CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2023-43991

    Last Modified: 30 May 2025

    An issue in PRIMA CLINIC mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 24 Jan 2024
    8.6
    High

    CVE-2023-6267

    Last Modified: 20 Nov 2025

    A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource may consume is being processed (deserialized) prior to the security constraints being evaluated and applied. This does not happen with configuration based security.

    Published: 24 Jan 2024
    9.8
    Critical

    CVE-2024-22751

    Last Modified: 20 Jun 2025

    D-Link DIR-882 DIR882A1_FW130B06 was discovered to contain a stack overflow via the sub_477AA0 function.

    Published: 24 Jan 2024
    5.5
    Medium

    CVE-2022-4964

    Last Modified: 20 Jun 2025

    Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.

    Published: 24 Jan 2024
    9.1
    Critical

    CVE-2021-42143

    Last Modified: 20 Jun 2025

    An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. An infinite loop bug exists during the handling of a ClientHello handshake message. This bug allows remote attackers to cause a denial of service by sending a malformed ClientHello handshake message with an odd length of cipher suites, which triggers an infinite loop (consuming all resources) and a buffer over-read that can disclose sensitive information.

    Published: 24 Jan 2024
    9.8
    Critical

    CVE-2021-42144

    Last Modified: 20 Jun 2025

    Buffer over-read vulnerability in Contiki-NG tinyDTLS through master branch 53a0d97 allows attackers obtain sensitive information via crafted input to dtls_ccm_decrypt_message().

    Published: 24 Jan 2024
    7.5
    High

    CVE-2021-42145

    Last Modified: 20 Jun 2025

    An assertion failure discovered in in check_certificate_request() in Contiki-NG tinyDTLS through master branch 53a0d97 allows attackers to cause a denial of service.

    Published: 24 Jan 2024
    7.5
    High

    CVE-2021-42146

    Last Modified: 20 Jun 2025

    An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers allow remote attackers to reuse the same epoch number within two times the TCP maximum segment lifetime, which is prohibited in RFC6347. This vulnerability allows remote attackers to obtain sensitive application (data of connected clients).

    Published: 24 Jan 2024
    9.1
    Critical

    CVE-2021-42147

    Last Modified: 30 May 2025

    Buffer over-read vulnerability in the dtls_sha256_update function in Contiki-NG tinyDTLS through master branch 53a0d97 allows remote attackers to cause a denial of service via crafted data packet.

    Published: 24 Jan 2024
    4.8
    Medium

    CVE-2021-43584

    Last Modified: 16 Jun 2025

    DOM-based Cross Site Scripting (XSS vulnerability in 'Tail Event Logs' functionality in Nagios Nagios Cross-Platform Agent (NCPA) before 2.4.0 allows attackers to run arbitrary code via the name element when filtering for a log.

    Published: 24 Jan 2024
    9.8
    Critical

    CVE-2023-51887

    Last Modified: 20 Jun 2025

    Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL.

    Published: 24 Jan 2024
    9.8
    Critical

    CVE-2023-51889

    Last Modified: 16 Jun 2025

    Stack Overflow vulnerability in the validate() function in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in the application URL.

    Published: 24 Jan 2024
    8.8
    High

    CVE-2023-43317

    Last Modified: 20 Jun 2025

    An issue in Coign CRM Portal v.06.06 allows a remote attacker to escalate privileges via the userPermissionsList parameter in Session Storage component.

    Published: 24 Jan 2024
    5.4
    Medium

    CVE-2023-43988

    Last Modified: 11 Jun 2025

    An issue in nature fitness saijo mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 24 Jan 2024
    5.4
    Medium

    CVE-2023-43989

    Last Modified: 16 Jun 2025

    An issue in mokumoku chohu mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 24 Jan 2024
    5.4
    Medium

    CVE-2023-43990

    Last Modified: 30 May 2025

    An issue in cherub-hair mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 24 Jan 2024
    5.4
    Medium

    CVE-2023-43992

    Last Modified: 20 Jun 2025

    An issue in STOCKMAN GROUP mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 24 Jan 2024
    5.4
    Medium

