CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2023-52105

    Last Modified: 21 Nov 2024

    The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2023-52104

    Last Modified: 2 Jun 2025

    Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 16 Jan 2024
    9.8
    Critical

    CVE-2023-52103

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds read.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2023-52102

    Last Modified: 11 Jun 2025

    Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 16 Jan 2024
    9.1
    Critical

    CVE-2023-52101

    Last Modified: 20 Jun 2025

    Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service availability and integrity.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2023-52100

    Last Modified: 2 Jun 2025

    The Celia Keyboard module has a vulnerability in access control. Successful exploitation of this vulnerability may affect availability.

    Published: 16 Jan 2024
    4
    Medium

    CVE-2024-0581

    Last Modified: 2 Jun 2025

    An Uncontrolled Resource Consumption vulnerability has been found on Sandsprite Scdbg.exe, affecting version 1.0. This vulnerability allows an attacker to send a specially crafted shellcode payload to the '/foff' parameter and cause an application shutdown. A malware program could use this shellcode sequence to shut down the application and evade the scan.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2023-52099

    Last Modified: 17 Jun 2025

    Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 16 Jan 2024
    9.9
    Critical

    CVE-2023-34063

    Last Modified: 20 Jun 2025

    Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability leading to unauthorized access to remote organizations and workflows.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2023-52098

    Last Modified: 11 Jun 2025

    Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2023-52108

    Last Modified: 2 Jun 2025

    Vulnerability of process priorities being raised in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.

    Published: 16 Jan 2024
    5.3
    Medium

    CVE-2024-0569

    Last Modified: 2 Jun 2025

    A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This affects the function getSysStatusCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument ssid/key leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.5cu.862_B20230228 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-250785 was assigned to this vulnerability.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2023-52107

    Last Modified: 21 Nov 2024

    Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2023-52116

    Last Modified: 2 Jun 2025

    Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2023-52115

    Last Modified: 13 Jun 2025

    The iaware module has a Use-After-Free (UAF) vulnerability. Successful exploitation of this vulnerability may affect the system functions.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2023-52114

    Last Modified: 21 Nov 2024

    Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2023-44112

    Last Modified: 21 Nov 2024

    Out-of-bounds access vulnerability in the device authentication module. Successful exploitation of this vulnerability may affect confidentiality.

    Published: 16 Jan 2024
    6.3
    Medium

    CVE-2011-10005

    Last Modified: 2 Jun 2025

    A vulnerability, which was classified as critical, was found in EasyFTP 1.7.0.2. Affected is an unknown function of the component MKD Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250716.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2023-52113

    Last Modified: 20 Jun 2025

    launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.

    Published: 16 Jan 2024
    5.3
    Medium

    CVE-2023-52112

    Last Modified: 20 Jun 2025

    Unauthorized file access vulnerability in the wallpaper service module. Successful exploitation of this vulnerability may cause features to perform abnormally.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2023-52111

    Last Modified: 11 Jun 2025

    Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2023-52110

    Last Modified: 20 Jun 2025

    The sensor module has an out-of-bounds access vulnerability.Successful exploitation of this vulnerability may affect availability.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2023-52109

    Last Modified: 2 Jun 2025

    Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2023-44117

    Last Modified: 17 Jun 2025

    Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2023-4566

    Last Modified: 20 Jun 2025

    Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 16 Jan 2024
    7.1
    High

    CVE-2024-0556

    Last Modified: 21 Nov 2024

    A Weak Cryptography for Passwords vulnerability has been detected on WIC200 affecting version 1.1. This vulnerability allows a remote user to intercept the traffic and retrieve the credentials from another user and decode it in base64 allowing the attacker to see the credentials in plain text.

    Published: 16 Jan 2024
    4.6
    Medium

    CVE-2024-0555

    Last Modified: 17 Jun 2025

    A Cross-Site Request Forgery (CSRF) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated user could lead another user into executing unwanted actions inside the application they are logged in. This vulnerability is possible due to the lack of propper CSRF token implementation.

    Published: 16 Jan 2024
    5.5
    Medium

    CVE-2024-0554

    Last Modified: 2 Jun 2025

    A Cross-site scripting (XSS) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated user could store a malicious javascript payload in the device model parameter via '/setup/diags_ir_learn.asp', allowing the attacker to retrieve the session details of another user.

    Published: 16 Jan 2024
    8.8
    High

    CVE-2024-21673

    Last Modified: 3 Jun 2025

    This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.0 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H allows an authenticated attacker to expose assets in your environment susceptible to exploitation which has high impact to confidentiality, high impact to integrity, high impact to availability, and does not require user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Confluence Data Center and Server 7.19: Upgrade to a release 7.19.18, or any higher 7.19.x release * Confluence Data Center and Server 8.5: Upgrade to a release 8.5.5 or any higher 8.5.x release * Confluence Data Center and Server 8.7: Upgrade to a release 8.7.2 or any higher release See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives ).

