CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2023-47171

    Last Modified: 4 Nov 2025

    An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.

    Published: 10 Jan 2024
    6.5
    Medium

    CVE-2023-49864

    Last Modified: 4 Nov 2025

    An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the `downloadURL_image` parameter.

    Published: 10 Jan 2024
    6.5
    Medium

    CVE-2023-49863

    Last Modified: 4 Nov 2025

    An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the `downloadURL_webpimage` parameter.

    Published: 10 Jan 2024
    6.5
    Medium

    CVE-2023-49862

    Last Modified: 4 Nov 2025

    An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the `downloadURL_gifimage` parameter.

    Published: 10 Jan 2024
    7.5
    High

    CVE-2023-49738

    Last Modified: 4 Nov 2025

    An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.

    Published: 10 Jan 2024
    8.5
    High

    CVE-2023-48730

    Last Modified: 4 Nov 2025

    A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.

    Published: 10 Jan 2024
    9.6
    Critical

    CVE-2023-48728

    Last Modified: 4 Nov 2025

    A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.

    Published: 10 Jan 2024
    9
    Critical

    CVE-2023-47861

    Last Modified: 4 Nov 2025

    A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.

    Published: 10 Jan 2024
    4.3
    Medium

    CVE-2023-49715

    Last Modified: 4 Nov 2025

    A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary code execution when chained with an LFI vulnerability. An attacker can send a series of HTTP requests to trigger this vulnerability.

    Published: 10 Jan 2024
    9.8
    Critical

    CVE-2023-47862

    Last Modified: 4 Nov 2025

    A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send a series of HTTP requests to trigger this vulnerability.

    Published: 10 Jan 2024
    8.8
    High

    CVE-2023-49589

    Last Modified: 4 Nov 2025

    An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to an arbitrary user password recovery. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 10 Jan 2024
    5.3
    Medium

    CVE-2023-50172

    Last Modified: 4 Nov 2025

    A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to the silent creation of a recovery pass code for any user.

    Published: 10 Jan 2024
    7.3
    High

    CVE-2023-49810

    Last Modified: 4 Nov 2025

    A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to captcha bypass, which can be abused by an attacker to brute force user credentials. An attacker can send a series of HTTP requests to trigger this vulnerability.

    Published: 10 Jan 2024
    9.8
    Critical

    CVE-2023-49599

    Last Modified: 4 Nov 2025

    An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can lead to privilege escalation. An attacker can gather system information via HTTP requests and brute force the salt offline, leading to forging a legitimate password recovery code for the admin user.

    Published: 10 Jan 2024
    —
    Unknown

    CVE-2024-22413

    Last Modified: 27 Mar 2024

    Further research determined the issue is not a vulnerability. The Creditcoin blockchain team takes the stance that there is no real bug or vulnerability here and that the creditcoin-cli command is working as it was designed to.

    Published: 10 Jan 2024
    6.5
    Medium

    CVE-2023-6158

    Last Modified: 8 Apr 2026

    The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the evo_eventpost_update_meta function in all versions up to, and including, 4.5.4 (for Pro) and 2.2.7 (for free). This makes it possible for unauthenticated attackers to update and remove arbitrary post metadata. Note that certain parameters may allow for content injection. CVE-2024-0238 appears to be a duplicate of this issue.

    Published: 10 Jan 2024
    8.1
    High

    CVE-2023-48266

    Last Modified: 17 Jun 2025

    The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

    Published: 10 Jan 2024
    8.1
    High

    CVE-2023-48265

    Last Modified: 17 Jun 2025

    The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

    Published: 10 Jan 2024
    8.1
    High

    CVE-2023-48264

    Last Modified: 17 Apr 2025

    The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

    Published: 10 Jan 2024
    8.1
    High

    CVE-2023-48263

    Last Modified: 17 Jun 2025

    The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

    Published: 10 Jan 2024
    8.1
    High

    CVE-2023-48262

    Last Modified: 17 Jun 2025

    The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

    Published: 10 Jan 2024
    5.3
    Medium

    CVE-2023-48261

    Last Modified: 3 Jun 2025

    The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.

    Published: 10 Jan 2024
    5.3
    Medium

    CVE-2023-48260

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.

    Published: 10 Jan 2024
    5.3
    Medium

    CVE-2023-48259

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.

    Published: 10 Jan 2024
    5.5
    Medium

    CVE-2023-48258

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote attacker to delete arbitrary files on the file system via a crafted URL or HTTP request through a victim’s session.

    Published: 10 Jan 2024
    7.8
    High

    CVE-2023-48257

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) with root privileges on the device. The vulnerability can be exploited directly by authenticated users, via crafted HTTP requests, or indirectly by unauthenticated users, by accessing already-exported backup packages, or crafting an import package and inducing an authenticated victim into sending the HTTP upload request.

