CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2023-47034

    Last Modified: 21 Nov 2024

    A vulnerability in UniswapFrontRunBot 0xdB94c allows attackers to cause financial losses via unspecified vectors.

    Published: 19 Jan 2024
    7.5
    High

    CVE-2023-47035

    Last Modified: 30 May 2025

    RPTC 0x3b08c was discovered to not conduct status checks on the parameter tradingOpen. This vulnerability can allow attackers to conduct unauthorized transfer operations.

    Published: 19 Jan 2024
    9.8
    Critical

    CVE-2023-50028

    Last Modified: 2 Jun 2025

    In the module "Sliding cart block" (blockslidingcart) up to version 2.3.8 from PrestashopModules.eu for PrestaShop, a guest can perform SQL injection.

    Published: 19 Jan 2024
    9.8
    Critical

    CVE-2023-50030

    Last Modified: 17 Jun 2025

    In the module "Jms Setting" (jmssetting) from Joommasters for PrestaShop, a guest can perform SQL injection in versions <= 1.1.0. The method `JmsSetting::getSecondImgs()` has a sensitive SQL call that can be executed with a trivial http call and exploited to forge a blind SQL injection.

    Published: 19 Jan 2024
    8.1
    High

    CVE-2023-50447

    Last Modified: 21 Nov 2024

    Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).

    Published: 19 Jan 2024
    9.8
    Critical

    CVE-2023-50693

    Last Modified: 30 May 2025

    An issue in Jester v.0.6.0 and before allows a remote attacker to send a malicious crafted request.

    Published: 19 Jan 2024
    6.1
    Medium

    CVE-2023-51946

    Last Modified: 20 Jun 2025

    Multiple reflected cross-site scripting (XSS) vulnerabilities in nasSvr.php in actidata actiNAS-SL-2U-8 3.2.03-SP1 allow remote attackers to inject arbitrary web script or HTML.

    Published: 19 Jan 2024
    9.1
    Critical

    CVE-2023-51947

    Last Modified: 20 Jun 2025

    Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to read and modify different types of data without authentication.

    Published: 19 Jan 2024
    7.5
    High

    CVE-2023-51948

    Last Modified: 20 Jun 2025

    A Site-wide directory listing vulnerability in /fm in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to list the files hosted by the web application.

    Published: 19 Jan 2024
    8.3
    High

    CVE-2024-22424

    Last Modified: 30 May 2025

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.15 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain. If an attacker can place malicious code on, for example, https://test.internal.example.com/, they can still perform a CSRF attack. In this case, the “Lax” SameSite cookie does not prevent the browser from sending the auth cookie, because the destination is a parent domain of the Argo CD API. Browsers generally block such attacks by applying CORS policies to sensitive requests with sensitive content types. Specifically, browsers will send a “preflight request” for POSTs with content type “application/json” asking the destination API “are you allowed to accept requests from my domain?” If the destination API does not answer “yes,” the browser will block the request. Before the patched versions, Argo CD did not validate that requests contained the correct content type header. So an attacker could bypass the browser’s CORS check by setting the content type to something which is considered “not sensitive” such as “text/plain.” The browser wouldn’t send the preflight request, and Argo CD would happily accept the contents (which are actually still JSON) and perform the requested action (such as running malicious code). A patch for this vulnerability has been released in the following Argo CD versions: 2.10-rc2, 2.9.4, 2.8.8, and 2.7.15. The patch contains a breaking API change. The Argo CD API will no longer accept non-GET requests which do not specify application/json as their Content-Type. The accepted content types list is configurable, and it is possible (but discouraged) to disable the content type check completely. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 19 Jan 2024
    7.8
    High

    CVE-2024-22562

    Last Modified: 16 Jun 2025

    swftools 0.9.2 was discovered to contain a Stack Buffer Underflow via the function dict_foreach_keyvalue at swftools/lib/q.c.

    Published: 19 Jan 2024
    7.5
    High

    CVE-2024-22563

    Last Modified: 2 Jun 2025

    openvswitch 2.17.8 was discovered to contain a memory leak via the function xmalloc__ in openvswitch-2.17.8/lib/util.c.

    Published: 19 Jan 2024
    5.4
    Medium

    CVE-2024-22877

    Last Modified: 2 Jun 2025

    StrangeBee TheHive 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case reporting functionality. This feature allows an attacker to insert malicious JavaScript code inside the template or its variables, that will be executed in the context of the TheHive application when the HTML report is opened.

    Published: 19 Jan 2024
    7.8
    High

    CVE-2024-22911

    Last Modified: 5 Jun 2025

    A stack-buffer-underflow vulnerability was found in SWFTools v0.9.2, in the function parseExpression at src/swfc.c:2602.

    Published: 19 Jan 2024
    7.8
    High

    CVE-2024-22912

    Last Modified: 17 Jun 2025

    A global-buffer-overflow was found in SWFTools v0.9.2, in the function countline at swf5compiler.flex:327. It allows an attacker to cause code execution.

