CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2023-51099

    Last Modified: 21 Nov 2024

    Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formexeCommand .

    Published: 26 Dec 2023
    5.4
    Medium

    CVE-2023-27150

    Last Modified: 21 Nov 2024

    openCRX 5.2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name field after creation of a Tracker in Manage Activity.

    Published: 26 Dec 2023
    7.5
    High

    CVE-2023-28616

    Last Modified: 21 Nov 2024

    An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space character. The serverd process logs such passwords in cleartext, and potentially sends these logs to the Syslog component.

    Published: 26 Dec 2023
    9.8
    Critical

    CVE-2023-51092

    Last Modified: 21 Nov 2024

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function upgrade.

    Published: 26 Dec 2023
    9.8
    Critical

    CVE-2023-51093

    Last Modified: 21 Nov 2024

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function fromSetLocalVlanInfo.

    Published: 26 Dec 2023
    6.1
    Medium

    CVE-2023-48003

    Last Modified: 21 Nov 2024

    An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' in the WebSocket messages.

    Published: 26 Dec 2023
    8.1
    High

    CVE-2023-49949

    Last Modified: 21 Nov 2024

    Passwork before 6.2.0 allows remote authenticated users to bypass 2FA by sending all one million of the possible 6-digit codes.

    Published: 26 Dec 2023
    9.8
    Critical

    CVE-2023-51094

    Last Modified: 21 Nov 2024

    Tenda M3 V1.0.0.12(4856) was discovered to contain a Command Execution vulnerability via the function TendaTelnet.

    Published: 26 Dec 2023
    9.8
    Critical

    CVE-2023-51095

    Last Modified: 21 Nov 2024

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formDelWlRfPolicy.

    Published: 26 Dec 2023
    9.8
    Critical

    CVE-2023-51090

    Last Modified: 21 Nov 2024

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formGetWeiXinConfig.

    Published: 26 Dec 2023
    9.8
    Critical

    CVE-2023-51091

    Last Modified: 21 Nov 2024

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function R7WebsSecurityHandler.

    Published: 26 Dec 2023
    9.8
    Critical

    CVE-2023-51100

    Last Modified: 21 Nov 2024

    Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formGetDiagnoseInfo .

    Published: 26 Dec 2023
    9.8
    Critical

    CVE-2023-51101

    Last Modified: 23 Apr 2025

    Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formSetUplinkInfo.

    Published: 26 Dec 2023
    9.8
    Critical

    CVE-2023-51102

    Last Modified: 21 Nov 2024

    Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formWifiMacFilterSet.

    Published: 26 Dec 2023
    7.5
    High

    CVE-2023-51103

    Last Modified: 21 Nov 2024

    A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in the function fz_new_pixmap_from_float_data() of pixmap.c.

    Published: 26 Dec 2023
    7.5
    High

    CVE-2023-51104

    Last Modified: 23 Apr 2025

    A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function pnm_binary_read_image() of load-pnm.c when span equals zero.

    Published: 26 Dec 2023
    7.5
    High

    CVE-2023-51105

    Last Modified: 21 Nov 2024

    A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function bmp_decompress_rle4() of load-bmp.c.

    Published: 26 Dec 2023
    7.5
    High

    CVE-2023-51106

    Last Modified: 21 Nov 2024

    A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in function pnm_binary_read_image() of load-pnm.c when fz_colorspace_n returns zero.

    Published: 26 Dec 2023
    7.5
    High

    CVE-2023-51107

    Last Modified: 21 Nov 2024

    A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in functon compute_color() of jquant2.c. NOTE: this is disputed by the supplier because there was not reasonable evidence to determine the existence of a vulnerability or identify the affected product.

    Published: 26 Dec 2023
    —
    Unknown

    CVE-2023-52071

    Last Modified: 23 Feb 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 26 Dec 2023
    8.1
    High

    CVE-2023-52086

    Last Modified: 21 Nov 2024

    resumable.php (aka PHP backend for resumable.js) 0.1.4 before 3c6dbf5 allows arbitrary file upload anywhere in the filesystem via ../ in multipart/form-data content to upload.php. (File overwrite hasn't been possible with the code available in GitHub in recent years, however.)

