| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-44111 | Hig | 0.49 | 7.5 | 0.00 | Oct 11, 2023 | Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-44104 | Hig | 0.49 | 7.5 | 0.00 | Oct 11, 2023 | Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-44103 | Hig | 0.49 | 7.5 | 0.00 | Oct 11, 2023 | Out-of-bounds read vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-44101 | Hig | 0.49 | 7.5 | 0.00 | Oct 11, 2023 | The Bluetooth module has a vulnerability in permission control for broadcast notifications.Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2023-44100 | Hig | 0.49 | 7.5 | 0.00 | Oct 11, 2023 | Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-44097 | Hig | 0.49 | 7.5 | 0.00 | Oct 11, 2023 | Vulnerability of the permission to access device SNs being improperly managed.Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-44095 | Hig | 0.49 | 7.5 | 0.00 | Oct 11, 2023 | Use-After-Free (UAF) vulnerability in the surfaceflinger module.Successful exploitation of this vulnerability can cause system crash. | ||
| CVE-2023-26370 | Hig | 0.51 | 7.8 | 0.00 | Oct 11, 2023 | Adobe Photoshop versions 23.5.5 (and earlier) and 24.7 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a… | ||
| CVE-2023-44109 | Hig | 0.49 | 7.5 | 0.00 | Oct 11, 2023 | Clone vulnerability in the huks ta module.Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-44096 | Hig | 0.49 | 7.5 | 0.00 | Oct 11, 2023 | Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-44093 | Hig | 0.49 | 7.5 | 0.00 | Oct 11, 2023 | Vulnerability of package names' public keys not being verified in the security module.Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-42138 | Hig | 0.51 | 7.8 | 0.00 | Oct 11, 2023 | Out-of-bounds read vulnerability exists in KV STUDIO Ver. 11.62 and earlier and KV REPLAY VIEWER Ver. 2.62 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user of KV STUDIO PLAYER open a specially… | ||
| CVE-2023-4990 | Hig | 0.54 | 8.3 | 0.01 | Oct 11, 2023 | Directory traversal vulnerability in MCL-Net versions prior to 4.6 Update Package (P01) may allow attackers to read arbitrary files. | ||
| CVE-2023-37536 | Hig | 0.53 | 8.2 | 0.01 | Oct 11, 2023 | An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request. | ||
| CVE-2023-26320 | Hig | 0.49 | 7.5 | 0.01 | Oct 11, 2023 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection. | ||
| CVE-2023-5511 | Hig | 0.50 | 8.8 | 0.00 | Oct 11, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository snipe/snipe-it prior to v.6.2.3. | ||
| CVE-2023-36127 | Hig | 0.49 | 7.5 | 0.01 | Oct 10, 2023 | User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | ||
| CVE-2023-45312 | Hig | 0.57 | 8.8 | 0.02 | Oct 10, 2023 | In the mtproto_proxy (aka MTProto proxy) component through 0.7.2 for Erlang, a low-privileged remote attacker can access an improperly secured default installation without authenticating and achieve remote command execution ability. | ||
| CVE-2023-31096 | Hig | 0.51 | 7.8 | 0.00 | Oct 10, 2023 | An issue was discovered in Broadcom) LSI PCI-SV92EX Soft Modem Kernel Driver through 2.2.100.1 (aka AGRSM64.sys). There is Local Privilege Escalation to SYSTEM via a Stack Overflow in RTLCopyMemory (IOCTL 0x1b2150). An attacker can exploit this to elevate privileges from a… | ||
| CVE-2023-41774 | Hig | 0.53 | 8.1 | 0.01 | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2023-41773 | Hig | 0.53 | 8.1 | 0.01 | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2023-41772 | Hig | 0.52 | 7.8 | 0.12 | Oct 10, 2023 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2023-41771 | Hig | 0.53 | 8.1 | 0.01 | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2023-41770 | Hig | 0.53 | 8.1 | 0.01 | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2023-41769 | Hig | 0.53 | 8.1 | 0.01 | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2023-41768 | Hig | 0.53 | 8.1 | 0.01 | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2023-41767 | Hig | 0.53 | 8.1 | 0.01 | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2023-41766 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2023 | Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | ||
| CVE-2023-41765 | Hig | 0.53 | 8.1 | 0.01 | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2023-38171 | Hig | 0.47 | 7.5 | 0.69 | Oct 10, 2023 | Microsoft QUIC Denial of Service Vulnerability | ||
| CVE-2023-38166 | Hig | 0.53 | 8.1 | 0.01 | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2023-38159 | Hig | 0.46 | 7.0 | 0.06 | Oct 10, 2023 | Windows Graphics Component Elevation of Privilege Vulnerability | ||
| CVE-2023-36902 | Hig | 0.46 | 7.0 | 0.01 | Oct 10, 2023 | Windows Runtime Remote Code Execution Vulnerability | ||
| CVE-2023-36790 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2023 | Windows RDP Encoder Mirror Driver Elevation of Privilege Vulnerability | ||
| CVE-2023-36789 | Hig | 0.47 | 7.2 | 0.02 | Oct 10, 2023 | Skype for Business Remote Code Execution Vulnerability | ||
| CVE-2023-36786 | Hig | 0.47 | 7.2 | 0.02 | Oct 10, 2023 | Skype for Business Remote Code Execution Vulnerability | ||
| CVE-2023-36785 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-36780 | Hig | 0.47 | 7.2 | 0.03 | Oct 10, 2023 | Skype for Business Remote Code Execution Vulnerability | ||
