Search Results (95529 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-24893 1 Microsoft 1 Visual Studio Code 2025-01-23 7.8 High
Visual Studio Code Remote Code Execution Vulnerability
CVE-2023-28300 1 Microsoft 1 Azure Service Connector 2025-01-23 7.5 High
Azure Service Connector Security Feature Bypass Vulnerability
CVE-2023-28297 1 Microsoft 10 Windows 10 1607, Windows 10 1809, Windows 10 20h2 and 7 more 2025-01-23 8.8 High
Windows Remote Procedure Call Service (RPCSS) Elevation of Privilege Vulnerability
CVE-2023-28292 1 Microsoft 5 Raw Image Extension, Windows 10 20h2, Windows 10 21h2 and 2 more 2025-01-23 7.8 High
Raw Image Extension Remote Code Execution Vulnerability
CVE-2023-28291 1 Microsoft 5 Raw Image Extension, Windows 10 20h2, Windows 10 21h2 and 2 more 2025-01-23 8.4 High
Raw Image Extension Remote Code Execution Vulnerability
CVE-2023-28222 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2025-01-23 7.1 High
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-28221 1 Microsoft 11 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 8 more 2025-01-23 7 High
Windows Error Reporting Service Elevation of Privilege Vulnerability
CVE-2023-28218 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2025-01-23 7 High
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2023-28217 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2025-01-23 7.5 High
Windows Network Address Translation (NAT) Denial of Service Vulnerability
CVE-2023-28216 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2025-01-23 7 High
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
CVE-2023-24931 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2025-01-23 7.5 High
Windows Secure Channel Denial of Service Vulnerability
CVE-2023-24912 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2025-01-23 7.8 High
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2023-21727 1 Microsoft 12 Windows 10 1607, Windows 10 1809, Windows 10 20h2 and 9 more 2025-01-23 8.8 High
Remote Procedure Call Runtime Remote Code Execution Vulnerability
CVE-2023-23384 1 Microsoft 1 Sql Server 2025-01-23 7.3 High
Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2023-24914 1 Microsoft 1 Windows 11 22h2 2025-01-23 7 High
Win32k Elevation of Privilege Vulnerability
CVE-2024-8234 1 Zyxel 3 Nwa1100-n Firmware, Nwaw1100-n, Nwaw1100-n Firmware 2025-01-22 7.5 High
** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and formDelcert() in the Zyxel NWA1100-N firmware version 1.00(AACE.1)C0 could allow an unauthenticated attacker to execute some OS commands to access system files on an affected device.
CVE-2024-43282 1 Themeum 1 Tutor Lms 2025-01-22 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2.
CVE-2023-32308 1 Anuko 1 Time Tracker 2025-01-22 8.2 High
anuko timetracker is an open source time tracking system. Boolean-based blind SQL injection vulnerability existed in Time Tracker invoices.php in versions prior to 1.22.11.5781. This was happening because of a coding error after validating parameters in POST requests. There was no check for errors before adjusting invoice sorting order. Because of this, it was possible to craft a POST request with malicious SQL for Time Tracker database. This issue has been fixed in version 1.22.11.5781. Users are advised to upgrade. Users unable to upgrade may insert an additional check for errors in a condition before calling `ttGroupHelper::getActiveInvoices()` in invoices.php.
CVE-2023-31131 1 Vmware 1 Greenplum Database 2025-01-22 7.4 High
Greenplum Database (GPDB) is an open source data warehouse based on PostgreSQL. In versions prior to 6.22.3 Greenplum Database used an unsafe methods to extract tar files within GPPKGs. greenplum-db is vulnerable to path traversal leading to arbitrary file writes. An attacker can use this vulnerability to overwrite data or system files potentially leading to crash or malfunction of the system. Any files which are accessible to the running process are at risk. All users are requested to upgrade to Greenplum Database version 6.23.2 or higher. There are no known workarounds for this vulnerability.
CVE-2023-30504 1 Arubanetworks 1 Edgeconnect Enterprise 2025-01-22 7.2 High
Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.