CVE Feed

    Dashboard / CVE

    9.6
    Critical

    CVE-2023-31546

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature.

    Published: 14 Dec 2023
    7.5
    High

    CVE-2023-41151

    Last Modified: 22 May 2025

    An uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may cause the application to crash when the server wants to send an error packet, while socket is blocked on writing.

    Published: 14 Dec 2023
    9.8
    Critical

    CVE-2023-44709

    Last Modified: 21 Nov 2024

    PlutoSVG commit 336c02997277a1888e6ccbbbe674551a0582e5c4 and before was discovered to contain an integer overflow via the component plutosvg_load_from_memory.

    Published: 14 Dec 2023
    10
    Critical

    CVE-2023-45894

    Last Modified: 21 Nov 2024

    The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the server, which allows a remote attacker to achieve remote code execution via standard kiosk breakout techniques.

    Published: 14 Dec 2023
    9.8
    Critical

    CVE-2023-46348

    Last Modified: 21 Nov 2024

    SQL njection vulnerability in SunnyToo sturls before version 1.1.13, allows attackers to escalate privileges and obtain sensitive information via StUrls::hookActionDispatcher and StUrls::getInstanceId methods.

    Published: 14 Dec 2023
    9.8
    Critical

    CVE-2023-47261

    Last Modified: 21 Nov 2024

    Dokmee ECM 7.4.6 allows remote code execution because the response to a GettingStarted/SaveSQLConnectionAsync /#/gettingstarted request contains a connection string for privileged SQL Server database access, and xp_cmdshell can be enabled.

    Published: 14 Dec 2023
    9.8
    Critical

    CVE-2023-48084

    Last Modified: 21 Nov 2024

    Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.

    Published: 14 Dec 2023
    9.8
    Critical

    CVE-2023-48085

    Last Modified: 22 May 2025

    Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php.

    Published: 14 Dec 2023
    5.3
    Medium

    CVE-2023-48631

    Last Modified: 21 Nov 2024

    @adobe/css-tools versions 4.3.1 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while attempting to parse CSS.

    Published: 14 Dec 2023
    9.8
    Critical

    CVE-2023-48925

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Buy Addons bavideotab before version 1.0.6, allows attackers to escalate privileges and obtain sensitive information via the component BaVideoTabSaveVideoModuleFrontController::run().

    Published: 14 Dec 2023
    9.8
    Critical

    CVE-2023-49934

    Last Modified: 4 Nov 2025

    An issue was discovered in SchedMD Slurm 23.11.x. There is SQL Injection against the SlurmDBD database. The fixed version is 23.11.1.

    Published: 14 Dec 2023
    7.5
    High

    CVE-2023-49936

    Last Modified: 4 Nov 2025

    An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. A NULL pointer dereference leads to denial of service. The fixed versions are 22.05.11, 23.02.7, and 23.11.1.

    Published: 14 Dec 2023
    7.2
    High

    CVE-2023-50011

    Last Modified: 21 Nov 2024

    PopojiCMS version 2.0.1 is vulnerable to remote command execution in the Meta Social field.

    Published: 14 Dec 2023
    8.8
    High

    CVE-2023-50017

    Last Modified: 21 Nov 2024

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/database/backup

    Published: 14 Dec 2023
    9.8
    Critical

    CVE-2023-50073

    Last Modified: 21 Nov 2024

    EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php.

    Published: 14 Dec 2023
    5.4
    Medium

    CVE-2023-50100

    Last Modified: 21 Nov 2024

    JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via carousel image editing.

    Published: 14 Dec 2023
    5.4
    Medium

    CVE-2023-50101

    Last Modified: 26 Nov 2024

    JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via Label management editing.

    Published: 14 Dec 2023
    5.4
    Medium

    CVE-2023-50102

    Last Modified: 21 Nov 2024

    JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS).

    Published: 14 Dec 2023
    5.4
    Medium

    CVE-2023-50137

    Last Modified: 21 Nov 2024

    JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) in the site management office.

    Published: 14 Dec 2023
    7.5
    High

    CVE-2023-50472

    Last Modified: 22 Jul 2025

    cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.

    Published: 14 Dec 2023
    9.8
    Critical

    CVE-2023-50563

    Last Modified: 21 Nov 2024

    Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.

