CVE-2023-3712
Last Modified: 12 Sept 2025Files or Directories Accessible to External Parties vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Privilege Escalation.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).
CVE-2023-41331
Last Modified: 21 Nov 2024SOFARPC is a Java RPC framework. Versions prior to 5.11.0 are vulnerable to remote command execution. Through a carefully crafted payload, an attacker can achieve JNDI injection or system command execution. In the default configuration of the SOFARPC framework, a blacklist is used to filter out dangerous classes encountered during the deserialization process. However, the blacklist is not comprehensive, and an actor can exploit certain native JDK classes and common third-party packages to construct gadget chains capable of achieving JNDI injection or system command execution attacks. Version 5.11.0 contains a fix for this issue. As a workaround, users can add `-Drpc_serialize_blacklist_override=javax.sound.sampled.AudioFileFormat` to the blacklist.
CVE-2023-3711
Last Modified: 12 Sept 2025Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Falsification through Prediction.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).
CVE-2023-39201
Last Modified: 21 Nov 2024Untrusted search path in CleanZoom before file date 07/24/2023 may allow a privileged user to conduct an escalation of privilege via local access.
CVE-2023-3710
Last Modified: 12 Sept 2025Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).
CVE-2023-39208
Last Modified: 21 Nov 2024Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to conduct a denial of service via network access.
CVE-2023-39215
Last Modified: 21 Nov 2024Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.
CVE-2023-41036
Last Modified: 27 Nov 2024Macvim is a text editor for MacOS. Prior to version 178, Macvim makes use of an insecure interprocess communication (IPC) mechanism which could lead to a privilege escalation. Distributed objects are a concept introduced by Apple which allow one program to vend an interface to another program. What is not made clear in the documentation is that this service can vend this interface to any other program on the machine. The impact of exploitation is a privilege escalation to root - this is likely to affect anyone who is not careful about the software they download and use MacVim to edit files that would require root privileges. Version 178 contains a fix for this issue.
CVE-2023-21520
Last Modified: 21 Nov 2024A PII Enumeration via Credential Recovery in the Self Service (Credential Recovery) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially associate a list of contact details with an AtHoc IWS organization.
CVE-2023-21523
Last Modified: 21 Nov 2024A Stored Cross-site Scripting (XSS) vulnerability in the Management Console (User Management and Alerts) of BlackBerry AtHoc version 7.15 could allow an attacker to execute script commands in the context of the affected user account.
CVE-2023-30962
Last Modified: 21 Nov 2024The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Gotham to launch attacks against other users. This vulnerability is resolved in Cerberus 100.230704.0-27-g031dd58 .
CVE-2023-21522
Last Modified: 21 Nov 2024A Reflected Cross-site Scripting (XSS) vulnerability in the Management Console (Reports) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially control a script that is executed in the victim's browser then they can execute script commands in the context of the affected user account.
CVE-2023-21521
Last Modified: 21 Nov 2024An SQL Injection vulnerability in the Management Console (Operator Audit Trail) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database, recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system.
CVE-2023-4501
Last Modified: 4 Aug 2026User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), versions 7.0 patch updates 19 and 20, 8.0 patch updates 8 and 9, and 9.0 patch update 1, when LDAP-based authentication is used with certain configurations. When the vulnerability is active, authentication succeeds with any valid username, regardless of whether the password is correct; it may also succeed with an invalid username (and any password). This allows an attacker with access to the product to impersonate any user. Mitigations: The issue is corrected in the upcoming patch update for each affected product. Product overlays and workaround instructions are available through OpenText Support. The vulnerable configurations are believed to be uncommon. Administrators can test for the vulnerability in their installations by attempting to sign on to a Visual COBOL or Enterprise Server component such as ESCWA using a valid username and incorrect password.
CVE-2023-36739
Last Modified: 30 Oct 20253D Viewer Remote Code Execution Vulnerability
CVE-2023-36740
Last Modified: 30 Oct 20253D Viewer Remote Code Execution Vulnerability
CVE-2023-36760
Last Modified: 30 Oct 20253D Viewer Remote Code Execution Vulnerability
CVE-2023-36761
Last Modified: 30 Oct 2025Microsoft Word Information Disclosure Vulnerability
CVE-2023-36762
Last Modified: 30 Oct 2025Microsoft Word Remote Code Execution Vulnerability
CVE-2023-36763
Last Modified: 30 Oct 2025Microsoft Outlook Information Disclosure Vulnerability
CVE-2023-36764
Last Modified: 30 Oct 2025Microsoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2023-36770
Last Modified: 30 Oct 20253D Builder Remote Code Execution Vulnerability
CVE-2023-36771
Last Modified: 30 Oct 20253D Builder Remote Code Execution Vulnerability
CVE-2023-36772
Last Modified: 30 Oct 20253D Builder Remote Code Execution Vulnerability
CVE-2023-36773
Last Modified: 30 Oct 20253D Builder Remote Code Execution Vulnerability
CVE-2023-36777
Last Modified: 30 Oct 2025Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2023-36788
Last Modified: 30 Oct 2025.NET Framework Remote Code Execution Vulnerability
CVE-2023-36792
Last Modified: 30 Oct 2025Visual Studio Remote Code Execution Vulnerability
CVE-2023-36793
Last Modified: 30 Oct 2025Visual Studio Remote Code Execution Vulnerability
CVE-2023-36794
Last Modified: 30 Oct 2025Visual Studio Remote Code Execution Vulnerability
CVE-2023-36796
Last Modified: 30 Oct 2025Visual Studio Remote Code Execution Vulnerability
CVE-2023-36799
Last Modified: 30 Oct 2025.NET Core and Visual Studio Denial of Service Vulnerability
CVE-2023-36800
Last Modified: 30 Oct 2025Dynamics Finance and Operations Cross-site Scripting Vulnerability
CVE-2023-38155
Last Modified: 30 Oct 2025Azure DevOps Server Remote Code Execution Vulnerability
CVE-2023-38160
Last Modified: 30 Oct 2025Windows TCP/IP Information Disclosure Vulnerability
CVE-2023-38163
Last Modified: 30 Oct 2025Windows Defender Attack Surface Reduction Security Feature Bypass
CVE-2023-38164
Last Modified: 30 Oct 2025Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-36886
Last Modified: 30 Oct 2025Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-33136
Last Modified: 30 Oct 2025Azure DevOps Server Remote Code Execution Vulnerability
CVE-2023-29332
Last Modified: 30 Oct 2025Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
CVE-2023-41764
Last Modified: 30 Oct 2025Microsoft Office Spoofing Vulnerability
CVE-2023-36736
Last Modified: 30 Oct 2025Microsoft Identity Linux Broker Remote Code Execution Vulnerability
CVE-2023-36742
Last Modified: 30 Oct 2025Visual Studio Code Remote Code Execution Vulnerability
CVE-2023-36744
Last Modified: 30 Oct 2025Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-36745
Last Modified: 30 Oct 2025Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-36756
Last Modified: 30 Oct 2025Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-36757
Last Modified: 30 Oct 2025Microsoft Exchange Server Spoofing Vulnerability
CVE-2023-36758
Last Modified: 30 Oct 2025Visual Studio Elevation of Privilege Vulnerability
CVE-2023-36759
Last Modified: 30 Oct 2025Visual Studio Elevation of Privilege Vulnerability
CVE-2023-36765
Last Modified: 30 Oct 2025Microsoft Office Elevation of Privilege Vulnerability
