CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2023-49599

    Last Modified: 4 Nov 2025

    An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can lead to privilege escalation. An attacker can gather system information via HTTP requests and brute force the salt offline, leading to forging a legitimate password recovery code for the admin user.

    Published: 10 Jan 2024
    —
    Unknown

    CVE-2024-22413

    Last Modified: 27 Mar 2024

    Further research determined the issue is not a vulnerability. The Creditcoin blockchain team takes the stance that there is no real bug or vulnerability here and that the creditcoin-cli command is working as it was designed to.

    Published: 10 Jan 2024
    6.5
    Medium

    CVE-2023-6158

    Last Modified: 8 Apr 2026

    The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the evo_eventpost_update_meta function in all versions up to, and including, 4.5.4 (for Pro) and 2.2.7 (for free). This makes it possible for unauthenticated attackers to update and remove arbitrary post metadata. Note that certain parameters may allow for content injection. CVE-2024-0238 appears to be a duplicate of this issue.

    Published: 10 Jan 2024
    8.1
    High

    CVE-2023-48266

    Last Modified: 17 Jun 2025

    The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

    Published: 10 Jan 2024
    8.1
    High

    CVE-2023-48265

    Last Modified: 17 Jun 2025

    The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

    Published: 10 Jan 2024
    8.1
    High

    CVE-2023-48264

    Last Modified: 17 Apr 2025

    The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

    Published: 10 Jan 2024
    8.1
    High

    CVE-2023-48263

    Last Modified: 17 Jun 2025

    The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

    Published: 10 Jan 2024
    8.1
    High

    CVE-2023-48262

    Last Modified: 17 Jun 2025

    The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

    Published: 10 Jan 2024
    5.3
    Medium

    CVE-2023-48261

    Last Modified: 3 Jun 2025

    The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.

    Published: 10 Jan 2024
    5.3
    Medium

    CVE-2023-48260

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.

    Published: 10 Jan 2024
    5.3
    Medium

    CVE-2023-48259

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.

    Published: 10 Jan 2024
    5.5
    Medium

    CVE-2023-48258

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote attacker to delete arbitrary files on the file system via a crafted URL or HTTP request through a victim’s session.

    Published: 10 Jan 2024
    7.8
    High

    CVE-2023-48257

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) with root privileges on the device. The vulnerability can be exploited directly by authenticated users, via crafted HTTP requests, or indirectly by unauthenticated users, by accessing already-exported backup packages, or crafting an import package and inducing an authenticated victim into sending the HTTP upload request.

    Published: 10 Jan 2024
    5.3
    Medium

    CVE-2023-48256

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote attacker to inject arbitrary HTTP response headers or manipulate HTTP response bodies inside a victim’s session via a crafted URL or HTTP request.

    Published: 10 Jan 2024
    6.3
    Medium

    CVE-2023-48255

    Last Modified: 17 Jun 2025

    The vulnerability allows an unauthenticated remote attacker to send malicious network requests containing arbitrary client-side script code and obtain its execution inside a victim’s session via a crafted URL, HTTP request, or simply by waiting for the victim to view the poisoned log.

    Published: 10 Jan 2024
    5.3
    Medium

    CVE-2023-48254

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s session via a crafted URL or HTTP request.

    Published: 10 Jan 2024
    8.8
    High

    CVE-2023-48253

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication database via a crafted HTTP request. By abusing this vulnerability it is possible to exfiltrate other users’ password hashes or update them with arbitrary values and access their accounts.

    Published: 10 Jan 2024
    8.8
    High

    CVE-2023-48252

    Last Modified: 17 Jun 2025

    The vulnerability allows an authenticated remote attacker to perform actions exceeding their authorized access via crafted HTTP requests.

    Published: 10 Jan 2024
    8.1
    High

    CVE-2023-48251

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote attacker to authenticate to the SSH service with root privileges through a hidden hard-coded account.

    Published: 10 Jan 2024
    5.5
    Medium

    CVE-2024-20711

    Last Modified: 17 Jun 2025

    Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jan 2024
    5.5
    Medium

    CVE-2024-20712

    Last Modified: 17 Jun 2025

    Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jan 2024
    5.5
    Medium

    CVE-2024-20713

    Last Modified: 17 Jun 2025

    Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jan 2024
    5.5
    Medium

    CVE-2024-20714

    Last Modified: 17 Jun 2025

    Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jan 2024
    5.5
    Medium

    CVE-2024-20715

    Last Modified: 17 Jun 2025

    Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jan 2024
    5.5
    Medium

    CVE-2024-20710

    Last Modified: 17 Jun 2025

    Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jan 2024
    8.1
    High

    CVE-2023-48250

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded accounts.

    Published: 10 Jan 2024
    6.5
    Medium

    CVE-2023-48249

    Last Modified: 17 Jun 2025

    The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is possible to steal session cookies of other active users.

    Published: 10 Jan 2024
    5.5
    Medium

    CVE-2023-48248

    Last Modified: 17 Jun 2025

    The vulnerability allows an authenticated remote attacker to upload a malicious file to the SD card containing arbitrary client-side script code and obtain its execution inside a victim’s session via a crafted URL, HTTP request, or simply by waiting for the victim to view the poisoned file.

    Published: 10 Jan 2024
    5.3
    Medium

    CVE-2023-48247

    Last Modified: 17 Jun 2025

    The vulnerability allows an unauthenticated remote attacker to read arbitrary files under the context of the application OS user (“root”) via a crafted HTTP request.

