CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2023-36766

    Last Modified: 30 Oct 2025

    Microsoft Excel Information Disclosure Vulnerability

    Published: 12 Sept 2023
    4.3
    Medium

    CVE-2023-36767

    Last Modified: 30 Oct 2025

    Microsoft Office Security Feature Bypass Vulnerability

    Published: 12 Sept 2023
    5.3
    Medium

    CVE-2023-36801

    Last Modified: 30 Oct 2025

    DHCP Server Service Information Disclosure Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-36802

    Last Modified: 30 Oct 2025

    Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

    Published: 12 Sept 2023
    5.5
    Medium

    CVE-2023-36803

    Last Modified: 30 Oct 2025

    Windows Kernel Information Disclosure Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-36804

    Last Modified: 30 Oct 2025

    Windows GDI Elevation of Privilege Vulnerability

    Published: 12 Sept 2023
    7
    High

    CVE-2023-36805

    Last Modified: 30 Oct 2025

    Windows MSHTML Platform Security Feature Bypass Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-38139

    Last Modified: 30 Oct 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 12 Sept 2023
    5.5
    Medium

    CVE-2023-38140

    Last Modified: 30 Oct 2025

    Windows Kernel Information Disclosure Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-38141

    Last Modified: 30 Oct 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-38142

    Last Modified: 30 Oct 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-38143

    Last Modified: 30 Oct 2025

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-38144

    Last Modified: 30 Oct 2025

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    Published: 12 Sept 2023
    8.8
    High

    CVE-2023-38146

    Last Modified: 30 Oct 2025

    Windows Themes Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    8.8
    High

    CVE-2023-38147

    Last Modified: 30 Oct 2025

    Windows Miracast Wireless Display Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    8.8
    High

    CVE-2023-38148

    Last Modified: 30 Oct 2025

    Internet Connection Sharing (ICS) Remote Code Execution Vulnerability

    Published: 12 Sept 2023
    7.5
    High

    CVE-2023-38149

    Last Modified: 30 Oct 2025

    Windows TCP/IP Denial of Service Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-38150

    Last Modified: 30 Oct 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 12 Sept 2023
    5.3
    Medium

    CVE-2023-38152

    Last Modified: 30 Oct 2025

    DHCP Server Service Information Disclosure Vulnerability

    Published: 12 Sept 2023
    7.2
    High

    CVE-2023-38156

    Last Modified: 11 Feb 2026

    Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-38161

    Last Modified: 30 Oct 2025

    Windows GDI Elevation of Privilege Vulnerability

    Published: 12 Sept 2023
    7.5
    High

    CVE-2023-38162

    Last Modified: 30 Oct 2025

    DHCP Server Service Denial of Service Vulnerability

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-35355

    Last Modified: 30 Oct 2025

    Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

    Published: 12 Sept 2023
    8.8
    High

    CVE-2023-29463

    Last Modified: 27 Feb 2025

    The JMX Console within the Rockwell Automation Pavilion8 is exposed to application users and does not require authentication. If exploited, a malicious user could potentially retrieve other application users’ session data and or log users out of their session.

    Published: 12 Sept 2023
    6.8
    Medium

    CVE-2023-34470

    Last Modified: 21 Nov 2024

    AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper access control via the local network. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity and availability.

    Published: 12 Sept 2023
    4.9
    Medium

    CVE-2023-34469

    Last Modified: 21 Nov 2024

    AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper access control via the physical network. A successful exploit of this vulnerability may lead to a loss of confidentiality. 

    Published: 12 Sept 2023
    4.8
    Medium

    CVE-2023-4039

    Last Modified: 23 Jun 2026

    **DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker to exploit an existing buffer overflow in dynamically-sized local variables in your application without this being detected. This stack-protector failure only applies to C99-style dynamically-sized local variables or those created using alloca(). The stack-protector operates as intended for statically-sized local variables. The default behavior when the stack-protector detects an overflow is to terminate your application, resulting in controlled loss of availability. An attacker who can exploit a buffer overflow without triggering the stack-protector might be able to change program flow control to cause an uncontrolled loss of availability or to go further and affect confidentiality or integrity. NOTE: The GCC project argues that this is a missed hardening bug and not a vulnerability by itself.

    Published: 12 Sept 2023
    7.5
    High

    CVE-2023-4914

    Last Modified: 21 Nov 2024

    Relative Path Traversal in GitHub repository cecilapp/cecil prior to 7.47.1.

    Published: 12 Sept 2023
    6.1
    Medium

    CVE-2023-4913

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository cecilapp/cecil prior to 7.47.1.

    Published: 12 Sept 2023
    9.8
    Critical

    CVE-2023-2071

    Last Modified: 21 Nov 2024

    Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets.  The device has the functionality, through a CIP class, to execute exported functions from libraries.  There is a routine that restricts it to execute specific functions from two dynamic link library files.  By using a CIP class, an attacker can upload a self-made library to the device which allows the attacker to bypass the security check and execute any code written in the function.

    Published: 12 Sept 2023
    6.5
    Medium

    CVE-2023-40712

    Last Modified: 21 Nov 2024

    Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, to craft a URL, which could lead to unmasking the secret configuration of the task that otherwise would be masked in the UI. Users are strongly advised to upgrade to version 2.7.1 or later which has removed the vulnerability.

    Published: 12 Sept 2023
    4.3
    Medium

    CVE-2023-40611

    Last Modified: 25 Jun 2025

    Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc. Users should upgrade to version 2.7.1 or later which has removed the vulnerability.