| CVE-2023-36778 | Hig | 0.52 | 8.0 | 0.04 | Oct 10, 2023 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2023-36776 | Hig | 0.46 | 7.0 | 0.02 | Oct 10, 2023 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2023-36743 | Hig | 0.51 | 7.8 | 0.04 | Oct 10, 2023 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2023-36737 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2023 | Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | ||
| CVE-2023-36732 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2023 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2023-36731 | Hig | 0.51 | 7.8 | 0.08 | Oct 10, 2023 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2023-36730 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-36729 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2023 | Named Pipe File System Elevation of Privilege Vulnerability | ||
| CVE-2023-36726 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2023 | Windows Internet Key Exchange (IKE) Extension Elevation of Privilege Vulnerability | ||
| CVE-2023-36725 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-36723 | Hig | 0.51 | 7.8 | 0.02 | Oct 10, 2023 | Windows Container Manager Service Elevation of Privilege Vulnerability | ||
| CVE-2023-36721 | Hig | 0.46 | 7.0 | 0.00 | Oct 10, 2023 | Windows Error Reporting Service Elevation of Privilege Vulnerability |
- risk 0.49cvss 7.5epss 0.00
Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
Out-of-bounds read vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
The Bluetooth module has a vulnerability in permission control for broadcast notifications.Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of the permission to access device SNs being improperly managed.Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
Use-After-Free (UAF) vulnerability in the surfaceflinger module.Successful exploitation of this vulnerability can cause system crash.
- risk 0.51cvss 7.8epss 0.00
Adobe Photoshop versions 23.5.5 (and earlier) and 24.7 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…
- risk 0.49cvss 7.5epss 0.00
Clone vulnerability in the huks ta module.Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of package names' public keys not being verified in the security module.Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.51cvss 7.8epss 0.00
Out-of-bounds read vulnerability exists in KV STUDIO Ver. 11.62 and earlier and KV REPLAY VIEWER Ver. 2.62 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user of KV STUDIO PLAYER open a specially…
- risk 0.54cvss 8.3epss 0.01
Directory traversal vulnerability in MCL-Net versions prior to 4.6 Update Package (P01) may allow attackers to read arbitrary files.
- risk 0.53cvss 8.2epss 0.01
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
- risk 0.49cvss 7.5epss 0.01
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.
- risk 0.50cvss 8.8epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository snipe/snipe-it prior to v.6.2.3.
- risk 0.49cvss 7.5epss 0.01
User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
- risk 0.57cvss 8.8epss 0.02
In the mtproto_proxy (aka MTProto proxy) component through 0.7.2 for Erlang, a low-privileged remote attacker can access an improperly secured default installation without authenticating and achieve remote command execution ability.
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in Broadcom) LSI PCI-SV92EX Soft Modem Kernel Driver through 2.2.100.1 (aka AGRSM64.sys). There is Local Privilege Escalation to SYSTEM via a Stack Overflow in RTLCopyMemory (IOCTL 0x1b2150). An attacker can exploit this to elevate privileges from a…
- risk 0.53cvss 8.1epss 0.01
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.52cvss 7.8epss 0.12
Win32k Elevation of Privilege Vulnerability
- risk 0.53cvss 8.1epss 0.01
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
- risk 0.53cvss 8.1epss 0.01
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.47cvss 7.5epss 0.69
Microsoft QUIC Denial of Service Vulnerability
- risk 0.53cvss 8.1epss 0.01
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.46cvss 7.0epss 0.06
Windows Graphics Component Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Runtime Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows RDP Encoder Mirror Driver Elevation of Privilege Vulnerability
- risk 0.47cvss 7.2epss 0.02
Skype for Business Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.02
Skype for Business Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.03
Skype for Business Remote Code Execution Vulnerability
- risk 0.52cvss 8.0epss 0.04
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.46cvss 7.0epss 0.02
Win32k Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.04
Win32k Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Azure Network Watcher VM Agent Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Win32k Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.08
Win32k Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Named Pipe File System Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Internet Key Exchange (IKE) Extension Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.02
Windows Container Manager Service Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows Error Reporting Service Elevation of Privilege Vulnerability