Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2023-41993
Known exploited
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
CVSS Score
8.8
EPSS Score
0.09
Published
2023-09-21
CVE-2023-41991
Known exploited
A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
CVSS Score
5.5
EPSS Score
0.067
Published
2023-09-21
CVE-2023-42793
Known exploited
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
CVSS Score
9.8
EPSS Score
0.946
Published
2023-09-19
CVE-2023-41179
Known exploited
A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation. Note that an attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.
CVSS Score
7.2
EPSS Score
0.015
Published
2023-09-19
CVE-2023-38205
Known exploited
Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
CVSS Score
7.5
EPSS Score
0.943
Published
2023-09-14
CVE-2023-26369
Known exploited
Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVSS Score
7.8
EPSS Score
0.004
Published
2023-09-13
CVE-2023-36802
Known exploited
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
CVSS Score
7.8
EPSS Score
0.75
Published
2023-09-12
CVE-2023-36761
Known exploited
Microsoft Word Information Disclosure Vulnerability
CVSS Score
6.5
EPSS Score
0.037
Published
2023-09-12
CVE-2023-4863
Known exploited
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
CVSS Score
8.8
EPSS Score
0.94
Published
2023-09-12
CVE-2023-41990
Known exploited
The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Ventura 13.2, watchOS 9.3. Processing a font file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1.
CVSS Score
7.8
EPSS Score
0.041
Published
2023-09-12


Contact Us

Shodan ® - All rights reserved