CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2023-36730

    Last Modified: 14 Apr 2025

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

    Published: 10 Oct 2023
    7.8
    High

    CVE-2023-36731

    Last Modified: 14 Apr 2025

    Win32k Elevation of Privilege Vulnerability

    Published: 10 Oct 2023
    7.8
    High

    CVE-2023-36732

    Last Modified: 14 Apr 2025

    Win32k Elevation of Privilege Vulnerability

    Published: 10 Oct 2023
    8.1
    High

    CVE-2023-41774

    Last Modified: 14 Apr 2025

    Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

    Published: 10 Oct 2023
    8.1
    High

    CVE-2023-41773

    Last Modified: 14 Apr 2025

    Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

    Published: 10 Oct 2023
    7.8
    High

    CVE-2023-41772

    Last Modified: 14 Apr 2025

    Win32k Elevation of Privilege Vulnerability

    Published: 10 Oct 2023
    8.1
    High

    CVE-2023-41771

    Last Modified: 14 Apr 2025

    Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

    Published: 10 Oct 2023
    8.1
    High

    CVE-2023-41770

    Last Modified: 14 Apr 2025

    Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

    Published: 10 Oct 2023
    8.1
    High

    CVE-2023-41769

    Last Modified: 14 Apr 2025

    Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

    Published: 10 Oct 2023
    8.1
    High

    CVE-2023-41768

    Last Modified: 14 Apr 2025

    Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

    Published: 10 Oct 2023
    8.1
    High

    CVE-2023-41767

    Last Modified: 14 Apr 2025

    Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

    Published: 10 Oct 2023
    7.8
    High

    CVE-2023-41766

    Last Modified: 14 Apr 2025

    Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

    Published: 10 Oct 2023
    8.1
    High

    CVE-2023-41765

    Last Modified: 14 Apr 2025

    Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

    Published: 10 Oct 2023
    5.3
    Medium

    CVE-2023-41763

    Last Modified: 28 Oct 2025

    Skype for Business Elevation of Privilege Vulnerability

    Published: 10 Oct 2023
    7.8
    High

    CVE-2023-36737

    Last Modified: 14 Apr 2025

    Azure Network Watcher VM Agent Elevation of Privilege Vulnerability

    Published: 10 Oct 2023
    7
    High

    CVE-2023-36902

    Last Modified: 14 Apr 2025

    Windows Runtime Remote Code Execution Vulnerability

    Published: 10 Oct 2023
    9.8
    Critical

    CVE-2023-35349

    Last Modified: 14 Apr 2025

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

    Published: 10 Oct 2023
    3.1
    Low

    CVE-2023-5496

    Last Modified: 16 Jun 2025

    A vulnerability was found in Translator PoqDev Add-On 1.0.11 on Firefox. It has been rated as problematic. This issue affects some unknown processing of the component Select Text Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-241649 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Oct 2023
    5.3
    Medium

    CVE-2023-44399

    Last Modified: 21 Nov 2024

    ZITADEL provides identity infrastructure. In versions 2.37.2 and prior, ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. While this settings was properly working during the authentication process it did not work correctly on the password reset flow. This meant that even if this feature was active that an attacker could use the password reset function to verify if an account exist within ZITADEL. This bug has been patched in versions 2.37.3 and 2.38.0. No known workarounds are available.

    Published: 10 Oct 2023
    8.5
    High

    CVE-2023-41679

    Last Modified: 16 Dec 2025

    An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions may allow a remote and authenticated attacker with at least "device management" permission on his profile and belonging to a specific ADOM to add and delete CLI script on other ADOMs

    Published: 10 Oct 2023
    7.8
    High

    CVE-2023-25607

    Last Modified: 16 Dec 2025

    An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78 ] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions, FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and FortiADC  7.1.0, 7.0.0 through 7.0.3, 6.2 all versions, 6.1 all versions, 6.0 all versions management interface may allow an authenticated attacker with at least READ permissions on system settings to execute arbitrary commands on the underlying shell due to an unsafe usage of the wordexp function.

    Published: 10 Oct 2023
    6.5
    Medium

    CVE-2023-37935

    Last Modified: 21 Nov 2024

    A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET requests to those services.

    Published: 10 Oct 2023
    9.8
    Critical

    CVE-2023-36548

    Last Modified: 21 Nov 2024

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.

    Published: 10 Oct 2023
    9.8
    Critical

    CVE-2023-36547

    Last Modified: 21 Nov 2024

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.

    Published: 10 Oct 2023
    9.8
    Critical

    CVE-2023-34993

    Last Modified: 21 Nov 2024

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.

    Published: 10 Oct 2023
    9.8
    Critical

    CVE-2023-36550

    Last Modified: 21 Nov 2024

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.

    Published: 10 Oct 2023
    8.8
    High

    CVE-2023-36549

    Last Modified: 21 Nov 2024

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.

    Published: 10 Oct 2023
    8.8
    High

    CVE-2023-34989

    Last Modified: 21 Nov 2024

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters.

    Published: 10 Oct 2023
    8.8
    High

    CVE-2023-34987

    Last Modified: 21 Nov 2024

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters.