    Published: 26 Dec 2023
    7.5
    High

    CVE-2023-52096

    Last Modified: 21 Nov 2024

    SteVe Community ocpp-jaxb before 0.0.8 generates invalid timestamps such as ones with month 00 in certain situations (such as when an application receives a StartTransaction Open Charge Point Protocol message with a timestamp parameter of 1000000). This may lead to a SQL exception in applications, and may undermine the integrity of transaction records.

    Published: 26 Dec 2023
    6.1
    Medium

    CVE-2023-49438

    Last Modified: 4 Nov 2025

    An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to malicious sites via a crafted URL by abusing the ?next parameter on the /login and /register routes.

    Published: 26 Dec 2023
    7.3
    High

    CVE-2023-7107

    Last Modified: 23 Oct 2025

    A vulnerability was found in code-projects E-Commerce Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file user_signup.php. The manipulation of the argument firstname/middlename/email/address/contact/username leads to sql injection. The attack may be launched remotely. VDB-249002 is the identifier assigned to this vulnerability.

    Published: 25 Dec 2023
    6.3
    Medium

    CVE-2023-7106

    Last Modified: 23 Oct 2025

    A vulnerability was found in code-projects E-Commerce Website 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file product_details.php?prod_id=11. The manipulation of the argument prod_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249001 was assigned to this vulnerability.

    Published: 25 Dec 2023
    4.7
    Medium

    CVE-2023-7105

    Last Modified: 23 Oct 2025

    A vulnerability was found in code-projects E-Commerce Website 1.0. It has been classified as critical. Affected is an unknown function of the file index_search.php. The manipulation of the argument search leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249000.

    Published: 25 Dec 2023
    5.5
    Medium

    CVE-2023-7104

    Last Modified: 18 Dec 2025

    A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.

    Published: 25 Dec 2023
    5.3
    Medium

    CVE-2023-7100

    Last Modified: 4 Mar 2025

    A vulnerability, which was classified as critical, was found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file /admin/bwdates-report-details.php. The manipulation of the argument fdate/tdate leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 25 Dec 2023
    6.3
    Medium

    CVE-2023-7099

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This issue affects some unknown processing of the file bwdates-report-result.php. The manipulation of the argument fromdate leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248951.

    Published: 25 Dec 2023
    7.5
    High

    CVE-2023-49880

    Last Modified: 21 Nov 2024

    In the Message Entry and Repair (MER) facility of IBM Financial Transaction Manager for SWIFT Services 3.2.4 the sending address and the message type of FIN messages are assumed to be immutable. However, an attacker might modify these elements of a business transaction. IBM X-Force ID: 273183.

    Published: 25 Dec 2023
    7.2
    High

    CVE-2021-38927

    Last Modified: 21 Nov 2024

    IBM Aspera Console 3.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 210322.

    Published: 25 Dec 2023
    7
    High

    CVE-2023-43064

    Last Modified: 21 Nov 2024

    Facsimile Support for IBM i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause arbitrary code to run with the privilege of the user invoking the facsimile support. IBM X-Force ID: 267689.

    Published: 25 Dec 2023
    3.1
    Low

    CVE-2023-7098

    Last Modified: 21 Nov 2024

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in icret EasyImages 2.8.3. This vulnerability affects unknown code of the file app/hide.php. The manipulation of the argument key leads to path traversal: '../filedir'. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. VDB-248950 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 25 Dec 2023
    6.3
    Medium

    CVE-2023-7097

    Last Modified: 23 Oct 2025

    A vulnerability classified as critical has been found in code-projects Water Billing System 1.0. This affects an unknown part of the file /addbill.php. The manipulation of the argument owners_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248949 was assigned to this vulnerability.

    Published: 25 Dec 2023
    2
    Low

    CVE-2023-7096

    Last Modified: 11 Dec 2025

    A flaw has been found in code-projects Faculty Management System 1.0. The affected element is an unknown function of the file /admin/php/crud.php. This manipulation of the argument fieldname/tablename causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

    Published: 25 Dec 2023
    9.8
    Critical

    CVE-2023-7095

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in Totolink A7100RU 7.4cu.2313_B20191024. Affected by this issue is the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The manipulation of the argument flag leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248942 is the identifier assigned to this vulnerability.

