CVE Feed

    Dashboard / CVE

    8
    High

    CVE-2024-20654

    Last Modified: 17 Jun 2025

    Microsoft ODBC Driver Remote Code Execution Vulnerability

    Published: 9 Jan 2024
    8
    High

    CVE-2024-20676

    Last Modified: 3 May 2025

    Azure Storage Mover Remote Code Execution Vulnerability

    Published: 9 Jan 2024
    7.8
    High

    CVE-2024-20677

    Last Modified: 3 May 2025

    A security vulnerability exists in FBX that could lead to remote code execution. To mitigate this vulnerability, the ability to insert FBX files has been disabled in Word, Excel, PowerPoint and Outlook for Windows and Mac. Versions of Office that had this feature enabled will no longer have access to it. This includes Office 2019, Office 2021, Office LTSC for Mac 2021, and Microsoft 365. As of February 13, 2024, the ability to insert FBX files has also been disabled in 3D Viewer. 3D models in Office documents that were previously inserted from a FBX file will continue to work as expected unless the Link to File option was chosen at insert time. This change is effective as of the January 9, 2024 security update.

    Published: 9 Jan 2024
    8.8
    High

    CVE-2024-20674

    Last Modified: 3 May 2025

    Windows Kerberos Security Feature Bypass Vulnerability

    Published: 9 Jan 2024
    6.6
    Medium

    CVE-2024-20666

    Last Modified: 3 May 2025

    BitLocker Security Feature Bypass Vulnerability

    Published: 9 Jan 2024
    3.7
    Low

    CVE-2024-0347

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Engineers Online Portal 1.0 and classified as problematic. This issue affects some unknown processing of the file signup_teacher.php. The manipulation of the argument Password leads to weak password requirements. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250115.

    Published: 9 Jan 2024
    3.5
    Low

    CVE-2024-0346

    Last Modified: 21 Nov 2024

    A vulnerability has been found in CodeAstro Vehicle Booking System 1.0 and classified as problematic. This vulnerability affects unknown code of the file usr/user-give-feedback.php of the component Feedback Page. The manipulation of the argument My Testemonial leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-250114 is the identifier assigned to this vulnerability.

    Published: 9 Jan 2024
    4.3
    Medium

    CVE-2024-22164

    Last Modified: 3 Jun 2025

    In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a denial of service (DoS) to the Investigation. The attachment endpoint does not properly limit the size of the request which lets an attacker cause the Investigation to become inaccessible.

    Published: 9 Jan 2024
    6.5
    Medium

    CVE-2024-22165

    Last Modified: 28 Feb 2025

    In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can create a malformed Investigation to perform a denial of service (DoS). The malformed investigation prevents the generation and rendering of the Investigations manager until it is deleted.<br>The vulnerability requires an authenticated session and access to create an Investigation. It only affects the availability of the Investigations manager, but without the manager, the Investigations functionality becomes unusable for most users.

    Published: 9 Jan 2024
    4.3
    Medium

    CVE-2024-0345

    Last Modified: 17 Apr 2025

    A vulnerability, which was classified as problematic, was found in CodeAstro Vehicle Booking System 1.0. This affects an unknown part of the file usr/usr-register.php of the component User Registration. The manipulation of the argument Full_Name/Last_Name/Address with the input <script>alert(document.cookie)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250113 was assigned to this vulnerability.

    Published: 9 Jan 2024
    5.5
    Medium

    CVE-2024-0344

    Last Modified: 14 May 2025

    A vulnerability, which was classified as critical, has been found in soxft TimeMail up to 1.1. Affected by this issue is some unknown functionality of the file check.php. The manipulation of the argument c leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250112.

    Published: 9 Jan 2024
    4.3
    Medium

    CVE-2024-0343

    Last Modified: 17 Jun 2025

    A vulnerability classified as problematic was found in CodeAstro Simple House Rental System 5.6. Affected by this vulnerability is an unknown functionality of the component Login Panel. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250111.

    Published: 9 Jan 2024
    5.3
    Medium

    CVE-2023-7223

    Last Modified: 17 Jun 2025

    A vulnerability classified as problematic has been found in Totolink T6 4.1.9cu.5241_B20210923. This affects an unknown part of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument topicurl with the input showSyslog leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249867. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 9 Jan 2024
    6.3
    Medium

    CVE-2024-0342

    Last Modified: 17 Jun 2025

    A vulnerability classified as critical has been found in Inis up to 2.0.1. Affected is an unknown function of the file /app/api/controller/default/Sqlite.php. The manipulation of the argument sql leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-250110 is the identifier assigned to this vulnerability.

