Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-35644

Windows Sysmain Service Elevation of Privilege

CVE
#windows
CVE-2023-48313: DOM-based stored cross-site scripting

Umbraco is an ASP.NET content management system (CMS). Starting in 10.0.0 and prior to versions 10.8.1 and 12.3.4, Umbraco contains a cross-site scripting (XSS) vulnerability enabling attackers to bring malicious content into a website or application. Versions 10.8.1 and 12.3.4 contain a patch for this issue.

CVE-2023-43364: removed eval from search cli method by dan-pavlov · Pull Request #130 · ArjunSharda/Searchor

main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.

CVE-2023-36696

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2023-36391

Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

CVE-2023-49923: Enterprise Search 8.11.2 / 7.17.16 Security Update (ESA-2023-31)

An issue was discovered by Elastic whereby the Documents API of App Search logged the raw contents of indexed documents at INFO log level. Depending on the contents of such documents, this could lead to the insertion of sensitive or private information in the App Search logs. Elastic has released 8.11.2 and 7.17.16 that resolves this issue by changing the log level at which these are logged to DEBUG, which is disabled by default.

CVE-2023-20275: Cisco Security Advisory: Cisco Adaptive Security Appliance and Firepower Threat Defense Software VPN Packet Validation Vulnerability

A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to send packets with another VPN user's source IP address. This vulnerability is due to improper validation of the packet's inner source IP address after decryption. An attacker could exploit this vulnerability by sending crafted packets through the tunnel. A successful exploit could allow the attacker to send a packet impersonating another VPN user's IP address. It is not possible for the attacker to receive return packets.

CVE-2023-36020

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

CVE-2023-36011

Win32k Elevation of Privilege Vulnerability

CVE-2023-36006

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability