025Microsoft Office Elevation of Privilege Vulnerability
CVE-2023-36570
Last Modified: 14 Apr 2025Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2023-36571
Last Modified: 14 Apr 2025Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2023-36572
Last Modified: 14 Apr 2025Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2023-36573
Last Modified: 14 Apr 2025Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2023-36574
Last Modified: 14 Apr 2025Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2023-36575
Last Modified: 14 Apr 2025Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2023-36576
Last Modified: 14 Apr 2025Windows Kernel Information Disclosure Vulnerability
CVE-2023-36577
Last Modified: 14 Apr 2025Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2023-36578
Last Modified: 14 Apr 2025Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2023-36579
Last Modified: 14 Apr 2025Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVE-2023-36581
Last Modified: 14 Apr 2025Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
