CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2023-28565

    Last Modified: 27 Feb 2025

    Memory corruption in WLAN HAL while handling command streams through WMI interfaces.

    Published: 5 Sept 2023
    7.8
    High

    CVE-2023-28564

    Last Modified: 27 Feb 2025

    Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.

    Published: 5 Sept 2023
    9.8
    Critical

    CVE-2023-28562

    Last Modified: 27 Feb 2025

    Memory corruption while handling payloads from remote ESL.

    Published: 5 Sept 2023
    7.8
    High

    CVE-2023-28560

    Last Modified: 27 Feb 2025

    Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.

    Published: 5 Sept 2023
    7.8
    High

    CVE-2023-28559

    Last Modified: 27 Feb 2025

    Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload.

    Published: 5 Sept 2023
    7.8
    High

    CVE-2023-28558

    Last Modified: 21 Nov 2024

    Memory corruption in WLAN handler while processing PhyID in Tx status handler.

    Published: 5 Sept 2023
    7.8
    High

    CVE-2023-28557

    Last Modified: 21 Nov 2024

    Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload.

    Published: 5 Sept 2023
    7.8
    High

    CVE-2023-28549

    Last Modified: 27 Feb 2025

    Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload.

    Published: 5 Sept 2023
    7.8
    High

    CVE-2023-28548

    Last Modified: 27 Feb 2025

    Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART.

    Published: 5 Sept 2023
    7.8
    High

    CVE-2023-28544

    Last Modified: 27 Feb 2025

    Memory corruption in WLAN while sending transmit command from HLOS to UTF handlers.

    Published: 5 Sept 2023
    8.4
    High

    CVE-2023-28538

    Last Modified: 27 Feb 2025

    Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.

    Published: 5 Sept 2023
    6.5
    Medium

    CVE-2023-21667

    Last Modified: 21 Nov 2024

    Transient DOS in Bluetooth HOST while passing descriptor to validate the blacklisted BT keyboard.

    Published: 5 Sept 2023
    7.8
    High

    CVE-2023-21664

    Last Modified: 27 Feb 2025

    Memory Corruption in Core Platform while printing the response buffer in log.

    Published: 5 Sept 2023
    6.7
    Medium

    CVE-2023-21663

    Last Modified: 21 Nov 2024

    Memory Corruption while accessing metadata in Display.

    Published: 5 Sept 2023
    7.8
    High

    CVE-2023-21662

    Last Modified: 27 Feb 2025

    Memory corruption in Core Platform while printing the response buffer in log.

    Published: 5 Sept 2023
    6.7
    Medium

    CVE-2023-21655

    Last Modified: 21 Nov 2024

    Memory corruption in Audio while validating and mapping metadata.

    Published: 5 Sept 2023
    6.7
    Medium

    CVE-2023-21654

    Last Modified: 21 Nov 2024

    Memory corruption in Audio during playback session with audio effects enabled.

    Published: 5 Sept 2023
    7.5
    High

    CVE-2023-21653

    Last Modified: 21 Nov 2024

    Transient DOS in Modem while processing RRC reconfiguration message.

    Published: 5 Sept 2023
    7.5
    High

    CVE-2023-21646

    Last Modified: 21 Nov 2024

    Transient DOS in Modem while processing invalid System Information Block 1.

    Published: 5 Sept 2023
    6.7
    Medium

    CVE-2023-21644

    Last Modified: 21 Nov 2024

    Memory corruption in RIL due to Integer Overflow while triggering qcril_uim_request_apdu request.

    Published: 5 Sept 2023
    6.7
    Medium

    CVE-2023-21636

    Last Modified: 21 Nov 2024

    Memory Corruption due to improper validation of array index in Linux while updating adn record.

    Published: 5 Sept 2023
    8.4
    High

    CVE-2022-40534

    Last Modified: 27 Feb 2025

    Memory corruption due to improper validation of array index in Audio.

    Published: 5 Sept 2023
    6.7
    Medium

    CVE-2022-40524

    Last Modified: 21 Nov 2024

    Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service.

    Published: 5 Sept 2023
    8.4
    High

    CVE-2022-33275

    Last Modified: 27 Feb 2025

    Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.

    Published: 5 Sept 2023
    5.1
    Medium

    CVE-2022-33220

    Last Modified: 21 Nov 2024

    Information disclosure in Automotive multimedia due to buffer over-read.

    Published: 5 Sept 2023
    6.3
    Medium

    CVE-2023-4748

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in Yongyou UFIDA-NC up to 20230807. This issue affects some unknown processing of the file PrintTemplateFileServlet.java. The manipulation of the argument filePath leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-238637 was assigned to this vulnerability.

    Published: 5 Sept 2023
    —
    Unknown

    CVE-2023-4765

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 5 Sept 2023
    4.4
    Medium

    CVE-2023-4636

    Last Modified: 8 Apr 2026

    The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 5 Sept 2023
    5.3
    Medium

    CVE-2023-35906

    Last Modified: 21 Nov 2024

    IBM Aspera Faspex 5.0.5 could allow a remote attacked to bypass IP restrictions due to improper access controls. IBM X-Force ID: 259649.

    Published: 5 Sept 2023
    5.9
    Medium

    CVE-2023-22870

    Last Modified: 21 Nov 2024

    IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an attacker using man in the middle techniques. IBM X-Force ID: 244121.

    Published: 5 Sept 2023
    5.1
    Medium

    CVE-2023-29261

    Last Modified: 21 Nov 2024

    IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow a local user with specific information about the system to obtain privileged information due to inadequate memory clearing during operations. IBM X-Force ID: 252139.

