CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2024-0706

    Last Modified: 22 Jan 2024

    ***REJECT*** This was a false positive report.

    Published: 18 Jan 2024
    —
    Unknown

    CVE-2024-0704

    Last Modified: 1 Feb 2024

    very low impact - impractical to correct

    Published: 18 Jan 2024
    5.3
    Medium

    CVE-2023-28901

    Last Modified: 17 Jun 2025

    The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing remote attackers to obtain recent trip data, vehicle mileage, fuel consumption, average and maximum speed, and other information of Skoda Connect service users by specifying an arbitrary vehicle VIN number.

    Published: 18 Jan 2024
    5.3
    Medium

    CVE-2023-28900

    Last Modified: 17 Jun 2025

    The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing to obtain nicknames and other user identifiers of Skoda Connect service users by specifying an arbitrary vehicle VIN number.

    Published: 18 Jan 2024
    —
    Unknown

    CVE-2024-23595

    Last Modified: 7 Jun 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 18 Jan 2024
    7.5
    High

    CVE-2023-40052

    Last Modified: 21 Nov 2024

    This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0 .  An attacker who can produce a malformed web request may cause the crash of a PASOE agent potentially disrupting the thread activities of many web application clients. Multiple of these DoS attacks could lead to the flooding of invalid requests as compared to the server’s remaining ability to process valid requests.

    Published: 18 Jan 2024
    9.1
    Critical

    CVE-2023-40051

    Last Modified: 2 Jun 2025

    This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0. An attacker can formulate a request for a WEB transport that allows unintended file uploads to a server directory path on the system running PASOE. If the upload contains a payload that can further exploit the server or its network, the launch of a larger scale attack may be possible.

    Published: 18 Jan 2024
    6.1
    Medium

    CVE-2023-7153

    Last Modified: 20 May 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Macroturk Software and Internet Technologies Macro-Bel allows Reflected XSS. This issue affects Macro-Bel: before V.1.0.1.

    Published: 18 Jan 2024
    9.1
    Critical

    CVE-2024-22317

    Last Modified: 2 Jun 2025

    IBM App Connect Enterprise 11.0.0.1 through 11.0.0.24 and 12.0.1.0 through 12.0.11.0 could allow a remote attacker to obtain sensitive information or cause a denial of service due to improper restriction of excessive authentication attempts. IBM X-Force ID: 279143.

    Published: 18 Jan 2024
    —
    Unknown

    CVE-2024-0694

    Last Modified: 18 Jan 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-6620. Reason: This candidate is a reservation duplicate of CVE-2023-6620. Notes: All CVE users should reference CVE-2023-6620 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 18 Jan 2024
    9.8
    Critical

    CVE-2023-5806

    Last Modified: 20 May 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mergen Software Quality Management System allows SQL Injection. This issue affects Quality Management System: before v1.2.

    Published: 18 Jan 2024
    —
    Unknown

    CVE-2024-0686

    Last Modified: 4 Mar 2024

    Incorrect assignment

    Published: 18 Jan 2024
    5.4
    Medium

    CVE-2023-51463

    Last Modified: 19 Sept 2025

    Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

    Published: 18 Jan 2024
    5.4
    Medium

    CVE-2023-51464

    Last Modified: 19 Sept 2025

    Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 18 Jan 2024
    6.3
    Medium

    CVE-2024-0669

    Last Modified: 17 Jun 2025

    A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element.

    Published: 18 Jan 2024
    6.4
    Medium

    CVE-2023-6958

    Last Modified: 8 Apr 2026

    The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 18 Jan 2024
    6.4
    Medium

    CVE-2024-0381

    Last Modified: 8 Apr 2026

    The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of the 'tag' attribute in the wprm-recipe-name, wprm-recipe-date, and wprm-recipe-counter shortcodes in all versions up to, and including, 9.1.0. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 18 Jan 2024
    6.1
    Medium

    CVE-2023-6970

    Last Modified: 8 Apr 2026

    The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 18 Jan 2024
    6.5
    Medium

    CVE-2024-0580

    Last Modified: 2 Jun 2025

    Omission of user-controlled key authorization in the IDMSistemas platform, affecting the QSige product. This vulnerability allows an attacker to extract sensitive information from the API by making a request to the parameter '/qsige.locator/quotePrevious/centers/X', where X supports values 1,2,3, etc.

