CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2023-48714

    Last Modified: 17 Jun 2025

    Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to versions 4.13.39 and 5.1.11, if a user should not be able to see a record, but that record can be added to a `GridField` using the `GridFieldAddExistingAutocompleter` component, the record's title can be accessed by that user. Versions 4.13.39 and 5.1.11 contain a fix for this issue.

    Published: 23 Jan 2024
    5.3
    Medium

    CVE-2023-44401

    Last Modified: 17 Jun 2025

    The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `canView` permission checks are bypassed for ORM data in paginated GraphQL query results where the total number of records is greater than the number of records per page. Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t paginated per se. This has been fixed in versions 4.3.7 and 5.1.3 by ensuring no new records are pulled in from the database after performing `canView` permission checks for each page of results. This may result in some pages in the query results having less than the maximum number of records per page even when there are more pages of results. This behavior is consistent with how pagination works in other areas of Silverstripe CMS, such as in `GridField`, and is a result of having to perform permission checks in PHP rather than in the database directly. One may disable these permission checks by disabling the `CanViewPermission` plugin.

    Published: 23 Jan 2024
    4.4
    Medium

    CVE-2024-0703

    Last Modified: 8 Apr 2026

    The Sticky Buttons – floating buttons builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via sticky URLs in all versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 23 Jan 2024
    —
    Unknown

    CVE-2024-23854

    Last Modified: 23 Jan 2024

    This CVE ID was unused by the CNA.

    Published: 23 Jan 2024
    8.8
    High

    CVE-2024-23348

    Last Modified: 30 May 2025

    Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier allows a remote authenticated attacker to execute arbitrary JavaScript code by uploading a specially crafted SVG file.

    Published: 23 Jan 2024
    5.4
    Medium

    CVE-2024-23183

    Last Modified: 20 Jun 2025

    Cross-site scripting vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier allows a remote authenticated attacker to execute an arbitrary script on the logged-in user's web browser.

    Published: 23 Jan 2024
    8.1
    High

    CVE-2024-23182

    Last Modified: 30 May 2025

    Relative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier allows a remote authenticated attacker to delete arbitrary files on the server.

    Published: 23 Jan 2024
    6.1
    Medium

    CVE-2024-23181

    Last Modified: 20 Jun 2025

    Cross-site scripting vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier allows a remote unauthenticated attacker to execute an arbitrary script on the logged-in user's web browser.

    Published: 23 Jan 2024
    8.8
    High

    CVE-2024-23180

    Last Modified: 4 Jun 2025

    Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier allows a remote authenticated attacker to execute arbitrary code by uploading a specially crafted SVG file.

    Published: 23 Jan 2024
    6.1
    Medium

    CVE-2024-0587

    Last Modified: 8 Apr 2026

    The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'disqus_name' parameter in all versions up to, and including, 1.0.92.1 due to insufficient input sanitization and output escaping on the executed JS file. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 23 Jan 2024
    7.4
    High

    CVE-2024-23842

    Last Modified: 31 Dec 2025

    Improper Input Validation in Hitron Systems DVR LGUVR-16H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

    Published: 23 Jan 2024
    7.4
    High

    CVE-2024-22772

    Last Modified: 31 Dec 2025

    Improper Input Validation in Hitron Systems DVR LGUVR-8H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

    Published: 23 Jan 2024
    7.4
    High

    CVE-2024-22771

    Last Modified: 31 Dec 2025

    Improper Input Validation in Hitron Systems DVR LGUVR-4H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

    Published: 23 Jan 2024
    7.4
    High

    CVE-2024-22770

    Last Modified: 31 Dec 2025

    Improper Input Validation in Hitron Systems DVR HVR-16781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

    Published: 23 Jan 2024
    7.4
    High

    CVE-2024-22769

    Last Modified: 31 Dec 2025

    Improper Input Validation in Hitron Systems DVR HVR-8781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

    Published: 23 Jan 2024
    7.4
    High

    CVE-2024-22768

    Last Modified: 31 Dec 2025

    Improper Input Validation in Hitron Systems DVR HVR-4781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

    Published: 23 Jan 2024
    5.9
    Medium

    CVE-2024-23218

    Last Modified: 2 Apr 2026

    A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, tvOS 17.3, watchOS 10.3. An attacker may be able to decrypt legacy RSA PKCS#1 v1.5 ciphertexts without having the private key.

