CVE-2023-6335
Last Modified: 2 Jun 2025Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled Filename.This issue affects Workforce Access: before 8.7.
CVE-2023-6334
Last Modified: 17 Jun 2025Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HYPR Workforce Access on Windows allows Overflow Buffers.This issue affects Workforce Access: before 8.7.
CVE-2023-5097
Last Modified: 17 Jun 2025Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: before 8.7.
CVE-2023-51381
Last Modified: 17 Jan 2024This CVE ID has been rejected or withdrawn by GitHub.
CVE-2023-22514
Last Modified: 12 May 2025This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.8, and a CVSS Vector of: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H which allows an unauthenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Sourcetree for Mac and Sourcetree for Windows customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.15 See the release notes (https://www.sourcetreeapp.com/download-archives). You can download the latest version of Sourcetree for Mac and Sourcetree for Windows from the download center (https://www.sourcetreeapp.com/download-archives). This vulnerability was reported via our Penetration Testing program.
CVE-2023-22512
Last Modified: 12 May 2025This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7.5, this vulnerability allows an unauthenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a vulnerable host (Confluence instance) connected to a network, which has no impact to confidentiality, no impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 7.19: Upgrade to a release greater than or equal to 7.19.14 Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.1 Confluence Data Center and Server 8.6 or above: No need to upgrade, you're already on a patched version See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives ]). This vulnerability was reported via our Bug Bounty program.
CVE-2023-7234
Last Modified: 2 Jun 2025OPCUAServerToolkit will write a log message once an OPC UA client has successfully connected containing the client's self-defined description field.
CVE-2024-0603
Last Modified: 2 Jun 2025A vulnerability classified as critical has been found in ZhiCms up to 4.0. This affects an unknown part of the file app/plug/controller/giftcontroller.php. The manipulation of the argument mylike leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250839.
CVE-2024-23347
Last Modified: 20 Jun 2025Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application.
CVE-2023-37523
Last Modified: 3 Jun 2025Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious script on the user's browser.
CVE-2024-23434
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23435
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23436
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23437
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23438
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23430
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23431
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23432
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23433
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23429
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23422
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23423
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23424
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23425
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23426
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23427
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23428
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23420
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23421
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23413
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23414
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23415
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23416
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23417
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23418
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23419
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23412
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23410
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23411
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23406
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23407
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23408
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23409
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23399
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23400
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23401
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23402
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23403
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23404
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2024-23405
Last Modified: 1 Jan 2025To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
