CVE Feed

    Dashboard / CVE

    7
    High

    CVE-2023-39413

    Last Modified: 4 Nov 2025

    Multiple integer underflow vulnerabilities exist in the LXT2 lxt2_rd_iter_radix shift operation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to memory corruption. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer underflow when performing the left shift operation.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-39444

    Last Modified: 4 Nov 2025

    Multiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functionality of GTKWave 3.3.115. A specially-crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write perfomed by the string copy loop.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-39443

    Last Modified: 4 Nov 2025

    Multiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functionality of GTKWave 3.3.115. A specially-crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write perfomed by the prefix copy loop.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-38583

    Last Modified: 4 Nov 2025

    A stack-based buffer overflow vulnerability exists in the LXT2 lxt2_rd_expand_integer_to_bits function of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

    Published: 8 Jan 2024
    9.1
    Critical

    CVE-2023-47211

    Last Modified: 4 Nov 2025

    A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-7224

    Last Modified: 21 Nov 2024

    OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party libraries using the DYLD_INSERT_LIBRARIES environment variable

    Published: 8 Jan 2024
    5.3
    Medium

    CVE-2023-51701

    Last Modified: 3 Jun 2025

    fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. A reverse proxy server built with `@fastify/reply-from` could misinterpret the incoming body by passing an header `ContentType: application/json ; charset=utf-8`. This can lead to bypass of security checks. This vulnerability has been patched in '@fastify/reply-from` version 9.6.0.

    Published: 8 Jan 2024
    7.5
    High

    CVE-2024-21644

    Last Modified: 17 Jun 2025

    pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the `SECRET_KEY` variable. This issue has been patched in version 0.5.0b3.dev77.

    Published: 8 Jan 2024
    5.3
    Medium

    CVE-2024-21645

    Last Modified: 21 Nov 2024

    pyLoad is the free and open-source Download Manager written in pure Python. A log injection vulnerability was identified in `pyload` allowing any unauthenticated actor to inject arbitrary messages into the logs gathered by `pyload`. Forged or otherwise, corrupted log files can be used to cover an attacker’s tracks or even to implicate another party in the commission of a malicious act. This vulnerability has been patched in version 0.5.0b3.dev77.

    Published: 8 Jan 2024
    6.1
    Medium

    CVE-2023-6552

    Last Modified: 17 Apr 2025

    Lack of "current" GET parameter validation during the action of changing a language leads to an open redirect vulnerability.

    Published: 8 Jan 2024
    9.8
    Critical

    CVE-2023-6921

    Last Modified: 16 Jun 2025

    Blind SQL Injection vulnerability in PrestaShow Google Integrator (PrestaShop addon) allows for data extraction and modification. This attack is possible via command insertion in one of the cookies.

    Published: 8 Jan 2024
    5.5
    Medium

    CVE-2023-5091

    Last Modified: 22 May 2025

    Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU processing operations to gain access to already freed memory. This issue affects Valhall GPU Kernel Driver: from r37p0 through r40p0.

    Published: 8 Jan 2024
    5.4
    Medium

    CVE-2023-41710

    Last Modified: 4 Nov 2025

    User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added sanitization for this content. No publicly available exploits are known.

    Published: 8 Jan 2024
    5.4
    Medium

    CVE-2023-29052

    Last Modified: 4 Nov 2025

    Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added sanitization for this content. No publicly available exploits are known.

    Published: 8 Jan 2024
    8.1
    High

    CVE-2023-29051

    Last Modified: 4 Nov 2025

    User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature by default was not effective in this case. Unauthorized users could discover and modify application state, including objects related to other users and contexts. We now make sure that the switch to disable user-generated templates by default works as intended and will remove the feature in future generations of the product. No publicly available exploits are known.

    Published: 8 Jan 2024
    7.6
    High

    CVE-2023-29050

    Last Modified: 21 Nov 2024

    The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the intended hierarchy. Unauthorized users could break confidentiality of information in the directory and potentially cause high load on the directory server, leading to denial of service. Encoding has been added for user-provided fragments that are used when constructing the LDAP query. No publicly available exploits are known.

    Published: 8 Jan 2024
    5.4
    Medium

    CVE-2023-29049

    Last Modified: 17 Apr 2025

    The "upsell" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure users to a compromised account, or gain temporary access to a legitimate account, could inject script code to gain persistent code execution capabilities under a trusted domain. User input for this widget is now sanitized to avoid malicious content the be processed. No publicly available exploits are known.

