| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-0352 | Hig | 0.53 | 7.3 | 0.73 | Jan 9, 2024 | A vulnerability classified as critical was found in Likeshop up to 2.5.7.20210311. This vulnerability affects the function FileServer::userFormImage of the file server/application/api/controller/File.php of the component HTTP POST Request Handler. The manipulation of the… | ||
| CVE-2023-47994 | Hig | 0.57 | 8.8 | 0.01 | Jan 9, 2024 | An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows attackers to obtain sensitive information, cause a denial of service and/or run arbitrary code. | ||
| CVE-2023-47992 | Hig | 0.57 | 8.8 | 0.01 | Jan 9, 2024 | An integer overflow vulnerability in FreeImageIO.cpp::_MemoryReadProc in FreeImage 3.18.0 allows attackers to obtain sensitive information, cause a denial-of-service attacks and/or run arbitrary code. | ||
| CVE-2023-37297 | Hig | 0.54 | 8.3 | 0.00 | Jan 9, 2024 | AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability. | ||
| CVE-2023-37296 | Hig | 0.54 | 8.3 | 0.00 | Jan 9, 2024 | AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack memory corruption via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability. | ||
| CVE-2023-37295 | Hig | 0.54 | 8.3 | 0.00 | Jan 9, 2024 | AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability. … | ||
| CVE-2023-37294 | Hig | 0.54 | 8.3 | 0.00 | Jan 9, 2024 | AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability. … | ||
| CVE-2023-34333 | Hig | 0.51 | 7.8 | 0.00 | Jan 9, 2024 | AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause an untrusted pointer to dereference via a local network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability. … | ||
| CVE-2023-34332 | Hig | 0.51 | 7.8 | 0.00 | Jan 9, 2024 | AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause an untrusted pointer to dereference by a local network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability. … | ||
| CVE-2023-7032 | Hig | 0.51 | 7.8 | 0.00 | Jan 9, 2024 | A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain higher privileges by providing a harmful serialized object. | ||
| CVE-2024-21325 | Hig | 0.51 | 7.8 | 0.01 | Jan 9, 2024 | Microsoft Printer Metadata Troubleshooter Tool Remote Code Execution Vulnerability | ||
| CVE-2024-21318 | Hig | 0.60 | 8.8 | 0.31 | Jan 9, 2024 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2024-21312 | Hig | 0.49 | 7.5 | 0.04 | Jan 9, 2024 | .NET Framework Denial of Service Vulnerability | ||
| CVE-2024-21310 | Hig | 0.52 | 7.8 | 0.12 | Jan 9, 2024 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-21309 | Hig | 0.51 | 7.8 | 0.01 | Jan 9, 2024 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-21307 | Hig | 0.49 | 7.5 | 0.02 | Jan 9, 2024 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2024-20700 | Hig | 0.49 | 7.5 | 0.04 | Jan 9, 2024 | Windows Hyper-V Remote Code Execution Vulnerability | ||
| CVE-2024-20698 | Hig | 0.51 | 7.8 | 0.09 | Jan 9, 2024 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2024-20697 | Hig | 0.53 | 7.3 | 0.72 | Jan 9, 2024 | Windows libarchive Remote Code Execution Vulnerability | ||
| CVE-2024-20696 | Hig | 0.48 | 7.3 | 0.03 | Jan 9, 2024 | Windows libarchive Remote Code Execution Vulnerability | ||
| CVE-2024-20687 | Hig | 0.49 | 7.5 | 0.03 | Jan 9, 2024 | Microsoft AllJoyn API Denial of Service Vulnerability | ||
| CVE-2024-20686 | Hig | 0.51 | 7.8 | 0.01 | Jan 9, 2024 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2024-20683 | Hig | 0.51 | 7.8 | 0.04 | Jan 9, 2024 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2024-20682 | Hig | 0.51 | 7.8 | 0.01 | Jan 9, 2024 | Windows Cryptographic Services Remote Code Execution Vulnerability | ||
| CVE-2024-20681 | Hig | 0.51 | 7.8 | 0.01 | Jan 9, 2024 | Windows Subsystem for Linux Elevation of Privilege Vulnerability | ||
| CVE-2024-20677 | Hig | 0.51 | 7.8 | 0.03 | Jan 9, 2024 | A security vulnerability exists in FBX that could lead to remote code execution. To mitigate this vulnerability, the ability to insert FBX files has been disabled in Word, Excel, PowerPoint and Outlook for Windows and Mac. Versions of Office that had this feature enabled will no… | ||
| CVE-2024-20676 | Hig | 0.52 | 8.0 | 0.03 | Jan 9, 2024 | Azure Storage Mover Remote Code Execution Vulnerability | ||
| CVE-2024-20674 | Hig | 0.59 | 8.8 | 0.17 | Jan 9, 2024 | Windows Kerberos Security Feature Bypass Vulnerability | ||
