CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2018-25097

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, was found in Acumos Design Studio up to 2.0.7. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 2.0.8 is able to address this issue. The name of the patch is 0df8a5e8722188744973168648e4c74c69ce67fd. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-249420.

    Published: 2 Jan 2024
    5.3
    Medium

    CVE-2024-0191

    Last Modified: 3 Jun 2025

    A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/uploads/. The manipulation leads to file and directory information exposure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249504.

    Published: 2 Jan 2024
    3.5
    Low

    CVE-2024-0190

    Last Modified: 17 Jun 2025

    A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0 and classified as problematic. This issue affects some unknown processing of the file add_quiz.php of the component Quiz Handler. The manipulation of the argument Quiz Title/Quiz Description with the input </title><scRipt>alert(x)</scRipt> leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249503.

    Published: 2 Jan 2024
    2.6
    Low

    CVE-2017-20188

    Last Modified: 3 Jun 2025

    A vulnerability has been found in Zimbra zm-ajax up to 8.8.1 and classified as problematic. Affected by this vulnerability is the function XFormItem.prototype.setError of the file WebRoot/js/ajax/dwt/xforms/XFormItem.js. The manipulation of the argument message leads to cross site scripting. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 8.8.2 is able to address this issue. The identifier of the patch is 8d039d6efe80780adc40c6f670c06d21de272105. It is recommended to upgrade the affected component. The identifier VDB-249421 was assigned to this vulnerability.

    Published: 2 Jan 2024
    3.5
    Low

    CVE-2024-0189

    Last Modified: 9 May 2025

    A vulnerability has been found in RRJ Nueva Ecija Engineer Online Portal 1.0 and classified as problematic. This vulnerability affects unknown code of the file teacher_message.php of the component Create Message Handler. The manipulation of the argument Content with the input </title><scRipt>alert(x)</scRipt> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249502 is the identifier assigned to this vulnerability.

    Published: 2 Jan 2024
    3.5
    Low

    CVE-2015-10128

    Last Modified: 17 Apr 2025

    A vulnerability was found in rt-prettyphoto Plugin up to 1.2 on WordPress and classified as problematic. Affected by this issue is the function royal_prettyphoto_plugin_links of the file rt-prettyphoto.php. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 1.3 is able to address this issue. The patch is identified as 0d3d38cfa487481b66869e4212df1cefc281ecb7. It is recommended to upgrade the affected component. VDB-249422 is the identifier assigned to this vulnerability.

    Published: 2 Jan 2024
    —
    Unknown

    CVE-2024-0198

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Jan 2024
    9.8
    Critical

    CVE-2023-6436

    Last Modified: 20 May 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ekol Informatics Website Template allows SQL Injection. This issue affects Website Template: through 20231215.

    Published: 2 Jan 2024
    3.1
    Low

    CVE-2024-0188

    Last Modified: 17 Jun 2025

    A vulnerability, which was classified as problematic, was found in RRJ Nueva Ecija Engineer Online Portal 1.0. This affects an unknown part of the file change_password_teacher.php. The manipulation leads to weak password requirements. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-249501 was assigned to this vulnerability.

    Published: 2 Jan 2024
    4.3
    Medium

    CVE-2023-47858

    Last Modified: 17 Jun 2025

    Mattermost fails to properly verify the permissions needed for viewing archived public channels,  allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams/<team-id>/channels/deleted endpoint.

    Published: 2 Jan 2024
    3.7
    Low

    CVE-2023-50333

    Last Modified: 17 Jun 2025

    Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change group names.

    Published: 2 Jan 2024
    4.3
    Medium

    CVE-2023-48732

    Last Modified: 3 Jun 2025

    Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSocket broadcasting the information about who was notified about a post to everyone else in the channel.

    Published: 2 Jan 2024
    4
    Medium

    CVE-2023-49142

    Last Modified: 17 Jun 2025

    in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia audio crash through modify a released pointer.

    Published: 2 Jan 2024
    4
    Medium

    CVE-2023-49135

    Last Modified: 21 Nov 2024

    in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.

    Published: 2 Jan 2024
    4
    Medium

    CVE-2023-48360

    Last Modified: 17 Jun 2025

    in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.

    Published: 2 Jan 2024
    4
    Medium

    CVE-2023-47857

    Last Modified: 3 Jun 2025

    in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia camera crash through modify a released pointer.

    Published: 2 Jan 2024
    2.9
    Low

    CVE-2023-47216

    Last Modified: 17 Apr 2025

    in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through occupy all resources

    Published: 2 Jan 2024
    8.4
    High

    CVE-2023-43514

    Last Modified: 11 Aug 2025

    Memory corruption while invoking IOCTLs calls from user space for internal mem MAP and internal mem UNMAP.

    Published: 2 Jan 2024
    7.5
    High

    CVE-2023-43512

    Last Modified: 21 Nov 2024

    Transient DOS while parsing GATT service data when the total amount of memory that is required by the multiple services is greater than the actual size of the services buffer.

    Published: 2 Jan 2024
    7.5
    High

    CVE-2023-43511

    Last Modified: 11 Aug 2025

    Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.

    Published: 2 Jan 2024
    7.8
    High

    CVE-2023-33120

    Last Modified: 11 Aug 2025

    Memory corruption in Audio when memory map command is executed consecutively in ADSP.