    CVE-2023-43993

    Last Modified: 21 Nov 2024

    An issue in smaregi_app_market mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 24 Jan 2024
    5.4
    Medium

    CVE-2023-43994

    Last Modified: 16 Jun 2025

    An issue in Cleaning_makotoya mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 24 Jan 2024
    5.4
    Medium

    CVE-2023-43995

    Last Modified: 20 Jun 2025

    An issue in picot.golf mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 24 Jan 2024
    5.4
    Medium

    CVE-2023-43996

    Last Modified: 20 Jun 2025

    An issue in Q co ltd mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 24 Jan 2024
    5.4
    Medium

    CVE-2023-43997

    Last Modified: 20 Jun 2025

    An issue in Yoruichi hobby base mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 24 Jan 2024
    5.4
    Medium

    CVE-2023-43998

    Last Modified: 21 Nov 2024

    An issue in Books-futaba mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 24 Jan 2024
    5.4
    Medium

    CVE-2023-44000

    Last Modified: 11 Jun 2025

    An issue in Otakara lapis totuka mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 24 Jan 2024
    5.4
    Medium

    CVE-2023-44001

    Last Modified: 30 May 2025

    An issue in Ailand clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 24 Jan 2024
    7.8
    High

    CVE-2023-51711

    Last Modified: 30 May 2025

    An issue was discovered in Regify Regipay Client for Windows version 4.5.1.0 allows DLL hijacking: a user can trigger the execution of arbitrary code every time the product is executed.

    Published: 24 Jan 2024
    9.8
    Critical

    CVE-2023-51885

    Last Modified: 30 May 2025

    Buffer Overflow vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via the length of the LaTeX string component.

    Published: 24 Jan 2024
    7.5
    High

    CVE-2023-51886

    Last Modified: 30 May 2025

    Buffer Overflow vulnerability in the main() function in Mathtex 1.05 and before allows a remote attacker to cause a denial of service when using \convertpath.

    Published: 24 Jan 2024
    7.5
    High

    CVE-2023-51888

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in the nomath() function in Mathtex v.1.05 and before allows a remote attacker to cause a denial of service via a crafted string in the application URL.

    Published: 24 Jan 2024
    7.5
    High

    CVE-2023-51890

    Last Modified: 17 Jun 2025

    An infinite loop issue discovered in Mathtex 1.05 and before allows a remote attackers to consume CPU resources via crafted string in the application URL.

    Published: 24 Jan 2024
    9.8
    Critical

    CVE-2023-52038

    Last Modified: 30 May 2025

    An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.

    Published: 24 Jan 2024
    9.8
    Critical

    CVE-2023-52039

    Last Modified: 30 May 2025

    An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.

    Published: 24 Jan 2024
    9.8
    Critical

    CVE-2023-52040

    Last Modified: 21 Nov 2024

    An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.

    Published: 24 Jan 2024
    5.5
    Medium

    CVE-2023-6110

    Last Modified: 15 Apr 2026

    A flaw was found in OpenStack. When a user tries to delete a non-existing access rule in it's scope, it deletes other existing access rules which are not associated with any application credentials.

    Published: 24 Jan 2024
    9.8
    Critical

    CVE-2024-22651

    Last Modified: 21 Nov 2024

    There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmware v1.04.

    Published: 24 Jan 2024
    4.8
    Medium

    CVE-2024-22720

    Last Modified: 5 Jun 2025

    Kanboard 1.2.34 is vulnerable to Html Injection in the group management feature.

    Published: 24 Jan 2024
    6.1
    Medium

    CVE-2024-22725

    Last Modified: 4 Jun 2025

    Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability was present in the server's error reporting.

    Published: 24 Jan 2024
    6.5
    Medium

    CVE-2024-23638

    Last Modified: 17 Jun 2025

    Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.

