Количество 26 124
Количество 26 124
CVE-2023-28231
DHCP Server Service Remote Code Execution Vulnerability
CVE-2023-28229
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
CVE-2023-28228
Windows Spoofing Vulnerability
CVE-2023-28227
Windows Bluetooth Driver Remote Code Execution Vulnerability
CVE-2023-28226
Windows Enroll Engine Security Feature Bypass Vulnerability
CVE-2023-28225
Windows NTLM Elevation of Privilege Vulnerability
CVE-2023-28224
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
CVE-2023-28223
Windows Domain Name Service Remote Code Execution Vulnerability
CVE-2023-28222
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-28221
Windows Error Reporting Service Elevation of Privilege Vulnerability
CVE-2023-28220
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
CVE-2023-28219
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
CVE-2023-28218
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2023-28217
Windows Network Address Translation (NAT) Denial of Service Vulnerability
CVE-2023-28216
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
CVE-2023-2816
Consul Envoy Extension Downsteam Proxy Configuration By Upstream Service Owner
CVE-2023-28155
The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2023-28154
Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.
CVE-2023-28117
Sentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True`
CVE-2023-28115
Snappy vulnerable to PHAR deserialization, allowing remote code execution
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-28231 DHCP Server Service Remote Code Execution Vulnerability | CVSS3: 8.8 | 37% Средний | больше 3 лет назад | |
CVE-2023-28229 Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | CVSS3: 7 | 2% Низкий | больше 3 лет назад | |
CVE-2023-28228 Windows Spoofing Vulnerability | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
CVE-2023-28227 Windows Bluetooth Driver Remote Code Execution Vulnerability | CVSS3: 7.5 | 7% Низкий | больше 3 лет назад | |
CVE-2023-28226 Windows Enroll Engine Security Feature Bypass Vulnerability | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
CVE-2023-28225 Windows NTLM Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
CVE-2023-28224 Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability | CVSS3: 7.1 | 0% Низкий | больше 3 лет назад | |
CVE-2023-28223 Windows Domain Name Service Remote Code Execution Vulnerability | CVSS3: 6.6 | 1% Низкий | больше 3 лет назад | |
CVE-2023-28222 Windows Kernel Elevation of Privilege Vulnerability | CVSS3: 7.1 | 1% Низкий | больше 3 лет назад | |
CVE-2023-28221 Windows Error Reporting Service Elevation of Privilege Vulnerability | CVSS3: 7 | 0% Низкий | больше 3 лет назад | |
CVE-2023-28220 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | CVSS3: 8.1 | 15% Средний | больше 3 лет назад | |
CVE-2023-28219 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | CVSS3: 8.1 | 15% Средний | больше 3 лет назад | |
CVE-2023-28218 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | CVSS3: 7 | 12% Средний | больше 3 лет назад | |
CVE-2023-28217 Windows Network Address Translation (NAT) Denial of Service Vulnerability | CVSS3: 7.5 | 2% Низкий | больше 3 лет назад | |
CVE-2023-28216 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | CVSS3: 7 | 0% Низкий | больше 3 лет назад | |
CVE-2023-2816 Consul Envoy Extension Downsteam Proxy Configuration By Upstream Service Owner | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
CVE-2023-28155 The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | CVSS3: 6.1 | 1% Низкий | 6 месяцев назад | |
CVE-2023-28154 Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object. | 1% Низкий | 12 месяцев назад | ||
CVE-2023-28117 Sentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True` | 1% Низкий | 12 месяцев назад | ||
CVE-2023-28115 Snappy vulnerable to PHAR deserialization, allowing remote code execution | 3% Низкий | 9 дней назад |
Уязвимостей на страницу