High · CVSS 7.5
Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. See Honeywell Security Notification for recommendations on upgrading and versioning.
Published Jul 13, 2023 · Updated Mar 5, 2025
High · CVSS 7.5
Server information leak of configuration data when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.
Published Jul 13, 2023 · Updated Mar 5, 2025
High · CVSS 8.8
A command injection vulnerability in the configuration parser of the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 5.10 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 5.10 through 5.36 Patch 2, and VPN series firmware versions 5.00 through 5.36 Patch 2, could allow an unauthenticated, LAN-based attacker to execute some OS commands by using a crafted GRE configuration when the cloud management mode is enabled.
Published Jul 17, 2023 · Updated Mar 5, 2025
High · CVSS 7.5
An executable used in Rockwell Automation ThinManager ThinServer can be configured to enable an API feature in the HTTPS Server Settings. This feature is disabled by default. When the API is enabled and handling requests, a path traversal vulnerability exists that allows a remote actor to leverage the privileges of the server’s file system and read arbitrary files stored in it. A malicious user could exploit this vulnerability by executing a path that contains manipulating variables.
Published Jul 18, 2023 · Updated Mar 5, 2025
High · CVSS 7.8
A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privilege escalation.
If tcf_change_indev() fails, fw_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_bind_filter(). If an attacker can control the reference counter and set it to zero, they can cause the reference to be freed, leading to a use-after-free vulnerability.
We recommend upgrading past commit 0323bce598eea038714f941ce2b22541c46d488f.
Published Jul 21, 2023 · Updated Mar 5, 2025
Medium · CVSS 4.4
An out-of-bounds read vulnerability was found in the SR-IPv6 implementation in the Linux kernel. The flaw exists within the processing of seg6 attributes. The issue results from the improper validation of user-supplied data, which can result in a read past the end of an allocated buffer. This flaw allows a privileged local user to disclose sensitive information on affected installations of the Linux kernel.
Published Jul 24, 2023 · Updated Mar 5, 2025
High · CVSS 8.1
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_LOGOFF and SMB2_CLOSE commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the kernel.
Published Jul 24, 2023 · Updated Mar 5, 2025
High · CVSS 7.5
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.
Published Jul 25, 2023 · Updated Mar 5, 2025
Medium · CVSS 6.5
A vulnerability, which was classified as critical, has been found in SourceCodester/projectworlds House Rental and Property Listing 1.0. This issue affects some unknown processing of the file /index.php. The manipulation of the argument keywords/location leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Published Jul 16, 2023 · Updated Mar 4, 2025
High · CVSS 7.8
Microsoft Office Graphics Remote Code Execution Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
High · CVSS 7
Microsoft ActiveX Remote Code Execution Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
Medium · CVSS 6.6
Microsoft Failover Cluster Remote Code Execution Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
High · CVSS 8.8
Microsoft ODBC Driver Remote Code Execution Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
High · CVSS 7.5
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
High · CVSS 7.5
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
High · CVSS 8.8
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
High · CVSS 7.8
Microsoft Excel Remote Code Execution Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
High · CVSS 8.8
Microsoft SharePoint Server Spoofing Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
High · CVSS 8.8
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
High · CVSS 7.8
Microsoft Excel Remote Code Execution Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
Critical · CVSS 9.8
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
High · CVSS 8.8
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
High · CVSS 7.5
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
High · CVSS 7.8
Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
Critical · CVSS 9.6
Microsoft Office Security Feature Bypass Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
High · CVSS 8.8
Microsoft SharePoint Remote Code Execution Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
High · CVSS 7.8
Microsoft Office Elevation of Privilege Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
High · CVSS 7.8
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Published Jul 14, 2023 · Updated Feb 28, 2025
Medium · CVSS 6.8
Microsoft Outlook Remote Code Execution Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
Medium · CVSS 4.3
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
Medium · CVSS 5.5
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
Medium · CVSS 5.5
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
Medium · CVSS 5.5
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
Medium · CVSS 6.2
Microsoft DirectMusic Information Disclosure Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
High · CVSS 7.1
Microsoft Install Service Elevation of Privilege Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
Medium · CVSS 6.3
Microsoft Defender Elevation of Privilege Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
Medium · CVSS 5.5
Microsoft Excel Information Disclosure Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
High · CVSS 8.2
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
Medium · CVSS 5.4
Microsoft Power Apps (online) Spoofing Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
Medium · CVSS 6.5
Microsoft Failover Cluster Information Disclosure Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
Medium · CVSS 5.5
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
Medium · CVSS 6.5
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
Medium · CVSS 5.5
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
High · CVSS 8.2
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
Medium · CVSS 6.5
Microsoft Outlook Spoofing Vulnerability
Published Jul 11, 2023 · Updated Feb 28, 2025
Medium · CVSS 4.3
Microsoft Edge for iOS Spoofing Vulnerability
Published Jul 14, 2023 · Updated Feb 28, 2025
Medium · CVSS 6.3
Microsoft Edge for Android (Chromium-based) Tampering Vulnerability
Published Jul 14, 2023 · Updated Feb 28, 2025
Medium · CVSS 4.3
Microsoft Edge for Android Spoofing Vulnerability
Published Jul 21, 2023 · Updated Feb 28, 2025
Medium · CVSS 4.7
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Published Jul 21, 2023 · Updated Feb 28, 2025
Medium · CVSS 6.5
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Published Jul 21, 2023 · Updated Feb 28, 2025