    Published: 23 Jan 2024
    6.3
    Medium

    CVE-2023-42887

    Last Modified: 4 Nov 2025

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.6.4, macOS Sonoma 14.2. An app may be able to read arbitrary files.

    Published: 23 Jan 2024
    5.5
    Medium

    CVE-2023-42937

    Last Modified: 4 Nov 2025

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS Ventura 13.6.4, macOS Sonoma 14.2, macOS Monterey 12.7.3, iOS 17.2 and iPadOS 17.2. An app may be able to access sensitive user data.

    Published: 23 Jan 2024
    8.8
    High

    CVE-2024-23214

    Last Modified: 2 Apr 2026

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 23 Jan 2024
    5.5
    Medium

    CVE-2024-23215

    Last Modified: 2 Apr 2026

    An issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. An app may be able to access user-sensitive data.

    Published: 23 Jan 2024
    7.5
    High

    CVE-2024-23203

    Last Modified: 2 Apr 2026

    The issue was addressed with additional permissions checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, macOS Ventura 13.6.5. A shortcut may be able to use sensitive data with certain actions without prompting the user.

    Published: 23 Jan 2024
    6.2
    Medium

    CVE-2024-23223

    Last Modified: 2 Apr 2026

    A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. An app may be able to access sensitive user data.

    Published: 23 Jan 2024
    6.2
    Medium

    CVE-2024-23219

    Last Modified: 2 Apr 2026

    The issue was addressed with improved authentication. This issue is fixed in iOS 17.3 and iPadOS 17.3. Stolen Device Protection may be unexpectedly disabled.

    Published: 23 Jan 2024
    7.5
    High

    CVE-2024-23204

    Last Modified: 2 Apr 2026

    The issue was addressed with additional permissions checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, watchOS 10.3. A shortcut may be able to use sensitive data with certain actions without prompting the user.

    Published: 23 Jan 2024
    7.8
    High

    CVE-2024-23212

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, watchOS 10.3. An app may be able to execute arbitrary code with kernel privileges.

    Published: 23 Jan 2024
    7.8
    High

    CVE-2024-23208

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. An app may be able to execute arbitrary code with kernel privileges.

    Published: 23 Jan 2024
    7.8
    High

    CVE-2023-42881

    Last Modified: 4 Nov 2025

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2. Processing a file may lead to unexpected app termination or arbitrary code execution.

    Published: 23 Jan 2024
    5.5
    Medium

    CVE-2024-23224

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.3, macOS Ventura 13.6.4. An app may be able to access sensitive user data.

    Published: 23 Jan 2024
    8.8
    High

    CVE-2024-23209

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.3. Processing web content may lead to arbitrary code execution.

    Published: 23 Jan 2024
    8.8
    High

    CVE-2024-23213

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. Processing web content may lead to arbitrary code execution.

    Published: 23 Jan 2024
    3.3
    Low

    CVE-2024-23210

    Last Modified: 2 Apr 2026

    This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. An app may be able to view a user's phone number in system logs.

    Published: 23 Jan 2024
    5.5
    Medium

    CVE-2024-23207

    Last Modified: 2 Apr 2026

    This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, watchOS 10.3. An app may be able to access sensitive user data.

    Published: 23 Jan 2024
    3.3
    Low

    CVE-2024-23211

    Last Modified: 2 Apr 2026

    A privacy issue was addressed with improved handling of user preferences. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, watchOS 10.3. A user's private browsing activity may be visible in Settings.

