CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2023-46224

    Last Modified: 21 Nov 2024

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

    Published: 19 Dec 2023
    7.5
    High

    CVE-2023-46262

    Last Modified: 21 Nov 2024

    An unauthenticated attacked could send a specifically crafted web request causing a Server-Side Request Forgery (SSRF) in Ivanti Avalanche Remote Control server.

    Published: 19 Dec 2023
    9.8
    Critical

    CVE-2023-46221

    Last Modified: 21 Nov 2024

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

    Published: 19 Dec 2023
    9.8
    Critical

    CVE-2023-46216

    Last Modified: 21 Nov 2024

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

    Published: 19 Dec 2023
    9.8
    Critical

    CVE-2023-46222

    Last Modified: 21 Nov 2024

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

    Published: 19 Dec 2023
    9.8
    Critical

    CVE-2023-41727

    Last Modified: 6 May 2025

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

    Published: 19 Dec 2023
    9.8
    Critical

    CVE-2023-46217

    Last Modified: 27 Nov 2024

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

    Published: 19 Dec 2023
    9.8
    Critical

    CVE-2023-46265

    Last Modified: 21 Nov 2024

    An unauthenticated could abuse a XXE vulnerability in the Smart Device Server to leak data or perform a Server-Side Request Forgery (SSRF).

    Published: 19 Dec 2023
    9.8
    Critical

    CVE-2023-46257

    Last Modified: 6 May 2025

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

    Published: 19 Dec 2023
    7.5
    High

    CVE-2023-46804

    Last Modified: 21 Nov 2024

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).

    Published: 19 Dec 2023
    9.8
    Critical

    CVE-2023-46263

    Last Modified: 21 Nov 2024

    An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution.

    Published: 19 Dec 2023
    9.8
    Critical

    CVE-2023-46225

    Last Modified: 21 Nov 2024

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

    Published: 19 Dec 2023
    9.8
    Critical

    CVE-2023-46259

    Last Modified: 21 Nov 2024

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

    Published: 19 Dec 2023
    9.8
    Critical

    CVE-2023-46223

    Last Modified: 21 Nov 2024

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

    Published: 19 Dec 2023
    9.1
    Critical

    CVE-2021-22962

    Last Modified: 21 Nov 2024

    An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.

    Published: 19 Dec 2023
    7.5
    High

    CVE-2023-50272

    Last Modified: 7 May 2025

    A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 6 (iLO 6). The vulnerability could be remotely exploited to allow authentication bypass.

    Published: 19 Dec 2023
    5.4
    Medium

    CVE-2023-25715

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in GamiPress GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress.This issue affects GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress: from n/a through 2.5.6.

    Published: 19 Dec 2023
    6.5
    Medium

    CVE-2023-44991

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Media File Renamer: Rename Files (Manual, Auto & AI).This issue affects Media File Renamer: Rename Files (Manual, Auto & AI): from n/a through 5.6.9.

    Published: 19 Dec 2023
    5.3
    Medium

    CVE-2023-44983

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Aruba.It Aruba HiSpeed Cache.This issue affects Aruba HiSpeed Cache: from n/a through 2.0.6.

    Published: 19 Dec 2023
    8.1
    High

    CVE-2023-43870

    Last Modified: 27 Nov 2024

    When installing the Net2 software a root certificate is installed into the trusted store. A potential hacker could access the installer batch file or reverse engineer the source code to gain access to the root certificate password. Using the root certificate and password they could then create their own certificates to emulate another site. Then by establishing a proxy service to emulate the site they could monitor traffic passed between the end user and the site allowing access to the data content.

    Published: 19 Dec 2023
    7.2
    High

    CVE-2023-6280

    Last Modified: 21 Nov 2024

    An XXE (XML External Entity) vulnerability has been detected in 52North WPS affecting versions prior to 4.0.0-beta.11. This vulnerability allows the use of external entities in its WebProcessingService servlet for an attacker to retrieve files by making HTTP requests to the internal network.

    Published: 19 Dec 2023
    5.9
    Medium

    CVE-2023-6711

    Last Modified: 21 Nov 2024

    Vulnerability exists in SCI IEC 60870-5-104 and HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Specially crafted messages sent to the mentioned components are not validated properly and can result in buffer overflow and as final consequence to a reboot of an RTU500 CMU.

