CVE Feed

    Dashboard / CVE

    4.5
    Medium

    CVE-2023-50248

    Last Modified: 21 Nov 2024

    CKAN is an open-source data management system for powering data hubs and data portals. Starting in version 2.0.0 and prior to versions 2.9.10 and 2.10.3, when submitting a POST request to the `/dataset/new` endpoint (including either the auth cookie or the `Authorization` header) with a specially-crafted field, an attacker can create an out-of-memory error in the hosting server. To trigger this error, the attacker need to have permissions to create or edit datasets. This vulnerability has been patched in CKAN 2.10.3 and 2.9.10.

    Published: 13 Dec 2023
    4.3
    Medium

    CVE-2023-49878

    Last Modified: 21 Nov 2024

    IBM System Storage Virtualization Engine TS7700 3957-VEC, 3948-VED and 3957-VEC could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 272652.

    Published: 13 Dec 2023
    4.3
    Medium

    CVE-2023-49877

    Last Modified: 21 Nov 2024

    IBM System Storage Virtualization Engine TS7700 3957-VEC, 3948-VED and 3957-VEC could allow a remote authenticated user to obtain sensitive information, caused by improper filtering of URLs. By submitting a specially crafted HTTP GET request, an attacker could exploit this vulnerability to view application source code, system configuration information, or other sensitive data related to the Management Interface. IBM X-Force ID: 272651.

    Published: 13 Dec 2023
    3.5
    Low

    CVE-2023-6775

    Last Modified: 21 Nov 2024

    A vulnerability was found in CodeAstro POS and Inventory Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /item/item_con. The manipulation of the argument item_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-247911.

    Published: 13 Dec 2023
    4.3
    Medium

    CVE-2023-6774

    Last Modified: 21 Nov 2024

    A vulnerability was found in CodeAstro POS and Inventory Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /accounts_con/register_account. The manipulation of the argument Username with the input <script>alert(document.cookie)</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-247910 is the identifier assigned to this vulnerability.

    Published: 13 Dec 2023
    6.3
    Medium

    CVE-2023-49296

    Last Modified: 21 Nov 2024

    The Arduino Create Agent allows users to use the Arduino Create applications to upload code to any USB connected Arduino board directly from the browser. A vulnerability in versions prior to 1.3.6 affects the endpoint `/certificate.crt` and the way the web interface of the ArduinoCreateAgent handles custom error messages. An attacker that is able to persuade a victim into clicking on a malicious link can perform a Reflected Cross-Site Scripting attack on the web interface of the create agent, which would allow the attacker to execute arbitrary browser client side code. Version 1.3.6 contains a fix for the issue.

    Published: 13 Dec 2023
    7.5
    High

    CVE-2023-46247

    Last Modified: 21 Nov 2024

    Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). Contracts containing large arrays might underallocate the number of slots they need by 1. Prior to v0.3.8, the calculation to determine how many slots a storage variable needed used `math.ceil(type_.size_in_bytes / 32)`. The intermediate floating point step can produce a rounding error if there are enough bits set in the IEEE-754 mantissa. Roughly speaking, if `type_.size_in_bytes` is large (> 2**46), and slightly less than a power of 2, the calculation can overestimate how many slots are needed by 1. If `type_.size_in_bytes` is slightly more than a power of 2, the calculation can underestimate how many slots are needed by 1. This issue is patched in version 0.3.8.

    Published: 13 Dec 2023
    4.3
    Medium

    CVE-2023-6773

    Last Modified: 21 Nov 2024

    A vulnerability has been found in CodeAstro POS and Inventory Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /accounts_con/register_account of the component User Creation Handler. The manipulation of the argument account_type with the input Admin leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247909 was assigned to this vulnerability.

    Published: 13 Dec 2023
    4.7
    Medium

    CVE-2023-6772

    Last Modified: 22 May 2025

    A vulnerability, which was classified as critical, was found in OTCMS 7.01. Affected is an unknown function of the file /admin/ind_backstage.php. The manipulation of the argument sqlContent leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247908.

    Published: 13 Dec 2023
    2.7
    Low

    CVE-2023-6793

    Last Modified: 2 Dec 2024

    An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to revoke active XML API keys from the firewall and disrupt XML API usage.

    Published: 13 Dec 2023
    5.5
    Medium

    CVE-2023-6771

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in SourceCodester Simple Student Attendance System 1.0. This issue affects the function save_attendance of the file actions.class.php. The manipulation of the argument sid leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-247907.

    Published: 13 Dec 2023
    4.9
    Medium

    CVE-2023-6791

    Last Modified: 25 Feb 2026

    A credential disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to obtain the plaintext credentials of stored external system integrations such as LDAP, SCP, RADIUS, TACACS+, and SNMP from the web interface.

    Published: 13 Dec 2023
    8.6
    High

    CVE-2023-46727

    Last Modified: 21 Nov 2024

    GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, GLPI inventory endpoint can be used to drive a SQL injection attack. Version 10.0.11 contains a patch for the issue. As a workaround, disable native inventory.

    Published: 13 Dec 2023
    4.3
    Medium

    CVE-2023-6789

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface. Then, when viewed by a properly authenticated administrator, the JavaScript payload executes and disguises all associated actions as performed by that unsuspecting authenticated administrator.

