CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2023-51064

    Last Modified: 20 Jun 2025

    QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based reflected XSS vulnerability within the component qnme-ajax?method=tree_table.

    Published: 13 Jan 2024
    8.8
    High

    CVE-2023-51066

    Last Modified: 6 Jun 2025

    An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily execute commands.

    Published: 13 Jan 2024
    5.4
    Medium

    CVE-2023-51068

    Last Modified: 3 Jun 2025

    An authenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link.

    Published: 13 Jan 2024
    7.5
    High

    CVE-2023-51070

    Last Modified: 21 Nov 2024

    An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensitive SMB settings on the QStar Server.

    Published: 13 Jan 2024
    7.5
    High

    CVE-2023-51804

    Last Modified: 3 Jun 2025

    An issue in rymcu forest v.0.02 allows a remote attacker to obtain sensitive information via manipulation of the HTTP body URL in the com.rymcu.forest.web.api.common.UploadController file.

    Published: 13 Jan 2024
    6.5
    Medium

    CVE-2023-51805

    Last Modified: 20 Jun 2025

    SQL Injection vulnerability in TDuckCLoud tduck-platform v.4.0 allows a remote attacker to obtain sensitive information via the getFormKey parameter in the search function of FormDataMysqlService.java file.

    Published: 13 Jan 2024
    7.5
    High

    CVE-2023-52289

    Last Modified: 17 Jun 2025

    An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a POST request to a /update-resource-data/<file_path> URI (from views.py), allows attackers to write to arbitrary files.

    Published: 13 Jan 2024
    7.5
    High

    CVE-2023-52288

    Last Modified: 20 Jun 2025

    An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a GET request to a /resource-data/<file_path>.txt URI (from views.py), allows attackers to read arbitrary files.

    Published: 13 Jan 2024
    8.8
    High

    CVE-2023-33472

    Last Modified: 11 Jun 2025

    An issue was discovered in Scada-LTS v2.7.5.2 build 4551883606 and before, allows remote attackers with low-level authentication to escalate privileges, execute arbitrary code, and obtain sensitive information via Event Handlers function.

    Published: 13 Jan 2024
    6.5
    Medium

    CVE-2024-22137

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MailMunch Constant Contact Forms by MailMunch allows Stored XSS.This issue affects Constant Contact Forms by MailMunch: from n/a through 2.0.11.

    Published: 12 Jan 2024
    7.1
    High

    CVE-2024-22142

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs Profile Builder Pro allows Reflected XSS.This issue affects Profile Builder Pro: from n/a through 3.10.0.

    Published: 12 Jan 2024
    2.4
    Low

    CVE-2024-0230

    Last Modified: 2 Apr 2026

    A session management issue was addressed with improved checks. This issue is fixed in Magic Keyboard Firmware Update 2.0.6. An attacker with physical access to the accessory may be able to extract its Bluetooth pairing key and monitor Bluetooth traffic.

    Published: 12 Jan 2024
    4.3
    Medium

    CVE-2022-4962

    Last Modified: 13 Feb 2025

    A vulnerability was found in Apollo 2.0.0/2.0.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /users of the component Configuration Center. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. VDB-250430 is the identifier assigned to this vulnerability. NOTE: The maintainer explains that user data information like user id, name, and email are not sensitive.

    Published: 12 Jan 2024
    8.8
    High

    CVE-2023-49647

    Last Modified: 3 Jun 2025

    Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.

    Published: 12 Jan 2024
    5.3
    Medium

    CVE-2024-21639

    Last Modified: 21 Nov 2024

    CEF (Chromium Embedded Framework ) is a simple framework for embedding Chromium-based browsers in other applications. `CefLayeredWindowUpdaterOSR::OnAllocatedSharedMemory` does not check the size of the shared memory, which leads to out-of-bounds read outside the sandbox. This vulnerability was patched in commit 1f55d2e.

    Published: 12 Jan 2024
    4.2
    Medium

    CVE-2023-49801

    Last Modified: 21 Nov 2024

    Lif Auth Server is a server for validating logins, managing information, and account recovery for Lif Accounts. The issue relates to the `get_pfp` and `get_banner` routes on Auth Server. The issue is that there is no check to ensure that the file that Auth Server is receiving through these URLs is correct. This could allow an attacker access to files they shouldn't have access to. This issue has been patched in version 1.4.0.

    Published: 12 Jan 2024
    7.4
    High

    CVE-2023-42463

    Last Modified: 21 Nov 2024

    Wazuh is a free and open source platform used for threat prevention, detection, and response. This bug introduced a stack overflow hazard that could allow a local privilege escalation. This vulnerability was patched in version 4.5.3.