    Published: 19 Jan 2024
    7.8
    High

    CVE-2024-22913

    Last Modified: 30 May 2025

    A heap-buffer-overflow was found in SWFTools v0.9.2, in the function swf5lex at lex.swf5.c:1321. It allows an attacker to cause code execution.

    Published: 19 Jan 2024
    5.5
    Medium

    CVE-2024-22914

    Last Modified: 21 Nov 2024

    A heap-use-after-free was found in SWFTools v0.9.2, in the function input at lex.swf5.c:2620. It allows an attacker to cause denial of service.

    Published: 19 Jan 2024
    7.8
    High

    CVE-2024-22919

    Last Modified: 5 Jun 2025

    swftools0.9.2 was discovered to contain a global-buffer-overflow vulnerability via the function parseExpression at swftools/src/swfc.c:2587.

    Published: 19 Jan 2024
    7.8
    High

    CVE-2024-22920

    Last Modified: 21 Nov 2024

    swftools 0.9.2 was discovered to contain a heap-use-after-free via the function bufferWriteData in swftools/lib/action/compile.c.

    Published: 19 Jan 2024
    7.8
    High

    CVE-2024-22955

    Last Modified: 20 Jun 2025

    swftools 0.9.2 was discovered to contain a stack-buffer-underflow vulnerability via the function parseExpression at swftools/src/swfc.c:2576.

    Published: 19 Jan 2024
    7.8
    High

    CVE-2024-22956

    Last Modified: 30 May 2025

    swftools 0.9.2 was discovered to contain a heap-use-after-free vulnerability via the function removeFromTo at swftools/src/swfc.c:838

    Published: 19 Jan 2024
    5.3
    Medium

    CVE-2024-21733

    Last Modified: 3 Nov 2025

    Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL versions may also be affected. Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.

    Published: 19 Jan 2024
    8.8
    High

    CVE-2023-43824

    Last Modified: 21 Nov 2024

    A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wTitleTextLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

    Published: 18 Jan 2024
    8.8
    High

    CVE-2023-43823

    Last Modified: 2 Jun 2025

    A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wTTitleLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

    Published: 18 Jan 2024
    8.8
    High

    CVE-2023-43822

    Last Modified: 16 Jun 2025

    A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesTimeLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

    Published: 18 Jan 2024
    8.8
    High

    CVE-2023-43821

    Last Modified: 21 Nov 2024

    A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesActionLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

    Published: 18 Jan 2024
    8.8
    High

    CVE-2023-43820

    Last Modified: 21 Nov 2024

    A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesPrevValueLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

    Published: 18 Jan 2024
    8.8
    High

    CVE-2023-43819

    Last Modified: 17 Jun 2025

    A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the InitialMacroLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

    Published: 18 Jan 2024
    8.8
    High

    CVE-2023-43818

    Last Modified: 17 Jun 2025

    A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

    Published: 18 Jan 2024
    7.5
    High

    CVE-2023-43817

    Last Modified: 17 Jun 2025

    A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wMailContentLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve code execution.

    Published: 18 Jan 2024
    6.3
    Medium

    CVE-2023-43816

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wKPFStringLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve code execution.

    Published: 18 Jan 2024
    7.1
    High

    CVE-2023-43815

    Last Modified: 2 Jun 2025

    A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wScreenDESCTextLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve code execution.

    Published: 18 Jan 2024
    8.2
    High

    CVE-2023-5131

    Last Modified: 17 Jun 2025

    A heap buffer-overflow exists in Delta Electronics ISPSoft. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DVP file to achieve code execution.

    Published: 18 Jan 2024
    8.2
    High

    CVE-2023-5130

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability exists in Delta Electronics WPLSoft. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DVP file to achieve code execution.

    Published: 18 Jan 2024
    6.5
    Medium

    CVE-2024-22418

    Last Modified: 17 Jun 2025

    Group-Office is an enterprise CRM and groupware tool. Affected versions are subject to a vulnerability which is present in the file upload mechanism of Group Office. It allows an attacker to execute arbitrary JavaScript code by embedding it within a file's name. For instance, using a filename such as “><img src=x onerror=prompt('XSS')>.jpg” triggers the vulnerability. When this file is uploaded, the JavaScript code within the filename is executed. This issue has been addressed in version 6.8.29. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 18 Jan 2024
    7.3
    High

    CVE-2024-22415

    Last Modified: 21 Nov 2024

    jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion + rename) using Language Server Protocol. Installations of jupyter-lsp running in environments without configured file system access control (on the operating system level), and with jupyter-server instances exposed to non-trusted network are vulnerable to unauthorised access and modification of file system beyond the jupyter root directory. This issue has been patched in version 2.2.2 and all users are advised to upgrade. Users unable to upgrade should uninstall jupyter-lsp.

