CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2023-49762

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in AppMySite AppMySite – Create an app with the Best Mobile App Builder.This issue affects AppMySite – Create an app with the Best Mobile App Builder: from n/a through 3.11.0.

    Published: 21 Dec 2023
    6.5
    Medium

    CVE-2022-45377

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload for WooCommerce.This issue affects Drag and Drop Multiple File Upload for WooCommerce: from n/a through 1.0.8.

    Published: 21 Dec 2023
    9.8
    Critical

    CVE-2023-32242

    Last Modified: 27 Aug 2025

    Deserialization of Untrusted Data vulnerability in xtemos WoodMart - Multipurpose WooCommerce Theme.This issue affects WoodMart - Multipurpose WooCommerce Theme: from n/a through 1.0.36.

    Published: 21 Dec 2023
    10
    Critical

    CVE-2023-49778

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in Hakan Demiray Sayfa Sayac.This issue affects Sayfa Sayac: from n/a through 2.6.

    Published: 21 Dec 2023
    8.1
    High

    CVE-2023-49826

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4.1.

    Published: 21 Dec 2023
    9.8
    Critical

    CVE-2023-51656

    Last Modified: 13 Feb 2025

    Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4. Users are recommended to upgrade to version 1.2.2, which fixes the issue.

    Published: 21 Dec 2023
    7.5
    High

    CVE-2023-5594

    Last Modified: 21 Nov 2024

    Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.

    Published: 21 Dec 2023
    6.3
    Medium

    CVE-2023-51655

    Last Modified: 21 Nov 2024

    In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration

    Published: 21 Dec 2023
    6.1
    Medium

    CVE-2023-5989

    Last Modified: 20 May 2026

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uyumsoft Information System and Technologies' LioXERP allows an authenticated user to execute Stored XSS. This issue affects LioXERP: before v.146.

    Published: 21 Dec 2023
    6.1
    Medium

    CVE-2023-5988

    Last Modified: 20 May 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uyumsoft Information System and Technologies LioXERP allows Reflected XSS. This issue affects LioXERP: before v.146.

    Published: 21 Dec 2023
    4.3
    Medium

    CVE-2023-48291

    Last Modified: 13 Feb 2025

    Apache Airflow, in versions prior to 2.8.0, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to craft a request that could give the user write access to various DAG resources for DAGs that the user had no access to, thus, enabling the user to clear DAGs they shouldn't. This is a missing fix for CVE-2023-42792 in Apache Airflow 2.7.2  Users of Apache Airflow are strongly advised to upgrade to version 2.8.0 or newer to mitigate the risk associated with this vulnerability.

    Published: 21 Dec 2023
    6.5
    Medium

    CVE-2023-50783

    Last Modified: 13 Feb 2025

    Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable. This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification. Users are recommended to upgrade to 2.8.0, which fixes this issue

    Published: 21 Dec 2023
    5.4
    Medium

    CVE-2023-47265

    Last Modified: 13 Feb 2025

    Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XSS vulnerability that allows a DAG author to add an unbounded and not-sanitized javascript in the parameter description field of the DAG. This Javascript can be executed on the client side of any of the user who looks at the tasks in the browser sandbox. While this issue does not allow to exit the browser sandbox or manipulation of the server-side data - more than the DAG author already has, it allows to modify what the user looking at the DAG details sees in the browser - which opens up all kinds of possibilities of misleading other users. Users of Apache Airflow are recommended to upgrade to version 2.8.0 or newer to mitigate the risk associated with this vulnerability

    Published: 21 Dec 2023
    6.5
    Medium

    CVE-2023-49920

    Last Modified: 13 Feb 2025

    Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET request without CSRF validation. As a result, it was possible for a malicious website opened in the same browser - by the user who also had Airflow UI opened - to trigger the execution of DAGs without the user's consent. Users are advised to upgrade to version 2.8.0 or later which is not affected

    Published: 21 Dec 2023
    4.3
    Medium

    CVE-2023-7026

    Last Modified: 21 Nov 2024

    A vulnerability was found in Lightxun IPTV Gateway up to 20231208. It has been rated as problematic. This issue affects some unknown processing of the file /ZHGXTV/index.php/admin/index/web_upload_template.html. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248579.

