CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2022-39337

    Last Modified: 21 Nov 2024

    Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat versions 1.20 and prior have a permission bypass vulnerability. System authentication can be bypassed and invoke interfaces without authorization. Version 1.2.1 contains a patch for this issue.

    Published: 22 Dec 2023
    8.4
    High

    CVE-2023-51661

    Last Modified: 17 Apr 2025

    Wasmer is a WebAssembly runtime that enables containers to run anywhere: from Desktop to the Cloud, Edge and even the browser. Wasm programs can access the filesystem outside of the sandbox. Service providers running untrusted Wasm code on Wasmer can unexpectedly expose the host filesystem. This vulnerability has been patched in version 4.2.4.

    Published: 22 Dec 2023
    3.5
    Low

    CVE-2023-7076

    Last Modified: 21 Nov 2024

    A vulnerability was found in slawkens MyAAC up to 0.8.13. It has been declared as problematic. This vulnerability affects unknown code of the file system/pages/bugtracker.php. The manipulation of the argument bug[2]['subject']/bug[2]['text']/report['subject'] leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 0.8.14 is able to address this issue. The name of the patch is 83a91ec540072d319dd338abff45f8d5ebf48190. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-248848.

    Published: 22 Dec 2023
    3.5
    Low

    CVE-2023-7075

    Last Modified: 21 Nov 2024

    A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /main/checkout.php. The manipulation of the argument pt leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248846 is the identifier assigned to this vulnerability.

    Published: 22 Dec 2023
    3.5
    Low

    CVE-2023-7059

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester School Visitor Log e-Book 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file log-book.php. The manipulation of the argument Full Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248750 is the identifier assigned to this vulnerability.

    Published: 22 Dec 2023
    6.3
    Medium

    CVE-2023-7058

    Last Modified: 17 Apr 2025

    A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument page leads to path traversal: '../filedir'. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248749 was assigned to this vulnerability.

    Published: 22 Dec 2023
    3.5
    Low

    CVE-2023-7057

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, has been found in code-projects Faculty Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/pages/yearlevel.php. The manipulation of the argument Year Level/Section leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-248744.

    Published: 22 Dec 2023
    2.4
    Low

    CVE-2023-7056

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic was found in code-projects Faculty Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/pages/subjects.php. The manipulation of the argument Description/Units leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248743.

    Published: 22 Dec 2023
    4.3
    Medium

    CVE-2023-7055

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in PHPGurukul Online Notes Sharing System 1.0. Affected is an unknown function of the file /user/profile.php of the component Contact Information Handler. The manipulation of the argument mobilenumber leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-248742 is the identifier assigned to this vulnerability.

    Published: 22 Dec 2023
    5.5
    Medium

    CVE-2023-7054

    Last Modified: 21 Nov 2024

    A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /user/add-notes.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248741 was assigned to this vulnerability.

    Published: 22 Dec 2023
    3.1
    Low

    CVE-2023-7053

    Last Modified: 21 Nov 2024

    A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /user/signup.php. The manipulation leads to weak password requirements. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-248740.

    Published: 22 Dec 2023
    4.3
    Medium

    CVE-2023-7052

    Last Modified: 21 Nov 2024

    A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been classified as problematic. This affects an unknown part of the file /user/profile.php. The manipulation of the argument name leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248739.

    Published: 22 Dec 2023
    5.4
    Medium

    CVE-2023-45957

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the component admin/AdminRequestSqlController.php of thirty bees before 1.5.0 allows attackers to execute arbitrary web script or HTML via $e->getMessage() error mishandling.

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51014

    Last Modified: 21 Nov 2024

    TOTOLINK EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanSecDns parameter’ of the setLanConfig interface of the cstecgi .cgi

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51025

    Last Modified: 21 Nov 2024

    TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to an unauthorized arbitrary command execution in the ‘admuser’ parameter of the setPasswordCfg interface of the cstecgi .cgi.

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51026

    Last Modified: 21 Nov 2024

    TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘hour’ parameter of the setRebootScheCfg interface of the cstecgi .cgi.

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51027

    Last Modified: 21 Nov 2024

    TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘apcliAuthMode’ parameter of the setWiFiExtenderConfig interface of the cstecgi .cgi.

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51028

    Last Modified: 21 Nov 2024

    TOTOLINK EX1800T 9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the apcliChannel parameter of the setWiFiExtenderConfig interface of the cstecgi.cgi.

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2022-47532

    Last Modified: 21 Nov 2024

    FileRun 20220519 allows SQL Injection via the "dir" parameter in a /?module=users&section=cpanel&page=list request.

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51012

    Last Modified: 21 Nov 2024

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanGateway parameter’ of the setLanConfig interface of the cstecgi .cgi.

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51013

    Last Modified: 21 Nov 2024

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanNetmask parameter’ of the setLanConfig interface of the cstecgi .cgi.

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51015

    Last Modified: 21 Nov 2024

    TOTOLINX EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the ‘enable parameter’ of the setDmzCfg interface of the cstecgi .cgi

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51016

    Last Modified: 21 Nov 2024

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the setRebootScheCfg interface of the cstecgi .cgi.

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51017

    Last Modified: 21 Nov 2024

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanIp parameter’ of the setLanConfig interface of the cstecgi .cgi.

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51018

    Last Modified: 17 Apr 2025

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘opmode’ parameter of the setWiFiApConfig interface of the cstecgi .cgi.

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51707

    Last Modified: 23 Apr 2025

    MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets. AG and vxAG 9.3.0.259.x are unaffected.

