CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2023-7188

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in Shipping 100 Fahuo100 up to 1.1. Affected is an unknown function of the file member/login.php. The manipulation of the argument M_pwd leads to sql injection. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. VDB-249390 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Dec 2023
    5.5
    Medium

    CVE-2023-7187

    Last Modified: 21 Nov 2024

    A vulnerability was found in Totolink N350RT 9.3.5u.6139_B20201216. It has been rated as critical. This issue affects some unknown processing of the file /cgi-bin/cstecgi.cgi?action=login&flag=ie8 of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow. The exploit has been disclosed to the public and may be used. The identifier VDB-249389 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Dec 2023
    5.5
    Medium

    CVE-2023-7186

    Last Modified: 21 Nov 2024

    A vulnerability was found in 7-card Fakabao up to 1.0_build20230805. It has been declared as critical. This vulnerability affects unknown code of the file member/notify.php. The manipulation of the argument out_trade_no leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249388. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Dec 2023
    5.5
    Medium

    CVE-2023-7185

    Last Modified: 21 Nov 2024

    A vulnerability was found in 7-card Fakabao up to 1.0_build20230805. It has been classified as critical. This affects an unknown part of the file shop/wxpay_notify.php. The manipulation of the argument out_trade_no leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249387. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Dec 2023
    5.5
    Medium

    CVE-2023-7184

    Last Modified: 21 Nov 2024

    A vulnerability was found in 7-card Fakabao up to 1.0_build20230805 and classified as critical. Affected by this issue is some unknown functionality of the file shop/notify.php. The manipulation of the argument out_trade_no leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-249386 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Dec 2023
    5.5
    Medium

    CVE-2023-7183

    Last Modified: 17 Apr 2025

    A vulnerability has been found in 7-card Fakabao up to 1.0_build20230805 and classified as critical. Affected by this vulnerability is an unknown functionality of the file shop/alipay_notify.php. The manipulation of the argument out_trade_no leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-249385 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Dec 2023
    7.6
    High

    CVE-2023-52180

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes.This issue affects Recipe Maker For Your Food Blog from Zip Recipes: from n/a through 8.1.0.

    Published: 31 Dec 2023
    9.1
    Critical

    CVE-2023-49777

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Product Add-Ons.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.3.0.

    Published: 31 Dec 2023
    10
    Critical

    CVE-2023-52181

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in Presslabs Theme per user.This issue affects Theme per user: from n/a through 1.0.1.

    Published: 31 Dec 2023
    9
    Critical

    CVE-2023-39157

    Last Modified: 28 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.10.

    Published: 31 Dec 2023
    5.3
    Medium

    CVE-2023-6094

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior. The vulnerability results from lack of protection for sensitive information during transmission. An attacker eavesdropping on the traffic between the web browser and server may obtain sensitive information. This type of attack could be executed to gather sensitive information or to facilitate a subsequent attack against the target.

    Published: 31 Dec 2023
    9.9
    Critical

    CVE-2023-52182

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz – WordPress Quizzes Builder: from n/a through 1.3.0.

    Published: 31 Dec 2023
    5.3
    Medium

    CVE-2023-6093

    Last Modified: 21 Nov 2024

    A clickjacking vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior. This vulnerability is caused by incorrectly restricts frame objects, which can lead to user confusion about which interface the user is interacting with. This vulnerability may lead the attacker to trick the user into interacting with the application.

    Published: 31 Dec 2023
    6.3
    Medium

    CVE-2023-7130

    Last Modified: 21 Nov 2024

    A vulnerability has been found in code-projects College Notes Gallery 2.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file login.php. The manipulation of the argument user leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-249133 was assigned to this vulnerability.

    Published: 31 Dec 2023
    5.5
    Medium

    CVE-2023-52284

    Last Modified: 21 Nov 2024

    Bytecode Alliance wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) before 1.3.0 can have an "double free or corruption" error for a valid WebAssembly module because push_pop_frame_ref_offset is mishandled.

    Published: 31 Dec 2023
    7.5
    High

    CVE-2023-52286

    Last Modified: 21 Nov 2024

    Tencent tdsqlpcloud through 1.8.5 allows unauthenticated remote attackers to discover database credentials via an index.php/api/install/get_db_info request, a related issue to CVE-2023-42387.

    Published: 31 Dec 2023
    7.5
    High

    CVE-2021-46901

    Last Modified: 21 Nov 2024

    examples/6lbr/apps/6lbr-webserver/httpd.c in CETIC-6LBR (aka 6lbr) 1.5.0 has a strcat stack-based buffer overflow via a request for a long URL over a 6LoWPAN network.