    Published: 10 Jan 2024
    5.3
    Medium

    CVE-2023-48256

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote attacker to inject arbitrary HTTP response headers or manipulate HTTP response bodies inside a victim’s session via a crafted URL or HTTP request.

    Published: 10 Jan 2024
    6.3
    Medium

    CVE-2023-48255

    Last Modified: 17 Jun 2025

    The vulnerability allows an unauthenticated remote attacker to send malicious network requests containing arbitrary client-side script code and obtain its execution inside a victim’s session via a crafted URL, HTTP request, or simply by waiting for the victim to view the poisoned log.

    Published: 10 Jan 2024
    5.3
    Medium

    CVE-2023-48254

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s session via a crafted URL or HTTP request.

    Published: 10 Jan 2024
    8.8
    High

    CVE-2023-48253

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication database via a crafted HTTP request. By abusing this vulnerability it is possible to exfiltrate other users’ password hashes or update them with arbitrary values and access their accounts.

    Published: 10 Jan 2024
    8.8
    High

    CVE-2023-48252

    Last Modified: 17 Jun 2025

    The vulnerability allows an authenticated remote attacker to perform actions exceeding their authorized access via crafted HTTP requests.

    Published: 10 Jan 2024
    8.1
    High

    CVE-2023-48251

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote attacker to authenticate to the SSH service with root privileges through a hidden hard-coded account.

    Published: 10 Jan 2024
    5.5
    Medium

    CVE-2024-20711

    Last Modified: 17 Jun 2025

    Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jan 2024
    5.5
    Medium

    CVE-2024-20712

    Last Modified: 17 Jun 2025

    Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jan 2024
    5.5
    Medium

    CVE-2024-20713

    Last Modified: 17 Jun 2025

    Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jan 2024
    5.5
    Medium

    CVE-2024-20714

    Last Modified: 17 Jun 2025

    Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jan 2024
    5.5
    Medium

    CVE-2024-20715

    Last Modified: 17 Jun 2025

    Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jan 2024
    5.5
    Medium

    CVE-2024-20710

    Last Modified: 17 Jun 2025

    Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jan 2024
    8.1
    High

    CVE-2023-48250

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded accounts.

    Published: 10 Jan 2024
    6.5
    Medium

    CVE-2023-48249

    Last Modified: 17 Jun 2025

    The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is possible to steal session cookies of other active users.

    Published: 10 Jan 2024
    5.5
    Medium

    CVE-2023-48248

    Last Modified: 17 Jun 2025

    The vulnerability allows an authenticated remote attacker to upload a malicious file to the SD card containing arbitrary client-side script code and obtain its execution inside a victim’s session via a crafted URL, HTTP request, or simply by waiting for the victim to view the poisoned file.

    Published: 10 Jan 2024
    5.3
    Medium

    CVE-2023-48247

    Last Modified: 17 Jun 2025

    The vulnerability allows an unauthenticated remote attacker to read arbitrary files under the context of the application OS user (“root”) via a crafted HTTP request.

    Published: 10 Jan 2024
    6.5
    Medium

    CVE-2023-48246

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.

    Published: 10 Jan 2024
    6.5
    Medium

    CVE-2023-48245

    Last Modified: 17 Jun 2025

    The vulnerability allows an unauthenticated remote attacker to upload arbitrary files under the context of the application OS user (“root”) via a crafted HTTP request.

    Published: 10 Jan 2024
    5.3
    Medium

    CVE-2023-48244

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s session via a crafted URL or HTTP request.

    Published: 10 Jan 2024
    8.1
    High

    CVE-2023-48243

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is possible to obtain remote code execution (RCE) with root privileges on the device.

    Published: 10 Jan 2024
    6.5
    Medium

    CVE-2023-48242

    Last Modified: 17 Jun 2025

    The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.

    Published: 10 Jan 2024
    —
    Unknown

    CVE-2024-0398

    Last Modified: 5 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 10 Jan 2024
    6.3
    Medium

    CVE-2024-0389

    Last Modified: 9 May 2025

    A vulnerability, which was classified as critical, was found in SourceCodester Student Attendance System 1.0. Affected is an unknown function of the file attendance_report.php. The manipulation of the argument class_id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-250230 is the identifier assigned to this vulnerability.

    Published: 10 Jan 2024
    3.1
    Low

    CVE-2023-49619

    Last Modified: 11 Jun 2025

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer. This issue affects Apache Answer: through 1.2.0. Under normal circumstances, a user can only bookmark a question once, and will only increase the number of questions bookmarked once. However, repeat submissions through the script can increase the number of collection of the question many times. Users are recommended to upgrade to version [1.2.1], which fixes the issue.

    Published: 10 Jan 2024