    Published: 18 Jan 2024
    4.4
    Medium

    CVE-2023-48359

    Last Modified: 20 Jun 2025

    In autotest driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with System execution privileges needed

    Published: 18 Jan 2024
    4.4
    Medium

    CVE-2023-48358

    Last Modified: 20 Jun 2025

    In drm driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

    Published: 18 Jan 2024
    4.4
    Medium

    CVE-2023-48357

    Last Modified: 20 Jun 2025

    In vsp driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

    Published: 18 Jan 2024
    4.4
    Medium

    CVE-2023-48356

    Last Modified: 20 Jun 2025

    In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

    Published: 18 Jan 2024
    4.4
    Medium

    CVE-2023-48355

    Last Modified: 20 Jun 2025

    In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

    Published: 18 Jan 2024
    5.5
    Medium

    CVE-2023-48354

    Last Modified: 20 Jun 2025

    In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution privileges needed

    Published: 18 Jan 2024
    4.4
    Medium

    CVE-2023-48353

    Last Modified: 20 Jun 2025

    In vsp driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution privileges needed

    Published: 18 Jan 2024
    5.5
    Medium

    CVE-2023-48352

    Last Modified: 20 Jun 2025

    In phasecheckserver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

    Published: 18 Jan 2024
    5.5
    Medium

    CVE-2023-48351

    Last Modified: 20 Jun 2025

    In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

    Published: 18 Jan 2024
    5.5
    Medium

    CVE-2023-48350

    Last Modified: 20 Jun 2025

    In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

    Published: 18 Jan 2024
    5.5
    Medium

    CVE-2023-48349

    Last Modified: 20 Jun 2025

    In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

    Published: 18 Jan 2024
    5.5
    Medium

    CVE-2023-48348

    Last Modified: 20 Jun 2025

    In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

    Published: 18 Jan 2024
    5.5
    Medium

    CVE-2023-48347

    Last Modified: 20 Jun 2025

    In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

    Published: 18 Jan 2024
    5.5
    Medium

    CVE-2023-48346

    Last Modified: 20 Jun 2025

    In video decoder, there is a possible improper input validation. This could lead to local denial of service with no additional execution privileges needed

    Published: 18 Jan 2024
    5.5
    Medium

    CVE-2023-48345

    Last Modified: 2 Jun 2025

    In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

    Published: 18 Jan 2024
    5.5
    Medium

    CVE-2023-48344

    Last Modified: 20 Jun 2025

    In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

    Published: 18 Jan 2024
    5.5
    Medium

    CVE-2023-48343

    Last Modified: 20 Jun 2025

    In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

    Published: 18 Jan 2024
    4.4
    Medium

    CVE-2023-48342

    Last Modified: 20 Jun 2025

    In media service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

    Published: 18 Jan 2024
    5.5
    Medium

    CVE-2023-48341

    Last Modified: 20 Jun 2025

    In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

    Published: 18 Jan 2024
    5.5
    Medium

    CVE-2023-48340

    Last Modified: 20 Jun 2025

    In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

    Published: 18 Jan 2024
    4.4
    Medium

    CVE-2023-48339

    Last Modified: 20 Jun 2025

    In jpg driver, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed

    Published: 18 Jan 2024
    5
    Medium

    CVE-2023-6184

    Last Modified: 2 Jun 2025

    Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting

    Published: 18 Jan 2024
    5.3
    Medium

    CVE-2021-4433

    Last Modified: 21 Nov 2024

    A vulnerability was found in Karjasoft Sami HTTP Server 2.0. It has been classified as problematic. Affected is an unknown function of the component HTTP HEAD Rrequest Handler. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250836.

    Published: 18 Jan 2024
    5.5
    Medium

    CVE-2024-22365

    Last Modified: 12 May 2026

    linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY.

    Published: 18 Jan 2024
    8.8
    High

    CVE-2023-51217

    Last Modified: 2 Jun 2025

    An issue discovered in TenghuTOS TWS-200 firmware version:V4.0-201809201424 allows a remote attacker to execute arbitrary code via crafted command on the ping page component.

    Published: 18 Jan 2024
    5.5
    Medium

    CVE-2023-51258

    Last Modified: 21 Nov 2024

    A memory leak issue discovered in YASM v.1.3.0 allows a local attacker to cause a denial of service via the new_Token function in the modules/preprocs/nasm/nasm-pp:1512.

    Published: 18 Jan 2024
    5.5
    Medium

    CVE-2024-0684

    Last Modified: 4 Nov 2025

    A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function, potentially leading to an application crash and denial of service.

    Published: 18 Jan 2024
    8.8
    High

    CVE-2024-22819

    Last Modified: 2 Jun 2025

    FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_templets_update.

    Published: 18 Jan 2024
    8.8
    High

    CVE-2024-22818

    Last Modified: 9 Jun 2025

    FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerbility via /system/site/filterKeyword_save

    Published: 18 Jan 2024
    8.8
    High

    CVE-2024-22817

    Last Modified: 5 Jun 2025

    FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_conf_updagte

    Published: 18 Jan 2024
    8.8
    High

    CVE-2024-22699

    Last Modified: 5 Jun 2025

    FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/update_group_save.

    Published: 18 Jan 2024