CVE Feed

    Dashboard / CVE

    6.6
    Medium

    CVE-2023-3712

    Last Modified: 12 Sept 2025

    Files or Directories Accessible to External Parties vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Privilege Escalation.This issue affects PM43 versions prior to P10.19.050004.  Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).

    Published: 12 Sept 2023
    9.8
    Critical

    CVE-2023-41331

    Last Modified: 21 Nov 2024

    SOFARPC is a Java RPC framework. Versions prior to 5.11.0 are vulnerable to remote command execution. Through a carefully crafted payload, an attacker can achieve JNDI injection or system command execution. In the default configuration of the SOFARPC framework, a blacklist is used to filter out dangerous classes encountered during the deserialization process. However, the blacklist is not comprehensive, and an actor can exploit certain native JDK classes and common third-party packages to construct gadget chains capable of achieving JNDI injection or system command execution attacks. Version 5.11.0 contains a fix for this issue. As a workaround, users can add `-Drpc_serialize_blacklist_override=javax.sound.sampled.AudioFileFormat` to the blacklist.

    Published: 12 Sept 2023
    6.4
    Medium

    CVE-2023-3711

    Last Modified: 12 Sept 2025

    Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Falsification through Prediction.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).

    Published: 12 Sept 2023
    7.2
    High

    CVE-2023-39201

    Last Modified: 21 Nov 2024

    Untrusted search path in CleanZoom before file date 07/24/2023 may allow a privileged user to conduct an escalation of privilege via local access.

    Published: 12 Sept 2023
    9.9
    Critical

    CVE-2023-3710

    Last Modified: 12 Sept 2025

    Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).

    Published: 12 Sept 2023
    6.5
    Medium

    CVE-2023-39208

    Last Modified: 21 Nov 2024

    Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to conduct a denial of service via network access.

    Published: 12 Sept 2023
    7.1
    High

    CVE-2023-39215

    Last Modified: 21 Nov 2024

    Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-41036

    Last Modified: 27 Nov 2024

    Macvim is a text editor for MacOS. Prior to version 178, Macvim makes use of an insecure interprocess communication (IPC) mechanism which could lead to a privilege escalation. Distributed objects are a concept introduced by Apple which allow one program to vend an interface to another program. What is not made clear in the documentation is that this service can vend this interface to any other program on the machine. The impact of exploitation is a privilege escalation to root - this is likely to affect anyone who is not careful about the software they download and use MacVim to edit files that would require root privileges. Version 178 contains a fix for this issue.

    Published: 12 Sept 2023
    5.3
    Medium

    CVE-2023-21520

    Last Modified: 21 Nov 2024

    A PII Enumeration via Credential Recovery in the Self Service (Credential Recovery) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially associate a list of contact details with an AtHoc IWS organization.

    Published: 12 Sept 2023
    5.4
    Medium

    CVE-2023-21523

    Last Modified: 21 Nov 2024

    A Stored Cross-site Scripting (XSS) vulnerability in the Management Console (User Management and Alerts) of BlackBerry AtHoc version 7.15 could allow an attacker to execute script commands in the context of the affected user account.

    Published: 12 Sept 2023
    6.8
    Medium

    CVE-2023-30962

    Last Modified: 21 Nov 2024

    The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Gotham to launch attacks against other users. This vulnerability is resolved in Cerberus 100.230704.0-27-g031dd58 .

    Published: 12 Sept 2023
    6.1
    Medium

    CVE-2023-21522

    Last Modified: 21 Nov 2024

    A Reflected Cross-site Scripting (XSS) vulnerability in the Management Console (Reports) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially control a script that is executed in the victim's browser then they can execute script commands in the context of the affected user account. 

    Published: 12 Sept 2023
    7.2
    High

    CVE-2023-21521

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability in the Management Console  (Operator Audit Trail) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database, recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system.

    Published: 12 Sept 2023
    9.8
    Critical

    CVE-2023-4501

    Last Modified: 4 Aug 2026

    User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), versions 7.0 patch updates 19 and 20, 8.0 patch updates 8 and 9, and 9.0 patch update 1, when LDAP-based authentication is used with certain configurations. When the vulnerability is active, authentication succeeds with any valid username, regardless of whether the password is correct; it may also succeed with an invalid username (and any password). This allows an attacker with access to the product to impersonate any user. Mitigations: The issue is corrected in the upcoming patch update for each affected product. Product overlays and workaround instructions are available through OpenText Support. The vulnerable configurations are believed to be uncommon. Administrators can test for the vulnerability in their installations by attempting to sign on to a Visual COBOL or Enterprise Server component such as ESCWA using a valid username and incorrect password.