    Published: 14 Dec 2023
    5.4
    Medium

    CVE-2023-50565

    Last Modified: 26 Nov 2024

    A cross-site scripting (XSS) vulnerability in the component /logs/dopost.html in RPCMS v3.5.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 14 Dec 2023
    5.4
    Medium

    CVE-2023-50566

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in EyouCMS-V1.6.5-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Public Security Registration Number parameter.

    Published: 14 Dec 2023
    6.1
    Medium

    CVE-2023-6571

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in kubeflow/kubeflow

    Published: 14 Dec 2023
    6.5
    Medium

    CVE-2023-6570

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery (SSRF) in kubeflow/kubeflow

    Published: 14 Dec 2023
    7.5
    High

    CVE-2023-49933

    Last Modified: 4 Nov 2025

    An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. There is Improper Enforcement of Message Integrity During Transmission in a Communication Channel. This allows attackers to modify RPC traffic in a way that bypasses message hash checks. The fixed versions are 22.05.11, 23.02.7, and 23.11.1.

    Published: 14 Dec 2023
    8.8
    High

    CVE-2023-49935

    Last Modified: 4 Nov 2025

    An issue was discovered in SchedMD Slurm 23.02.x and 23.11.x. There is Incorrect Access Control because of a slurmd Message Integrity Bypass. An attacker can reuse root-level authentication tokens during interaction with the slurmd process. This bypasses the RPC message hashes that protect against undesired MUNGE credential reuse. The fixed versions are 23.02.7 and 23.11.1.

    Published: 14 Dec 2023
    9.8
    Critical

    CVE-2023-49937

    Last Modified: 4 Nov 2025

    An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. Because of a double free, attackers can cause a denial of service or possibly execute arbitrary code. The fixed versions are 22.05.11, 23.02.7, and 23.11.1.

    Published: 14 Dec 2023
    8.2
    High

    CVE-2023-49938

    Last Modified: 4 Nov 2025

    An issue was discovered in SchedMD Slurm 22.05.x and 23.02.x. There is Incorrect Access Control: an attacker can modified their extended group list that is used with the sbcast subsystem, and open files with an unauthorized set of extended groups. The fixed versions are 22.05.11 and 23.02.7.

    Published: 14 Dec 2023
    7.5
    High

    CVE-2023-50471

    Last Modified: 4 Nov 2025

    cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.

    Published: 14 Dec 2023
    7.1
    High

    CVE-2023-6291

    Last Modified: 11 Nov 2025

    A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users.

    Published: 14 Dec 2023
    9.8
    Critical

    CVE-2023-48049

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in Cybrosys Techno Solutions Website Blog Search (aka website_search_blog) v. 13.0 through 13.0.1.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the name parameter in controllers/main.py component.

    Published: 14 Dec 2023
    8.6
    High

    CVE-2023-50269

    Last Modified: 21 May 2025

    Squid is a caching proxy for the Web. Due to an Uncontrolled Recursion bug in versions 2.6 through 2.7.STABLE9, versions 3.1 through 5.9, and versions 6.0.1 through 6.5, Squid may be vulnerable to a Denial of Service attack against HTTP Request parsing. This problem allows a remote client to perform Denial of Service attack by sending a large X-Forwarded-For header when the follow_x_forwarded_for feature is configured. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives.

    Published: 14 Dec 2023
    5.5
    Medium

    CVE-2024-0443

    Last Modified: 21 Jul 2026

    A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), which is called when the blkcg reference count reaches 0. This circular dependency will prevent blkcg and some blkgs from being freed after they are made offline. This issue may allow an attacker with a local access to cause system instability, such as an out of memory error.

    Published: 14 Dec 2023
    7.7
    High

    CVE-2023-6563

    Last Modified: 22 Sept 2026

    An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the "consents" tab of the admin User Interface, the UI attempts to load a huge number of offline client sessions leading to excessive memory and CPU consumption which could potentially crash the entire system.

    Published: 14 Dec 2023
    6.5
    Medium

    CVE-2023-21751

    Last Modified: 1 Jan 2025

    Azure DevOps Server Spoofing Vulnerability

    Published: 13 Dec 2023
    8.4
    High

    CVE-2023-45170

    Last Modified: 22 May 2025

    IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piobe command to escalate privileges or cause a denial of service. IBM X-Force ID: 267968.

    Published: 13 Dec 2023
    8.4
    High

    CVE-2023-45174

    Last Modified: 21 Nov 2024

    IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a privileged local user to exploit a vulnerability in the qdaemon command to escalate privileges or cause a denial of service. IBM X-Force ID: 267972.