    Published: 19 Dec 2023
    8.1
    High

    CVE-2023-6913

    Last Modified: 21 Nov 2024

    A session hijacking vulnerability has been detected in the Imou Life application affecting version 6.7.0. This vulnerability could allow an attacker to hijack user accounts due to the QR code functionality not properly filtering codes when scanning a new device and directly running WebView without prompting or displaying it to the user. This vulnerability could trigger phishing attacks.

    Published: 19 Dec 2023
    7.4
    High

    CVE-2023-1514

    Last Modified: 21 Nov 2024

    A vulnerability exists in the component RTU500 Scripting interface. When a client connects to a server using TLS, the server presents a certificate. This certificate links a public key to the identity of the service and is signed by a Certification Authority (CA), allowing the client to validate that the remote service can be trusted and is not malicious. If the client does not validate the parameters of the certificate, then attackers could be able to spoof the identity of the service. An attacker could exploit the vulnerability by using faking the identity of a RTU500 device and intercepting the messages initiated via the RTU500 Scripting interface.

    Published: 19 Dec 2023
    8.8
    High

    CVE-2023-6873

    Last Modified: 13 Feb 2025

    Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 121.

    Published: 19 Dec 2023
    6.5
    Medium

    CVE-2023-6872

    Last Modified: 13 Feb 2025

    Browser tab titles were being leaked by GNOME to system logs. This could potentially expose the browsing habits of users running in a private tab. This vulnerability affects Firefox < 121.

    Published: 19 Dec 2023
    4.3
    Medium

    CVE-2023-6871

    Last Modified: 21 Nov 2024

    Under certain conditions, Firefox did not display a warning when a user attempted to navigate to a new protocol handler. This vulnerability affects Firefox < 121.

    Published: 19 Dec 2023
    4.3
    Medium

    CVE-2023-6870

    Last Modified: 13 Feb 2025

    Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox. *This issue only affects Android versions of Firefox and Firefox Focus.* This vulnerability affects Firefox < 121.

    Published: 19 Dec 2023
    6.5
    Medium

    CVE-2023-6869

    Last Modified: 7 May 2025

    A `&lt;dialog>` element could have been manipulated to paint content outside of a sandboxed iframe. This could allow untrusted content to display under the guise of trusted content. This vulnerability affects Firefox < 121.

    Published: 19 Dec 2023
    4.3
    Medium

    CVE-2023-6868

    Last Modified: 13 Feb 2025

    In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. *This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121.

    Published: 19 Dec 2023
    8.8
    High

    CVE-2023-6866

    Last Modified: 13 Feb 2025

    TypedArrays can be fallible and lacked proper exception handling. This could lead to abuse in other APIs which expect TypedArrays to always succeed. This vulnerability affects Firefox < 121.

    Published: 19 Dec 2023
    5.5
    Medium

    CVE-2019-25158

    Last Modified: 21 Nov 2024

    A vulnerability has been found in pedroetb tts-api up to 2.1.4 and classified as critical. This vulnerability affects the function onSpeechDone of the file app.js. The manipulation leads to os command injection. Upgrading to version 2.2.0 is able to address this issue. The patch is identified as 29d9c25415911ea2f8b6de247cb5c4607d13d434. It is recommended to upgrade the affected component. VDB-248278 is the identifier assigned to this vulnerability.

    Published: 19 Dec 2023
    8.8
    High

    CVE-2023-6730

    Last Modified: 21 Nov 2024

    Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.

    Published: 19 Dec 2023
    2.4
    Low

    CVE-2023-6945

    Last Modified: 21 Nov 2024

    A vulnerability has been found in SourceCodester Online Student Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file edit-student-detail.php. The manipulation of the argument notmsg leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248377 was assigned to this vulnerability.

    Published: 19 Dec 2023
    7.7
    High

    CVE-2023-49734

    Last Modified: 13 Feb 2025

    An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the charts allowing him to incorrectly have write permissions to these charts.This issue affects Apache Superset: before 2.1.2, from 3.0.0 before 3.0.2. Users are recommended to upgrade to version 3.0.2 or 2.1.3, which fixes the issue.