    Published: 16 Jan 2024
    8.8
    High

    CVE-2024-21672

    Last Modified: 2 Jun 2025

    This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.3 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H allows an unauthenticated attacker to remotely expose assets in your environment susceptible to exploitation which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Confluence Data Center and Server 7.19: Upgrade to a release 7.19.18, or any higher 7.19.x release * Confluence Data Center and Server 8.5: Upgrade to a release 8.5.5 or any higher 8.5.x release * Confluence Data Center and Server 8.7: Upgrade to a release 8.7.2 or any higher release See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives).

    Published: 16 Jan 2024
    9.8
    Critical

    CVE-2023-22527

    Last Modified: 24 Oct 2025

    A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2024-21674

    Last Modified: 21 Nov 2024

    This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.6 and a CVSS Vector of CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N allows an unauthenticated attacker to expose assets in your environment susceptible to exploitation which has high impact to confidentiality, no impact to integrity, no impact to availability, and does not require user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Confluence Data Center and Server 7.19: Upgrade to a release 7.19.18, or any higher 7.19.x release * Confluence Data Center and Server 8.5: Upgrade to a release 8.5.5 or any higher 8.5.x release * Confluence Data Center and Server 8.7: Upgrade to a release 8.7.2 or any higher release See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives ).

    Published: 16 Jan 2024
    8.8
    High

    CVE-2023-22526

    Last Modified: 20 Jun 2025

    This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 7.19: Upgrade to a release 7.19.17, or any higher 7.19.x release Confluence Data Center and Server 8.5: Upgrade to a release 8.5.5 or any higher 8.5.x release Confluence Data Center and Server 8.7: Upgrade to a release 8.7.2 or any higher release See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was discovered by m1sn0w and reported via our Bug Bounty program

    Published: 16 Jan 2024
    7
    High

    CVE-2024-22428

    Last Modified: 21 Nov 2024

    Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user to escalate privileges and execute arbitrary code on the affected system. Dell recommends customers upgrade at the earliest opportunity.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2024-22362

    Last Modified: 20 Jun 2025

    Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a denial-of-service (DoS) condition.

    Published: 16 Jan 2024
    6.6
    Medium

    CVE-2023-6457

    Last Modified: 21 Nov 2024

    Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Windows (Hitachi Tuning Manager server component) allows local users to read and write specific files.This issue affects Hitachi Tuning Manager: before 8.8.5-04.

    Published: 16 Jan 2024
    5.3
    Medium

    CVE-2023-49107

    Last Modified: 2 Jun 2025

    Generation of Error Message Containing Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent modules).This issue affects Hitachi Device Manager: before 8.8.5-04.

    Published: 16 Jan 2024
    4.6
    Medium

    CVE-2023-49106

    Last Modified: 21 Nov 2024

    Missing Password Field Masking vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent component).This issue affects Hitachi Device Manager: before 8.8.5-04.

    Published: 16 Jan 2024
    7.8
    High

    CVE-2024-21886

    Last Modified: 15 Apr 2026

    A heap buffer overflow flaw was found in the DisableDevice function in the X.Org server. This issue may lead to an application crash or, in some circumstances, remote code execution in SSH X11 forwarding environments.

    Published: 16 Jan 2024
    7.8
    High

    CVE-2024-21885

    Last Modified: 15 Apr 2026

    A flaw was found in X.Org server. In the XISendDeviceHierarchyEvent function, it is possible to exceed the allocated array length when certain new device IDs are added to the xXIHierarchyInfo struct. This can trigger a heap buffer overflow condition, which may lead to an application crash or remote code execution in SSH X11 forwarding environments.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2024-0553

    Last Modified: 24 Mar 2026

    A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981.

    Published: 16 Jan 2024
    9.8
    Critical

    CVE-2023-6816

    Last Modified: 19 Mar 2026

    A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow if a bigger value was used.

    Published: 16 Jan 2024
    7.2
    High

    CVE-2024-22627

    Last Modified: 20 Jun 2025

    Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_distributor.php?id=.

    Published: 16 Jan 2024
    4.9
    Medium

    CVE-2024-20974

    Last Modified: 4 Nov 2025

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

    Published: 16 Jan 2024
    5.5
    Medium

    CVE-2024-20969

    Last Modified: 3 Jun 2025

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).

    Published: 16 Jan 2024
    4.9
    Medium

    CVE-2024-20970

    Last Modified: 4 Nov 2025

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

    Published: 16 Jan 2024
    6.5
    Medium

    CVE-2024-20960

    Last Modified: 4 Nov 2025

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: RAPID). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

    Published: 16 Jan 2024
    6.6
    Medium

    CVE-2024-0607

    Last Modified: 20 Nov 2025

    A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a loop and writes to the `dst` array. On each iteration, 8 bytes are written, but `dst` is an array of u32, so each element only has space for 4 bytes. That means every iteration overwrites part of the previous element corrupting this array of u32. This flaw allows a local user to cause a denial of service or potentially break NetFilter functionality.

    Published: 16 Jan 2024
    7.5
    High

    CVE-2024-0567

    Last Modified: 20 Nov 2025

    A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.

    Published: 16 Jan 2024
    5.8
    Medium

    CVE-2023-45236

    Last Modified: 4 Nov 2025

    EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.

    Published: 16 Jan 2024