CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2023-49688

    Last Modified: 21 Nov 2024

    Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txtUser' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 21 Dec 2023
    —
    Unknown

    CVE-2023-49687

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 21 Dec 2023
    —
    Unknown

    CVE-2023-49686

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 21 Dec 2023
    —
    Unknown

    CVE-2023-49685

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 21 Dec 2023
    3.5
    Low

    CVE-2023-48308

    Last Modified: 27 Nov 2024

    Nextcloud/Cloud is a calendar app for Nextcloud. An attacker can gain access to stacktrace and internal paths of the server when generating an exception while editing a calendar appointment. It is recommended that the Nextcloud Calendar app is upgraded to 4.5.3

    Published: 21 Dec 2023
    —
    Unknown

    CVE-2023-49684

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 21 Dec 2023
    —
    Unknown

    CVE-2023-49683

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 21 Dec 2023
    5.9
    Medium

    CVE-2023-48298

    Last Modified: 27 Nov 2024

    ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. This vulnerability is an integer underflow resulting in crash due to stack buffer overflow in decompression of FPC codec. It can be triggered and exploited by an unauthenticated attacker. The vulnerability is very similar to CVE-2023-47118 with how the vulnerable function can be exploited.

    Published: 21 Dec 2023
    —
    Unknown

    CVE-2023-49682

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 21 Dec 2023
    9.8
    Critical

    CVE-2023-49681

    Last Modified: 21 Nov 2024

    Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cmbQual' parameter of the Employer/InsertWalkin.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 21 Dec 2023
    8
    High

    CVE-2023-49084

    Last Modified: 25 Feb 2026

    Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL Injection and insufficient processing of the include file path, it is possible to execute arbitrary code on the server. Exploitation of the vulnerability is possible for an authorized user. The vulnerable component is the `link.php`. Impact of the vulnerability execution of arbitrary code on the server.

    Published: 21 Dec 2023
    —
    Unknown

    CVE-2023-49680

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 21 Dec 2023
    —
    Unknown

    CVE-2023-49679

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 21 Dec 2023
    —
    Unknown

    CVE-2023-49678

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 21 Dec 2023
    9.8
    Critical

    CVE-2023-49677

    Last Modified: 21 Nov 2024

    Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cmbQual' parameter of the Employer/InsertJob.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 21 Dec 2023
    8.8
    High

    CVE-2023-7024

    Last Modified: 24 Oct 2025

    Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 21 Dec 2023
    7.7
    High

    CVE-2023-37520

    Last Modified: 21 Nov 2024

    Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay.

    Published: 21 Dec 2023
    4.3
    Medium

    CVE-2023-7051

    Last Modified: 21 Nov 2024

    A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /user/manage-notes.php of the component Notes Handler. The manipulation of the argument delid leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248738 is the identifier assigned to this vulnerability.

    Published: 21 Dec 2023
    7.7
    High

    CVE-2023-37519

    Last Modified: 23 Apr 2025

    Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server. 

    Published: 21 Dec 2023
    3.5
    Low

    CVE-2023-7050

    Last Modified: 21 Nov 2024

    A vulnerability has been found in PHPGurukul Online Notes Sharing System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file user/profile.php. The manipulation of the argument name/email leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248737 was assigned to this vulnerability.

    Published: 21 Dec 2023
    5.3
    Medium

    CVE-2023-27319

    Last Modified: 21 Nov 2024

    ONTAP Mediator versions prior to 1.7 are susceptible to a vulnerability that can allow an unauthenticated attacker to enumerate URLs via REST API.

    Published: 21 Dec 2023
    —
    Unknown

    CVE-2023-48723

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 21 Dec 2023
    9.8
    Critical

    CVE-2023-48722

    Last Modified: 21 Nov 2024

    Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_results.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 21 Dec 2023
    9.8
    Critical

    CVE-2023-48720

    Last Modified: 21 Nov 2024

    Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'password' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 21 Dec 2023
    —
    Unknown

    CVE-2023-48719

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 21 Dec 2023
    9.8
    Critical

    CVE-2023-48718

    Last Modified: 27 Nov 2024

    Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_students.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 21 Dec 2023
    —
    Unknown

    CVE-2023-48717

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 21 Dec 2023
    9.8
    Critical

    CVE-2023-48716

    Last Modified: 21 Nov 2024

    Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_id' parameter of the add_classes.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 21 Dec 2023
    —
    Unknown

    CVE-2023-48690

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 21 Dec 2023
    9.8
    Critical

    CVE-2023-48689

    Last Modified: 23 Apr 2025

    Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'byname' parameter of the train.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 21 Dec 2023
    7.5
    High

    CVE-2023-6847

    Last Modified: 21 Nov 2024

    An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed a bypass of Private Mode by using a specially crafted API request. To exploit this vulnerability, an attacker would need network access to the Enterprise Server appliance configured in Private Mode. This vulnerability affected all versions of GitHub Enterprise Server since 3.9 and was fixed in version 3.9.7, 3.10.4, and 3.11.1. This vulnerability was reported via the GitHub Bug Bounty program.

    Published: 21 Dec 2023
    2.7
    Low

    CVE-2023-51380

    Last Modified: 16 Dec 2024

    An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed issue comments to be read with an improperly scoped token. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.7.19, 3.8.12, 3.9.7, 3.10.4, and 3.11.1.

