Total
36333 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-36559 | 1 Microsoft | 1 Edge Chromium | 2026-06-17 | N/A | 4.2 MEDIUM |
| Microsoft Edge (Chromium-based) Spoofing Vulnerability | |||||
| CVE-2023-36558 | 1 Microsoft | 3 .net, Asp.net Core, Visual Studio 2022 | 2026-06-17 | N/A | 6.2 MEDIUM |
| ASP.NET Core Security Feature Bypass Vulnerability | |||||
| CVE-2023-36557 | 1 Microsoft | 10 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 7 more | 2026-06-17 | N/A | 7.8 HIGH |
| PrintHTML API Remote Code Execution Vulnerability | |||||
| CVE-2023-36551 | 1 Fortinet | 1 Fortisiem | 2026-06-17 | N/A | 4.3 MEDIUM |
| A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows attacker to information disclosure via a crafted http request. | |||||
| CVE-2023-36537 | 1 Zoom | 1 Rooms | 2026-06-17 | N/A | 7.3 HIGH |
| Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access. | |||||
| CVE-2023-36533 | 1 Zoom | 2 Meeting Software Development Kit, Video Software Development Kit | 2026-06-17 | N/A | 7.1 HIGH |
| Uncontrolled resource consumption in Zoom SDKs before 5.14.7 may allow an unauthenticated user to enable a denial of service via network access. | |||||
| CVE-2023-36523 | 1 Gopiplus | 1 Email Download Link | 2026-06-17 | N/A | 5.3 MEDIUM |
| Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gopi Ramasamy Email download link.This issue affects Email download link: from n/a through 3.7. | |||||
| CVE-2023-36507 | 1 Reputeinfosystems | 1 Bookingpress | 2026-06-17 | N/A | 5.3 MEDIUM |
| Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Repute Infosystems BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin.This issue affects BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin: from n/a through 1.0.64. | |||||
| CVE-2023-36505 | 1 Ninjaforms | 1 Ninja Forms | 2026-06-17 | N/A | 6.8 MEDIUM |
| Improper Input Validation vulnerability in Saturday Drive Ninja Forms Contact Form.This issue affects Ninja Forms Contact Form : from n/a through 3.6.24. | |||||
| CVE-2023-36496 | 1 Pingidentity | 1 Pingdirectory | 2026-06-17 | N/A | 7.7 HIGH |
| Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server. | |||||
| CVE-2023-36490 | 1 Intel | 1 Memory And Storage Tool | 2026-06-17 | N/A | 5.0 MEDIUM |
| Improper initialization in some Intel(R) MAS software before version 2.3 may allow an authenticated user to potentially enable denial of service via local access. | |||||
| CVE-2023-36487 | 1 Ilias | 1 Ilias | 2026-06-17 | N/A | 9.8 CRITICAL |
| The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account. | |||||
| CVE-2023-36486 | 1 Ilias | 1 Ilias | 2026-06-17 | N/A | 7.2 HIGH |
| The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user by uploading a workflow definition file with a malicious filename. | |||||
| CVE-2023-36485 | 1 Ilias | 1 Ilias | 2026-06-17 | N/A | 7.2 HIGH |
| The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user via a malicious BPMN2 workflow definition file. | |||||
| CVE-2023-36462 | 1 Joinmastodon | 1 Mastodon | 2026-06-17 | N/A | 5.4 MEDIUM |
| Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 2.6.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, an attacker can craft a verified profile link using specific formatting to conceal arbitrary parts of the link, enabling it to appear to link to a different URL altogether. The link is visually misleading, but clicking on it will reveal the actual link. This can still be used for phishing, though, similar to IDN homograph attacks. Versions 3.5.9, 4.0.5, and 4.1.3 contain a patch for this issue. | |||||
| CVE-2023-36439 | 1 Microsoft | 1 Exchange Server | 2026-06-17 | N/A | 8.0 HIGH |
| Microsoft Exchange Server Remote Code Execution Vulnerability | |||||
| CVE-2023-36438 | 1 Microsoft | 12 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 9 more | 2026-06-17 | N/A | 7.5 HIGH |
| Windows TCP/IP Information Disclosure Vulnerability | |||||
| CVE-2023-36437 | 1 Microsoft | 1 Azure Pipelines Agent | 2026-06-17 | N/A | 8.8 HIGH |
| Azure DevOps Server Remote Code Execution Vulnerability | |||||
| CVE-2023-36436 | 1 Microsoft | 11 Windows 10 1507, Windows 10 1809, Windows 10 21h1 and 8 more | 2026-06-17 | N/A | 7.8 HIGH |
| Windows MSHTML Platform Remote Code Execution Vulnerability | |||||
| CVE-2023-36435 | 1 Microsoft | 4 .net, Windows 11 21h2, Windows 11 22h2 and 1 more | 2026-06-17 | N/A | 7.5 HIGH |
| Microsoft QUIC Denial of Service Vulnerability | |||||
