CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2023-46279

    Last Modified: 13 Feb 2025

    Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the latest version, which fixes the issue.

    Published: 15 Dec 2023
    9.8
    Critical

    CVE-2023-29234

    Last Modified: 13 Feb 2025

    A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 through 3.2.4. Users are recommended to upgrade to the latest version, which fixes the issue.

    Published: 15 Dec 2023
    7.4
    High

    CVE-2023-48380

    Last Modified: 21 May 2025

    Softnext Mail SQR Expert is an email management platform, it has insufficient filtering for a special character within a spcific function. A remote attacker authenticated as a localhost can exploit this vulnerability to perform command injection attacks, to execute arbitrary system command, manipulate system or disrupt service.

    Published: 15 Dec 2023
    5.3
    Medium

    CVE-2023-48379

    Last Modified: 21 Nov 2024

    Softnext Mail SQR Expert is an email management platform, it has inadequate filtering for a specific URL parameter within a specific function. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response.

    Published: 15 Dec 2023
    7.5
    High

    CVE-2023-48378

    Last Modified: 21 Nov 2024

    Softnext Mail SQR Expert has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.

    Published: 15 Dec 2023
    9.8
    Critical

    CVE-2023-48376

    Last Modified: 21 Nov 2024

    SmartStar Software CWS is a web-based integration platform, its file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.

    Published: 15 Dec 2023
    8.8
    High

    CVE-2023-48375

    Last Modified: 21 Nov 2024

    SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users are able to access data or perform actions that they should not be allowed to perform via commands. An authenticated with normal user privilege can execute administrator privilege, resulting in performing arbitrary system operations or disrupting service.

    Published: 15 Dec 2023
    6.5
    Medium

    CVE-2023-48374

    Last Modified: 21 Nov 2024

    SmartStar Software CWS is a web-base integration platform, it has a vulnerability of using a hard-coded for a specific account with low privilege. An unauthenticated remote attacker can exploit this vulnerability to run partial processes and obtain partial information, but can't disrupt service or obtain sensitive information.

    Published: 15 Dec 2023
    7.5
    High

    CVE-2023-6827

    Last Modified: 8 Apr 2026

    The Essential Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'ajaxUploadFonts' function in versions up to, and including, 4.3.5. This makes it possible for authenticated attackers with subscriber-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible. CVE-2023-6140 appears to be a duplicate of this issue.

    Published: 15 Dec 2023
    7.2
    High

    CVE-2023-6826

    Last Modified: 8 Apr 2026

    The E2Pdf plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'import_action' function in versions up to, and including, 1.20.25. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin, to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 15 Dec 2023
    7.5
    High

    CVE-2023-48373

    Last Modified: 21 May 2025

    ITPison OMICARD EDM has a path traversal vulnerability within its parameter “FileName” in a specific function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.

    Published: 15 Dec 2023
    9.8
    Critical

    CVE-2023-48372

    Last Modified: 21 Nov 2024

    ITPison OMICARD EDM 's SMS-related function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.

    Published: 15 Dec 2023
    9.8
    Critical

    CVE-2023-48371

    Last Modified: 21 Nov 2024

    ITPison OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service.

    Published: 15 Dec 2023
    4.3
    Medium

    CVE-2023-50715

    Last Modified: 21 Nov 2024

    Home Assistant is open source home automation software. Prior to version 2023.12.3, the login page discloses all active user accounts to any unauthenticated browsing request originating on the Local Area Network. Version 2023.12.3 contains a patch for this issue. When starting the Home Assistant 2023.12 release, the login page returns all currently active user accounts to browsing requests from the Local Area Network. Tests showed that this occurs when the request is not authenticated and the request originated locally, meaning on the Home Assistant host local subnet or any other private subnet. The rationale behind this is to make the login more user-friendly and an experience better aligned with other applications that have multiple user-profiles. However, as a result, all accounts are displayed regardless of them having logged in or not and for any device that navigates to the server. This disclosure is mitigated by the fact that it only occurs for requests originating from a LAN address. But note that this applies to the local subnet where Home Assistant resides and to any private subnet that can reach it.

    Published: 15 Dec 2023
    4.3
    Medium

    CVE-2023-36878

    Last Modified: 1 Jan 2025

    Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

    Published: 15 Dec 2023
    4.3
    Medium

    CVE-2023-6832

    Last Modified: 27 Nov 2024

    Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.

    Published: 15 Dec 2023
    8.1
    High

    CVE-2023-6831

    Last Modified: 21 Nov 2024

    Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.

    Published: 15 Dec 2023
    9.8
    Critical

    CVE-2023-40954

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12.0 through v12.0.2, v.13.0 through v13.0.2, v.14.0 through v14.0.2.1, v.15.0 through v15.0.2, and v16.0 through v16.0.2.1 allows a remote attacker to gain privileges via the recency parameter in models/web_progress.py component.

    Published: 15 Dec 2023
    5.3
    Medium

    CVE-2023-42183

    Last Modified: 21 Nov 2024

    lockss-daemon (aka Classic LOCKSS Daemon) before 1.77.3 performs post-Unicode normalization, which may allow bypass of intended access restrictions, such as when U+1FEF is converted to a backtick.

