SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

9 results for “kev-cve-2023-21237” · 1.68 s · cached

Facets · 1 entity types

9 CVEClear type filter
CVE-2026-26723CVE

CVE-2026-26723

Cross Site Scripting vulnerability in Key Systems Inc Global Facilities Management Software v. 20230721a allows a remote attacker to execute arbitrary code via the function parameter.

CVSS 8.2EPSS 0.5%
Match for kev-cve-2023-21237
CVE-2026-22039CVE

CVE-2026-22039

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization boundary bypass in namespaced Kyverno Policy apiCall…

CVSS 9.9EPSS 0.6%
Match for kev-cve-2023-21237
CVE-2026-39429CVE

CVE-2026-39429

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by the root shard and…

CVSS 8.2EPSS 0.5%kcp
Match for kev-cve-2023-21237
CVE-2026-32193CVE

CVE-2026-32193

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.

CVSS 8.8EPSS 0.4%microsoft
Match for kev-cve-2023-21237
CVE-2026-34612CVE

CVE-2026-34612

Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code Exec…

CVSS 9.9EPSS 0.7%kestra
Match for kev-cve-2023-21237
CVE-2026-38428CVE

CVE-2026-38428

Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitiza…

CVSS 9.8EPSS 0.5%kestra
Match for kev-cve-2023-21237
CVE-2024-56123CVE

CVE-2024-56123

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2023-21237
CVE-2026-26722CVE

CVE-2026-26722

An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to escalate privileges via PIN component of the login functionality.

CVSS 9.4EPSS 0.5%
Match for kev-cve-2023-21237
CVE-2023-26243CVE

CVE-2023-26243

An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decryption binary used to decrypt firmware files has an information leak that allows…

CVSS 7.8EPSS 0.3%hyundai
Match for kev-cve-2023-21237
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.