    Published: 21 Dec 2023
    4.9
    Medium

    CVE-2023-51379

    Last Modified: 16 Dec 2024

    An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed issue comments to be updated with an improperly scoped token. This vulnerability did not allow unauthorized access to any repository content as it also required contents:write and issues:read permissions. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.17.19, 3.8.12, 3.9.7, 3.10.4, and 3.11.1. 

    Published: 21 Dec 2023
    8.3
    High

    CVE-2023-46648

    Last Modified: 21 Nov 2024

    An insufficient entropy vulnerability was identified in GitHub Enterprise Server (GHES) that allowed an attacker to brute force a user invitation to the GHES Management Console. To exploit this vulnerability, an attacker would need knowledge that a user invitation was pending. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1. This vulnerability was reported via the GitHub Bug Bounty program.

    Published: 21 Dec 2023
    6.3
    Medium

    CVE-2023-46649

    Last Modified: 21 Nov 2024

    A race condition in GitHub Enterprise Server was identified that could allow an attacker administrator access. To exploit this, an organization needs to be converted from a user. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.7.19, 3.8.12, 3.9.7, 3.10.4, and 3.11.1. 

    Published: 21 Dec 2023
    6.5
    Medium

    CVE-2023-6804

    Last Modified: 27 Nov 2024

    Improper privilege management allowed arbitrary workflows to be committed and run using an improperly scoped PAT. To exploit this, a workflow must have already existed in the target repo. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.

    Published: 21 Dec 2023
    5.8
    Medium

    CVE-2023-6803

    Last Modified: 21 Nov 2024

    A race condition in GitHub Enterprise Server allows an outside collaborator to be added while a repository is being transferred. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.

    Published: 21 Dec 2023
    7.2
    High

    CVE-2023-6802

    Last Modified: 21 Nov 2024

    An insertion of sensitive information into the log file in the audit log in GitHub Enterprise Server was identified that could allow an attacker to gain access to the management console. To exploit this, an attacker would need access to the log files for the GitHub Enterprise Server appliance, a backup archive created with GitHub Enterprise Server Backup Utilities, or a service which received streamed logs. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1. 

    Published: 21 Dec 2023
    8.1
    High

    CVE-2023-6746

    Last Modified: 23 Apr 2025

    An insertion of sensitive information into log file vulnerability was identified in the log files for a GitHub Enterprise Server back-end service that could permit an `adversary in the middle attack` when combined with other phishing techniques. To exploit this, an attacker would need access to the log files for the GitHub Enterprise Server appliance, a backup archive created with GitHub Enterprise Server Backup Utilities, or a service which received streamed logs. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.7.19, 3.8.12, 3.9.7, 3.10.4, and 3.11.1. 

    Published: 21 Dec 2023
    6.8
    Medium

    CVE-2023-46645

    Last Modified: 21 Nov 2024

    A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary file reading when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.7.19, 3.8.12, 3.9.7, 3.10.4, and 3.11.1. This vulnerability was reported via the GitHub Bug Bounty program.

    Published: 21 Dec 2023
    3.9
    Low

    CVE-2023-6690

    Last Modified: 21 Nov 2024

    A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by making a GraphQL mutation to alter repository permissions during the transfer. This vulnerability affected GitHub Enterprise Server version 3.8.0 and above and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.

    Published: 21 Dec 2023
    8
    High

    CVE-2023-46647

    Last Modified: 21 Nov 2024

    Improper privilege management in all versions of GitHub Enterprise Server allows users with authorized access to the management console with an editor role to escalate their privileges by making requests to the endpoint used for bootstrapping the instance. This vulnerability affected GitHub Enterprise Server version 3.8.0 and above and was fixed in version 3.8.12, 3.9.6, 3.10.3, and 3.11.0.

    Published: 21 Dec 2023
    5.3
    Medium

    CVE-2023-46646

    Last Modified: 16 Dec 2024

    Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get a check run" API endpoint. This vulnerability did not allow unauthorized access to any repository content besides the name. This vulnerability affected GitHub Enterprise Server version 3.7.0 and above and was fixed in version 3.17.19, 3.8.12, 3.9.7 3.10.4, and 3.11.0.

    Published: 21 Dec 2023
    —
    Unknown

    CVE-2023-48688

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 21 Dec 2023
    9.8
    Critical

    CVE-2023-48687

    Last Modified: 21 Nov 2024

    Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'from' parameter of the reservation.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 21 Dec 2023
    —
    Unknown

    CVE-2023-48686

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 21 Dec 2023
    4.6
    Medium

    CVE-2023-41097

    Last Modified: 23 Apr 2025

    An Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM potentially allows Padding Oracle Crypto Attack on CBC PKCS7.This issue affects GSDK: through 4.4.0.

    Published: 21 Dec 2023
    9.8
    Critical

    CVE-2023-48685

    Last Modified: 21 Nov 2024

    Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'psd' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 21 Dec 2023
    —
    Unknown

    CVE-2023-46791

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 21 Dec 2023
    5.4
    Medium

    CVE-2023-7041

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in codelyfe Stupid Simple CMS up to 1.2.4. Affected by this issue is some unknown functionality of the file /file-manager/rename.php. The manipulation of the argument newName leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248690 is the identifier assigned to this vulnerability.

    Published: 21 Dec 2023