    Published: 15 Dec 2023
    9.8
    Critical

    CVE-2023-48050

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-attendance) v. 13.0 through 16.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the db parameter in the controllers/controllers.py component.

    Published: 15 Dec 2023
    9.8
    Critical

    CVE-2023-50089

    Last Modified: 26 Nov 2024

    A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication.

    Published: 15 Dec 2023
    9.8
    Critical

    CVE-2023-50469

    Last Modified: 21 Nov 2024

    Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 was discovered to contain a buffer overflow via the ApCliEncrypType parameter at /apply.cgi.

    Published: 15 Dec 2023
    9.8
    Critical

    CVE-2023-50917

    Last Modified: 21 Nov 2024

    MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majordomo mailing-list manager.

    Published: 15 Dec 2023
    9.8
    Critical

    CVE-2023-50918

    Last Modified: 21 Nov 2024

    app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.

    Published: 15 Dec 2023
    5.4
    Medium

    CVE-2023-50728

    Last Modified: 21 Nov 2024

    octokit/webhooks is a GitHub webhook events toolset for Node.js. Starting in 9.26.0 and prior to 9.26.3, 10.9.2, 11.1.2, and 12.0.4, there is a problem caused by an issue with error handling in the @octokit/webhooks library because the error can be undefined in some cases. The resulting request was found to cause an uncaught exception that ends the nodejs process. The bug is fixed in octokit/webhooks.js 9.26.3, 10.9.2, 11.1.2, and 12.0.4, app.js 14.02, octokit.js 3.1.2, and Protobot 12.3.3.

    Published: 15 Dec 2023
    6.4
    Medium

    CVE-2023-4489

    Last Modified: 21 May 2025

    The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK v7.18.3 and earlier. This makes the first S0 key generated at startup predictable, potentially allowing network key prediction and unauthorized S0 network access.

    Published: 14 Dec 2023
    8.8
    High

    CVE-2023-6707

    Last Modified: 25 Feb 2026

    Use after free in CSS in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

    Published: 14 Dec 2023
    8.8
    High

    CVE-2023-6706

    Last Modified: 25 Feb 2026

    Use after free in FedCM in Google Chrome prior to 120.0.6099.109 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 14 Dec 2023
    8.8
    High

    CVE-2023-6705

    Last Modified: 25 Feb 2026

    Use after free in WebRTC in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 14 Dec 2023
    8.8
    High

    CVE-2023-6704

    Last Modified: 13 Feb 2025

    Use after free in libavif in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted image file. (Chromium security severity: High)

    Published: 14 Dec 2023
    8.8
    High

    CVE-2023-6703

    Last Modified: 25 Feb 2026

    Use after free in Blink in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 14 Dec 2023
    8.8
    High

    CVE-2023-6702

    Last Modified: 4 Nov 2025

    Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 14 Dec 2023
    6
    Medium

    CVE-2023-49347

    Last Modified: 21 Nov 2024

    Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may read private information from windows, present false information to users, or deny access to the application.

    Published: 14 Dec 2023
    6
    Medium

    CVE-2023-49346

    Last Modified: 21 Nov 2024

    Temporary data passed between application components by Budgie Extras WeatherShow applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or deny access to the application and panel.

    Published: 14 Dec 2023
    6
    Medium

    CVE-2023-49345

    Last Modified: 21 May 2025

    Temporary data passed between application components by Budgie Extras Takeabreak applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or deny access to the application and panel.

    Published: 14 Dec 2023
    6
    Medium

    CVE-2023-49344

    Last Modified: 21 Nov 2024

    Temporary data passed between application components by Budgie Extras Window Shuffler applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or deny access to the application and panel.

    Published: 14 Dec 2023
    6
    Medium

    CVE-2023-49343

    Last Modified: 21 Nov 2024

    Temporary data passed between application components by Budgie Extras Dropby applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or deny access to the application and panel.

    Published: 14 Dec 2023
    6
    Medium

    CVE-2023-49342

    Last Modified: 21 Nov 2024

    Temporary data passed between application components by Budgie Extras Clockworks applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or deny access to the application and panel.

    Published: 14 Dec 2023
    7.5
    High

    CVE-2023-0248

    Last Modified: 21 Nov 2024

    An attacker with physical access to the Kantech Gen1 ioSmart card reader with firmware version prior to 1.07.02 in certain circumstances can recover the reader's communication memory between the card and reader.

    Published: 14 Dec 2023
    7.5
    High

    CVE-2023-49786

    Last Modified: 13 Feb 2025

    Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1; as well as certified-asterisk prior to 18.9-cert6; Asterisk is susceptible to a DoS due to a race condition in the hello handshake phase of the DTLS protocol when handling DTLS-SRTP for media setup. This attack can be done continuously, thus denying new DTLS-SRTP encrypted calls during the attack. Abuse of this vulnerability may lead to a massive Denial of Service on vulnerable Asterisk servers for calls that rely on DTLS-SRTP. Commit d7d7764cb07c8a1872804321302ef93bf62cba05 contains a fix, which is part of versions 18.20.1, 20.5.1, 21.0.1, amd 18.9-cert6.