    Published: 9 Jan 2024
    7.2
    High

    CVE-2023-7222

    Last Modified: 21 Nov 2024

    A vulnerability was found in Totolink X2000R 1.0.0-B20221212.1452. It has been declared as critical. This vulnerability affects the function formTmultiAP of the file /bin/boa of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249856. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 9 Jan 2024
    3.5
    Low

    CVE-2024-0341

    Last Modified: 17 Apr 2025

    A vulnerability was found in Inis up to 2.0.1. It has been rated as problematic. This issue affects some unknown processing of the file /app/api/controller/default/File.php of the component GET Request Handler. The manipulation of the argument path leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. The identifier VDB-250109 was assigned to this vulnerability.

    Published: 9 Jan 2024
    9.8
    Critical

    CVE-2023-7221

    Last Modified: 14 May 2025

    A vulnerability was found in Totolink T6 4.1.9cu.5241_B20210923. It has been classified as critical. This affects the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The manipulation of the argument v41 leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249855. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 9 Jan 2024
    4.8
    Medium

    CVE-2024-0226

    Last Modified: 21 Nov 2024

    Synopsys Seeker versions prior to 2023.12.0 are vulnerable to a stored cross-site scripting vulnerability through a specially crafted payload.

    Published: 9 Jan 2024
    7.8
    High

    CVE-2023-51746

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < V13.3.0.13), Teamcenter Visualization V14.1 (All versions < V14.1.0.12), Teamcenter Visualization V14.2 (All versions < V14.2.0.9), Teamcenter Visualization V14.3 (All versions < V14.3.0.6). The affected applications contain a stack overflow vulnerability while parsing specially crafted CGM files. This could allow an attacker to execute code in the context of the current process.

    Published: 9 Jan 2024
    7.8
    High

    CVE-2023-51745

    Last Modified: 3 Jun 2025

    A vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < V13.3.0.13), Teamcenter Visualization V14.1 (All versions < V14.1.0.12), Teamcenter Visualization V14.2 (All versions < V14.2.0.9), Teamcenter Visualization V14.3 (All versions < V14.3.0.6). The affected applications contain a stack overflow vulnerability while parsing specially crafted CGM files. This could allow an attacker to execute code in the context of the current process.

    Published: 9 Jan 2024
    3.3
    Low

    CVE-2023-51744

    Last Modified: 9 Jun 2025

    A vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < V13.3.0.13), Teamcenter Visualization V14.1 (All versions < V14.1.0.12), Teamcenter Visualization V14.2 (All versions < V14.2.0.9), Teamcenter Visualization V14.3 (All versions < V14.3.0.6). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted CGM files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.

    Published: 9 Jan 2024
    7.8
    High

    CVE-2023-51439

    Last Modified: 17 Apr 2025

    A vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < V13.3.0.13), Teamcenter Visualization V14.1 (All versions < V14.1.0.12), Teamcenter Visualization V14.2 (All versions < V14.2.0.9), Teamcenter Visualization V14.3 (All versions < V14.3.0.6). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted CGM files. This could allow an attacker to execute code in the context of the current process.

    Published: 9 Jan 2024
    10
    Critical

    CVE-2023-51438

    Last Modified: 22 May 2025

    A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC647E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC847E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows). In default installations of maxView Storage Manager where Redfish® server is configured for remote system management, a vulnerability has been identified that can provide unauthorized access.

    Published: 9 Jan 2024
    9.8
    Critical

    CVE-2023-49621

    Last Modified: 16 Dec 2025

    A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application uses default credential with admin privileges. An attacker could use the credentials to gain complete control of the affected device.

    Published: 9 Jan 2024
    7.5
    High

    CVE-2023-49252

    Last Modified: 16 Dec 2025

    A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The affected application allows IP configuration change without authentication to the device. This could allow an attacker to cause denial of service condition.

    Published: 9 Jan 2024
    8.8
    High

    CVE-2023-49251

    Last Modified: 16 Dec 2025

    A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application allows an attacker to add their own login credentials to the device. This allows an attacker to remotely login as root and take control of the device even after the affected device is fully set up.

    Published: 9 Jan 2024
    7.8
    High

    CVE-2023-49132

    Last Modified: 27 Aug 2025

    A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to uninitialized pointer access while parsing specially crafted PAR files. An attacker could leverage this vulnerability to execute code in the context of the current process.

    Published: 9 Jan 2024
    7.8
    High

    CVE-2023-49131

    Last Modified: 27 Aug 2025

    A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to uninitialized pointer access while parsing specially crafted PAR files. An attacker could leverage this vulnerability to execute code in the context of the current process.

    Published: 9 Jan 2024
    7.8
    High

    CVE-2023-49130

    Last Modified: 27 Aug 2025

    A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to uninitialized pointer access while parsing specially crafted PAR files. An attacker could leverage this vulnerability to execute code in the context of the current process.

