CVE Feed

    Dashboard / CVE

    6
    Medium

    CVE-2023-23441

    Last Modified: 21 Nov 2024

    Some Honor products are affected by out of bounds read vulnerability, successful exploitation could cause information leak.

    Published: 29 Dec 2023
    3.3
    Low

    CVE-2023-23430

    Last Modified: 17 Apr 2025

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

    Published: 29 Dec 2023
    4
    Medium

    CVE-2023-23429

    Last Modified: 27 Jan 2026

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

    Published: 29 Dec 2023
    3.3
    Low

    CVE-2023-23428

    Last Modified: 27 Jan 2026

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

    Published: 29 Dec 2023
    5
    Medium

    CVE-2023-7148

    Last Modified: 21 Nov 2024

    A vulnerability has been found in ShifuML shifu 0.12.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file src/main/java/ml/shifu/shifu/core/DataPurifier.java of the component Java Expression Language Handler. The manipulation of the argument FilterExpression leads to code injection. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249151.

    Published: 29 Dec 2023
    4
    Medium

    CVE-2023-23427

    Last Modified: 27 Jan 2026

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

    Published: 29 Dec 2023
    6.6
    Medium

    CVE-2023-23426

    Last Modified: 21 Nov 2024

    Some Honor products are affected by file writing vulnerability, successful exploitation could cause information disclosure.

    Published: 29 Dec 2023
    6.5
    Medium

    CVE-2023-23424

    Last Modified: 27 Nov 2024

    Some Honor products are affected by file writing vulnerability, successful exploitation could cause code execution

    Published: 29 Dec 2023
    3.3
    Low

    CVE-2023-23440

    Last Modified: 21 Nov 2024

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

    Published: 29 Dec 2023
    4
    Medium

    CVE-2023-23439

    Last Modified: 21 Nov 2024

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

    Published: 29 Dec 2023
    6.3
    Medium

    CVE-2023-7147

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in gopeak MasterLab up to 3.3.10. Affected is the function base64ImageContent of the file app/ctrl/User.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. VDB-249150 is the identifier assigned to this vulnerability.

    Published: 29 Dec 2023
    4
    Medium

    CVE-2023-23438

    Last Modified: 21 Nov 2024

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions

    Published: 29 Dec 2023
    3.3
    Low

    CVE-2023-23437

    Last Modified: 21 Nov 2024

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak

    Published: 29 Dec 2023
    7.3
    High

    CVE-2023-23436

    Last Modified: 27 Jan 2026

    Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file

    Published: 29 Dec 2023
    4
    Medium

    CVE-2023-23435

    Last Modified: 27 Jan 2026

    Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file

    Published: 29 Dec 2023
    4
    Medium

    CVE-2023-23434

    Last Modified: 21 Nov 2024

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

    Published: 29 Dec 2023
    6.3
    Medium

    CVE-2023-7146

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in gopeak MasterLab up to 3.3.10. This issue affects the function sqlInjectDelete of the file app/ctrl/framework/Feature.php of the component HTTP POST Request Handler. The manipulation of the argument phone leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-249149 was assigned to this vulnerability.

    Published: 29 Dec 2023
    4
    Medium

    CVE-2023-23433

    Last Modified: 21 Nov 2024

    Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.

    Published: 29 Dec 2023
    7.3
    High

    CVE-2023-23431

    Last Modified: 21 Nov 2024

    Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.

    Published: 29 Dec 2023
    6.3
    Medium

    CVE-2023-7145

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in gopeak MasterLab up to 3.3.10. This vulnerability affects the function sqlInject of the file app/ctrl/Framework.php of the component HTTP POST Request Handler. The manipulation of the argument pwd leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249148.

    Published: 29 Dec 2023
    7.3
    High

    CVE-2023-23432

    Last Modified: 27 Nov 2024

    Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.

    Published: 29 Dec 2023
    6.3
    Medium

    CVE-2023-7144

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in gopeak MasterLab up to 3.3.10. This affects the function sqlInject of the file app/ctrl/framework/Feature.php of the component HTTP POST Request Handler. The manipulation of the argument pwd leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249147.

    Published: 29 Dec 2023
    2.4
    Low

    CVE-2023-7143

    Last Modified: 29 Oct 2025

    A vulnerability was found in code-projects Client Details System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/regester.php. The manipulation of the argument fname/lname/email/contact leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-249146 is the identifier assigned to this vulnerability.

    Published: 29 Dec 2023
    4.3
    Medium

    CVE-2023-7142

    Last Modified: 29 Oct 2025

    A vulnerability was found in code-projects Client Details System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/clientview.php. The manipulation of the argument ID leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-249145 was assigned to this vulnerability.

    Published: 29 Dec 2023
    3.3
    Low

    CVE-2023-52085

    Last Modified: 21 Nov 2024

    Winter is a free, open-source content management system. Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would then be included without further processing in the compilation of custom stylesheets via LESS. This had the potential to lead to a Local File Inclusion vulnerability. This issue has been patched in v1.2.4.

    Published: 29 Dec 2023
    6.1
    Medium

    CVE-2023-31299

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Barcode field of a container.

    Published: 29 Dec 2023
    4.8
    Medium

    CVE-2023-31298

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the User ID field when creating a new system user.

    Published: 29 Dec 2023
    6.1
    Medium

    CVE-2023-31301

    Last Modified: 21 Nov 2024

    Stored Cross Site Scripting (XSS) Vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the Username field of the login form and application log.

    Published: 29 Dec 2023
    5.5
    Medium

    CVE-2023-31292

    Last Modified: 17 Apr 2025

    An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obtain sensitive information and bypass authentication via "Back Button Refresh" attack.