    Published: 12 Jan 2024
    3.1
    Low

    CVE-2023-49099

    Last Modified: 17 Jun 2025

    Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with posts can be accessed by guest users even when login is required. This vulnerability has been patched in 3.2.0.beta4 and 3.1.4.

    Published: 12 Jan 2024
    4.3
    Medium

    CVE-2024-21655

    Last Modified: 3 Jun 2025

    Discourse is a platform for community discussion. For fields that are client editable, limits on sizes are not imposed. This allows a malicious actor to cause a Discourse instance to use excessive disk space and also often excessive bandwidth. The issue is patched 3.1.4 and 3.2.0.beta4.

    Published: 12 Jan 2024
    3.5
    Low

    CVE-2023-49098

    Last Modified: 3 Jun 2025

    Discourse-reactions is a plugin that allows user to add their reactions to the post. Data about a user's reaction notifications could be exposed. This vulnerability was patched in commit 2c26939.

    Published: 12 Jan 2024
    8.6
    High

    CVE-2023-48297

    Last Modified: 17 Jun 2025

    Discourse is a platform for community discussion. The message serializer uses the full list of expanded chat mentions (@all and @here) which can lead to a very long array of users. This issue was patched in versions 3.1.4 and beta 3.2.0.beta5.

    Published: 12 Jan 2024
    9.6
    Critical

    CVE-2023-51698

    Last Modified: 17 Jun 2025

    Atril is a simple multi-page document viewer. Atril is vulnerable to a critical Command Injection Vulnerability. This vulnerability gives the attacker immediate access to the target system when the target user opens a crafted document or clicks on a crafted link/URL using a maliciously crafted CBT document which is a TAR archive. A patch is available at commit ce41df6.

    Published: 12 Jan 2024
    9
    Critical

    CVE-2024-22206

    Last Modified: 21 Nov 2024

    Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router. This vulnerability was patched in version 4.29.3.

    Published: 12 Jan 2024
    6.3
    Medium

    CVE-2024-0475

    Last Modified: 17 Jun 2025

    A vulnerability, which was classified as critical, has been found in code-projects Dormitory Management System 1.0. Affected by this issue is some unknown functionality of the file modifyuser.php. The manipulation of the argument user_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250580.

    Published: 12 Jan 2024
    4.3
    Medium

    CVE-2010-10011

    Last Modified: 3 Jun 2025

    A vulnerability, which was classified as problematic, was found in Acritum Femitter Server 1.04. Affected is an unknown function. The manipulation leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-250446 is the identifier assigned to this vulnerability.

    Published: 12 Jan 2024
    4.2
    Medium

    CVE-2023-31031

    Last Modified: 9 Oct 2025

    NVIDIA DGX Station A100 and DGX Station A800 SBIOS contains a vulnerability where a user may cause a heap-based buffer overflow by local access. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and data tampering.

    Published: 12 Jan 2024
    6.5
    Medium

    CVE-2023-31025

    Last Modified: 17 Jun 2025

    NVIDIA DGX A100 BMC contains a vulnerability where an attacker may cause an LDAP user injection. A successful exploit of this vulnerability may lead to information disclosure.

    Published: 12 Jan 2024
    6.6
    Medium

    CVE-2023-31034

    Last Modified: 17 Jun 2025

    NVIDIA DGX A100 SBIOS contains a vulnerability where a local attacker can cause input validation checks to be bypassed by causing an integer overflow. A successful exploit of this vulnerability may lead to denial of service, information disclosure, and data tampering.

    Published: 12 Jan 2024
    6.8
    Medium

    CVE-2023-31033

    Last Modified: 3 Jun 2025

    NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue for a critical function by an adjacent network . A successful exploit of this vulnerability may lead to escalation of privileges, code execution, denial of service, information disclosure, and data tampering.

    Published: 12 Jan 2024
    7.5
    High

    CVE-2023-31035

    Last Modified: 21 Nov 2024

    NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that could be used to execute arbitrary code at the SMM level. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, and information disclosure.

    Published: 12 Jan 2024
    7.5
    High

    CVE-2023-31032

    Last Modified: 3 Jun 2025

    NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a dynamic variable evaluation by local access. A successful exploit of this vulnerability may lead to denial of service.

    Published: 12 Jan 2024
    9
    Critical

    CVE-2023-31024

    Last Modified: 3 Jun 2025

    NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause stack memory corruption by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.

    Published: 12 Jan 2024
    9.3
    Critical

    CVE-2023-31030

    Last Modified: 3 Jun 2025

    NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.

    Published: 12 Jan 2024
    9.3
    Critical

    CVE-2023-31029

    Last Modified: 21 Nov 2024

    NVIDIA DGX A100 baseboard management controller (BMC) contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.

