CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2023-6335

    Last Modified: 2 Jun 2025

    Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled Filename.This issue affects Workforce Access: before 8.7.

    Published: 16 Jan 2024
    5.3
    Medium

    CVE-2023-6334

    Last Modified: 17 Jun 2025

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HYPR Workforce Access on Windows allows Overflow Buffers.This issue affects Workforce Access: before 8.7.

    Published: 16 Jan 2024
    7
    High

    CVE-2023-5097

    Last Modified: 17 Jun 2025

    Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: before 8.7.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2023-51381

    Last Modified: 17 Jan 2024

    This CVE ID has been rejected or withdrawn by GitHub.

    Published: 16 Jan 2024
    7.8
    High

    CVE-2023-22514

    Last Modified: 12 May 2025

    This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.8, and a CVSS Vector of: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H which allows an unauthenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Sourcetree for Mac and Sourcetree for Windows customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.15 See the release notes (https://www.sourcetreeapp.com/download-archives). You can download the latest version of Sourcetree for Mac and Sourcetree for Windows from the download center (https://www.sourcetreeapp.com/download-archives). This vulnerability was reported via our Penetration Testing program.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2023-22512

    Last Modified: 12 May 2025

    This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7.5, this vulnerability allows an unauthenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a vulnerable host (Confluence instance) connected to a network, which has no impact to confidentiality, no impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 7.19: Upgrade to a release greater than or equal to 7.19.14 Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.1 Confluence Data Center and Server 8.6 or above: No need to upgrade, you're already on a patched version See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives ]). This vulnerability was reported via our Bug Bounty program.

    Published: 16 Jan 2024
    5.3
    Medium

    CVE-2023-7234

    Last Modified: 2 Jun 2025

    OPCUAServerToolkit will write a log message once an OPC UA client has successfully connected containing the client's self-defined description field.

    Published: 16 Jan 2024
    7.3
    High

    CVE-2024-0603

    Last Modified: 2 Jun 2025

    A vulnerability classified as critical has been found in ZhiCms up to 4.0. This affects an unknown part of the file app/plug/controller/giftcontroller.php. The manipulation of the argument mylike leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250839.

    Published: 16 Jan 2024
    7.8
    High

    CVE-2024-23347

    Last Modified: 20 Jun 2025

    Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application.

    Published: 16 Jan 2024
    5.6
    Medium

    CVE-2023-37523

    Last Modified: 3 Jun 2025

    Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious script on the user's browser.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23434

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23435

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23436

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23437

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23438

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23430

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23431

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23432

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23433

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23429

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23422

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23423

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23424

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23425

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23426

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23427

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23428

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23420

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23421

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23413

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23414

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23415

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23416

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23417

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23418

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23419

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23412

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23410

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23411

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23406

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23407

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23408

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23409

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23399

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23400

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23401

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23402

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23403

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23404

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024
    —
    Unknown

    CVE-2024-23405

    Last Modified: 1 Jan 2025

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 16 Jan 2024