    Published: 31 Dec 2023
    7.5
    High

    CVE-2021-46900

    Last Modified: 17 Apr 2025

    Sympa before 6.2.62 relies on a cookie parameter for certain security objectives, but does not ensure that this parameter exists and has an unpredictable value. Specifically, the cookie parameter is both a salt for stored passwords and an XSS protection mechanism.

    Published: 31 Dec 2023
    4.8
    Medium

    CVE-2023-52269

    Last Modified: 21 Nov 2024

    MDaemon SecurityGateway through 9.0.3 allows XSS via a crafted Message Content Filtering rule. This might allow domain administrators to conduct attacks against global administrators.

    Published: 31 Dec 2023
    2.1
    Low

    CVE-2023-52275

    Last Modified: 21 Nov 2024

    Gallery3d on Tecno Camon X CA7 devices allows attackers to view hidden images by navigating to data/com.android.gallery3d/.privatealbum/.encryptfiles and guessing the correct image file extension.

    Published: 31 Dec 2023
    7.8
    High

    CVE-2023-52277

    Last Modified: 21 Nov 2024

    Royal RoyalTSX before 6.0.2.1 allows attackers to cause a denial of service (Heap Memory Corruption and application crash) or possibly have unspecified other impact via a long hostname in an RTSZ file, if the victim clicks on Test Connection. This occurs during SecureGatewayHost object processing in RAPortCheck.createNWConnection.

    Published: 31 Dec 2023
    7.7
    High

    CVE-2023-6998

    Last Modified: 21 Nov 2024

    Improper privilege management vulnerability in CoolKit Technology eWeLink on Android and iOS allows application lockscreen bypass.This issue affects eWeLink before 5.2.0.

    Published: 30 Dec 2023
    4.7
    Medium

    CVE-2023-7181

    Last Modified: 21 Nov 2024

    A vulnerability was found in Muyun DedeBIZ up to 6.2.12 and classified as critical. Affected by this issue is some unknown functionality of the component Add Attachment Handler. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249368. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 30 Dec 2023
    5.5
    Medium

    CVE-2023-7180

    Last Modified: 19 Mar 2025

    A vulnerability has been found in Tongda OA 2017 up to 11.9 and classified as critical. Affected by this vulnerability is an unknown functionality of the file general/project/proj/delete.php. The manipulation of the argument PROJ_ID_STR leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-249367. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 30 Dec 2023
    4.7
    Medium

    CVE-2023-7179

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in Campcodes Online College Library System 1.0. Affected is an unknown function of the file /admin/category_row.php of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-249366 is the identifier assigned to this vulnerability.

    Published: 30 Dec 2023
    4.7
    Medium

    CVE-2023-7178

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in Campcodes Online College Library System 1.0. This issue affects some unknown processing of the file /admin/book_row.php of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249365 was assigned to this vulnerability.

    Published: 30 Dec 2023
    8.8
    High

    CVE-2023-49299

    Last Modified: 13 Feb 2025

    Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server.This issue affects Apache DolphinScheduler: until 3.1.9. Users are recommended to upgrade to version 3.1.9, which fixes the issue.

    Published: 30 Dec 2023
    4.7
    Medium

    CVE-2023-7177

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in Campcodes Online College Library System 1.0. This vulnerability affects unknown code of the file /admin/book_add.php of the component HTTP POST Request Handler. The manipulation of the argument category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249364.

    Published: 30 Dec 2023
    4.7
    Medium

    CVE-2023-7176

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in Campcodes Online College Library System 1.0. This affects an unknown part of the file /admin/return_add.php of the component HTTP POST Request Handler. The manipulation of the argument student leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249363.

    Published: 30 Dec 2023
    4.7
    Medium

    CVE-2023-7175

    Last Modified: 17 Apr 2025

    A vulnerability was found in Campcodes Online College Library System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/borrow_add.php of the component HTTP POST Request Handler. The manipulation of the argument student leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-249362 is the identifier assigned to this vulnerability.

    Published: 30 Dec 2023
    4.3
    Medium

    CVE-2023-7173

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file registration.php. The manipulation of the argument First Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249357 was assigned to this vulnerability.