| CVE-2024-20672 | Hig | 0.49 | 7.5 | 0.03 | Jan 9, 2024 | .NET Denial of Service Vulnerability | ||
| CVE-2024-20661 | Hig | 0.49 | 7.5 | 0.03 | Jan 9, 2024 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2024-20658 | Hig | 0.51 | 7.8 | 0.01 | Jan 9, 2024 | Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability | ||
| CVE-2024-20657 | Hig | 0.46 | 7.0 | 0.01 | Jan 9, 2024 | Windows Group Policy Elevation of Privilege Vulnerability | ||
| CVE-2024-20656 | Hig | 0.51 | 7.8 | 0.04 | Jan 9, 2024 | Visual Studio Elevation of Privilege Vulnerability | ||
| CVE-2024-20654 | Hig | 0.52 | 8.0 | 0.02 | Jan 9, 2024 | Microsoft ODBC Driver Remote Code Execution Vulnerability | ||
| CVE-2024-20653 | Hig | 0.51 | 7.8 | 0.04 | Jan 9, 2024 | Microsoft Common Log File System Elevation of Privilege Vulnerability | ||
| CVE-2024-20652 | Hig | 0.53 | 8.1 | 0.02 | Jan 9, 2024 | Windows HTML Platforms Security Feature Bypass Vulnerability | ||
| CVE-2024-0056 | Hig | 0.57 | 8.7 | 0.01 | Jan 9, 2024 | Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability | ||
| CVE-2022-48618 | Hig | 0.58 | 7.0 | 0.00 | KEV | Jan 9, 2024 | The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this… | |
| CVE-2023-7222 | Hig | 0.47 | 7.2 | 0.01 | Jan 9, 2024 | A vulnerability was found in Totolink X2000R 1.0.0-B20221212.1452. It has been declared as critical. This vulnerability affects the function formTmultiAP of the file /bin/boa of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer… | ||
| CVE-2022-36765 | Hig | 0.46 | 7.0 | 0.00 | Jan 9, 2024 | EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability. | ||
| CVE-2022-36764 | Hig | 0.46 | 7.0 | 0.00 | Jan 9, 2024 | EDK2 is susceptible to a vulnerability in the Tcg2MeasurePeImage() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability. | ||
| CVE-2022-36763 | Hig | 0.46 | 7.0 | 0.00 | Jan 9, 2024 | EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability. | ||
| CVE-2024-0213 | Hig | 0.53 | 8.2 | 0.00 | Jan 9, 2024 | A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause a Denial of Service (DoS), through exploiting a memory corruption issue in the TA service, which runs as root. This may also result in the… | ||
| CVE-2024-0206 | Hig | 0.46 | 7.1 | 0.00 | Jan 9, 2024 | A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation of privileges. This was achieved by adding an entry to the registry under the Trellix ENS registry… | ||
| CVE-2023-5376 | Hig | 0.56 | 8.6 | 0.01 | Jan 9, 2024 | An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware version 2024/01. | ||
| CVE-2023-51746 | Hig | 0.51 | 7.8 | 0.00 | Jan 9, 2024 | A vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < V13.3.0.13), Teamcenter Visualization V14.1 (All versions < V14.1.0.12), Teamcenter Visualization V14.2 (All versions < V14.2.0.9), Teamcenter Visualization… | ||
| CVE-2023-51745 | Hig | 0.51 | 7.8 | 0.00 | Jan 9, 2024 | A vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < V13.3.0.13), Teamcenter Visualization V14.1 (All versions < V14.1.0.12), Teamcenter Visualization V14.2 (All versions < V14.2.0.9), Teamcenter Visualization… | ||
| CVE-2023-51439 | Hig | 0.51 | 7.8 | 0.00 | Jan 9, 2024 | A vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < V13.3.0.13), Teamcenter Visualization V14.1 (All versions < V14.1.0.12), Teamcenter Visualization V14.2 (All versions < V14.2.0.9), Teamcenter Visualization… | ||
| CVE-2023-49722 | Hig | 0.54 | 8.3 | 0.00 | Jan 9, 2024 | Network port 8899 open in WiFi firmware of BCC101/BCC102/BCC50 products, that allows an attacker to connect to the device via same WiFi network. | ||
| CVE-2023-49252 | Hig | 0.49 | 7.5 | 0.01 | Jan 9, 2024 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The affected application allows IP configuration change without authentication to the device. This could allow an attacker to cause denial of service condition. |
- risk 0.53cvss 7.3epss 0.73
A vulnerability classified as critical was found in Likeshop up to 2.5.7.20210311. This vulnerability affects the function FileServer::userFormImage of the file server/application/api/controller/File.php of the component HTTP POST Request Handler. The manipulation of the…
- risk 0.57cvss 8.8epss 0.01
An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows attackers to obtain sensitive information, cause a denial of service and/or run arbitrary code.
