Vulnerabilities (CVE)

Filtered by CWE-20
Total 13255 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-28732 1 Acymailing 1 Acymailing 2026-06-17 N/A 6.5 MEDIUM
Missing access control in AnyMailing Joomla Plugin allows to list and access files containing sensitive information from the plugin itself and access to system files via path traversal, when being granted access to the campaign's creation on front-office. This issue affects AnyMailing Joomla Plugin in versions below 8.3.0.
CVE-2023-28731 1 Acymailing 1 Acymailing 2026-06-17 N/A 9.8 CRITICAL
AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.
CVE-2023-28710 1 Apache 1 Apache-airflow-providers-apache-spark 2026-06-17 N/A 7.5 HIGH
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Spark Provider.This issue affects Apache Airflow Spark Provider: before 4.0.1.
CVE-2023-28707 1 Apache 1 Apache-airflow-providers-apache-drill 2026-06-17 N/A 7.5 HIGH
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider: before 2.3.2.
CVE-2023-28649 1 Snapone 2 Orvc, Ovrc-300-pro 2026-06-17 N/A 8.6 HIGH
The Hub in the Snap One OvrC cloud platform is a device used to centralize and manage nested devices connected to it. A vulnerability exists in which an attacker could impersonate a hub and send device requests to claim already claimed devices. The OvrC cloud platform receives the requests but does not validate if the found devices are already managed by another user.
CVE-2023-28578 1 Qualcomm 680 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 677 more 2026-06-17 N/A 9.3 CRITICAL
Memory corruption in Core Services while executing the command for removing a single event listener.
CVE-2023-28574 1 Qualcomm 156 Ar8035, Ar8035 Firmware, Qam8255p and 153 more 2026-06-17 N/A 9.0 CRITICAL
Memory corruption in core services when Diag handler receives a command to configure event listeners.
CVE-2023-28513 5 Hp, Ibm, Linux and 2 more 9 Hp-ux, Aix, I and 6 more 2026-06-17 N/A 5.9 MEDIUM
IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.3 CD and IBM MQ Appliance 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.2 LTS, under certain configurations, is vulnerable to a denial of service attack caused by an error processing messages. IBM X-Force ID: 250397.
CVE-2023-28402 2026-06-17 N/A 7.2 HIGH
Improper input validation in some Intel(R) BIOS Guard firmware may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2023-28374 1 Intel 7 Killer, Killer Wi-fi 6e Ax1675, Killer Wi-fi 6e Ax1690 and 4 more 2026-06-17 N/A 6.1 MEDIUM
Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
CVE-2023-28330 1 Moodle 1 Moodle 2026-06-17 N/A 6.5 MEDIUM
Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.
CVE-2023-28324 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 9.8 CRITICAL
A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.
CVE-2023-28304 1 Microsoft 2 Odbc, Ole Db 2026-06-17 N/A 7.8 HIGH
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
CVE-2023-28302 1 Microsoft 12 Windows 10 1607, Windows 10 1809, Windows 10 20h2 and 9 more 2026-06-17 N/A 7.5 HIGH
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVE-2023-28301 1 Microsoft 1 Edge 2026-06-17 N/A 3.7 LOW
Microsoft Edge (Chromium-based) Tampering Vulnerability
CVE-2023-28291 1 Microsoft 5 Raw Image Extension, Windows 10 20h2, Windows 10 21h2 and 2 more 2026-06-17 N/A 8.4 HIGH
Raw Image Extension Remote Code Execution Vulnerability
CVE-2023-28274 1 Microsoft 8 Windows 10 1809, Windows 10 20h2, Windows 10 21h2 and 5 more 2026-06-17 N/A 7.8 HIGH
Windows Win32k Elevation of Privilege Vulnerability
CVE-2023-28200 1 Apple 3 Ipados, Iphone Os, Macos 2026-06-17 N/A 5.5 MEDIUM
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to disclose kernel memory.
CVE-2023-28130 1 Checkpoint 1 Gaia Portal 2026-06-17 N/A 7.2 HIGH
Local user may lead to privilege escalation using Gaia Portal hostnames page.
CVE-2023-28113 1 Russh Project 1 Russh 2026-06-17 N/A 5.9 MEDIUM
russh is a Rust SSH client and server library. Starting in version 0.34.0 and prior to versions 0.36.2 and 0.37.1, Diffie-Hellman key validation is insufficient, which can lead to insecure shared secrets and therefore breaks confidentiality. Connections between a russh client and server or those of a russh peer with some other misbehaving peer are most likely to be problematic. These may vulnerable to eavesdropping. Most other implementations reject such keys, so this is mainly an interoperability issue in such a case. This issue is fixed in versions 0.36.2 and 0.37.1