5.3
    Medium

    CVE-2023-22232

    Last Modified: 6 Apr 2023

    Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the integrity of a minor feature. Exploitation of this issue does not require user interaction.

    Source:h4shur
    Published:17 Feb 2023
    8.2
    High

    CVE-2023-22098

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: Only applicable to 7.0.x platform. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

    Published:17 Oct 2023
    4.9
    Medium

    CVE-2023-22077

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle Database Recovery Manager component of Oracle Database Server. Supported versions that are affected are 19.3-19.20 and 21.3-21.11. Easily exploitable vulnerability allows high privileged attacker having DBA account privilege with network access via Oracle Net to compromise Oracle Database Recovery Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Database Recovery Manager. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

    Published:17 Oct 2023
    2.4
    Low

    CVE-2023-22074

    Last Modified: 13 Feb 2025

    Vulnerability in the Oracle Database Sharding component of Oracle Database Server. Supported versions that are affected are 19.3-19.20 and 21.3-21.11. Easily exploitable vulnerability allows high privileged attacker having Create Session, Select Any Dictionary privilege with network access via Oracle Net to compromise Oracle Database Sharding. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Database Sharding. CVSS 3.1 Base Score 2.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:L).

    Published:17 Oct 2023
    7.5
    High

    CVE-2023-22047

    Last Modified: 21 Nov 2024

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

    Published:18 Jul 2023
    7.8
    High

    CVE-2023-21987

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

    Published:18 Apr 2023
    5.3
    Medium

    CVE-2023-21971

    Last Modified: 21 Nov 2024

    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors as well as unauthorized update, insert or delete access to some of MySQL Connectors accessible data and unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:H).

    Published:18 Apr 2023
    5.3
    Medium

    CVE-2023-21939

    Last Modified: 13 Feb 2025

    Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).

    Published:18 Apr 2023
    7.5
    High

    CVE-2023-21931

    Last Modified: 13 Feb 2025

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

    Published:18 Apr 2023
    4.9
    Medium

    CVE-2023-21887

    Last Modified: 21 Nov 2024

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

    Published:17 Jan 2023
    7.5
    High

    CVE-2023-21839

    Last Modified: 27 Oct 2025

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

    Published:17 Jan 2023
    7.5
    High

    CVE-2023-21837

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

    Published:17 Jan 2023
    7.8
    High

    CVE-2023-21823

    Last Modified: 30 Oct 2025

    Windows Graphics Component Remote Code Execution Vulnerability

    Published:14 Feb 2023
    7.8
    High

    CVE-2023-21817

    Last Modified: 1 Jan 2025

    Windows Kerberos Elevation of Privilege Vulnerability

    Published:14 Feb 2023
    7.8
    High

    CVE-2023-21768

    Last Modified: 1 Jan 2025

    Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

    Published:10 Jan 2023
    4.7
    Medium

    CVE-2023-21766

    Last Modified: 1 Jan 2025

    Windows Overlay Filter Information Disclosure Vulnerability

    Published:10 Jan 2023
    7.1
    High

    CVE-2023-21752

    Last Modified: 6 Apr 2023

    Windows Backup Service Elevation of Privilege Vulnerability

    Source:nu11secur1ty
    Published:10 Jan 2023
    7.8
    High

    CVE-2023-21746

    Last Modified: 1 Jan 2025

    Windows NTLM Elevation of Privilege Vulnerability

    Published:10 Jan 2023
    8.8
    High

    CVE-2023-21742

    Last Modified: 28 Feb 2025

    Microsoft SharePoint Server Remote Code Execution Vulnerability

    Published:10 Jan 2023
    7
    High

    CVE-2023-21739

    Last Modified: 1 Jan 2025

    Windows Bluetooth Driver Elevation of Privilege Vulnerability

    Published:10 Jan 2023
    9.8
    Critical

    CVE-2023-21716

    Last Modified: 19 Aug 2026

    Microsoft Word Remote Code Execution Vulnerability

    Published:14 Feb 2023
    8.8
    High

    CVE-2023-21707

    Last Modified: 19 Aug 2026

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Published:14 Feb 2023
    7.8
    High

    CVE-2023-21688

    Last Modified: 1 Jan 2025

    NT OS Kernel Elevation of Privilege Vulnerability

    Published:14 Feb 2023
    8.8
    High

    CVE-2023-21674

    Last Modified: 30 Oct 2025

    Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

    Published:10 Jan 2023
    7.8
    High

    CVE-2023-21608

    Last Modified: 23 Oct 2025

    Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published:18 Jan 2023
    6.8
    Medium

    CVE-2023-21563

    Last Modified: 1 Jan 2025

    BitLocker Security Feature Bypass Vulnerability

    Published:10 Jan 2023
    6.6
    Medium

    CVE-2023-21560

    Last Modified: 1 Jan 2025

    Windows Boot Manager Security Feature Bypass Vulnerability

    Published:10 Jan 2023
    9.8
    Critical

    CVE-2023-21554

    Last Modified: 23 Jan 2025

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

    Published:11 Apr 2023
    7.8
    High

    CVE-2023-21537

    Last Modified: 1 Jan 2025

    Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability

    Published:10 Jan 2023
    5.5
    Medium

    CVE-2023-21288

    Last Modified: 21 Nov 2024

    In visitUris of Notification.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.