- risk 0.57cvss 8.8epss 0.01
An integer overflow vulnerability in FreeImageIO.cpp::_MemoryReadProc in FreeImage 3.18.0 allows attackers to obtain sensitive information, cause a denial-of-service attacks and/or run arbitrary code.
- risk 0.54cvss 8.3epss 0.00
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
- risk 0.54cvss 8.3epss 0.00
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack memory corruption via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
- risk 0.54cvss 8.3epss 0.00
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability. …
- risk 0.54cvss 8.3epss 0.00
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability. …
- risk 0.51cvss 7.8epss 0.00
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause an untrusted pointer to dereference via a local network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability. …
- risk 0.51cvss 7.8epss 0.00
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause an untrusted pointer to dereference by a local network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability. …
- risk 0.51cvss 7.8epss 0.00
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain higher privileges by providing a harmful serialized object.
- risk 0.51cvss 7.8epss 0.01
Microsoft Printer Metadata Troubleshooter Tool Remote Code Execution Vulnerability
- risk 0.60cvss 8.8epss 0.31
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.04
.NET Framework Denial of Service Vulnerability
- risk 0.52cvss 7.8epss 0.12
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.02
Remote Desktop Client Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.04
Windows Hyper-V Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.09
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.53cvss 7.3epss 0.72
Windows libarchive Remote Code Execution Vulnerability
- risk 0.48cvss 7.3epss 0.03
Windows libarchive Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.03
Microsoft AllJoyn API Denial of Service Vulnerability
- risk 0.51cvss 7.8epss 0.01
Win32k Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.04
Win32k Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Cryptographic Services Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Subsystem for Linux Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.03
A security vulnerability exists in FBX that could lead to remote code execution. To mitigate this vulnerability, the ability to insert FBX files has been disabled in Word, Excel, PowerPoint and Outlook for Windows and Mac. Versions of Office that had this feature enabled will no…
- risk 0.52cvss 8.0epss 0.03
Azure Storage Mover Remote Code Execution Vulnerability
- risk 0.59cvss 8.8epss 0.17
Windows Kerberos Security Feature Bypass Vulnerability
- risk 0.49cvss 7.5epss 0.03
.NET Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Group Policy Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.04
Visual Studio Elevation of Privilege Vulnerability
- risk 0.52cvss 8.0epss 0.02
Microsoft ODBC Driver Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.04
Microsoft Common Log File System Elevation of Privilege Vulnerability
- risk 0.53cvss 8.1epss 0.02
Windows HTML Platforms Security Feature Bypass Vulnerability
- risk 0.57cvss 8.7epss 0.01
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
- risk 0.58cvss 7.0epss 0.00
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this…
- risk 0.47cvss 7.2epss 0.01
A vulnerability was found in Totolink X2000R 1.0.0-B20221212.1452. It has been declared as critical. This vulnerability affects the function formTmultiAP of the file /bin/boa of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer…
- risk 0.46cvss 7.0epss 0.00
EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.
- risk 0.46cvss 7.0epss 0.00
EDK2 is susceptible to a vulnerability in the Tcg2MeasurePeImage() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.
- risk 0.46cvss 7.0epss 0.00
EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.
- risk 0.53cvss 8.2epss 0.00
A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause a Denial of Service (DoS), through exploiting a memory corruption issue in the TA service, which runs as root. This may also result in the…
- risk 0.46cvss 7.1epss 0.00
A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation of privileges. This was achieved by adding an entry to the registry under the Trellix ENS registry…
- risk 0.56cvss 8.6epss 0.01
An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware version 2024/01.
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < V13.3.0.13), Teamcenter Visualization V14.1 (All versions < V14.1.0.12), Teamcenter Visualization V14.2 (All versions < V14.2.0.9), Teamcenter Visualization…
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < V13.3.0.13), Teamcenter Visualization V14.1 (All versions < V14.1.0.12), Teamcenter Visualization V14.2 (All versions < V14.2.0.9), Teamcenter Visualization…
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < V13.3.0.13), Teamcenter Visualization V14.1 (All versions < V14.1.0.12), Teamcenter Visualization V14.2 (All versions < V14.2.0.9), Teamcenter Visualization…
- risk 0.54cvss 8.3epss 0.00
Network port 8899 open in WiFi firmware of BCC101/BCC102/BCC50 products, that allows an attacker to connect to the device via same WiFi network.
- risk 0.49cvss 7.5epss 0.01
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The affected application allows IP configuration change without authentication to the device. This could allow an attacker to cause denial of service condition.