    Published: 12 Jan 2024
    7.3
    High

    CVE-2024-0474

    Last Modified: 17 Jun 2025

    A vulnerability classified as critical was found in code-projects Dormitory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250579.

    Published: 12 Jan 2024
    6.3
    Medium

    CVE-2024-0463

    Last Modified: 23 Oct 2025

    A vulnerability was found in code-projects Online Faculty Clearance 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /production/admin_view_info.php of the component HTTP POST Request Handler. The manipulation of the argument haydi leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250568.

    Published: 12 Jan 2024
    6.3
    Medium

    CVE-2024-0473

    Last Modified: 3 Jun 2025

    A vulnerability classified as critical has been found in code-projects Dormitory Management System 1.0. Affected is an unknown function of the file comment.php. The manipulation of the argument com leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-250578 is the identifier assigned to this vulnerability.

    Published: 12 Jan 2024
    3.5
    Low

    CVE-2024-0472

    Last Modified: 21 Nov 2024

    A vulnerability was found in code-projects Dormitory Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file modifyuser.php. The manipulation of the argument mname leads to information disclosure. The exploit has been disclosed to the public and may be used. The identifier VDB-250577 was assigned to this vulnerability.

    Published: 12 Jan 2024
    6.3
    Medium

    CVE-2024-0462

    Last Modified: 23 Oct 2025

    A vulnerability was found in code-projects Online Faculty Clearance 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /production/designee_view_status.php of the component HTTP POST Request Handler. The manipulation of the argument haydi leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250567.

    Published: 12 Jan 2024
    7.5
    High

    CVE-2023-31036

    Last Modified: 17 Jun 2025

    NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where, when it is launched with the non-default command line option --model-control explicit, an attacker may use the model load API to cause a relative path traversal. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

    Published: 12 Jan 2024
    9.1
    Critical

    CVE-2024-21887

    Last Modified: 31 Oct 2025

    A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

    Published: 12 Jan 2024
    8.2
    High

    CVE-2023-46805

    Last Modified: 31 Oct 2025

    An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

    Published: 12 Jan 2024
    6.3
    Medium

    CVE-2024-0471

    Last Modified: 13 Jun 2025

    A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin_route/dec_service_credits.php. The manipulation of the argument date leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250576.

    Published: 12 Jan 2024
    6.3
    Medium

    CVE-2024-0470

    Last Modified: 3 Jun 2025

    A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been classified as critical. This affects an unknown part of the file /admin_route/inc_service_credits.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250575.

    Published: 12 Jan 2024
    6.3
    Medium

    CVE-2024-0461

    Last Modified: 23 Oct 2025

    A vulnerability was found in code-projects Online Faculty Clearance 1.0. It has been classified as critical. Affected is an unknown function of the file deactivate.php of the component HTTP POST Request Handler. The manipulation of the argument haydi leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-250566 is the identifier assigned to this vulnerability.

    Published: 12 Jan 2024
    4.7
    Medium

    CVE-2023-28899

    Last Modified: 21 Nov 2024

    By sending a specific reset UDS request via OBDII port of Skoda vehicles, it is possible to cause vehicle engine shutdown and denial of service of other vehicle components even when the vehicle is moving at a high speed. No safety critical functions affected. 

    Published: 12 Jan 2024
    6.3
    Medium

    CVE-2024-0469

    Last Modified: 21 Nov 2024

    A vulnerability was found in code-projects Human Resource Integrated System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file update_personal_info.php. The manipulation of the argument sex leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-250574 is the identifier assigned to this vulnerability.

    Published: 12 Jan 2024
    6.3
    Medium

    CVE-2024-0468

    Last Modified: 21 Nov 2024

    A vulnerability has been found in code-projects Fighting Cock Information System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/action/new-father.php. The manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250573 was assigned to this vulnerability.

    Published: 12 Jan 2024
    5.3
    Medium

    CVE-2023-28898

    Last Modified: 21 Nov 2024

    The Real-Time Streaming Protocol implementation in the MIB3 infotainment incorrectly handles requests to /logs URI, when the id parameter equals to zero. This issue allows an attacker connected to the in-vehicle Wi-Fi network to cause denial-of-service of the infotainment system, when the certain preconditions are met. Vulnerability discovered on Škoda Superb III (3V3) - 2.0 TDI manufactured in 2022.

    Published: 12 Jan 2024
    3.5
    Low

    CVE-2024-0467

    Last Modified: 17 Jun 2025

    A vulnerability, which was classified as problematic, was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file edit_position_query.php. The manipulation of the argument pos_name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250572.

    Published: 12 Jan 2024