CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2024-0482

    Last Modified: 3 Jun 2025

    A vulnerability classified as critical has been found in Taokeyun up to 1.0.5. This affects the function index of the file application/index/controller/app/Video.php of the component HTTP POST Request Handler. The manipulation of the argument cid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250587.

    Published: 13 Jan 2024
    6.3
    Medium

    CVE-2024-0481

    Last Modified: 21 Nov 2024

    A vulnerability was found in Taokeyun up to 1.0.5. It has been rated as critical. Affected by this issue is the function shopGoods of the file application/index/controller/app/store/Goods.php of the component HTTP POST Request Handler. The manipulation of the argument keyword leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-250586 is the identifier assigned to this vulnerability.

    Published: 13 Jan 2024
    7.3
    High

    CVE-2024-0479

    Last Modified: 17 Jun 2025

    A vulnerability was found in Taokeyun up to 1.0.5. It has been classified as critical. Affected is the function login of the file application/index/controller/m/User.php of the component HTTP POST Request Handler. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250584.

    Published: 13 Jan 2024
    6.3
    Medium

    CVE-2024-0478

    Last Modified: 16 Jun 2025

    A vulnerability was found in code-projects Fighting Cock Information System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/pages/edit_chicken.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250583.

    Published: 13 Jan 2024
    6.3
    Medium

    CVE-2024-0477

    Last Modified: 14 May 2025

    A vulnerability has been found in code-projects Fighting Cock Information System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/action/update-deworm.php. The manipulation of the argument usage_deworm leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-250582 is the identifier assigned to this vulnerability.

    Published: 13 Jan 2024
    2.4
    Low

    CVE-2024-0476

    Last Modified: 3 Jun 2025

    A vulnerability, which was classified as problematic, was found in Blood Bank & Donor Management 1.0. This affects an unknown part of the file request-received-bydonar.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250581 was assigned to this vulnerability.

    Published: 13 Jan 2024
    7.5
    High

    CVE-2023-51065

    Last Modified: 16 Jun 2025

    Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to obtain system backups and other sensitive information from the QStar Server.

    Published: 13 Jan 2024
    6.1
    Medium

    CVE-2023-51067

    Last Modified: 16 Jun 2025

    An unauthenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link.

    Published: 13 Jan 2024
    6.5
    Medium

    CVE-2023-51071

    Last Modified: 3 Jun 2025

    An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily disable the SMB service on a victim's Qstar instance by executing a specific command in a link.

    Published: 13 Jan 2024
    7.5
    High

    CVE-2023-46942

    Last Modified: 3 Jun 2025

    Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.

    Published: 13 Jan 2024
    9.1
    Critical

    CVE-2023-46943

    Last Modified: 21 Nov 2024

    An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generating tokens is hardcoded as "secret". A weak HMAC secret poses a risk because attackers can use the predictable secret to create valid JSON Web Tokens (JWTs), allowing them access to important information and actions within the application.

    Published: 13 Jan 2024
    5.4
    Medium

    CVE-2023-50072

    Last Modified: 3 Jun 2025

    A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated user to upload a note on a file which acts as a stored XSS payload. Any user who opens the note of a document file will trigger the XSS.

    Published: 13 Jan 2024
    5.3
    Medium

    CVE-2023-51062

    Last Modified: 16 Jun 2025

    An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0 allows attackers to disclose the SMB Log contents via executing a crafted command.

    Published: 13 Jan 2024
    8.8
    High

    CVE-2023-51063

    Last Modified: 3 Jun 2025

    QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based Reflected Cross Site Scripting (XSS) vulnerability within the component qnme-ajax?method=tree_level.

    Published: 13 Jan 2024
    6.1
    Medium

    CVE-2023-51064

    Last Modified: 20 Jun 2025

    QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based reflected XSS vulnerability within the component qnme-ajax?method=tree_table.

    Published: 13 Jan 2024
    8.8
    High

    CVE-2023-51066

    Last Modified: 6 Jun 2025

    An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily execute commands.

    Published: 13 Jan 2024
    5.4
    Medium

    CVE-2023-51068

    Last Modified: 3 Jun 2025

    An authenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link.

    Published: 13 Jan 2024
    7.5
    High

    CVE-2023-51070

    Last Modified: 21 Nov 2024

    An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensitive SMB settings on the QStar Server.

    Published: 13 Jan 2024
    7.5
    High

    CVE-2023-51804

    Last Modified: 3 Jun 2025

    An issue in rymcu forest v.0.02 allows a remote attacker to obtain sensitive information via manipulation of the HTTP body URL in the com.rymcu.forest.web.api.common.UploadController file.