    Published: 23 Jan 2024
    —
    Unknown

    CVE-2023-42915

    Last Modified: 14 Feb 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 23 Jan 2024
    5.5
    Medium

    CVE-2023-40528

    Last Modified: 4 Nov 2025

    This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 17, watchOS 10, macOS Sonoma 14, iOS 17 and iPadOS 17, macOS Ventura 13.6.4. An app may be able to bypass Privacy preferences.

    Published: 23 Jan 2024
    5.5
    Medium

    CVE-2023-42935

    Last Modified: 4 Nov 2025

    An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be able to view the previous logged in user’s desktop from the fast user switching screen.

    Published: 23 Jan 2024
    5.5
    Medium

    CVE-2023-42888

    Last Modified: 4 Nov 2025

    The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS Ventura 13.6.4, macOS Sonoma 14.2, macOS Monterey 12.7.3, iOS 17.2 and iPadOS 17.2. Processing a maliciously crafted image may result in disclosure of process memory.

    Published: 23 Jan 2024
    3.3
    Low

    CVE-2024-23217

    Last Modified: 2 Apr 2026

    A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, macOS Ventura 13.6.5, watchOS 10.3. An app may be able to bypass certain Privacy preferences.

    Published: 23 Jan 2024
    5.5
    Medium

    CVE-2024-23848

    Last Modified: 12 May 2026

    In the Linux kernel through 6.7.1, there is a use-after-free in cec_queue_msg_fh, related to drivers/media/cec/core/cec-adap.c and drivers/media/cec/core/cec-api.c.

    Published: 23 Jan 2024
    8.8
    High

    CVE-2024-23222

    Last Modified: 3 Apr 2026

    A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version.

    Published: 23 Jan 2024
    9.8
    Critical

    CVE-2024-22076

    Last Modified: 16 Jun 2025

    MyQ Print Server before 8.2 patch 43 allows remote authenticated administrators to execute arbitrary code via PHP scripts that are reached through the administrative interface.

    Published: 23 Jan 2024
    5.1
    Medium

    CVE-2023-40551

    Last Modified: 20 Nov 2025

    A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase.

    Published: 23 Jan 2024
    6.2
    Medium

    CVE-2023-40549

    Last Modified: 20 Nov 2025

    An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an attacker to load a crafted PE binary, triggering the issue and crashing Shim, resulting in a denial of service.

    Published: 23 Jan 2024
    6.1
    Medium

    CVE-2023-45889

    Last Modified: 30 May 2025

    A Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.8 allows remote attackers to inject JavaScript into any webpage. NOTE: this issue exists because of an incomplete fix for CVE-2022-48612.

    Published: 23 Jan 2024
    5.4
    Medium

    CVE-2023-42143

    Last Modified: 30 May 2025

    Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5afc928c allows malicious users to create a backdoor by redirecting the device to an attacker-controlled machine which serves the manipulated firmware file. The device is updated with the manipulated firmware.

    Published: 23 Jan 2024
    5.5
    Medium

    CVE-2024-0911

    Last Modified: 4 Nov 2025

    A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a specially crafted file to trigger a heap-based buffer overflow, causing the application to crash.

    Published: 23 Jan 2024
    5.5
    Medium

    CVE-2024-23851

    Last Modified: 4 Nov 2025

    copy_params in drivers/md/dm-ioctl.c in the Linux kernel through 6.7.1 can attempt to allocate more than INT_MAX bytes, and crash, because of a missing param_kernel->data_size check. This is related to ctl_ioctl.

    Published: 23 Jan 2024
    5.5
    Medium

    CVE-2024-23849

    Last Modified: 4 Nov 2025

    In rds_recv_track_latency in net/rds/af_rds.c in the Linux kernel through 6.7.1, there is an off-by-one error for an RDS_MSG_RX_DGRAM_TRACE_MAX comparison, resulting in out-of-bounds access.

    Published: 23 Jan 2024
    7.5
    High

    CVE-2024-0743

    Last Modified: 3 Nov 2025

    An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.9, and Thunderbird < 115.9.

    Published: 23 Jan 2024