CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2023-26157

    Last Modified: 21 Nov 2024

    Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c.

    Published: 2 Jan 2024
    6.7
    Medium

    CVE-2023-32891

    Last Modified: 18 Jun 2025

    In bluetooth service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07933038; Issue ID: MSV-559.

    Published: 2 Jan 2024
    5.5
    Medium

    CVE-2023-32831

    Last Modified: 18 Jun 2025

    In wlan driver, there is a possible PIN crack due to use of insufficiently random values. This could lead to local information disclosure with no execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00325055; Issue ID: MSV-868.

    Published: 2 Jan 2024
    7.5
    High

    CVE-2023-32890

    Last Modified: 21 Nov 2024

    In modem EMM, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01183647; Issue ID: MOLY01183647 (MSV-963).

    Published: 2 Jan 2024
    7.5
    High

    CVE-2023-32889

    Last Modified: 18 Jun 2025

    In Modem IMS Call UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161825; Issue ID: MOLY01161825 (MSV-895).

    Published: 2 Jan 2024
    7.5
    High

    CVE-2023-32888

    Last Modified: 16 May 2025

    In Modem IMS Call UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161830; Issue ID: MOLY01161830 (MSV-894).

    Published: 2 Jan 2024
    7.5
    High

    CVE-2023-32887

    Last Modified: 16 Jun 2025

    In Modem IMS Stack, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161837; Issue ID: MOLY01161837 (MSV-892).

    Published: 2 Jan 2024
    7.5
    High

    CVE-2023-32886

    Last Modified: 3 Jun 2025

    In Modem IMS SMS UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00730807; Issue ID: MOLY00730807.

    Published: 2 Jan 2024
    6.7
    Medium

    CVE-2023-32885

    Last Modified: 17 Apr 2025

    In display drm, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07780685; Issue ID: ALPS07780685.

    Published: 2 Jan 2024
    6.7
    Medium

    CVE-2023-32884

    Last Modified: 3 Jun 2025

    In netdagent, there is a possible information disclosure due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07944011; Issue ID: ALPS07944011.

    Published: 2 Jan 2024
    6.7
    Medium

    CVE-2023-32883

    Last Modified: 3 Jun 2025

    In Engineer Mode, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08282249; Issue ID: ALPS08282249.

    Published: 2 Jan 2024
    6.7
    Medium

    CVE-2023-32882

    Last Modified: 18 Jun 2025

    In battery, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308616.

    Published: 2 Jan 2024
    4.4
    Medium

    CVE-2023-32881

    Last Modified: 18 Jun 2025

    In battery, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308080.

    Published: 2 Jan 2024
    4.4
    Medium

    CVE-2023-32880

    Last Modified: 16 Jun 2025

    In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308076.

    Published: 2 Jan 2024
    6.7
    Medium

    CVE-2023-32879

    Last Modified: 18 Jun 2025

    In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308064.

    Published: 2 Jan 2024
    4.4
    Medium

    CVE-2023-32878

    Last Modified: 16 May 2025

    In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08307992.

    Published: 2 Jan 2024
    6.7
    Medium

    CVE-2023-32877

    Last Modified: 17 Jun 2025

    In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308070.

    Published: 2 Jan 2024
    4.4
    Medium

    CVE-2023-32876

    Last Modified: 3 Jun 2025

    In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308612; Issue ID: ALPS08308612.

    Published: 2 Jan 2024
    4.4
    Medium

    CVE-2023-32875

    Last Modified: 16 Jun 2025

    In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308607; Issue ID: ALPS08304217.

    Published: 2 Jan 2024
    9.8
    Critical

    CVE-2023-32874

    Last Modified: 17 Apr 2025

    In Modem IMS Stack, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161803; Issue ID: MOLY01161803 (MSV-893).

    Published: 2 Jan 2024
    6.7
    Medium

    CVE-2023-32872

    Last Modified: 3 Jun 2025

    In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308607; Issue ID: ALPS08308607.

    Published: 2 Jan 2024
    7.8
    High

    CVE-2024-0193

    Last Modified: 5 Jun 2026

    A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, the element can be deactivated twice. This can cause a use-after-free issue on an NFT_CHAIN object or NFT_OBJECT object, allowing a local unprivileged user with CAP_NET_ADMIN capability to escalate their privileges on the system.

    Published: 2 Jan 2024
    3.8
    Low

    CVE-2020-26624

    Last Modified: 17 Jun 2025

    A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.

    Published: 2 Jan 2024
    3.8
    Low

    CVE-2020-26623

    Last Modified: 3 Jun 2025

    SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.

    Published: 2 Jan 2024
    3.8
    Low

    CVE-2020-26625

    Last Modified: 16 May 2025

    A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the 'user_id' parameter after the login portal.

    Published: 2 Jan 2024
    7.5
    High

    CVE-2023-49549

    Last Modified: 16 Jun 2025

    An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_getretvalpos function in the msj.c file.

    Published: 2 Jan 2024
    5.5
    Medium

    CVE-2023-49554

    Last Modified: 18 Jun 2025

    Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_directive function in the modules/preprocs/nasm/nasm-pp.c component.