    Published: 13 Jan 2024
    6.5
    Medium

    CVE-2023-51805

    Last Modified: 20 Jun 2025

    SQL Injection vulnerability in TDuckCLoud tduck-platform v.4.0 allows a remote attacker to obtain sensitive information via the getFormKey parameter in the search function of FormDataMysqlService.java file.

    Published: 13 Jan 2024
    7.5
    High

    CVE-2023-52289

    Last Modified: 17 Jun 2025

    An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a POST request to a /update-resource-data/<file_path> URI (from views.py), allows attackers to write to arbitrary files.

    Published: 13 Jan 2024
    7.5
    High

    CVE-2023-52288

    Last Modified: 20 Jun 2025

    An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a GET request to a /resource-data/<file_path>.txt URI (from views.py), allows attackers to read arbitrary files.

    Published: 13 Jan 2024
    8.8
    High

    CVE-2023-33472

    Last Modified: 11 Jun 2025

    An issue was discovered in Scada-LTS v2.7.5.2 build 4551883606 and before, allows remote attackers with low-level authentication to escalate privileges, execute arbitrary code, and obtain sensitive information via Event Handlers function.

    Published: 13 Jan 2024
    6.5
    Medium

    CVE-2024-22137

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MailMunch Constant Contact Forms by MailMunch allows Stored XSS.This issue affects Constant Contact Forms by MailMunch: from n/a through 2.0.11.

    Published: 12 Jan 2024
    7.1
    High

    CVE-2024-22142

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs Profile Builder Pro allows Reflected XSS.This issue affects Profile Builder Pro: from n/a through 3.10.0.

    Published: 12 Jan 2024
    2.4
    Low

    CVE-2024-0230

    Last Modified: 2 Apr 2026

    A session management issue was addressed with improved checks. This issue is fixed in Magic Keyboard Firmware Update 2.0.6. An attacker with physical access to the accessory may be able to extract its Bluetooth pairing key and monitor Bluetooth traffic.

    Published: 12 Jan 2024
    4.3
    Medium

    CVE-2022-4962

    Last Modified: 13 Feb 2025

    A vulnerability was found in Apollo 2.0.0/2.0.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /users of the component Configuration Center. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. VDB-250430 is the identifier assigned to this vulnerability. NOTE: The maintainer explains that user data information like user id, name, and email are not sensitive.

    Published: 12 Jan 2024
    8.8
    High

    CVE-2023-49647

    Last Modified: 3 Jun 2025

    Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.

    Published: 12 Jan 2024
    5.3
    Medium

    CVE-2024-21639

    Last Modified: 21 Nov 2024

    CEF (Chromium Embedded Framework ) is a simple framework for embedding Chromium-based browsers in other applications. `CefLayeredWindowUpdaterOSR::OnAllocatedSharedMemory` does not check the size of the shared memory, which leads to out-of-bounds read outside the sandbox. This vulnerability was patched in commit 1f55d2e.

    Published: 12 Jan 2024
    4.2
    Medium

    CVE-2023-49801

    Last Modified: 21 Nov 2024

    Lif Auth Server is a server for validating logins, managing information, and account recovery for Lif Accounts. The issue relates to the `get_pfp` and `get_banner` routes on Auth Server. The issue is that there is no check to ensure that the file that Auth Server is receiving through these URLs is correct. This could allow an attacker access to files they shouldn't have access to. This issue has been patched in version 1.4.0.

    Published: 12 Jan 2024
    7.4
    High

    CVE-2023-42463

    Last Modified: 21 Nov 2024

    Wazuh is a free and open source platform used for threat prevention, detection, and response. This bug introduced a stack overflow hazard that could allow a local privilege escalation. This vulnerability was patched in version 4.5.3.

    Published: 12 Jan 2024
    3.1
    Low

    CVE-2023-49099

    Last Modified: 17 Jun 2025

    Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with posts can be accessed by guest users even when login is required. This vulnerability has been patched in 3.2.0.beta4 and 3.1.4.

    Published: 12 Jan 2024
    4.3
    Medium

    CVE-2024-21655

    Last Modified: 3 Jun 2025

    Discourse is a platform for community discussion. For fields that are client editable, limits on sizes are not imposed. This allows a malicious actor to cause a Discourse instance to use excessive disk space and also often excessive bandwidth. The issue is patched 3.1.4 and 3.2.0.beta4.