    Published: 23 Jan 2024
    4.7
    Medium

    CVE-2024-23633

    Last Modified: 21 Nov 2024

    Label Studio, an open source data labeling tool had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. Prior to version 1.10.1, this feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. Executing arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. `data_import/uploader.py` lines 125C5 through 146 showed that if a URL passed the server side request forgery verification checks, the contents of the file would be downloaded using the filename in the URL. The downloaded file path could then be retrieved by sending a request to `/api/projects/{project_id}/file-uploads?ids=[{download_id}]` where `{project_id}` was the ID of the project and `{download_id}` was the ID of the downloaded file. Once the downloaded file path was retrieved by the previous API endpoint, `data_import/api.py`lines 595C1 through 616C62 demonstrated that the `Content-Type` of the response was determined by the file extension, since `mimetypes.guess_type` guesses the `Content-Type` based on the file extension. Since the `Content-Type` was determined by the file extension of the downloaded file, an attacker could import in a `.html` file that would execute JavaScript when visited. Version 1.10.1 contains a patch for this issue. Other remediation strategies are also available. For all user provided files that are downloaded by Label Studio, set the `Content-Security-Policy: sandbox;` response header when viewed on the site. The `sandbox` directive restricts a page's actions to prevent popups, execution of plugins and scripts and enforces a `same-origin` policy. Alternatively, restrict the allowed file extensions that may be downloaded.

    Published: 23 Jan 2024
    5.5
    Medium

    CVE-2024-23453

    Last Modified: 4 Jun 2025

    Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key when the application binary is reverse-engineered. This API key may be used for unexpected access of the associated service.

    Published: 23 Jan 2024
    7.1
    High

    CVE-2023-47115

    Last Modified: 30 May 2025

    Label Studio is an a popular open source data labeling tool. Versions prior to 1.9.2 have a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. Executing arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. The file `users/functions.py` lines 18-49 show that the only verification check is that the file is an image by extracting the dimensions from the file. Label Studio serves avatar images using Django's built-in `serve` view, which is not secure for production use according to Django's documentation. The issue with the Django `serve` view is that it determines the `Content-Type` of the response by the file extension in the URL path. Therefore, an attacker can upload an image that contains malicious HTML code and name the file with a `.html` extension to be rendered as a HTML page. The only file extension validation is performed on the client-side, which can be easily bypassed. Version 1.9.2 fixes this issue. Other remediation strategies include validating the file extension on the server side, not in client-side code; removing the use of Django's `serve` view and implement a secure controller for viewing uploaded avatar images; saving file content in the database rather than on the filesystem to mitigate against other file related vulnerabilities; and avoiding trusting user controlled inputs.

    Published: 23 Jan 2024
    5.7
    Medium

    CVE-2023-7237

    Last Modified: 17 Jun 2025

    Lantronix XPort sends weakly encoded credentials within web request headers.

    Published: 23 Jan 2024
    7.8
    High

    CVE-2023-52338

    Last Modified: 21 Nov 2024

    A link following vulnerability in the Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 23 Jan 2024
    7.8
    High

    CVE-2023-52337

    Last Modified: 20 Jun 2025

    An improper access control vulnerability in Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 23 Jan 2024
    7.1
    High

    CVE-2023-52331

    Last Modified: 22 Dec 2025

    A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 23 Jan 2024
    6.1
    Medium

    CVE-2023-52330

    Last Modified: 20 Jun 2025

    A cross-site scripting vulnerability in Trend Micro Apex Central could allow a remote attacker to execute arbitrary code on affected installations of Trend Micro Apex Central. Please note: user interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

    Published: 23 Jan 2024
    6.1
    Medium

    CVE-2023-52329

    Last Modified: 22 Dec 2025

    Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to CVE-2023-52326.

    Published: 23 Jan 2024
    6.1
    Medium

    CVE-2023-52328

    Last Modified: 22 Dec 2025

    Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to CVE-2023-52329.

    Published: 23 Jan 2024
    6.1
    Medium

    CVE-2023-52327

    Last Modified: 22 Dec 2025

    Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to CVE-2023-52328.

    Published: 23 Jan 2024
    6.1
    Medium

    CVE-2023-52326

    Last Modified: 22 Dec 2025

    Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to CVE-2023-52327.

    Published: 23 Jan 2024