    Published: 29 Dec 2023
    4.3
    Medium

    CVE-2023-31293

    Last Modified: 26 Nov 2024

    An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to obtain sensitive information and bypass profile restriction via improper access control in the Reader system user's web browser, allowing the journal to be displayed, despite the option being disabled.

    Published: 29 Dec 2023
    7.5
    High

    CVE-2023-31294

    Last Modified: 21 Nov 2024

    CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the Delivery Name field.

    Published: 29 Dec 2023
    7.5
    High

    CVE-2023-31295

    Last Modified: 21 Nov 2024

    CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the User Profile field.

    Published: 29 Dec 2023
    5.3
    Medium

    CVE-2023-31296

    Last Modified: 21 Nov 2024

    CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers to obtain sensitive information via the User Name field.

    Published: 29 Dec 2023
    7.5
    High

    CVE-2023-31300

    Last Modified: 17 Apr 2025

    An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via transmission of unencrypted, cleartext credentials during Password Reset feature.

    Published: 29 Dec 2023
    6.1
    Medium

    CVE-2023-31302

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Teller field.

    Published: 29 Dec 2023
    5.5
    Medium

    CVE-2023-50559

    Last Modified: 21 Nov 2024

    An issue was discovered in XiangShan v2.1, allows local attackers to obtain sensitive information via the L1D cache.

    Published: 29 Dec 2023
    7.8
    High

    CVE-2023-50571

    Last Modified: 21 Nov 2024

    easy-rules-mvel v4.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component MVELRule.

    Published: 29 Dec 2023
    9.8
    Critical

    CVE-2023-50035

    Last Modified: 21 Nov 2024

    PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is directly used in the SQL query without any sanitization and the SQL Injection payload being executed.

    Published: 29 Dec 2023
    8.8
    High

    CVE-2023-50070

    Last Modified: 21 Nov 2024

    Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_ticket via department_id, customer_id, and subject.

    Published: 29 Dec 2023
    8.8
    High

    CVE-2023-50071

    Last Modified: 21 Nov 2024

    Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_department via id or name.

    Published: 29 Dec 2023
    5.5
    Medium

    CVE-2023-50572

    Last Modified: 5 Sept 2025

    An issue in the component GroovyEngine.execute of jline-groovy v3.24.1 allows attackers to cause an OOM (OutofMemory) error.

    Published: 29 Dec 2023
    5.5
    Medium

    CVE-2023-50570

    Last Modified: 21 Nov 2024

    An issue in the component IPAddressBitsDivision of IPAddress v5.1.0 leads to an infinite loop. This is disputed because an infinite loop occurs only for cases in which the developer supplies invalid arguments. The product is not intended to always halt for contrived inputs.

    Published: 29 Dec 2023
    9.8
    Critical

    CVE-2023-52173

    Last Modified: 21 Nov 2024

    XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3ADBD0.

    Published: 29 Dec 2023
    9.8
    Critical

    CVE-2023-52174

    Last Modified: 21 Nov 2024

    XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3125D6.

    Published: 29 Dec 2023
    9.8
    Critical

    CVE-2023-23634

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in Documize version 5.4.2, allows remote attackers to execute arbitrary code via the user parameter of the /api/dashboard/activity endpoint.

    Published: 29 Dec 2023
    6.1
    Medium

    CVE-2023-50069

    Last Modified: 21 Nov 2024

    WireMock with GUI versions 3.2.0.0 through 3.0.4.0 are vulnerable to stored cross-site scripting (SXSS) through the recording feature. An attacker can host a malicious payload and perform a test mapping pointing to the attacker's file, and the result will render on the Matched page in the Body area, resulting in the execution of the payload. This occurs because the response body is not validated or sanitized.

    Published: 29 Dec 2023
    6.1
    Medium

    CVE-2023-52240

    Last Modified: 21 Nov 2024

    The Kantega SAML SSO OIDC Kerberos Single Sign-on apps before 6.20.0 for Atlassian products allow XSS if SAML POST Binding is enabled. This affects 4.4.2 through 4.14.8 before 4.14.9, 5.0.0 through 5.11.4 before 5.11.5, and 6.0.0 through 6.19.0 before 6.20.0. The full product names are Kantega SAML SSO OIDC Kerberos Single Sign-on for Jira Data Center & Server (Kantega SSO Enterprise), Kantega SAML SSO OIDC Kerberos Single Sign-on for Confluence Data Center & Server (Kantega SSO Enterprise), Kantega SAML SSO OIDC Kerberos Single Sign-on for Bitbucket Data Center & Server (Kantega SSO Enterprise), Kantega SAML SSO OIDC Kerberos Single Sign-on for Bamboo Data Center & Server (Kantega SSO Enterprise), and Kantega SAML SSO OIDC Kerberos Single Sign-on for FeCru Server (Kantega SSO Enterprise). (Here, FeCru refers to the Atlassian Fisheye and Crucible products running together.)

    Published: 29 Dec 2023
    4.3
    Medium

    CVE-2023-7141

    Last Modified: 29 Oct 2025

    A vulnerability was found in code-projects Client Details System 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/update-clients.php. The manipulation of the argument uid leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249144.

    Published: 28 Dec 2023
    4.3
    Medium

    CVE-2023-7140

    Last Modified: 29 Oct 2025

    A vulnerability was found in code-projects Client Details System 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/manage-users.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249143.

    Published: 28 Dec 2023
    4.3
    Medium

    CVE-2023-7139

    Last Modified: 29 Oct 2025

    A vulnerability has been found in code-projects Client Details System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/regester.php of the component HTTP POST Request Handler. The manipulation of the argument fname/lname/email/contact leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-249142 is the identifier assigned to this vulnerability.

    Published: 28 Dec 2023