    Published: 14 Dec 2023
    7.5
    High

    CVE-2023-37457

    Last Modified: 13 Feb 2025

    Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk versions 18.20.0 and prior, 20.5.0 and prior, and 21.0.0; as well as ceritifed-asterisk 18.9-cert5 and prior, the 'update' functionality of the PJSIP_HEADER dialplan function can exceed the available buffer space for storing the new value of a header. By doing so this can overwrite memory or cause a crash. This is not externally exploitable, unless dialplan is explicitly written to update a header based on data from an outside source. If the 'update' functionality is not used the vulnerability does not occur. A patch is available at commit a1ca0268254374b515fa5992f01340f7717113fa.

    Published: 14 Dec 2023
    4.9
    Medium

    CVE-2023-49294

    Last Modified: 13 Feb 2025

    Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, it is possible to read any arbitrary file even when the `live_dangerously` is not enabled. This allows arbitrary files to be read. Asterisk versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, contain a fix for this issue.

    Published: 14 Dec 2023
    7.5
    High

    CVE-2023-4694

    Last Modified: 21 Nov 2024

    Certain HP OfficeJet Pro printers are potentially vulnerable to a Denial of Service when sending a SOAP message to the service on TCP port 3911 that contains a body but no header.

    Published: 14 Dec 2023
    6.5
    Medium

    CVE-2023-50713

    Last Modified: 21 Nov 2024

    Speckle Server provides server, frontend, 3D viewer, and other JavaScript utilities for the Speckle 3D data platform. A vulnerability in versions prior to 2.17.6 affects users who: authorized an application which requested a 'token write' scope or, using frontend-2, created a Personal Access Token (PAT) with `token write` scope. When creating a new token an agent needs to authorise the request with an existing token (the 'requesting token'). The requesting token is required to have token write scope in order to generate new tokens. However, Speckle server was not verifying that other privileges granted to the new token were not in excess of the privileges of the requesting token. A malicious actor could use a token with only token write scope to subsequently generate further tokens with additional privileges. These privileges would only grant privileges up to the existing privileges of the user. This vulnerability cannot be used to escalate a user's privileges or grant privileges on behalf of other users. This has been patched as of version 2.17.6. All operators of Speckle servers should upgrade their server to version 2.17.6 or higher. Any users who authorized an application with 'token write' scope, or created a token in frontend-2 with `token write` scope should review existing tokens and permanently revoke any they do not recognize, revoke existing tokens and create new tokens, and review usage of their account for suspicious activity. No known workarounds for this issue exist.

    Published: 14 Dec 2023
    4.2
    Medium

    CVE-2023-50710

    Last Modified: 21 Nov 2024

    Hono is a web framework written in TypeScript. Prior to version 3.11.7, clients may override named path parameter values from previous requests if the application is using TrieRouter. So, there is a risk that a privileged user may use unintended parameters when deleting REST API resources. TrieRouter is used either explicitly or when the application matches a pattern that is not supported by the default RegExpRouter. Version 3.11.7 includes the change to fix this issue. As a workaround, avoid using TrieRouter directly.

    Published: 14 Dec 2023
    5.9
    Medium

    CVE-2023-49157

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andreas Münch Multiple Post Passwords allows Stored XSS.This issue affects Multiple Post Passwords: from n/a through 1.1.1.

    Published: 14 Dec 2023
    6.5
    Medium

    CVE-2023-49152

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Labs64 Credit Tracker allows Stored XSS.This issue affects Credit Tracker: from n/a through 1.1.17.

    Published: 14 Dec 2023
    6.5
    Medium

    CVE-2023-49151

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simple Calendar Simple Calendar – Google Calendar Plugin allows Stored XSS.This issue affects Simple Calendar – Google Calendar Plugin: from n/a through 3.2.6.

    Published: 14 Dec 2023
    6.5
    Medium

    CVE-2023-49150

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CurrencyRate.Today Crypto Converter Widget allows Stored XSS.This issue affects Crypto Converter Widget: from n/a through 1.8.1.

    Published: 14 Dec 2023
    7.6
    High

    CVE-2023-42801

    Last Modified: 21 Nov 2024

    Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit f57bd745b4cbed577ea654fad4701bea4d38b44c. A malicious game streaming server could exploit a buffer overflow vulnerability to crash a moonlight client. Achieving RCE is possible but unlikely, due to stack canaries in use by modern compiler toolchains. The published binaries for official clients Qt, Android, iOS/tvOS, and Embedded are built with stack canaries, but some unofficial clients may not use stack canaries. This vulnerability takes place after the pairing process, so it requires the client to be tricked into pairing to a malicious host. It is not possible to perform using a man-in-the-middle due to public key pinning that takes place during the pairing process. The bug was addressed in commit b2497a3918a6d79808d9fd0c04734786e70d5954.

    Published: 14 Dec 2023