    Published: 30 Dec 2023
    4.3
    Medium

    CVE-2018-25096

    Last Modified: 21 Nov 2024

    A vulnerability was found in MdAlAmin-aol Own Health Record 0.1-alpha/0.2-alpha/0.3-alpha/0.3.1-alpha. It has been rated as problematic. This issue affects some unknown processing of the file includes/logout.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. Upgrading to version 0.4-alpha is able to address this issue. The patch is named 58b413aa40820b49070782c786c526850ab7748f. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-249191.

    Published: 30 Dec 2023
    7.3
    High

    CVE-2023-7172

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the component Admin Dashboard. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249356.

    Published: 30 Dec 2023
    9.8
    Critical

    CVE-2023-50651

    Last Modified: 17 Apr 2025

    TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi.

    Published: 30 Dec 2023
    5.5
    Medium

    CVE-2022-46486

    Last Modified: 21 Nov 2024

    A lack of pointer-validation logic in the __scone_dispatch component of SCONE before v5.8.0 for Intel SGX allows attackers to access sensitive information.

    Published: 30 Dec 2023
    7.8
    High

    CVE-2022-46487

    Last Modified: 17 Apr 2025

    Improper initialization of x87 and SSE floating-point configuration registers in the __scone_entry component of SCONE before 5.8.0 for Intel SGX allows a local attacker to compromise the execution integrity of floating-point operations in an enclave or access sensitive information via side-channel analysis.

    Published: 30 Dec 2023
    9.8
    Critical

    CVE-2023-51136

    Last Modified: 21 Nov 2024

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formRebootSchedule.

    Published: 30 Dec 2023
    5.5
    Medium

    CVE-2023-38021

    Last Modified: 21 Nov 2024

    An issue was discovered in Fortanix EnclaveOS Confidential Computing Manager (CCM) Platform before 3.32 for Intel SGX. Lack of pointer-alignment validation logic in entry functions allows a local attacker to access unauthorized information. This relates to the enclave_ecall function and system call layer.

    Published: 30 Dec 2023
    5.5
    Medium

    CVE-2023-38022

    Last Modified: 21 Nov 2024

    An issue was discovered in Fortanix EnclaveOS Confidential Computing Manager (CCM) Platform before 3.29 for Intel SGX. Insufficient pointer validation allows a local attacker to access unauthorized information. This relates to strlen and sgx_is_within_user.

    Published: 30 Dec 2023
    5.5
    Medium

    CVE-2023-38023

    Last Modified: 21 Nov 2024

    An issue was discovered in SCONE Confidential Computing Platform before 5.8.0 for Intel SGX. Lack of pointer-alignment logic in __scone_dispatch and other entry functions allows a local attacker to access unauthorized information, aka an "AEPIC Leak."

    Published: 30 Dec 2023
    9.8
    Critical

    CVE-2023-41542

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the jmreport/qurestSql component.

    Published: 30 Dec 2023
    9.8
    Critical

    CVE-2023-41543

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in jeecg-boot v3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the component /sys/replicate/check.

    Published: 30 Dec 2023
    9.8
    Critical

    CVE-2023-41544

    Last Modified: 21 Nov 2024

    SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component.

    Published: 30 Dec 2023
    7.5
    High

    CVE-2023-50110

    Last Modified: 21 Nov 2024

    TestLink through 1.9.20 allows type juggling for authentication bypass because === is not used.

    Published: 30 Dec 2023
    9.8
    Critical

    CVE-2023-50578

    Last Modified: 21 Nov 2024

    Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.

    Published: 30 Dec 2023
    5.4
    Medium

    CVE-2023-50550

    Last Modified: 21 Nov 2024

    layui up to v2.74 was discovered to contain a cross-site scripting (XSS) vulnerability via the data-content parameter.

    Published: 30 Dec 2023
    9.8
    Critical

    CVE-2023-50589

    Last Modified: 21 Nov 2024

    Grupo Embras GEOSIAP ERP v2.2.167.02 was discovered to contain a SQL injection vulnerability via the codLogin parameter on the login page.

    Published: 30 Dec 2023
    9.8
    Critical

    CVE-2023-51135

    Last Modified: 21 Nov 2024

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formPasswordSetup.

    Published: 30 Dec 2023
    9.8
    Critical

    CVE-2023-51133

    Last Modified: 21 Nov 2024

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formRoute.

    Published: 30 Dec 2023
    7.5
    High

    CVE-2023-52266

    Last Modified: 21 Nov 2024

    ehttp 1.0.6 before 17405b9 has an epoll_socket.cpp read_func use-after-free. An attacker can make many connections over a short time to trigger this.

    Published: 30 Dec 2023