7.8
    High

    CVE-2023-29343

    Last Modified: 10 Jul 2025

    SysInternals Sysmon for Windows Elevation of Privilege Vulnerability

    Published:9 May 2023
    7.8
    High

    CVE-2023-29336

    Last Modified: 25 May 2025

    Win32k Elevation of Privilege Vulnerability

    Source:Milad karimi
    Published:9 May 2023
    6.5
    Medium

    CVE-2023-29324

    Last Modified: 10 Jul 2025

    Windows MSHTML Platform Security Feature Bypass Vulnerability

    Published:9 May 2023
    9.1
    Critical

    CVE-2023-29201

    Last Modified: 6 Feb 2025

    XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1, only escaped `<script>` and `<style>`-tags but neither attributes that can be used to inject scripts nor other dangerous HTML tags like `<iframe>`. As a consequence, any code relying on this "restricted" mode for security is vulnerable to JavaScript injection ("cross-site scripting"/XSS). When a privileged user with programming rights visits such a comment in XWiki, the malicious JavaScript code is executed in the context of the user session. This allows server-side code execution with programming rights, impacting the confidentiality, integrity and availability of the XWiki instance. This problem has been patched in XWiki 14.6 RC1 with the introduction of a filter with allowed HTML elements and attributes that is enabled in restricted mode. There are no known workarounds apart from upgrading to a version including the fix.

    Published:15 Apr 2023
    7.2
    High

    CVE-2023-29084

    Last Modified: 7 Feb 2025

    Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.

    Published:13 Apr 2023
    10
    Critical

    CVE-2023-29017

    Last Modified: 10 Feb 2025

    vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Prior to version 3.9.15, vm2 was not properly handling host objects passed to `Error.prepareStackTrace` in case of unhandled async errors. A threat actor could bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.15 of vm2. There are no known workarounds.

    Published:6 Apr 2023
    7
    High

    CVE-2023-29007

    Last Modified: 4 Nov 2025

    Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, a specially crafted `.gitmodules` file with submodule URLs that are longer than 1024 characters can used to exploit a bug in `config.c::git_config_copy_or_rename_section_in_file()`. This bug can be used to inject arbitrary configuration into a user's `$GIT_DIR/config` when attempting to remove the configuration section associated with that submodule. When the attacker injects configuration values which specify executables to run (such as `core.pager`, `core.editor`, `core.sshCommand`, etc.) this can lead to a remote code execution. A fix A fix is available in versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1. As a workaround, avoid running `git submodule deinit` on untrusted repositories or without prior inspection of any submodule sections in `$GIT_DIR/config`.

    Published:25 Apr 2023
    4.3
    Medium

    CVE-2023-28810

    Last Modified: 12 Dec 2024

    Some access control/intercom products have unauthorized modification of device network configuration vulnerabilities. Attackers can modify device network configuration by sending specific data packets to the vulnerable interface within the same local network.

    Published:15 Jun 2023
    6.7
    Medium

    CVE-2023-28772

    Last Modified: 5 May 2025

    An issue was discovered in the Linux kernel before 5.13.3. lib/seq_buf.c has a seq_buf_putmem_hex buffer overflow.

    Published:23 Mar 2023
    9.8
    Critical

    CVE-2023-28771

    Last Modified: 27 Oct 2025

    Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.

    Published:25 Apr 2023
    9.8
    Critical

    CVE-2023-28753

    Last Modified: 21 Jan 2025

    netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A malicious individual could leverage this overflow to create heap memory corruption with attacker controlled data.

    Published:18 May 2023
    7.5
    High

    CVE-2023-28588

    Last Modified: 11 Aug 2025

    Transient DOS in Bluetooth Host while rfc slot allocation.

    Published:5 Dec 2023
    6.1
    Medium

    CVE-2023-28467

    Last Modified: 21 Jan 2025

    In MyBB before 1.8.34, there is XSS in the User CP module via the user email field.

    Published:22 May 2023
    7.5
    High

    CVE-2023-28465

    Last Modified: 27 May 2025

    The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain directories via directory traversal, if an allowed directory name is a substring of the directory name chosen by the attacker. NOTE: this issue exists because of an incomplete fix for CVE-2023-24057.