    Published: 5 Sept 2023
    7.8
    High

    CVE-2023-4781

    Last Modified: 17 Sept 2026

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.

    Published: 5 Sept 2023
    7.8
    High

    CVE-2023-4921

    Last Modified: 25 Feb 2026

    A use-after-free vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local privilege escalation. When the plug qdisc is used as a class of the qfq qdisc, sending network packets triggers use-after-free in qfq_dequeue() due to the incorrect .peek handler of sch_plug and lack of error checking in agg_dequeue(). We recommend upgrading past commit 8fc134fee27f2263988ae38920bc03da416b03d8.

    Published: 5 Sept 2023
    6.5
    Medium

    CVE-2023-40584

    Last Modified: 21 Nov 2024

    Argo CD is a declarative continuous deployment for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug where the ArgoCD repo-server component is vulnerable to a Denial-of-Service attack vector. Specifically, the said component extracts a user-controlled tar.gz file without validating the size of its inner files. As a result, a malicious, low-privileged user can send a malicious tar.gz file that exploits this vulnerability to the repo-server, thereby harming the system's functionality and availability. Additionally, the repo-server is susceptible to another vulnerability due to the fact that it does not check the extracted file permissions before attempting to delete them. Consequently, an attacker can craft a malicious tar.gz archive in a way that prevents the deletion of its inner files when the manifest generation process is completed. A patch for this vulnerability has been released in versions 2.6.15, 2.7.14, and 2.8.3. Users are advised to upgrade. The only way to completely resolve the issue is to upgrade, however users unable to upgrade should configure RBAC (Role-Based Access Control) and provide access for configuring applications only to a limited number of administrators. These administrators should utilize trusted and verified Helm charts.

    Published: 5 Sept 2023
    9.9
    Critical

    CVE-2023-40029

    Last Modified: 21 Nov 2024

    Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively using Argo CD / kubectl apply. As a result, the full secret body is stored in`kubectl.kubernetes.io/last-applied-configuration` annotation. pull request #7139 introduced the ability to manage cluster labels and annotations. Since clusters are stored as secrets it also exposes the `kubectl.kubernetes.io/last-applied-configuration` annotation which includes full secret body. In order to view the cluster annotations via the Argo CD API, the user must have `clusters, get` RBAC access. **Note:** In many cases, cluster secrets do not contain any actually-secret information. But sometimes, as in bearer-token auth, the contents might be very sensitive. The bug has been patched in versions 2.8.3, 2.7.14, and 2.6.15. Users are advised to upgrade. Users unable to upgrade should update/deploy cluster secret with `server-side-apply` flag which does not use or rely on `kubectl.kubernetes.io/last-applied-configuration` annotation. Note: annotation for existing secrets will require manual removal.

    Published: 5 Sept 2023
    7
    High

    CVE-2023-42465

    Last Modified: 4 Nov 2025

    Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling a success value), and because the values do not resist flips of a single bit.

    Published: 5 Sept 2023
    5.5
    Medium

    CVE-2023-36308

    Last Modified: 4 Nov 2025

    disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence

    Published: 5 Sept 2023
    9.8
    Critical

    CVE-2023-39681

    Last Modified: 21 Nov 2024

    Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php. This vulnerability is triggered via a crafted payload.

    Published: 5 Sept 2023
    9.8
    Critical

    CVE-2023-36361

    Last Modified: 4 Apr 2025

    Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter.

    Published: 5 Sept 2023
    5.5
    Medium

    CVE-2023-36307

    Last Modified: 21 Nov 2024

    ZPLGFA 1.1.1 allows attackers to cause a panic (because of an integer index out of range during a ConvertToGraphicField call) via an image of zero width. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence

    Published: 5 Sept 2023
    9.8
    Critical

    CVE-2023-41009

    Last Modified: 21 Nov 2024

    File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted script to the authorization field in the header.

    Published: 5 Sept 2023
    9.8
    Critical

    CVE-2023-41507

    Last Modified: 21 Nov 2024

    Super Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component via the products, distance, lat, and lng parameters.

    Published: 5 Sept 2023
    8.8
    High

    CVE-2022-41763

    Last Modified: 21 Nov 2024

    An issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via the debugger of the ipAddress variable. A remote user, authenticated to the AMS server, could inject code in the PING function. The privileges of the command executed depend on the user that runs the service.

    Published: 5 Sept 2023
    4.9
    Medium

    CVE-2021-40546

    Last Modified: 21 Nov 2024

    Tenda AC6 US_AC6V4.0RTL_V02.03.01.26_cn.bin allows attackers (who have the administrator password) to cause a denial of service (device crash) via a long string in the wifiPwd_5G parameter to /goform/setWifi.

    Published: 5 Sept 2023
    5.4
    Medium

    CVE-2023-34637

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in IsarNet AG IsarFlow v5.23 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the dashboard title parameter in the IsarFlow Portal.

    Published: 5 Sept 2023
    6.1
    Medium

    CVE-2015-1390

    Last Modified: 21 Nov 2024

    Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator.

    Published: 5 Sept 2023
    8.8
    High

    CVE-2015-1391

    Last Modified: 21 Nov 2024

    Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism.

    Published: 5 Sept 2023
    7.2
    High

    CVE-2015-2201

    Last Modified: 21 Nov 2024

    Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows VisualRF remote OS command execution and file disclosure by administrative users.

    Published: 5 Sept 2023
    7.2
    High

    CVE-2015-2202

    Last Modified: 21 Nov 2024

    Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS.

    Published: 5 Sept 2023
    7.8
    High

    CVE-2020-35593

    Last Modified: 21 Nov 2024

    BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -host.

    Published: 5 Sept 2023