    Published: 25 Dec 2023
    5.3
    Medium

    CVE-2023-7094

    Last Modified: 23 Apr 2025

    A vulnerability classified as problematic was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected by this vulnerability is an unknown functionality of the file /protocol/nsasg6.0.tgz. The manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248941 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 25 Dec 2023
    7.5
    High

    CVE-2023-38321

    Last Modified: 21 Nov 2024

    OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to /opennds_auth/ that lacks a custom query string parameter and client-token.

    Published: 25 Dec 2023
    6.5
    Medium

    CVE-2022-39820

    Last Modified: 21 Nov 2024

    In Network Element Manager in NOKIA NFM-T R19.9, an Unprotected Storage of Credentials vulnerability occurs under /root/RestUploadManager.xml.DRC and /DEPOT/KECustom_199/OTNE_DRC/RestUploadManager.xml. A remote user, authenticated to the operating system, with access privileges to the directory /root or /DEPOT, is able to read cleartext credentials to access the web portal NFM-T and control all the PPS Network elements.

    Published: 25 Dec 2023
    4.9
    Medium

    CVE-2023-30451

    Last Modified: 21 Nov 2024

    In TYPO3 11.5.24, the filelist component allows attackers (who have access to the administrator panel) to read arbitrary files via directory traversal in the baseuri field, as demonstrated by POST /typo3/record/edit with ../../../ in data[sys_file_storage]*[data][sDEF][lDEF][basePath][vDEF].

    Published: 25 Dec 2023
    7.2
    High

    CVE-2023-36486

    Last Modified: 26 Nov 2024

    The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user by uploading a workflow definition file with a malicious filename.

    Published: 25 Dec 2023
    6.1
    Medium

    CVE-2022-43675

    Last Modified: 26 Nov 2024

    An issue was discovered in NOKIA NFM-T R19.9. Reflected XSS in the Network Element Manager exists via /oms1350/pages/otn/cpbLogDisplay via the filename parameter, under /oms1350/pages/otn/connection/E2ERoutingDisplayWithOverLay via the id parameter, and under /oms1350/pages/otn/mainOtn via all parameters.

    Published: 25 Dec 2023
    9.8
    Critical

    CVE-2022-34267

    Last Modified: 21 Nov 2024

    An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbitrary Java code can be uploaded and executed via a .jar archive to the ws-api/v2/customizations/api endpoint.

    Published: 25 Dec 2023
    9.8
    Critical

    CVE-2022-34268

    Last Modified: 21 Nov 2024

    An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication, leading to command execution on the host.

    Published: 25 Dec 2023
    8.8
    High

    CVE-2022-34269

    Last Modified: 16 Apr 2025

    An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF attack to deploy JSP code to the Apache Axis service running on the localhost interface, leading to command execution.

    Published: 25 Dec 2023
    9.8
    Critical

    CVE-2022-34270

    Last Modified: 16 Apr 2025

    An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager.

    Published: 25 Dec 2023
    8.8
    High

    CVE-2022-39818

    Last Modified: 21 Nov 2024

    In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parameter. This allows authenticated users to execute commands, with root privileges, on the operating system.

    Published: 25 Dec 2023
    8.8
    High

    CVE-2022-39822

    Last Modified: 21 Nov 2024

    In NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/easy1350.pl of the VM Manager WebUI via the id or host HTTP GET parameter. An authenticated attacker is required for exploitation.

    Published: 25 Dec 2023
    6.5
    Medium

    CVE-2022-41761

    Last Modified: 21 Nov 2024

    An issue was discovered in NOKIA NFM-T R19.9. An Absolute Path Traversal vulnerability exists under /cgi-bin/R19.9/viewlog.pl of the VM Manager WebUI via the logfile parameter, allowing a remote authenticated attacker to read arbitrary files.

    Published: 25 Dec 2023
    6.1
    Medium

    CVE-2022-41762

    Last Modified: 21 Nov 2024

    An issue was discovered in NOKIA NFM-T R19.9. Multiple Reflected XSS vulnerabilities exist in the Network Element Manager via any parameter to log.pl, the bench or pid parameter to top.pl, or the id parameter to easy1350.pl.

    Published: 25 Dec 2023