    Published: 2 Jan 2024
    5.5
    Medium

    CVE-2023-49557

    Last Modified: 18 Jun 2025

    An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasm/section.c component.

    Published: 2 Jan 2024
    5.3
    Medium

    CVE-2023-45561

    Last Modified: 13 Jun 2025

    An issue in A-WORLD OIRASE BEER_waiting Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.

    Published: 2 Jan 2024
    7.5
    High

    CVE-2023-45892

    Last Modified: 13 May 2025

    An issue discovered in the Order and Invoice pages in Floorsight Insights Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.

    Published: 2 Jan 2024
    7.5
    High

    CVE-2023-45893

    Last Modified: 21 Nov 2024

    An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.

    Published: 2 Jan 2024
    9.8
    Critical

    CVE-2023-47458

    Last Modified: 17 Apr 2025

    An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.

    Published: 2 Jan 2024
    5.5
    Medium

    CVE-2023-49555

    Last Modified: 17 Jun 2025

    An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the modules/preprocs/nasm/nasm-pp.c component.

    Published: 2 Jan 2024
    5.5
    Medium

    CVE-2023-49556

    Last Modified: 3 Jun 2025

    Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_delete_term function in the libyasm/expr.c component.

    Published: 2 Jan 2024
    7.5
    High

    CVE-2023-49550

    Last Modified: 16 May 2025

    An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component.

    Published: 2 Jan 2024
    7.5
    High

    CVE-2023-49551

    Last Modified: 21 Nov 2024

    An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_parse function in the msj.c file.

    Published: 2 Jan 2024
    7.5
    High

    CVE-2023-49552

    Last Modified: 17 Apr 2025

    An Out of Bounds Write in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_stringify function in the msj.c file.

    Published: 2 Jan 2024
    7.5
    High

    CVE-2023-49553

    Last Modified: 3 Jun 2025

    An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_destroy function in the msj.c file.

    Published: 2 Jan 2024
    5.5
    Medium

    CVE-2023-49558

    Last Modified: 3 Jun 2025

    An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the modules/preprocs/nasm/nasm-pp.c component.

    Published: 2 Jan 2024
    5.9
    Medium

    CVE-2023-50019

    Last Modified: 17 Apr 2025

    An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response.

    Published: 2 Jan 2024
    7.5
    High

    CVE-2023-50020

    Last Modified: 18 Jun 2025

    An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.

    Published: 2 Jan 2024
    7.3
    High

    CVE-2023-26159

    Last Modified: 3 Nov 2025

    Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error, it can be manipulated to misinterpret the hostname. An attacker could exploit this weakness to redirect traffic to a malicious site, potentially leading to information disclosure, phishing attacks, or other security breaches.

    Published: 2 Jan 2024
    4.9
    Medium

    CVE-2023-6693

    Last Modified: 25 Feb 2026

    A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if guest features VIRTIO_NET_F_HASH_REPORT, VIRTIO_F_VERSION_1 and VIRTIO_NET_F_MRG_RXBUF are enabled. This could allow a malicious user to overwrite local variables allocated on the stack. Specifically, the `out_sg` variable could be used to read a part of process memory and send it to the wire, causing an information leak.

    Published: 2 Jan 2024
    3.7
    Low

    CVE-2024-0186

    Last Modified: 3 Jun 2025

    A vulnerability classified as problematic has been found in HuiRan Host Reseller System up to 2.0.0. Affected is an unknown function of the file /user/index/findpass?do=4 of the component HTTP POST Request Handler. The manipulation leads to weak password recovery. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249444.

    Published: 1 Jan 2024
    4.7
    Medium

    CVE-2024-0185

    Last Modified: 21 Nov 2024

    A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been rated as critical. This issue affects some unknown processing of the file dasboard_teacher.php of the component Avatar Handler. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249443.

    Published: 1 Jan 2024
    2.4
    Low

    CVE-2024-0184

    Last Modified: 17 Jun 2025

    A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/edit_teacher.php of the component Add Enginer. The manipulation of the argument Firstname/Lastname leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249442 is the identifier assigned to this vulnerability.

    Published: 1 Jan 2024
    2.4
    Low

    CVE-2024-0183

    Last Modified: 13 May 2025

    A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/students.php of the component NIA Office. The manipulation leads to basic cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249441 was assigned to this vulnerability.

    Published: 1 Jan 2024
    7.3
    High

    CVE-2024-0182

    Last Modified: 3 Jun 2025

    A vulnerability was found in SourceCodester Engineers Online Portal 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/ of the component Admin Login. The manipulation of the argument username/password leads to sql injection. The attack may be launched remotely. The identifier of this vulnerability is VDB-249440.

    Published: 1 Jan 2024
    7.5
    High

    CVE-2023-6113

    Last Modified: 18 Jun 2025

    The WP STAGING WordPress Backup Plugin before 3.1.3 and WP STAGING Pro WordPress Backup Plugin before 5.1.3 do not prevent visitors from leaking key information about ongoing backups processes, allowing unauthenticated attackers to download said backups later.

    Published: 1 Jan 2024
    9.8
    Critical

    CVE-2023-5877

    Last Modified: 3 Jun 2025

    The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, including RFC1918 private addresses, leading to a Server Side Request Forgery (SSRF) issue.

    Published: 1 Jan 2024