    Published: 19 Dec 2023
    6.5
    Medium

    CVE-2023-49736

    Last Modified: 13 Feb 2025

    A where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow for SQL injection in Apache Superset.This issue affects Apache Superset: before 2.1.2, from 3.0.0 before 3.0.2. Users are recommended to upgrade to version 3.0.2, which fixes the issue.

    Published: 19 Dec 2023
    6.5
    Medium

    CVE-2023-46104

    Last Modified: 13 Feb 2025

    Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.   This vulnerability exists in Apache Superset versions up to and including 2.1.2 and versions 3.0.0, 3.0.1.

    Published: 19 Dec 2023
    7.1
    High

    CVE-2023-50376

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smp7, wp.Insider Simple Membership allows Reflected XSS.This issue affects Simple Membership: from n/a through 4.3.8.

    Published: 19 Dec 2023
    6.4
    Medium

    CVE-2023-5432

    Last Modified: 8 Apr 2026

    The Jquery news ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'jquery-news-ticker' shortcode in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Dec 2023
    6.4
    Medium

    CVE-2023-5413

    Last Modified: 8 Apr 2026

    The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'ihrss-gallery' shortcode in versions up to, and including, 13.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Dec 2023
    4.3
    Medium

    CVE-2023-42015

    Last Modified: 21 Nov 2024

    IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure. IBM X-Force ID: 265512.

    Published: 19 Dec 2023
    4.3
    Medium

    CVE-2019-25157

    Last Modified: 21 Nov 2024

    A vulnerability was found in Ethex Contracts. It has been classified as critical. This affects an unknown part of the file EthexJackpot.sol of the component Monthly Jackpot Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The patch is named 6b8664b698d3d953e16c284fadc6caeb9e58e3db. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248271.

    Published: 19 Dec 2023
    4.3
    Medium

    CVE-2014-125107

    Last Modified: 21 Nov 2024

    A vulnerability was found in Corveda PHPSandbox 1.3.4 and classified as critical. Affected by this issue is some unknown functionality of the component String Handler. The manipulation leads to protection mechanism failure. The attack may be launched remotely. Upgrading to version 1.3.5 is able to address this issue. The patch is identified as 48fde5ffa4d76014bad260a3cbab7ada3744a4cc. It is recommended to upgrade the affected component. VDB-248270 is the identifier assigned to this vulnerability.

    Published: 19 Dec 2023
    5.4
    Medium

    CVE-2023-6488

    Last Modified: 8 Apr 2026

    The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_button', 'su_members', and 'su_tabs' shortcodes in all versions up to, and including, 7.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Dec 2023
    8.8
    High

    CVE-2023-6940

    Last Modified: 7 May 2025

    with only one user interaction(download a malicious config), attackers can gain full command execution on the victim system.

    Published: 19 Dec 2023
    7.8
    High

    CVE-2023-6315

    Last Modified: 21 Nov 2024

    Out-of-bouds read vulnerability in FPWin Pro version 7.7.0.0 and all previous versions may allow attackers to execute arbitrary code via a specially crafted project file.

    Published: 19 Dec 2023
    7.8
    High

    CVE-2023-6314

    Last Modified: 21 Nov 2024

    Stack-based buffer overflow in FPWin Pro version 7.7.0.0 and all previous versions may allow attackers to execute arbitrary code via a specially crafted project file.

    Published: 19 Dec 2023
    5.3
    Medium

    CVE-2023-44982

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Perfect Images (Manage Image Sizes, Thumbnails, Replace, Retina).This issue affects Perfect Images (Manage Image Sizes, Thumbnails, Replace, Retina): from n/a through 6.4.5.

    Published: 19 Dec 2023
    7.8
    High

    CVE-2023-6932

    Last Modified: 12 May 2026

    A use-after-free vulnerability in the Linux kernel's ipv4: igmp component can be exploited to achieve local privilege escalation. A race condition can be exploited to cause a timer be mistakenly registered on a RCU read locked object which is freed by another thread. We recommend upgrading past commit e2b706c691905fe78468c361aaabc719d0a496f1.

    Published: 19 Dec 2023
    6.1
    Medium

    CVE-2023-49489

    Last Modified: 7 May 2025

    Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive information and escalate privileges via the APP_HOST parameter at config/i18n/en/main.php.

    Published: 19 Dec 2023