    Published:12 Dec 2023
    7.1
    High

    CVE-2023-28447

    Last Modified: 3 Nov 2025

    Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript code. An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user's browser session. This may lead to unauthorized access to sensitive user data, manipulation of the web application's behavior, or unauthorized actions performed on behalf of the user. Users are advised to upgrade to either version 3.1.48 or to 4.3.1 to resolve this issue. There are no known workarounds for this vulnerability.

    Published:28 Mar 2023
    8.8
    High

    CVE-2023-28434

    Last Modified: 26 Feb 2026

    Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. This issue has been patched in RELEASE.2023-03-20T20-16-18Z. As a workaround, enable browser API access and turn off `MINIO_BROWSER=off`.

    Published:22 Mar 2023
    7.5
    High

    CVE-2023-28432

    Last Modified: 24 Oct 2025

    Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.

    Published:22 Mar 2023
    9.8
    Critical

    CVE-2023-28354

    Last Modified: 15 Apr 2026

    An issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against affected targets, specifying known NRPE plugins, which in default installations are configured to accept command control characters and pass them to command-line interpreters for NRPE plugin execution. This allows the attacker to escape NRPE plugin execution and execute commands remotely on the target as NT_AUTHORITY\SYSTEM.

    Published:9 Jan 2025
    9.8
    Critical

    CVE-2023-28343

    Last Modified: 8 Apr 2023

    OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php.

    Source:Ahmed Alroky
    Published:14 Mar 2023
    6.5
    Medium

    CVE-2023-28330

    Last Modified: 21 Nov 2024

    Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.

    Published:23 Mar 2023
    8.8
    High

    CVE-2023-28329

    Last Modified: 21 Nov 2024

    Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).

    Published:23 Mar 2023
    8.2
    High

    CVE-2023-28324

    Last Modified: 21 Nov 2024

    A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.

    Published:30 Jun 2023
    7.8
    High

    CVE-2023-28311

    Last Modified: 20 Apr 2023

    Microsoft Word Remote Code Execution Vulnerability

    Source:nu11secur1ty
    Published:11 Apr 2023
    3.3
    Low

    CVE-2023-28303

    Last Modified: 1 Jan 2025

    Windows Snipping Tool Information Disclosure Vulnerability

    Published:13 Jun 2023
    7.8
    High

    CVE-2023-28293

    Last Modified: 26 Jun 2023

    Windows Kernel Elevation of Privilege Vulnerability

    Source:Amirhossein Bahramizadeh
    Published:11 Apr 2023
    8.1
    High

    CVE-2023-28288

    Last Modified: 26 Jun 2023

    Microsoft SharePoint Server Spoofing Vulnerability

    Source:Amirhossein Bahramizadeh
    Published:11 Apr 2023
    7.8
    High

    CVE-2023-28285

    Last Modified: 3 Jul 2023

    Microsoft Office Remote Code Execution Vulnerability

    Source:nu11secur1ty
    Published:11 Apr 2023
    7.8
    High

    CVE-2023-28252

    Last Modified: 28 Oct 2025

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    Published:11 Apr 2023
    8.1
    High

    CVE-2023-28244

    Last Modified: 23 Jan 2025

    Windows Kerberos Elevation of Privilege Vulnerability

    Published:11 Apr 2023
    8.8
    High

    CVE-2023-28231

    Last Modified: 23 Jan 2025

    DHCP Server Service Remote Code Execution Vulnerability

    Published:11 Apr 2023
    7
    High

    CVE-2023-28229

    Last Modified: 28 Oct 2025

    Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

    Published:11 Apr 2023
    7
    High

    CVE-2023-28218

    Last Modified: 23 Jan 2025

    Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

    Published:11 Apr 2023
    8.6
    High

    CVE-2023-28206

    Last Modified: 23 Oct 2025

    An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1, iOS 15.7.5 and iPadOS 15.7.5, macOS Big Sur 11.7.6. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.