    Published: 22 Dec 2023
    8.6
    High

    CVE-2023-51708

    Last Modified: 26 Nov 2024

    Bentley eB System Management Console applications within Assetwise Integrity Information Server allow an unauthenticated user to view configuration options via a crafted request, leading to information disclosure. This affects eB System management Console before 23.00.02.03 and Assetwise ALIM For Transportation before 23.00.01.25.

    Published: 22 Dec 2023
    7.8
    High

    CVE-2023-43116

    Last Modified: 21 Nov 2024

    A symbolic link following vulnerability in Buildkite Elastic CI for AWS versions prior to 6.7.1 and 5.22.5 allows the buildkite-agent user to change ownership of arbitrary directories via the PIPELINE_PATH variable in the fix-buildkite-agent-builds-permissions script.

    Published: 22 Dec 2023
    7
    High

    CVE-2023-43741

    Last Modified: 21 Nov 2024

    A time-of-check-time-of-use race condition vulnerability in Buildkite Elastic CI for AWS versions prior to 6.7.1 and 5.22.5 allows the buildkite-agent user to bypass a symbolic link check for the PIPELINE_PATH variable in the fix-buildkite-agent-builds-permissions script.

    Published: 22 Dec 2023
    7.5
    High

    CVE-2023-49356

    Last Modified: 23 Apr 2025

    A stack buffer overflow vulnerability in MP3Gain v1.6.2 allows an attacker to cause a denial of service via the WriteMP3GainAPETag function at apetag.c:592.

    Published: 22 Dec 2023
    7.5
    High

    CVE-2023-49391

    Last Modified: 21 Nov 2024

    An issue was discovered in free5GC version 3.3.0, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) on AMF component via crafted NGAP message.

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-50147

    Last Modified: 21 Nov 2024

    There is an arbitrary command execution vulnerability in the setDiagnosisCfg function of the cstecgi .cgi of the TOTOlink A3700R router device in its firmware version V9.1.2u.5822_B20200513.

    Published: 22 Dec 2023
    —
    Unknown

    CVE-2023-50569

    Last Modified: 15 Aug 2024

    DO NOT USE THIS CVE RECORD. Consult IDs: CVE-2023-50250. Reason: This record is a reservation duplicate of CVE-2023-50250. Notes: All CVE users should reference CVE-2023-50250 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51011

    Last Modified: 21 Nov 2024

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanPriDns parameter’ of the setLanConfig interface of the cstecgi .cgi

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51019

    Last Modified: 21 Nov 2024

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘key5g’ parameter of the setWiFiExtenderConfig interface of the cstecgi .cgi.

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51020

    Last Modified: 26 Nov 2024

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langType’ parameter of the setLanguageCfg interface of the cstecgi .cgi.

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51021

    Last Modified: 21 Nov 2024

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘merge’ parameter of the setRptWizardCfg interface of the cstecgi .cgi.

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51022

    Last Modified: 21 Nov 2024

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langFlag’ parameter of the setLanguageCfg interface of the cstecgi .cgi.

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51023

    Last Modified: 21 Nov 2024

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the ‘host_time’ parameter of the NTPSyncWithHost interface of the cstecgi .cgi.

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51024

    Last Modified: 21 Nov 2024

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘tz’ parameter of the setNtpCfg interface of the cstecgi .cgi.

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51033

    Last Modified: 21 Nov 2024

    TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi setOpModeCfg interface.

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51034

    Last Modified: 21 Nov 2024

    TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi UploadFirmwareFile interface.

    Published: 22 Dec 2023
    9.8
    Critical

    CVE-2023-51035

    Last Modified: 21 Nov 2024

    TOTOLINK EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution on the cstecgi.cgi NTPSyncWithHost interface.

    Published: 22 Dec 2023
    7.5
    High

    CVE-2023-51713

    Last Modified: 3 Nov 2025

    make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semantics.

    Published: 22 Dec 2023
    6.1
    Medium

    CVE-2023-51704

    Last Modified: 4 Nov 2025

    An issue was discovered in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. In includes/logging/RightsLogFormatter.php, group-*-member messages can result in XSS on Special:log/rights.

    Published: 22 Dec 2023
    7.5
    High

    CVE-2023-24609

    Last Modified: 21 Nov 2024

    Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension parsing in the TLS 1.3 server. An attacked device calculates an SHA-2 hash over at least 65 KB (in RAM). With a large number of crafted TLS messages, the CPU becomes heavily loaded. This occurs in tls13VerifyBinder and tls13TranscriptHashUpdate.

    Published: 22 Dec 2023
    8.8
    High

    CVE-2023-50186

    Last Modified: 17 Mar 2026

    GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of metadata within AV1 encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22300.

    Published: 22 Dec 2023
    5.4
    Medium

    CVE-2023-49086

    Last Modified: 4 Nov 2025

    Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). A vulnerability in versions prior to 1.2.27 bypasses an earlier fix for CVE-2023-39360, therefore leading to a DOM XSS attack. Exploitation of the vulnerability is possible for an authorized user. The vulnerable component is the `graphs_new.php`. The impact of the vulnerability is execution of arbitrary JavaScript code in the attacked user's browser. This issue has been patched in version 1.2.27.

    Published: 21 Dec 2023
    —
    Unknown

    CVE-2023-49690

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 21 Dec 2023
    9.8
    Critical

    CVE-2023-49689

    Last Modified: 21 Nov 2024

    Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'JobId' parameter of the Employer/DeleteJob.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 21 Dec 2023