NA - CVE-2023-39817 - ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER....
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
NA - CVE-2023-39930 - A first-factor authentication bypass...
A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS client request.
NA - CVE-2023-3010 - Grafana is an open-source platform for...
Grafana is an open-source platform for monitoring and observability. The WorldMap panel plugin, versions before 1.0.4 contains a DOM XSS vulnerability.
NA - CVE-2023-3112 - A vulnerability was reported in Elliptic Labs...
A vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker with local access to execute code with elevated privileges.
NA - CVE-2023-41255 - The vulnerability allows an unprivileged user...
The vulnerability allows an unprivileged user with access to the subnet of the TPC-110W device to gain a root shell on the device itself abusing the lack of authentication of the ‘su’ binary file...
NA - CVE-2023-41339 - GeoServer is an open source software server...
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The WMS specification defines an ``sld=`` parameter for GetMap, GetLegendGraphic and...
NA - CVE-2023-41372 - The vulnerability allows an unprivileged...
The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client application, inducing it to connect to an attacker -...
NA - CVE-2023-41721 - Instances of UniFi Network Application that (i)...
Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic,...
NA - CVE-2023-41960 - The vulnerability allows an...
The vulnerability allows an unprivileged(untrusted) third-party application to interact with a content-provider unsafely exposed by the Android Agent application, potentially modifying sensitive...