    Published: 8 Jan 2024
    8.8
    High

    CVE-2023-29048

    Last Modified: 6 Jun 2025

    A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user. Users and attackers could run system commands with limited privilege to gain unauthorized access to confidential information and potentially violate integrity by modifying resources. The template engine has been reconfigured to deny execution of harmful commands on a system level. No publicly available exploits are known.

    Published: 8 Jan 2024
    9.1
    Critical

    CVE-2024-0322

    Last Modified: 3 Jun 2025

    Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

    Published: 8 Jan 2024
    9.8
    Critical

    CVE-2024-0321

    Last Modified: 16 May 2025

    Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.

    Published: 8 Jan 2024
    6.3
    Medium

    CVE-2024-0308

    Last Modified: 3 Jun 2025

    A vulnerability was found in Inis up to 2.0.1. It has been rated as critical. This issue affects some unknown processing of the file app/api/controller/default/Proxy.php. The manipulation of the argument p_url leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249875.

    Published: 8 Jan 2024
    7.3
    High

    CVE-2024-0307

    Last Modified: 17 Jun 2025

    A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login_process.php. The manipulation of the argument password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249874 is the identifier assigned to this vulnerability.

    Published: 8 Jan 2024
    7.3
    High

    CVE-2024-0306

    Last Modified: 17 Jun 2025

    A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been classified as critical. This affects an unknown part of the file /admin/admin_login_process.php. The manipulation of the argument admin_password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249873 was assigned to this vulnerability.

    Published: 8 Jan 2024
    5.3
    Medium

    CVE-2024-0305

    Last Modified: 21 Nov 2024

    A vulnerability was found in Guangzhou Yingke Electronic Technology Ncast up to 2017 and classified as problematic. Affected by this issue is some unknown functionality of the file /manage/IPSetup.php of the component Guest Login. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249872.

    Published: 8 Jan 2024
    6.3
    Medium

    CVE-2024-0304

    Last Modified: 3 Jun 2025

    A vulnerability has been found in Youke365 up to 1.5.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /app/api/controller/collect.php. The manipulation of the argument url leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249871.

    Published: 8 Jan 2024
    6.3
    Medium

    CVE-2024-0303

    Last Modified: 17 Jun 2025

    A vulnerability, which was classified as critical, was found in Youke365 up to 1.5.3. Affected is an unknown function of the file /app/api/controller/caiji.php of the component Parameter Handler. The manipulation of the argument url leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-249870 is the identifier assigned to this vulnerability.

    Published: 8 Jan 2024
    6.3
    Medium

    CVE-2024-0302

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in fhs-opensource iparking 1.5.22.RELEASE. This issue affects some unknown processing of the file /vueLogin. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249869 was assigned to this vulnerability.

    Published: 8 Jan 2024
    6.3
    Medium

    CVE-2024-0301

    Last Modified: 17 Jun 2025

    A vulnerability classified as critical was found in fhs-opensource iparking 1.5.22.RELEASE. This vulnerability affects the function getData of the file src/main/java/com/xhb/pay/action/PayTempOrderAction.java. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249868.

    Published: 8 Jan 2024
    4
    Medium

    CVE-2023-47140

    Last Modified: 21 Nov 2024

    IBM CICS Transaction Gateway 9.3 could allow a user to transfer or view files due to improper access controls.

    Published: 8 Jan 2024
    6.3
    Medium

    CVE-2024-0300

    Last Modified: 21 Nov 2024

    A vulnerability was found in Byzoro Smart S150 Management Platform up to 20240101. It has been rated as critical. Affected by this issue is some unknown functionality of the file /useratte/userattestation.php of the component HTTP POST Request Handler. The manipulation of the argument web_img leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-249866 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Jan 2024
    6.5
    Medium

    CVE-2023-50948

    Last Modified: 3 Jun 2025

    IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 275671.

    Published: 8 Jan 2024
    7.3
    High

    CVE-2024-0299

    Last Modified: 3 Jun 2025

    A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been declared as critical. Affected by this vulnerability is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249865 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Jan 2024
    3.5
    Low

    CVE-2023-7215

    Last Modified: 3 Jun 2025

    A vulnerability, which was classified as problematic, has been found in Chanzhaoyu chatgpt-web 2.11.1. This issue affects some unknown processing. The manipulation of the argument Description with the input <image src onerror=prompt(document.domain)> leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249779.

