CVE Vulnerability Database

Search and browse 55 known security vulnerabilities. Filter by severity, vendor, product, and year.

55 vulnerabilities found
CVE-2023-35069
7.5 high

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bullwark allows Path Traversal. This issue affects Bullwark: before BLW-2016E-960H.

Biges Bullwark Momentum Series Jul 13, 2023
CVE-2023-33161
7.8 high

Microsoft Excel Remote Code Execution Vulnerability

Microsoft 365 Apps Jul 11, 2023
CVE-2023-33158
7.8 high

Microsoft Excel Remote Code Execution Vulnerability

Microsoft 365 Apps Jul 11, 2023
CVE-2023-33152
7.0 high

Microsoft ActiveX Remote Code Execution Vulnerability

Microsoft 365 Apps Jul 11, 2023
CVE-2023-33149
7.8 high

Microsoft Office Graphics Remote Code Execution Vulnerability

Microsoft 365 Apps Jul 11, 2023
CVE-2023-33148
7.8 high

Microsoft Office Elevation of Privilege Vulnerability

Microsoft 365 Apps Jul 11, 2023
CVE-2023-3273
7.5 high

Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by changing settings of the device such as the IP address based on missing access control.

Sick Icr890-4 Firmware Jul 10, 2023
CVE-2023-3272
7.5 high

Cleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a remote attacker to gather sensitive information by intercepting network traffic that is not encrypted.

Sick Icr890-4 Firmware Jul 10, 2023
CVE-2023-3271
8.2 high

Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints.

Sick Icr890-4 Firmware Jul 10, 2023
CVE-2023-35696
7.5 high

Unauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the device via HTTP requests.

Sick Icr890-4 Firmware Jul 10, 2023
CVE-2023-2885
8.1 high

Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in CBOT Chatbot allows Adversary in the Middle (AiTM).This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.

Cbot Cbot Core May 25, 2023
CVE-2023-2883
8.8 high

Authorization Bypass Through User-Controlled Key vulnerability in CBOT Chatbot allows Authentication Abuse, Authentication Bypass.This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.

Cbot Cbot Core May 25, 2023
CVE-2023-2065
8.8 high

Authorization Bypass Through User-Controlled Key vulnerability in Armoli Technology Cargo Tracking System allows Authentication Abuse, Authentication Bypass.This issue affects Cargo Tracking System: before 3558f28 .

Armoli Cargo Tracking System May 24, 2023
CVE-2023-2703
7.5 high

Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Finex Media Competition Management System allows Retrieve Embedded Sensitive Data, Collect Data as Provided by Users.This issue affects Competition Management System: before 23.07.

Finexmedia Competition Management System May 23, 2023
CVE-2023-2702
8.8 high

Authorization Bypass Through User-Controlled Key vulnerability in Finex Media Competition Management System allows Authentication Abuse, Authentication Bypass.This issue affects Competition Management System: before 23.07.

Finexmedia Competition Management System May 23, 2023
CVE-2023-23447
7.5 high

Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to influence the availability of the webserver by invocing several open file requests via the REST interface.

Sick Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-23446
7.5 high

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviledged account via the REST interface.

Sick Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-23445
7.5 high

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by using a therefore unpriviledged account via the REST interface.

Sick Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-29335
7.5 high

Microsoft Word Security Feature Bypass Vulnerability

Microsoft Windows 10 1507 May 9, 2023
CVE-2023-26246
7.8 high

An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, which is used during the firmware installation process, can be modified by an attacker to bypass the digital signature check. This indirectly allows an attacker

Hyundai Gen5W L Firmware Apr 27, 2023
CVE-2023-26245
7.8 high

An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, which is used during the firmware installation process, can be modified by an attacker to bypass the version check in order to install any firmware version (e.g.

Hyundai Gen5W L Firmware Apr 27, 2023
CVE-2023-26244
7.8 high

An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppDMClient binary file, which is used during the firmware installation process, can be modified by an attacker to bypass the digital signature check of AppUpgrade and .lge.upgrade.xml

Hyundai Gen5W L Firmware Apr 27, 2023
CVE-2023-26243
7.8 high

An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decryption binary used to decrypt firmware files has an information leak that allows an attacker to read the AES key and initialization vector from memory. An attacker may exploit this

Hyundai Gen5W L Firmware Apr 27, 2023
CVE-2023-1014
7.5 high

Improper Protection for Outbound Error Messages and Alert Signals vulnerability in Virames Vira-Investing allows Account Footprinting. This issue affects Vira-Investing: before 1.0.84.86.

Dizayn Vira-Investing Mar 30, 2023