    Published:10 Apr 2023
    8.8
    High

    CVE-2023-28205

    Last Modified: 23 Oct 2025

    A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 and iPadOS 15.7.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

    Published:7 Apr 2023
    3.3
    Low

    CVE-2023-28197

    Last Modified: 17 Jun 2025

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.3, macOS Big Sur 11.7.5, macOS Monterey 12.6.4. An app may be able to access user-sensitive data.

    Published:10 Jan 2024
    9.8
    Critical

    CVE-2023-28121

    Last Modified: 21 Nov 2024

    An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

    Published:12 Apr 2023
    9.2
    Critical

    CVE-2023-27997

    Last Modified: 24 Oct 2025

    A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.

    Published:13 Jun 2023
    8.8
    High

    CVE-2023-27842

    Last Modified: 26 Feb 2025

    Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code via the index.php compenent

    Published:21 Mar 2023
    8.8
    High

    CVE-2023-27826

    Last Modified: 10 Apr 2023

    SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Injection. which allows attackers to take over the system with root privilege by abusing doSystem() function.

    Source:Momen Eldawakhly
    Published:12 Apr 2023
    9.8
    Critical

    CVE-2023-27823

    Last Modified: 23 May 2023

    An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.

    Source:Anthony Cole
    Published:12 May 2023
    9.8
    Critical

    CVE-2023-27746

    Last Modified: 7 Feb 2025

    BlackVue DR750-2CH LTE v.1.012_2022.10.26 was discovered to contain a weak default passphrase which can be easily cracked via a brute force attack if the WPA2 handshake is intercepted.

    Published:13 Apr 2023
    9.8
    Critical

    CVE-2023-27742

    Last Modified: 23 Jan 2025

    IDURAR ERP/CRM v1 was discovered to contain a SQL injection vulnerability via the component /api/login.

    Published:16 May 2023
    5.5
    Medium

    CVE-2023-27704

    Last Modified: 10 Feb 2025

    Void Tools Everything lower than v1.4.1.1022 was discovered to contain a Regular Expression Denial of Service (ReDoS).

    Published:12 Apr 2023
    3.3
    Low

    CVE-2023-27703

    Last Modified: 10 Feb 2025

    The Android version of pikpak v1.29.2 was discovered to contain an information leak via the debug interface.

    Published:12 Apr 2023
    5.4
    Medium

    CVE-2023-27636

    Last Modified: 3 Jun 2024

    Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.

    Source:Aldi Saputra Wahyudi
    Published:16 Jun 2024
    7.4
    High

    CVE-2023-27587

    Last Modified: 25 Feb 2025

    ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an error message containing sensitive information prior to commit 8533b01. If an error occurs when adding an article, the website shows the user an error message. If the error originates from the Google Cloud TTS request, then it will include the full URL of the request. The request URL contains the Google Cloud API key. This has been patched in commit 8533b01. Upgrading should be accompanied by deleting the current GCP API key and issuing a new one. There are no known workarounds.

    Published:13 Mar 2023
    7.8
    High

    CVE-2023-27566

    Last Modified: 6 Mar 2025

    Cubism Core in Live2D Cubism Editor 4.2.03 allows out-of-bounds write via a crafted Section Offset Table or Count Info Table in an MOC3 file.

    Published:3 Mar 2023
    7.5
    High

    CVE-2023-27564

    Last Modified: 27 Jan 2025

    The n8n package 0.218.0 for Node.js allows Information Disclosure.

    Published:10 May 2023
    7.5
    High

    CVE-2023-27532

    Last Modified: 3 Nov 2025

    Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.

    Published:10 Mar 2023
    8.9
    High

    CVE-2023-27524

    Last Modified: 23 May 2023

    Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config. All superset installations should always set a unique secure random SECRET_KEY. Your SECRET_KEY is used to securely sign all session cookies and encrypting sensitive information on the database. Add a strong SECRET_KEY to your `superset_config.py` file like: SECRET_KEY = <YOUR_OWN_RANDOM_GENERATED_SECRET_KEY> Alternatively you can set it with `SUPERSET_SECRET_KEY` environment variable.

    Source:MaanVader
    Published:24 Apr 2023