    Published: 8 Jan 2024
    7.3
    High

    CVE-2024-0298

    Last Modified: 3 Jun 2025

    A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been classified as critical. Affected is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249864. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Jan 2024
    7.3
    High

    CVE-2024-0297

    Last Modified: 12 May 2025

    A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. This issue affects the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249863. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Jan 2024
    7.3
    High

    CVE-2024-0296

    Last Modified: 17 Apr 2025

    A vulnerability has been found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. This vulnerability affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument host_time leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249862 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Jan 2024
    5.4
    Medium

    CVE-2023-51246

    Last Modified: 16 Jun 2025

    A Cross Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.16 exists when using Source Code Mode as a backend user to add articles via the /admin/edit.php page.

    Published: 8 Jan 2024
    9
    Critical

    CVE-2023-50982

    Last Modified: 3 Jun 2025

    Stud.IP 5.x through 5.3.3 allows XSS with resultant upload of executable files, because upload_action and edit_action in Admin_SmileysController do not check the file extension. This leads to remote code execution with the privileges of the www-data user. The fixed versions are 5.3.4, 5.2.6, 5.1.7, and 5.0.9.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2024-0582

    Last Modified: 20 Nov 2025

    A memory leak flaw was found in the Linux kernel’s io_uring functionality in how a user registers a buffer ring with IORING_REGISTER_PBUF_RING, mmap() it, and then frees it. This flaw allows a local user to crash or potentially escalate their privileges on the system.

    Published: 8 Jan 2024
    6.1
    Medium

    CVE-2023-27739

    Last Modified: 18 Jun 2025

    easyXDM 2.5 allows XSS via the xdm_e parameter.

    Published: 8 Jan 2024
    8.8
    High

    CVE-2023-47890

    Last Modified: 3 Jun 2025

    pyLoad 0.5.0 is vulnerable to Unrestricted File Upload.

    Published: 8 Jan 2024
    7.5
    High

    CVE-2023-49961

    Last Modified: 18 Jun 2025

    WALLIX Bastion 7.x, 8.x, 9.x and 10.x and WALLIX Access Manager 3.x and 4.x have Incorrect Access Control which can lead to sensitive data exposure.

    Published: 8 Jan 2024
    7.2
    High

    CVE-2023-50162

    Last Modified: 3 Jun 2025

    SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function.

    Published: 8 Jan 2024
    8.8
    High

    CVE-2023-52072

    Last Modified: 17 Apr 2025

    FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/userconfig_updagte.

    Published: 8 Jan 2024
    8.8
    High

    CVE-2023-52073

    Last Modified: 3 Jun 2025

    FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/config_footer_updagte.

    Published: 8 Jan 2024
    8.8
    High

    CVE-2023-52074

    Last Modified: 13 Jun 2025

    FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component system/site/webconfig_updagte.

    Published: 8 Jan 2024
    6.5
    Medium

    CVE-2023-52271

    Last Modified: 3 Jun 2025

    The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process Light) process via an IOCTL (which will be named at a later time).

    Published: 8 Jan 2024
    5.9
    Medium

    CVE-2024-21647

    Last Modified: 3 Nov 2025

    Puma is a web server for Ruby/Rack applications built for parallelism. Prior to version 6.4.2, puma exhibited incorrect behavior when parsing chunked transfer encoding bodies in a way that allowed HTTP request smuggling. Fixed versions limits the size of chunk extensions. Without this limit, an attacker could cause unbounded resource (CPU, network bandwidth) consumption. This vulnerability has been fixed in versions 6.4.2 and 5.6.8.

    Published: 8 Jan 2024
    10
    Critical

    CVE-2024-22216

    Last Modified: 18 Jun 2025

    In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured for remote system management, unauthorized access can occur, with data modification and information disclosure. This affects 3.00.23484 through 4.14.00.26064 (except for the patched versions 3.07.23980 and 4.07.00.25339).

    Published: 8 Jan 2024
    7.3
    High

    CVE-2024-0295

    Last Modified: 16 Jun 2025

    A vulnerability, which was classified as critical, was found in Totolink LR1200GB 9.1.0u.6619_B20230130. This affects the function setWanCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument hostName leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249861 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Jan 2024