    Published:14 Aug 2023
    7.8
    High

    CVE-2023-21286

    Last Modified: 21 Nov 2024

    In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:14 Aug 2023
    5.5
    Medium

    CVE-2023-21285

    Last Modified: 21 Nov 2024

    In setMetadata of MediaSessionRecord.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:14 Aug 2023
    5.5
    Medium

    CVE-2023-21284

    Last Modified: 21 Nov 2024

    In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the Find my Device feature due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.

    Published:14 Aug 2023
    8.8
    High

    CVE-2023-21282

    Last Modified: 4 Nov 2025

    In TRANSPOSER_SETTINGS of lpp_tran.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.

    Published:14 Aug 2023
    7.8
    High

    CVE-2023-21281

    Last Modified: 21 Nov 2024

    In multiple functions of KeyguardViewMediator.java, there is a possible failure to lock after screen timeout due to a logic error in the code. This could lead to local escalation of privilege across users with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:14 Aug 2023
    7.8
    High

    CVE-2023-21275

    Last Modified: 21 Nov 2024

    In decideCancelProvisioningDialog of AdminIntegratedFlowPrepareActivity.java, there is a possible way to bypass factory reset protections due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:14 Aug 2023
    7.8
    High

    CVE-2023-21272

    Last Modified: 21 Nov 2024

    In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:14 Aug 2023
    7.3
    High

    CVE-2023-21251

    Last Modified: 21 Nov 2024

    In onCreate of ConfirmDialog.java, there is a possible way to connect to VNP bypassing user's consent due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.

    Published:12 Jul 2023
    3.3
    Low

    CVE-2023-21246

    Last Modified: 21 Nov 2024

    In ShortcutInfo of ShortcutInfo.java, there is a possible way for an app to retain notification listening access due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:12 Jul 2023
    5.5
    Medium

    CVE-2023-21238

    Last Modified: 21 Nov 2024

    In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:12 Jul 2023
    5.5
    Medium

    CVE-2023-21173

    Last Modified: 5 Dec 2024

    In multiple methods of DataUsageList.java, there is a possible way to learn about admin user's network activities due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262741858

    Published:28 Jun 2023
    8
    High

    CVE-2023-21125

    Last Modified: 2 Sept 2025

    In btif_hh_hsdata_rpt_copy_cb of bta_hh.cc, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:26 Aug 2025
    6.2
    Medium

    CVE-2023-21118

    Last Modified: 31 Jan 2025

    In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-269014004

    Published:15 May 2023
    7.8
    High

    CVE-2023-21109

    Last Modified: 24 Jan 2025

    In multiple places of AccessibilityService, there is a possible way to hide the app from the user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-261589597

    Published:15 May 2023
    7.8
    High

    CVE-2023-21097

    Last Modified: 5 Feb 2025

    In toUriInner of Intent.java, there is a possible way to launch an arbitrary activity due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-261858325

    Published:19 Apr 2023
    7.8
    High

    CVE-2023-21094

    Last Modified: 5 Feb 2025

    In sanitize of LayerState.cpp, there is a possible way to take over the screen display and swap the display content due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-248031255

    Published:19 Apr 2023
    7.8
    High

    CVE-2023-21086

    Last Modified: 5 Feb 2025

    In isToggleable of SecureNfcEnabler.java and SecureNfcPreferenceController.java, there is a possible way to enable NFC from a secondary account due to a permissions bypass. This could lead to local escalation of privilege from the Guest account with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-238298970

    Published:19 Apr 2023
    5.5
    Medium

    CVE-2023-21036

    Last Modified: 25 Feb 2025

    In BitmapExport.java, there is a possible failure to truncate images due to a logic error in the code.Product: AndroidVersions: Android kernelAndroid ID: A-264261868References: N/A

    Published:24 Mar 2023
    7.8
    High

    CVE-2023-20963

    Last Modified: 23 Oct 2025

    In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519

    Published:24 Mar 2023
    7.8
    High

    CVE-2023-20955

    Last Modified: 25 Feb 2025

    In onPrepareOptionsMenu of AppInfoDashboardFragment.java, there is a possible way to bypass admin restrictions and uninstall applications for all users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-258653813

    Published:24 Mar 2023