    Published: 2 Jan 2024
    7.8
    High

    CVE-2023-33118

    Last Modified: 11 Aug 2025

    Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL.

    Published: 2 Jan 2024
    7.8
    High

    CVE-2023-33117

    Last Modified: 11 Aug 2025

    Memory corruption when HLOS allocates the response payload buffer to copy the data received from ADSP in response to AVCS_LOAD_MODULE command.

    Published: 2 Jan 2024
    7.5
    High

    CVE-2023-33116

    Last Modified: 17 Jun 2025

    Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver.

    Published: 2 Jan 2024
    8.4
    High

    CVE-2023-33114

    Last Modified: 11 Aug 2025

    Memory corruption while running NPU, when NETWORK_UNLOAD and (NETWORK_UNLOAD or NETWORK_EXECUTE_V2) commands are submitted at the same time.

    Published: 2 Jan 2024
    8.4
    High

    CVE-2023-33113

    Last Modified: 11 Aug 2025

    Memory corruption when resource manager sends the host kernel a reply message with multiple fragments.

    Published: 2 Jan 2024
    7.5
    High

    CVE-2023-33112

    Last Modified: 11 Aug 2025

    Transient DOS when WLAN firmware receives "reassoc response" frame including RIC_DATA element.

    Published: 2 Jan 2024
    7.8
    High

    CVE-2023-33110

    Last Modified: 21 May 2025

    The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.

    Published: 2 Jan 2024
    7.5
    High

    CVE-2023-33109

    Last Modified: 11 Aug 2025

    Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.

    Published: 2 Jan 2024
    8.4
    High

    CVE-2023-33108

    Last Modified: 11 Aug 2025

    Memory corruption in Graphics Driver when destroying a context with KGSL_GPU_AUX_COMMAND_TIMELINE objects queued.

    Published: 2 Jan 2024
    8.4
    High

    CVE-2023-33094

    Last Modified: 11 Aug 2025

    Memory corruption while running VK synchronization with KASAN enabled.

    Published: 2 Jan 2024
    7.8
    High

    CVE-2023-33085

    Last Modified: 11 Aug 2025

    Memory corruption in wearables while processing data from AON.

    Published: 2 Jan 2024
    7.5
    High

    CVE-2023-33062

    Last Modified: 11 Aug 2025

    Transient DOS in WLAN Firmware while parsing a BTM request.

    Published: 2 Jan 2024
    7.5
    High

    CVE-2023-33040

    Last Modified: 3 Jun 2025

    Transient DOS in Data Modem during DTLS handshake.

    Published: 2 Jan 2024
    6.7
    Medium

    CVE-2023-33038

    Last Modified: 21 Nov 2024

    Memory corruption while receiving a message in Bus Socket Transport Server.

    Published: 2 Jan 2024
    7.1
    High

    CVE-2023-33037

    Last Modified: 17 Jun 2025

    Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data.

    Published: 2 Jan 2024
    7.1
    High

    CVE-2023-33036

    Last Modified: 21 Nov 2024

    Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call.

    Published: 2 Jan 2024
    8.4
    High

    CVE-2023-33033

    Last Modified: 21 May 2025

    Memory corruption in Audio during playback with speaker protection.

    Published: 2 Jan 2024
    9.3
    Critical

    CVE-2023-33032

    Last Modified: 16 Jun 2025

    Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.

    Published: 2 Jan 2024
    9.3
    Critical

    CVE-2023-33030

    Last Modified: 3 Jun 2025

    Memory corruption in HLOS while running playready use-case.

    Published: 2 Jan 2024
    9.8
    Critical

    CVE-2023-33025

    Last Modified: 17 Apr 2025

    Memory corruption in Data Modem when a non-standard SDP body, during a VOLTE call.

    Published: 2 Jan 2024
    7.6
    High

    CVE-2023-33014

    Last Modified: 3 Jun 2025

    Information disclosure in Core services while processing a Diag command.

    Published: 2 Jan 2024
    6.7
    Medium

    CVE-2023-28583

    Last Modified: 17 Jun 2025

    Memory corruption when IPv6 prefix timer object`s lifetime expires which are created while Netmgr daemon gets an IPv6 address.

    Published: 2 Jan 2024
    —
    Unknown

    CVE-2023-52319

    Last Modified: 17 Mar 2025

    This CVE Record has been withdrawn by its CNA.

    Published: 2 Jan 2024
    —
    Unknown

    CVE-2023-52320

    Last Modified: 17 Mar 2025

    This CVE Record has been withdrawn by its CNA.

    Published: 2 Jan 2024
    —
    Unknown

    CVE-2023-52321

    Last Modified: 17 Mar 2025

    This CVE Record has been withdrawn by its CNA.

    Published: 2 Jan 2024
    —
    Unknown

    CVE-2023-52315

    Last Modified: 17 Mar 2025

    This CVE Record has been withdrawn by its CNA.

    Published: 2 Jan 2024
    —
    Unknown

    CVE-2023-52316

    Last Modified: 17 Mar 2025

    This CVE Record has been withdrawn by its CNA.

    Published: 2 Jan 2024
    —
    Unknown

    CVE-2023-52317

    Last Modified: 17 Mar 2025

    This CVE Record has been withdrawn by its CNA.

    Published: 2 Jan 2024
    —
    Unknown

    CVE-2023-52318

    Last Modified: 17 Mar 2025

    This CVE Record has been withdrawn by its CNA.

    Published: 2 Jan 2024