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-41846

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0002). The affected application is vulnerable to memory corruption while parsing specially crafted SPP files. This could allow an attacker to execute code in the context of the current process.

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-41033

    Last Modified: 27 Feb 2025

    A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.260), Parasolid V35.1 (All versions < V35.1.246), Parasolid V36.0 (All versions < V36.0.156), Simcenter Femap V2301 (All versions < V2301.0003), Simcenter Femap V2306 (All versions < V2306.0001). The affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21266)

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-41032

    Last Modified: 27 Feb 2025

    A vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.253), Parasolid V35.1 (All versions < V35.1.184), Parasolid V36.0 (All versions < V36.0.142), Simcenter Femap V2301 (All versions < V2301.0003), Simcenter Femap V2306 (All versions < V2306.0001). The affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21263)

    Published: 12 Sept 2023
    3.9
    Low

    CVE-2023-40732

    Last Modified: 27 Feb 2025

    A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application does not invalidate the session token on logout. This could allow an attacker to perform session hijacking attacks.

    Published: 12 Sept 2023
    5.7
    Medium

    CVE-2023-40731

    Last Modified: 27 Feb 2025

    A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application allows users to upload arbitrary file types. This could allow an attacker to upload malicious files, that could potentially lead to code tampering.

    Published: 12 Sept 2023
    7.1
    High

    CVE-2023-40730

    Last Modified: 27 Feb 2025

    A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application lacks sufficient authorization checks. This could allow an attacker to access confidential information, perform administrative functions, or lead to a denial-of-service condition.

    Published: 12 Sept 2023
    7.3
    High

    CVE-2023-40729

    Last Modified: 27 Feb 2025

    A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application lacks security control to prevent unencrypted communication without HTTPS. An attacker who managed to gain machine-in-the-middle position could manipulate, or steal confidential information.

    Published: 12 Sept 2023
    7.3
    High

    CVE-2023-40728

    Last Modified: 27 Feb 2025

    A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application stores sensitive application data in an external insecure storage. This could allow an attacker to alter content, leading to arbitrary code execution or denial-of-service condition.

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-40727

    Last Modified: 27 Feb 2025

    A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application uses weak outdated application signing mechanism. This could allow an attacker to tamper the application code.

    Published: 12 Sept 2023
    8.8
    High

    CVE-2023-40726

    Last Modified: 27 Feb 2025

    A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application server responds with sensitive information about the server. This could allow an attacker to directly access the database.

    Published: 12 Sept 2023
    4
    Medium

    CVE-2023-40725

    Last Modified: 27 Feb 2025

    A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application returns inconsistent error messages in response to invalid user credentials during login session. This allows an attacker to enumerate usernames, and identify valid usernames.

    Published: 12 Sept 2023
    7.3
    High

    CVE-2023-40724

    Last Modified: 27 Feb 2025

    A vulnerability has been identified in QMS Automotive (All versions < V12.39). User credentials are found in memory as plaintext. An attacker could perform a memory dump, and get access to credentials, and use it for impersonation.

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-38076

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), Teamcenter Visualization V14.0 (All versions), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All versions < V14.2.0.6), Teamcenter Visualization V14.3 (All versions < V14.3.0.1), Tecnomatix Plant Simulation V2201 (All versions < V2201.0010), Tecnomatix Plant Simulation V2302 (All versions < V2302.0004). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted WRL files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21041)

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-38075

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), Teamcenter Visualization V14.0 (All versions), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All versions < V14.2.0.6), Teamcenter Visualization V14.3 (All versions < V14.3.0.1), Tecnomatix Plant Simulation V2201 (All versions < V2201.0010), Tecnomatix Plant Simulation V2302 (All versions < V2302.0004). The affected application contains a use-after-free vulnerability that could be triggered while parsing specially crafted WRL files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-20842)

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-38074

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), Teamcenter Visualization V14.0 (All versions), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All versions < V14.2.0.6), Teamcenter Visualization V14.3 (All versions < V14.3.0.1), Tecnomatix Plant Simulation V2201 (All versions < V2201.0010), Tecnomatix Plant Simulation V2302 (All versions < V2302.0004). The affected application contains a type confusion vulnerability while parsing WRL files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-20840)

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-38073

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), Teamcenter Visualization V14.0 (All versions), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All versions < V14.2.0.6), Teamcenter Visualization V14.3 (All versions < V14.3.0.1), Tecnomatix Plant Simulation V2201 (All versions < V2201.0010), Tecnomatix Plant Simulation V2302 (All versions < V2302.0004). The affected application contains a type confusion vulnerability while parsing WRL files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-20826)

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-38072

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), Teamcenter Visualization V14.0 (All versions), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All versions < V14.2.0.6), Teamcenter Visualization V14.3 (All versions < V14.3.0.1), Tecnomatix Plant Simulation V2201 (All versions < V2201.0010), Tecnomatix Plant Simulation V2302 (All versions < V2302.0004). The affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted WRL files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-20825)

    Published: 12 Sept 2023
    7.8
    High

    CVE-2023-38071

    Last Modified: 25 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), Teamcenter Visualization V14.0 (All versions), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All versions < V14.2.0.6), Teamcenter Visualization V14.3 (All versions < V14.3.0.1), Tecnomatix Plant Simulation V2201 (All versions < V2201.0010), Tecnomatix Plant Simulation V2302 (All versions < V2302.0004). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted WRL files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-20824)

    Published: 12 Sept 2023