    Published: 10 Jan 2024
    6.5
    Medium

    CVE-2023-48246

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.

    Published: 10 Jan 2024
    6.5
    Medium

    CVE-2023-48245

    Last Modified: 17 Jun 2025

    The vulnerability allows an unauthenticated remote attacker to upload arbitrary files under the context of the application OS user (“root”) via a crafted HTTP request.

    Published: 10 Jan 2024
    5.3
    Medium

    CVE-2023-48244

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s session via a crafted URL or HTTP request.

    Published: 10 Jan 2024
    8.1
    High

    CVE-2023-48243

    Last Modified: 17 Jun 2025

    The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is possible to obtain remote code execution (RCE) with root privileges on the device.

    Published: 10 Jan 2024
    6.5
    Medium

    CVE-2023-48242

    Last Modified: 17 Jun 2025

    The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.

    Published: 10 Jan 2024
    —
    Unknown

    CVE-2024-0398

    Last Modified: 5 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 10 Jan 2024
    6.3
    Medium

    CVE-2024-0389

    Last Modified: 9 May 2025

    A vulnerability, which was classified as critical, was found in SourceCodester Student Attendance System 1.0. Affected is an unknown function of the file attendance_report.php. The manipulation of the argument class_id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-250230 is the identifier assigned to this vulnerability.

    Published: 10 Jan 2024
    3.1
    Low

    CVE-2023-49619

    Last Modified: 11 Jun 2025

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer. This issue affects Apache Answer: through 1.2.0. Under normal circumstances, a user can only bookmark a question once, and will only increase the number of questions bookmarked once. However, repeat submissions through the script can increase the number of collection of the question many times. Users are recommended to upgrade to version [1.2.1], which fixes the issue.

    Published: 10 Jan 2024
    —
    Unknown

    CVE-2024-0393

    Last Modified: 12 Jan 2024

    This CVE ID was unused by the CNA.

    Published: 10 Jan 2024
    6.1
    Medium

    CVE-2024-0310

    Last Modified: 21 Nov 2024

    A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into report-only mode, allowing an attacker to bypass the content-security-policy configuration.

    Published: 10 Jan 2024
    6.5
    Medium

    CVE-2023-5455

    Last Modified: 18 Mar 2026

    A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.

    Published: 10 Jan 2024
    5.7
    Medium

    CVE-2023-41781

    Last Modified: 3 Jun 2025

    There is a Cross-site scripting (XSS)  vulnerability in ZTE MF258. Due to insufficient input validation of SMS interface parameter, an XSS attack will be triggered.

    Published: 10 Jan 2024
    7.1
    High

    CVE-2024-21643

    Last Modified: 10 Jun 2025

    IdentityModel Extensions for .NET provide assemblies for web developers that wish to use federated identity providers for establishing the caller's identity. Anyone leveraging the `SignedHttpRequest`protocol or the `SignedHttpRequestValidator`is vulnerable. Microsoft.IdentityModel trusts the `jku`claim by default for the `SignedHttpRequest`protocol. This raises the possibility to make any remote or local `HTTP GET` request. The vulnerability has been fixed in Microsoft.IdentityModel.Protocols.SignedHttpRequest. Users should update all their Microsoft.IdentityModel versions to 7.1.2 (for 7x) or higher, 6.34.0 (for 6x) or higher.

    Published: 10 Jan 2024
    5.3
    Medium

    CVE-2023-41603

    Last Modified: 17 Jun 2025

    D-Link R15 before v1.08.02 was discovered to contain no firewall restrictions for IPv6 traffic. This allows attackers to arbitrarily access any services running on the device that may be inadvertently listening via IPv6.

    Published: 10 Jan 2024
    4.9
    Medium

    CVE-2020-26630

    Last Modified: 22 May 2025

    A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload in the 'Doctor Specialization' field under the 'Go to Doctors' tab after logging in as an admin.

    Published: 10 Jan 2024
    9.8
    Critical

    CVE-2023-51967

    Last Modified: 20 Jun 2025

    Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function getIptvInfo.

    Published: 10 Jan 2024
    9.8
    Critical

    CVE-2023-52064

    Last Modified: 3 Jun 2025

    Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the $keywords parameter at /core/admin/copyfrom.php.

    Published: 10 Jan 2024
    4.9
    Medium

    CVE-2020-26627

    Last Modified: 3 Jun 2025

    A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a crafted payload entered into the 'Admin Remark' parameter under the 'Contact Us Queries -> Unread Query' tab.

    Published: 10 Jan 2024
    9.8
    Critical

    CVE-2020-26629

    Last Modified: 9 May 2025

    A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows an unauthenticated attacker to upload any file to the server.

    Published: 10 Jan 2024
    7.5
    High

    CVE-2023-49427

    Last Modified: 16 Jun 2025

    Buffer Overflow vulnerability in Tenda AX12 V22.03.01.46, allows remote attackers to cause a denial of service (DoS) via list parameter in SetNetControlList function.

    Published: 10 Jan 2024
    6.1
    Medium

    CVE-2020-26628

    Last Modified: 20 Jun 2025

    A Cross-Site Scripting (XSS) vulnerability was discovered in Hospital Management System V4.0 which allows an attacker to execute arbitrary web scripts or HTML code via a malicious payload appended to a username on the 'Edit Profile" page and triggered by another user visiting the profile.

    Published: 10 Jan 2024