    Published: 12 Jan 2024
    3.5
    Low

    CVE-2023-49098

    Last Modified: 3 Jun 2025

    Discourse-reactions is a plugin that allows user to add their reactions to the post. Data about a user's reaction notifications could be exposed. This vulnerability was patched in commit 2c26939.

    Published: 12 Jan 2024
    8.6
    High

    CVE-2023-48297

    Last Modified: 17 Jun 2025

    Discourse is a platform for community discussion. The message serializer uses the full list of expanded chat mentions (@all and @here) which can lead to a very long array of users. This issue was patched in versions 3.1.4 and beta 3.2.0.beta5.

    Published: 12 Jan 2024
    9.6
    Critical

    CVE-2023-51698

    Last Modified: 17 Jun 2025

    Atril is a simple multi-page document viewer. Atril is vulnerable to a critical Command Injection Vulnerability. This vulnerability gives the attacker immediate access to the target system when the target user opens a crafted document or clicks on a crafted link/URL using a maliciously crafted CBT document which is a TAR archive. A patch is available at commit ce41df6.

    Published: 12 Jan 2024
    9
    Critical

    CVE-2024-22206

    Last Modified: 21 Nov 2024

    Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router. This vulnerability was patched in version 4.29.3.

    Published: 12 Jan 2024
    6.3
    Medium

    CVE-2024-0475

    Last Modified: 17 Jun 2025

    A vulnerability, which was classified as critical, has been found in code-projects Dormitory Management System 1.0. Affected by this issue is some unknown functionality of the file modifyuser.php. The manipulation of the argument user_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250580.

    Published: 12 Jan 2024
    4.3
    Medium

    CVE-2010-10011

    Last Modified: 3 Jun 2025

    A vulnerability, which was classified as problematic, was found in Acritum Femitter Server 1.04. Affected is an unknown function. The manipulation leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-250446 is the identifier assigned to this vulnerability.

    Published: 12 Jan 2024
    4.2
    Medium

    CVE-2023-31031

    Last Modified: 9 Oct 2025

    NVIDIA DGX Station A100 and DGX Station A800 SBIOS contains a vulnerability where a user may cause a heap-based buffer overflow by local access. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and data tampering.

    Published: 12 Jan 2024
    6.5
    Medium

    CVE-2023-31025

    Last Modified: 17 Jun 2025

    NVIDIA DGX A100 BMC contains a vulnerability where an attacker may cause an LDAP user injection. A successful exploit of this vulnerability may lead to information disclosure.

    Published: 12 Jan 2024
    6.6
    Medium

    CVE-2023-31034

    Last Modified: 17 Jun 2025

    NVIDIA DGX A100 SBIOS contains a vulnerability where a local attacker can cause input validation checks to be bypassed by causing an integer overflow. A successful exploit of this vulnerability may lead to denial of service, information disclosure, and data tampering.

    Published: 12 Jan 2024
    6.8
    Medium

    CVE-2023-31033

    Last Modified: 3 Jun 2025

    NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue for a critical function by an adjacent network . A successful exploit of this vulnerability may lead to escalation of privileges, code execution, denial of service, information disclosure, and data tampering.

    Published: 12 Jan 2024
    7.5
    High

    CVE-2023-31035

    Last Modified: 21 Nov 2024

    NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that could be used to execute arbitrary code at the SMM level. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, and information disclosure.

    Published: 12 Jan 2024
    7.5
    High

    CVE-2023-31032

    Last Modified: 3 Jun 2025

    NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a dynamic variable evaluation by local access. A successful exploit of this vulnerability may lead to denial of service.

    Published: 12 Jan 2024
    9
    Critical

    CVE-2023-31024

    Last Modified: 3 Jun 2025

    NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause stack memory corruption by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.

    Published: 12 Jan 2024
    9.3
    Critical

    CVE-2023-31030

    Last Modified: 3 Jun 2025

    NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.

    Published: 12 Jan 2024
    9.3
    Critical

    CVE-2023-31029

    Last Modified: 21 Nov 2024

    NVIDIA DGX A100 baseboard management controller (BMC) contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.

    Published: 12 Jan 2024
    7.3
    High

    CVE-2024-0474

    Last Modified: 17 Jun 2025

    A vulnerability classified as critical was found in code-projects Dormitory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250579.

    Published: 12 Jan 2024
    6.3
    Medium

    CVE-2024-0463

    Last Modified: 23 Oct 2025

    A vulnerability was found in code-projects Online Faculty Clearance 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /production/admin_view_info.php of the component HTTP POST Request Handler. The manipulation of the argument haydi leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250568.

    Published: 12 Jan 2024