    Published: 18 Jan 2024
    5.4
    Medium

    CVE-2024-22402

    Last Modified: 9 Jun 2025

    Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users were able to load the first page of apps they were actually not allowed to access. Depending on the selection of apps installed this may present a permissions bypass. It is recommended that the Guests app is upgraded to 2.4.1, 2.5.1 or 3.0.1. There are no known workarounds for this vulnerability.

    Published: 18 Jan 2024
    4.1
    Medium

    CVE-2024-22401

    Last Modified: 21 Nov 2024

    Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users could change the allowed list of apps, allowing them to use apps that were not intended to be used. It is recommended that the Guests app is upgraded to 2.4.1, 2.5.1 or 3.0.1. There are no known workarounds for this vulnerability.

    Published: 18 Jan 2024
    4.1
    Medium

    CVE-2024-22404

    Last Modified: 2 Jun 2025

    Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected versions users can download "view-only" files by zipping the complete folder. It is recommended that the Files ZIP app is upgraded to 1.2.1, 1.4.1, or 1.5.0. Users unable to upgrade should disable the file zip app.

    Published: 18 Jan 2024
    3
    Low

    CVE-2024-22403

    Last Modified: 17 Jun 2025

    Nextcloud server is a self hosted personal cloud system. In affected versions OAuth codes did not expire. When an attacker would get access to an authorization code they could authenticate at any time using the code. As of version 28.0.0 OAuth codes are invalidated after 10 minutes and will no longer be authenticated. To exploit this vulnerability an attacker would need to intercept an OAuth code from a user session. It is recommended that the Nextcloud Server is upgraded to 28.0.0. There are no known workarounds for this vulnerability.

    Published: 18 Jan 2024
    3.1
    Low

    CVE-2024-22400

    Last Modified: 17 Jun 2025

    Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a link to the Nextcloud server and end up on a uncontrolled thirdparty server. It is recommended that the User Saml app is upgraded to version 5.1.5, 5.2.5, or 6.0.1. There are no known workarounds for this issue.

    Published: 18 Jan 2024
    0
    Low

    CVE-2024-22213

    Last Modified: 21 Nov 2024

    Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions users could be tricked into executing malicious code that would execute in their browser via HTML sent as a comment. It is recommended that the Nextcloud Deck is upgraded to version 1.9.5 or 1.11.2. There are no known workarounds for this vulnerability.

    Published: 18 Jan 2024
    9.6
    Critical

    CVE-2024-22212

    Last Modified: 21 Nov 2024

    Nextcloud Global Site Selector is a tool which allows you to run multiple small Nextcloud instances and redirect users to the right server. A problem in the password verification method allows an attacker to authenticate as another user. It is recommended that the Nextcloud Global Site Selector is upgraded to version 1.4.1, 2.1.2, 2.3.4 or 2.4.5. There are no known workarounds for this issue.

    Published: 18 Jan 2024
    3.5
    Low

    CVE-2024-0696

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, was found in AtroCore AtroPIM 1.8.4. This affects an unknown part of the file /#ProductSerie/view/ of the component Product Series Overview. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-251481 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 18 Jan 2024
    7.3
    High

    CVE-2024-22419

    Last Modified: 2 Jun 2025

    Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. The `concat` built-in can write over the bounds of the memory buffer that was allocated for it and thus overwrite existing valid data. The root cause is that the `build_IR` for `concat` doesn't properly adhere to the API of copy functions (for `>=0.3.2` the `copy_bytes` function). A contract search was performed and no vulnerable contracts were found in production. The buffer overflow can result in the change of semantics of the contract. The overflow is length-dependent and thus it might go unnoticed during contract testing. However, certainly not all usages of concat will result in overwritten valid data as we require it to be in an internal function and close to the return statement where other memory allocations don't occur. This issue has been addressed in 0.4.0.

    Published: 18 Jan 2024
    4.3
    Medium

    CVE-2024-0695

    Last Modified: 17 Jun 2025

    A vulnerability, which was classified as problematic, has been found in EFS Easy Chat Server 3.1. Affected by this issue is some unknown functionality of the component HTTP GET Request Handler. The manipulation of the argument USERNAME leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-251480. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 18 Jan 2024
    5.3
    Medium

    CVE-2024-0693

    Last Modified: 2 Jun 2025

    A vulnerability classified as problematic was found in EFS Easy File Sharing FTP 2.0. Affected by this vulnerability is an unknown functionality. The manipulation of the argument username leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-251479. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 18 Jan 2024
    —
    Unknown

    CVE-2024-0707

    Last Modified: 13 Feb 2024

    **REJECT** Not a valid vulnerability.

    Published: 18 Jan 2024
    7.5
    High

    CVE-2023-34348

    Last Modified: 21 Nov 2024

    AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to remotely crash the PI Message Subsystem of a PI Server, resulting in a denial-of-service condition.

    Published: 18 Jan 2024
    5.3
    Medium

    CVE-2023-31274

    Last Modified: 21 Nov 2024

    AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to cause the PI Message Subsystem of a PI Server to consume available memory resulting in throttled processing of new PI Data Archive events and a partial denial-of-service condition.

    Published: 18 Jan 2024