    Published: 13 Dec 2023
    8.4
    High

    CVE-2023-45166

    Last Modified: 21 Nov 2024

    IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piodmgrsu command to obtain elevated privileges. IBM X-Force ID: 267964.

    Published: 13 Dec 2023
    6.4
    Medium

    CVE-2023-49646

    Last Modified: 21 Nov 2024

    Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.

    Published: 13 Dec 2023
    7.3
    High

    CVE-2023-43586

    Last Modified: 25 Feb 2026

    Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access.

    Published: 13 Dec 2023
    7.1
    High

    CVE-2023-43585

    Last Modified: 21 Nov 2024

    Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5.16.5 may allow an authenticated user to conduct a disclosure of information via network access.

    Published: 13 Dec 2023
    4.9
    Medium

    CVE-2023-43583

    Last Modified: 21 Nov 2024

    Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user to conduct a disclosure of information via network access.

    Published: 13 Dec 2023
    6.5
    Medium

    CVE-2023-50709

    Last Modified: 21 Nov 2024

    Cube is a semantic layer for building data applications. Prior to version 0.34.34, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. The issue has been patched in `v0.34.34` and it's recommended that all users exposing Cube APIs to the public internet upgrade to the latest version to prevent service disruption. There are currently no workaround for older versions, and the recommendation is to upgrade.

    Published: 13 Dec 2023
    6.1
    Medium

    CVE-2023-47620

    Last Modified: 21 Nov 2024

    Scrypted is a home video integration and automation platform. In versions 0.55.0 and prior, a reflected cross-site scripting vulnerability exists in the plugin-http.ts file via the `owner' and 'pkg` parameters. An attacker can run arbitrary JavaScript code.

    Published: 13 Dec 2023
    6.1
    Medium

    CVE-2023-47623

    Last Modified: 21 Nov 2024

    Scrypted is a home video integration and automation platform. In versions 0.55.0 and prior, a reflected cross-site scripting vulnerability exists in the login page via the `redirect_uri` parameter. By specifying a url with the javascript scheme (`javascript:`), an attacker can run arbitrary JavaScript code after the login.

    Published: 13 Dec 2023
    7.5
    High

    CVE-2023-47624

    Last Modified: 21 Nov 2024

    Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, any user (regardless of their permissions) may be able to read files from the local file system due to a path traversal in the `/hls` endpoint. This issue may lead to Information Disclosure. As of time of publication, no patches are available.

    Published: 13 Dec 2023
    8.1
    High

    CVE-2023-47619

    Last Modified: 22 May 2025

    Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, users with the update permission are able to read arbitrary files, delete arbitrary files and send a GET request to arbitrary URLs and read the response. This issue may lead to Information Disclosure. As of time of publication, no patches are available.

    Published: 13 Dec 2023
    7.2
    High

    CVE-2023-48702

    Last Modified: 21 Nov 2024

    Jellyfin is a system for managing and streaming media. Prior to version 10.8.13, the `/System/MediaEncoder/Path` endpoint executes an arbitrary file using `ProcessStartInfo` via the `ValidateVersion` function. A malicious administrator can setup a network share and supply a UNC path to `/System/MediaEncoder/Path` which points to an executable on the network share, causing Jellyfin server to run the executable in the local context. The endpoint was removed in version 10.8.13.

    Published: 13 Dec 2023
    5.3
    Medium

    CVE-2023-50262

    Last Modified: 21 Nov 2024

    Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Dompdf performs an initial validation to ensure that paths within the SVG are allowed. One of the validations is that the SVG document does not reference itself. However, prior to version 2.0.4, a recursive chained using two or more SVG documents is not correctly validated. Depending on the system configuration and attack pattern this could exhaust the memory available to the executing process and/or to the server itself. php-svg-lib, when run in isolation, does not support SVG references for `image` elements. However, when used in combination with Dompdf, php-svg-lib will process SVG images referenced by an `image` element. Dompdf currently includes validation to prevent self-referential `image` references, but a chained reference is not checked. A malicious actor may thus trigger infinite recursion by chaining references between two or more SVG images. When Dompdf parses a malicious payload, it will crash due after exceeding the allowed execution time or memory usage. An attacker sending multiple request to a system can potentially cause resource exhaustion to the point that the system is unable to handle incoming request. Version 2.0.4 contains a fix for this issue.

    Published: 13 Dec 2023