    Published: 9 Jan 2024
    7.8
    High

    CVE-2023-49129

    Last Modified: 17 Jun 2025

    A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected applications contain a stack overflow vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

    Published: 9 Jan 2024
    7.8
    High

    CVE-2023-49128

    Last Modified: 27 Aug 2025

    A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted PAR file. This could allow an attacker to execute code in the context of the current process.

    Published: 9 Jan 2024
    7.8
    High

    CVE-2023-49127

    Last Modified: 27 Aug 2025

    A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

    Published: 9 Jan 2024
    7.8
    High

    CVE-2023-49126

    Last Modified: 27 Aug 2025

    A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

    Published: 9 Jan 2024
    7.8
    High

    CVE-2023-49124

    Last Modified: 27 Aug 2025

    A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

    Published: 9 Jan 2024
    7.8
    High

    CVE-2023-49123

    Last Modified: 27 Aug 2025

    A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

    Published: 9 Jan 2024
    7.8
    High

    CVE-2023-49122

    Last Modified: 27 Aug 2025

    A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

    Published: 9 Jan 2024
    7.8
    High

    CVE-2023-49121

    Last Modified: 27 Aug 2025

    A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

    Published: 9 Jan 2024
    7.8
    High

    CVE-2023-44120

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q4). The affected product's sudo configuration permits the local administrative account to execute several entries as root user. This could allow an authenticated local attacker to inject arbitrary code and gain root access.

    Published: 9 Jan 2024
    6.6
    Medium

    CVE-2023-42797

    Last Modified: 3 Jun 2025

    A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.20), CP-8050 MASTER MODULE (All versions < CPCI85 V05.20). The network configuration service of affected devices contains a flaw in the conversion of ipv4 addresses that could lead to an uninitialized variable being used in succeeding validation steps. By uploading specially crafted network configuration, an authenticated remote attacker could be able to inject commands that are executed on the device with root privileges during device startup.

    Published: 9 Jan 2024
    9.8
    Critical

    CVE-2023-5347

    Last Modified: 8 Oct 2025

    An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue affects JetNet devices older than firmware version 2024/01.

    Published: 9 Jan 2024
    8.3
    High

    CVE-2023-49722

    Last Modified: 17 Jun 2025

    Network port 8899 open in WiFi firmware of BCC101/BCC102/BCC50 products, that allows an attacker to connect to the device via same WiFi network.

    Published: 9 Jan 2024
    4.6
    Medium

    CVE-2024-22370

    Last Modified: 17 Jun 2025

    In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible

    Published: 9 Jan 2024
    8.6
    High

    CVE-2023-5376

    Last Modified: 8 Oct 2025

    An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware version 2024/01.

    Published: 9 Jan 2024
    8.2
    High

    CVE-2024-0213

    Last Modified: 17 Jun 2025

    A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause a Denial of Service (DoS), through exploiting a memory corruption issue in the TA service, which runs as root. This may also result in the disabling of event reporting to ePO, caused by failure to validate input from the file correctly.

    Published: 9 Jan 2024
    7.1
    High

    CVE-2024-0206

    Last Modified: 17 Apr 2025

    A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation of privileges. This was achieved by adding an entry to the registry under the Trellix ENS registry folder with a symbolic link to files that the user wouldn't normally have permission to. After a scan, the Engine would follow the links and remove the files

    Published: 9 Jan 2024
    5.7
    Medium

    CVE-2023-6149

    Last Modified: 16 Jun 2025

    Qualys Jenkins Plugin for WAS prior to version and including 2.0.11 was identified to be affected by a security flaw, which was missing a permission check while performing a connectivity check to Qualys Cloud Services. This allowed any user with login access to configure or edit jobs to utilize the plugin and configure potential a rouge endpoint via which it was possible to control response for certain request which could be injected with XXE payloads leading to XXE while processing the response data

    Published: 9 Jan 2024
    5.7
    Medium

    CVE-2023-6148

    Last Modified: 17 Apr 2025

    Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a permission check while performing a connectivity check to Qualys Cloud Services. This allowed any user with login access and access to configure or edit jobs to utilize the plugin to configure a potential rouge endpoint via which it was possible to control response for certain request which could be injected with XSS payloads leading to XSS while processing the response data

    Published: 9 Jan 2024
    5.7
    Medium

    CVE-2023-6147

    Last Modified: 13 Feb 2025

    Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a permission check while performing a connectivity check to Qualys Cloud Services. This allowed any user with login access to configure or edit jobs to utilize the plugin and configure potential a rouge endpoint via which it was possible to control response for certain request which could be injected with XXE payloads leading to XXE while processing the response data

    Published: 9 Jan 2024
    —
    Unknown

    CVE-2024-0339

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 9 Jan 2024
    9.8
    Critical

    CVE-2023-7220

    Last Modified: 17 Jun 2025

    A vulnerability was found in Totolink NR1800X 9.1.0u.6279_B20210910 and classified as critical. Affected by this issue is the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-249854 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 9 Jan 2024