    Published: 21 Dec 2023
    7.8
    High

    CVE-2023-7025

    Last Modified: 24 Apr 2025

    A vulnerability was found in KylinSoft hedron-domain-hook up to 3.8.0.12-0k0.5. It has been declared as critical. This vulnerability affects the function init_kcm of the component DBus Handler. The manipulation leads to improper access controls. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. VDB-248578 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 21 Dec 2023
    6.3
    Medium

    CVE-2023-7023

    Last Modified: 19 Mar 2025

    A vulnerability was found in Tongda OA 2017 up to 11.9. It has been rated as critical. Affected by this issue is some unknown functionality of the file general/vehicle/query/delete.php. The manipulation of the argument VU_ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-248570 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 21 Dec 2023
    6.3
    Medium

    CVE-2023-7022

    Last Modified: 24 Apr 2025

    A vulnerability was found in Tongda OA 2017 up to 11.9. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file general/work_plan/manage/delete_all.php. The manipulation of the argument DELETE_STR leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248569 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 21 Dec 2023
    6.6
    Medium

    CVE-2023-28025

    Last Modified: 21 Nov 2024

    Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage.

    Published: 21 Dec 2023
    6.3
    Medium

    CVE-2023-7021

    Last Modified: 1 Aug 2025

    A vulnerability was found in Tongda OA 2017 up to 11.9. It has been classified as critical. Affected is an unknown function of the file general/vehicle/checkup/delete_search.php. The manipulation of the argument VU_ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-248568. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 21 Dec 2023
    4.3
    Medium

    CVE-2023-45700

    Last Modified: 21 Nov 2024

    HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.

    Published: 21 Dec 2023
    6.3
    Medium

    CVE-2023-7020

    Last Modified: 19 Mar 2025

    A vulnerability was found in Tongda OA 2017 up to 11.9 and classified as critical. This issue affects some unknown processing of the file general/wiki/cp/ct/view.php. The manipulation of the argument TEMP_ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-248567. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 21 Dec 2023
    7.5
    High

    CVE-2023-6200

    Last Modified: 5 Jun 2025

    A race condition was found in the Linux Kernel. Under certain conditions, an unauthenticated attacker from an adjacent network could send an ICMPv6 router advertisement packet, causing arbitrary code execution.

    Published: 21 Dec 2023
    5.4
    Medium

    CVE-2023-48114

    Last Modified: 21 Nov 2024

    SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored XSS by using image/svg+xml and an uploaded SVG document. This occurs because the application tries to allow youtube.com URLs, but actually allows youtube.com followed by an @ character and an attacker-controlled domain name.

    Published: 21 Dec 2023
    9.1
    Critical

    CVE-2023-50475

    Last Modified: 26 Nov 2024

    An issue was discovered in bcoin-org bcoin version 2.2.0, allows remote attackers to obtain sensitive information via weak hashing algorithms in the component \vendor\faye-websocket.js.

    Published: 21 Dec 2023
    9.8
    Critical

    CVE-2023-51050

    Last Modified: 21 Nov 2024

    S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_productauth parameter at /admin/ajax.php.

    Published: 21 Dec 2023
    9.8
    Critical

    CVE-2023-51051

    Last Modified: 21 Nov 2024

    S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_textauth parameter at /admin/ajax.php.

    Published: 21 Dec 2023
    9.8
    Critical

    CVE-2023-51052

    Last Modified: 24 Apr 2025

    S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_formauth parameter at /admin/ajax.php.

    Published: 21 Dec 2023
    9.8
    Critical

    CVE-2023-29485

    Last Modified: 21 Nov 2024

    An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to bypass network filtering, execute arbitrary code, and obtain sensitive information via DarkLayer Guard threat prevention module. NOTE: Heimdal disputes the validity of this issue arguing that their DNS Security for Endpoint filters DNS traffic on the endpoint by intercepting system-generated DNS requests. The product was not designed to intercept DNS requests from third-party solutions.

    Published: 21 Dec 2023
    9.1
    Critical

    CVE-2023-29487

    Last Modified: 26 Nov 2024

    An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to cause a denial of service (DoS) via the Threat To Process Correlation threat prevention module. NOTE: Heimdal asserts this is not a valid vulnerability. Their DNS Security for Endpoint solution includes an optional feature to provide extra information on the originating process that made a DNS request. The lack of process identification in DNS logs is therefore falsely categorized as a DoS issue.

    Published: 21 Dec 2023
    9.8
    Critical

    CVE-2023-51049

    Last Modified: 21 Nov 2024

    S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_bbsauth parameter at /admin/ajax.php.

    Published: 21 Dec 2023
    5.4
    Medium

    CVE-2023-48115

    Last Modified: 21 Nov 2024

    SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored DOM XSS because an XSS protection mechanism is skipped when messageHTML and messagePlainText are set in the same request.