    Published: 10 Oct 2023
    8.8
    High

    CVE-2023-34986

    Last Modified: 21 Nov 2024

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters.

    Published: 10 Oct 2023
    8.8
    High

    CVE-2023-34985

    Last Modified: 21 Nov 2024

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters.

    Published: 10 Oct 2023
    8.8
    High

    CVE-2023-34988

    Last Modified: 21 Nov 2024

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters.

    Published: 10 Oct 2023
    5.3
    Medium

    CVE-2023-42782

    Last Modified: 21 Nov 2024

    A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages to the syslog server of FortiAnalyzer via the knoweldge of an authorized device serial number.

    Published: 10 Oct 2023
    10
    Critical

    CVE-2023-34992

    Last Modified: 14 Jan 2026

    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests.

    Published: 10 Oct 2023
    3.5
    Low

    CVE-2023-36637

    Last Modified: 21 Nov 2024

    An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to inject HTML tags in FortiMail's calendar via input fields.

    Published: 10 Oct 2023
    3.3
    Low

    CVE-2023-37939

    Last Modified: 21 Nov 2024

    An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Windows 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions, Linux 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions and Mac 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions, 6.2 all versions, may allow a local authenticated attacker with no Administrative privileges to retrieve the list of files or folders excluded from malware scanning.

    Published: 10 Oct 2023
    5.3
    Medium

    CVE-2023-41675

    Last Modified: 21 Nov 2024

    A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to crash the WAD process via multiple crafted packets reaching proxy policies or firewall policies with proxy mode alongside SSL deep packet inspection.

    Published: 10 Oct 2023
    8.8
    High

    CVE-2023-36556

    Last Modified: 16 Dec 2025

    An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the same web domain via crafted HTTP or HTTPs requests.

    Published: 10 Oct 2023
    6.7
    Medium

    CVE-2022-22298

    Last Modified: 21 Nov 2024

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiIsolator version 1.0.0, FortiIsolator version 1.1.0, FortiIsolator version 1.2.0 through 1.2.2, FortiIsolator version 2.0.0 through 2.0.1, FortiIsolator version 2.1.0 through 2.1.2, FortiIsolator version 2.2.0, FortiIsolator version 2.3.0 through 2.3.4 allows attacker to execute arbitrary OS commands in the underlying shell via specially crafted input parameters.

    Published: 10 Oct 2023
    5.5
    Medium

    CVE-2023-25604

    Last Modified: 21 Nov 2024

    An insertion of sensitive information into log file vulnerability in Fortinet FortiGuest 1.0.0 allows a local attacker to access plaintext passwords in the RADIUS logs.

    Published: 10 Oct 2023
    8.1
    High

    CVE-2023-41841

    Last Modified: 16 Dec 2025

    An improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4 allows an attacker belonging to the prof-admin profile to perform elevated actions.

    Published: 10 Oct 2023
    7.1
    High

    CVE-2023-41838

    Last Modified: 21 Nov 2024

    An improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 may allow attacker to execute unauthorized code or commands via FortiManager cli.

    Published: 10 Oct 2023
    7.5
    High

    CVE-2023-40718

    Last Modified: 21 Nov 2024

    A interpretation conflict in Fortinet IPS Engine versions 7.321, 7.166 and 6.158 allows attacker to evade IPS features via crafted TCP packets.

    Published: 10 Oct 2023
    7.8
    High

    CVE-2023-42788

    Last Modified: 16 Dec 2025

    An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.8, version 6.4.0 through 6.4.12 and version 6.2.0 through 6.2.11 may allow a local attacker with low privileges to execute unauthorized code via specifically crafted arguments to a CLI command

    Published: 10 Oct 2023
    6.5
    Medium

    CVE-2023-42787

    Last Modified: 12 Aug 2026

    A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web console via client side code execution.

    Published: 10 Oct 2023
    4.3
    Medium

    CVE-2023-44249

    Last Modified: 13 Feb 2025

    An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 allows a remote attacker with low privileges to read sensitive information via crafted HTTP requests.

    Published: 10 Oct 2023
    3.9
    Low

    CVE-2023-36555

    Last Modified: 21 Nov 2024

    An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via the SAML and Security Fabric components.

    Published: 10 Oct 2023
    6.5
    Medium

    CVE-2023-33301

    Last Modified: 21 Nov 2024

    An improper access control vulnerability in Fortinet FortiOS 7.2.0 - 7.2.4 and 7.4.0 allows an attacker to access a restricted resource from a non trusted host.

    Published: 10 Oct 2023
    6.3
    Medium

    CVE-2023-5495

    Last Modified: 13 Feb 2025

    A vulnerability was found in QDocs Smart School 6.4.1. It has been classified as critical. This affects an unknown part of the file /course/filterRecords/ of the component HTTP POST Request Handler. The manipulation of the argument searchdata[0][title]/searchdata[0][searchfield]/searchdata[0][searchvalue] leads to sql injection. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-241647. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Oct 2023
    6.3
    Medium

    CVE-2023-5494

    Last Modified: 21 Nov 2024

    A vulnerability was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230928 and classified as critical. Affected by this issue is some unknown functionality of the file /log/download.php. The manipulation of the argument file leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-241646 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Oct 2023