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-36739

    Last Modified: 30 Oct 2025

    3D Viewer Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-36740

    Last Modified: 30 Oct 2025

    3D Viewer Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-36760

    Last Modified: 30 Oct 2025

    3D Viewer Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    6.5
    Medium

    CVE-2023-36761

    Last Modified: 30 Oct 2025

    Microsoft Word Information Disclosure Vulnerability

    Published: 12 Sept 2023
    7.3
    High

    CVE-2023-36762

    Last Modified: 30 Oct 2025

    Microsoft Word Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    7.5
    High

    CVE-2023-36763

    Last Modified: 30 Oct 2025

    Microsoft Outlook Information Disclosure Vulnerability

    Published: 12 Sept 2023
    8.8
    High

    CVE-2023-36764

    Last Modified: 30 Oct 2025

    Microsoft SharePoint Server Elevation of Privilege Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-36770

    Last Modified: 30 Oct 2025

    3D Builder Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-36771

    Last Modified: 30 Oct 2025

    3D Builder Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-36772

    Last Modified: 30 Oct 2025

    3D Builder Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-36773

    Last Modified: 30 Oct 2025

    3D Builder Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    5.7
    Medium

    CVE-2023-36777

    Last Modified: 30 Oct 2025

    Microsoft Exchange Server Information Disclosure Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-36788

    Last Modified: 30 Oct 2025

    .NET Framework Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-36792

    Last Modified: 30 Oct 2025

    Visual Studio Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-36793

    Last Modified: 30 Oct 2025

    Visual Studio Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-36794

    Last Modified: 30 Oct 2025

    Visual Studio Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-36796

    Last Modified: 30 Oct 2025

    Visual Studio Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    6.5
    Medium

    CVE-2023-36799

    Last Modified: 30 Oct 2025

    .NET Core and Visual Studio Denial of Service Vulnerability

    Published: 12 Sept 2023
    7.6
    High

    CVE-2023-36800

    Last Modified: 30 Oct 2025

    Dynamics Finance and Operations Cross-site Scripting Vulnerability

    Published: 12 Sept 2023
    7
    High

    CVE-2023-38155

    Last Modified: 30 Oct 2025

    Azure DevOps Server Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    5.5
    Medium

    CVE-2023-38160

    Last Modified: 30 Oct 2025

    Windows TCP/IP Information Disclosure Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-38163

    Last Modified: 30 Oct 2025

    Windows Defender Attack Surface Reduction Security Feature Bypass

    Published: 12 Sept 2023
    7.6
    High

    CVE-2023-38164

    Last Modified: 30 Oct 2025

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

    Published: 12 Sept 2023
    7.6
    High

    CVE-2023-36886

    Last Modified: 30 Oct 2025

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

    Published: 12 Sept 2023
    8.8
    High

    CVE-2023-33136

    Last Modified: 30 Oct 2025

    Azure DevOps Server Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    7.5
    High

    CVE-2023-29332

    Last Modified: 30 Oct 2025

    Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability

    Published: 12 Sept 2023
    5.5
    Medium

    CVE-2023-41764

    Last Modified: 30 Oct 2025

    Microsoft Office Spoofing Vulnerability

    Published: 12 Sept 2023
    4.4
    Medium

    CVE-2023-36736

    Last Modified: 30 Oct 2025

    Microsoft Identity Linux Broker Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-36742

    Last Modified: 30 Oct 2025

    Visual Studio Code Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    8
    High

    CVE-2023-36744

    Last Modified: 30 Oct 2025

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    8
    High

    CVE-2023-36745

    Last Modified: 30 Oct 2025

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    8
    High

    CVE-2023-36756

    Last Modified: 30 Oct 2025

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    8
    High

    CVE-2023-36757

    Last Modified: 30 Oct 2025

    Microsoft Exchange Server Spoofing Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-36758

    Last Modified: 30 Oct 2025

    Visual Studio Elevation of Privilege Vulnerability

    Published: 12 Sept 2023
    6.7
    Medium

    CVE-2023-36759

    Last Modified: 30 Oct 2025

    Visual Studio Elevation of Privilege Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-36765

    Last Modified: 30 Oct 2025

    Microsoft Office Elevation of Privilege Vulnerability

    Published: 12 Sept 2023