    Published: 21 Dec 2023
    5.4
    Medium

    CVE-2023-48116

    Last Modified: 21 Nov 2024

    SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored XSS via a crafted description of a Calendar appointment.

    Published: 21 Dec 2023
    5.4
    Medium

    CVE-2023-50473

    Last Modified: 21 Nov 2024

    Cross-Site Scripting (XSS) vulnerability in bill-ahmed qbit-matUI version 1.16.4, allows remote attackers to obtain sensitive information via fixed session identifiers (SID) in index.js file.

    Published: 21 Dec 2023
    9.8
    Critical

    CVE-2023-50477

    Last Modified: 21 Nov 2024

    An issue was discovered in nos client version 0.6.6, allows remote attackers to escalate privileges via getRPCEndpoint.js.

    Published: 21 Dec 2023
    7.5
    High

    CVE-2023-50481

    Last Modified: 21 Nov 2024

    An issue was discovered in blinksocks version 3.3.8, allows remote attackers to obtain sensitive information via weak encryption algorithms in the component /presets/ssr-auth-chain.js.

    Published: 21 Dec 2023
    9.8
    Critical

    CVE-2023-51048

    Last Modified: 21 Nov 2024

    S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_newsauth parameter at /admin/ajax.php.

    Published: 21 Dec 2023
    7
    High

    CVE-2023-6546

    Last Modified: 18 Feb 2026

    A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a use-after-free problem on a struct gsm_dlci while restarting the gsm mux. This could allow a local unprivileged user to escalate their privileges on the system.

    Published: 21 Dec 2023
    9.8
    Critical

    CVE-2023-29486

    Last Modified: 21 Nov 2024

    An issue was discovered in Heimdal Thor agent versions 3.4.2 and before 3.7.0 on Windows, allows attackers to bypass USB access restrictions, execute arbitrary code, and obtain sensitive information via Next-Gen Antivirus component. NOTE: Heimdal argues that the limitation described here is a Microsoft Windows issue, not a Heimdal specific vulnerability. The USB control solution by Heimdal is meant to manage Microsoft Windows native USB restrictions. They maintain that their solution functions as a management layer over Windows settings and is not to blame for limitations in Windows' detection capabilities.

    Published: 21 Dec 2023
    5.3
    Medium

    CVE-2023-45703

    Last Modified: 21 Nov 2024

    HCL Launch may mishandle input validation of an uploaded archive file leading to a denial of service due to resource exhaustion.

    Published: 20 Dec 2023
    6.5
    Medium

    CVE-2023-51390

    Last Modified: 21 Nov 2024

    journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of a service integration in plaintext to the supplied logging pipeline, including credential information contained in the configuration if any. The problem has been patched in journalpump 2.5.0.

    Published: 20 Dec 2023
    6.5
    Medium

    CVE-2023-46131

    Last Modified: 21 Nov 2024

    Grails is a framework used to build web applications with the Groovy programming language. A specially crafted web request can lead to a JVM crash or denial of service. Any Grails framework application using Grails data binding is vulnerable. This issue has been patched in version 3.3.17, 4.1.3, 5.3.4, 6.1.0.

    Published: 20 Dec 2023
    9.8
    Critical

    CVE-2023-48434

    Last Modified: 21 Nov 2024

    Online Voting System Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the reg_action.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 20 Dec 2023
    9.8
    Critical

    CVE-2023-48433

    Last Modified: 21 Nov 2024

    Online Voting System Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the login_action.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 20 Dec 2023
    6.5
    Medium

    CVE-2022-44684

    Last Modified: 2 Jan 2025

    Windows Local Session Manager (LSM) Denial of Service Vulnerability

    Published: 20 Dec 2023
    5.4
    Medium

    CVE-2023-49272

    Last Modified: 5 Dec 2025

    Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'children' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.

    Published: 20 Dec 2023
    8.8
    High

    CVE-2023-23970

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in WooRockets Corsa.This issue affects Corsa: from n/a through 1.5.

    Published: 20 Dec 2023
    5.4
    Medium

    CVE-2023-49271

    Last Modified: 6 Jan 2026

    Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_out_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.

    Published: 20 Dec 2023
    5.4
    Medium

    CVE-2023-49270

    Last Modified: 6 Jan 2026

    Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_in_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.

    Published: 20 Dec 2023
    9.8
    Critical

    CVE-2023-25970

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Zendrop Zendrop – Global Dropshipping.This issue affects Zendrop – Global Dropshipping: from n/a through 1.0.0.

    Published: 20 Dec 2023