Show filters
41,197 Total Results
Displaying 211-220 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2023-2163

Disclosure Date: September 20, 2023 (last updated May 21, 2024)
Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe, resulting in arbitrary read/write in kernel memory, lateral privilege escalation, and container escape.
Attacker Value
Unknown

CVE-2023-38185

Disclosure Date: August 08, 2023 (last updated January 05, 2025)
Microsoft Exchange Server Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2023-35386

Disclosure Date: August 08, 2023 (last updated January 07, 2025)
Windows Kernel Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2023-2640

Disclosure Date: July 26, 2023 (last updated October 08, 2023)
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.
Attacker Value
Unknown

CVE-2022-22302

Disclosure Date: July 11, 2023 (last updated October 08, 2023)
A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2.0 through 6.2.9 and 6.0.0 through 6.0.13 and FortiAuthenticator version 5.5.0 and all versions of 6.1 and 6.0 may allow a local unauthorized party to retrieve the Fortinet private keys used to establish secure communication with both Apple Push Notification and Google Cloud Messaging services, via accessing the files on the filesystem.
Attacker Value
Unknown

CVE-2023-35116

Disclosure Date: June 14, 2023 (last updated November 08, 2023)
jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, because the steps of constructing a cyclic data structure and trying to serialize it cannot be achieved by an external attacker.
Attacker Value
Unknown

CVE-2023-20888

Disclosure Date: June 07, 2023 (last updated October 08, 2023)
Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in remote code execution.
Attacker Value
Unknown

CVE-2023-25780

Disclosure Date: May 30, 2023 (last updated October 08, 2023)
It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A LAN attacker with normal user privilege can exploit this vulnerability to modify substitute agent to arbitrary users, resulting in serious consequence.
Attacker Value
Unknown

CVE-2023-28702

Disclosure Date: May 30, 2023 (last updated October 08, 2023)
ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary system commands, disrupt system or terminate service.
Attacker Value
Unknown

CVE-2023-20110

Disclosure Date: May 17, 2023 (last updated October 08, 2023)
A vulnerability in the web-based management interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface inadequately validates user input. An attacker could exploit this vulnerability by authenticating to the application as a low-privileged user and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to read sensitive data on the underlying database.