    Published: 13 Dec 2023
    7.2
    High

    CVE-2023-46726

    Last Modified: 21 Nov 2024

    GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP 7.4 only, the LDAP server configuration form can be used to execute arbitrary code previously uploaded as a GLPI document. Version 10.0.11 contains a patch for the issue.

    Published: 13 Dec 2023
    5.5
    Medium

    CVE-2023-6795

    Last Modified: 21 Nov 2024

    An OS command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.

    Published: 13 Dec 2023
    6.5
    Medium

    CVE-2023-43813

    Last Modified: 21 Nov 2024

    GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, the saved search feature can be used to perform a SQL injection. Version 10.0.11 contains a patch for the issue.

    Published: 13 Dec 2023
    5.5
    Medium

    CVE-2023-6794

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.

    Published: 13 Dec 2023
    5.5
    Medium

    CVE-2023-6792

    Last Modified: 21 Nov 2024

    An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated API user to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.

    Published: 13 Dec 2023
    8.8
    High

    CVE-2023-6790

    Last Modified: 21 Nov 2024

    A DOM-Based cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to execute a JavaScript payload in the context of an administrator’s browser when they view a specifically crafted link to the PAN-OS web interface.

    Published: 13 Dec 2023
    4.3
    Medium

    CVE-2023-6767

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, was found in SourceCodester Wedding Guest e-Book 1.0. This affects an unknown part of the file /endpoint/add-guest.php. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-247899.

    Published: 13 Dec 2023
    4.3
    Medium

    CVE-2023-6766

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in PHPGurukul Teacher Subject Allocation Management System 1.0. Affected is an unknown function of the file /admin/course.php of the component Delete Course Handler. The manipulation of the argument delid leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247896.

    Published: 13 Dec 2023
    5.5
    Medium

    CVE-2023-6765

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. This issue affects the function prepare of the file email_setup.php. The manipulation of the argument name leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-247895.

    Published: 13 Dec 2023
    4.3
    Medium

    CVE-2023-50779

    Last Modified: 13 Feb 2025

    Missing permission checks in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified token.

    Published: 13 Dec 2023
    8.8
    High

    CVE-2023-50778

    Last Modified: 13 Feb 2025

    A cross-site request forgery (CSRF) vulnerability in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allows attackers to connect to an attacker-specified URL using an attacker-specified token.

    Published: 13 Dec 2023
    4.3
    Medium

    CVE-2023-50777

    Last Modified: 22 May 2025

    Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier does not mask PaaSLane authentication tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

    Published: 13 Dec 2023
    4.3
    Medium

    CVE-2023-50776

    Last Modified: 13 Feb 2025

    Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier stores PaaSLane authentication tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

    Published: 13 Dec 2023
    4.3
    Medium

    CVE-2023-50775

    Last Modified: 13 Feb 2025

    A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to copy jobs.

    Published: 13 Dec 2023
    8.1
    High

    CVE-2023-50774

    Last Modified: 13 Feb 2025

    A cross-site request forgery (CSRF) vulnerability in Jenkins HTMLResource Plugin 1.02 and earlier allows attackers to delete arbitrary files on the Jenkins controller file system.

    Published: 13 Dec 2023
    4.3
    Medium

    CVE-2023-50773

    Last Modified: 13 Feb 2025

    Jenkins Dingding JSON Pusher Plugin 2.0 and earlier does not mask access tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

    Published: 13 Dec 2023
    4.3
    Medium

    CVE-2023-50772

    Last Modified: 13 Feb 2025

    Jenkins Dingding JSON Pusher Plugin 2.0 and earlier stores access tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

    Published: 13 Dec 2023
    6.1
    Medium

    CVE-2023-50771

    Last Modified: 28 May 2025

    Jenkins OpenId Connect Authentication Plugin 2.6 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.

    Published: 13 Dec 2023
    6.7
    Medium

    CVE-2023-50770

    Last Modified: 13 Feb 2025

    Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverable format, allowing attackers with access to the Jenkins controller file system to recover the plain text password of that account, likely gaining administrator access to Jenkins.

    Published: 13 Dec 2023
    4.3
    Medium

    CVE-2023-50769

    Last Modified: 13 Feb 2025

    Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 13 Dec 2023
    8.8
    High

    CVE-2023-50768

    Last Modified: 22 May 2025

    A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 13 Dec 2023
    5.4
    Medium

    CVE-2023-50767

    Last Modified: 13 Feb 2025

    Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML.

    Published: 13 Dec 2023
    8.8
    High

    CVE-2023-50766

    Last Modified: 13 Feb 2025

    A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML.

    Published: 13 Dec 2023
    4.3
    Medium

    CVE-2023-50765

    Last Modified: 13 Feb 2025

    A missing permission check in Jenkins Scriptler Plugin 342.v6a_89fd40f466 and earlier allows attackers with Overall/Read permission to read the contents of a Groovy script by knowing its ID.

    Published: 13 Dec 2023
    8.1
    High

    CVE-2023-50764

    Last Modified: 13 Feb 2025

    Jenkins Scriptler Plugin 342.v6a_89fd40f466 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing attackers with Scriptler/Configure permission to delete arbitrary files on the Jenkins controller file system.

    Published: 13 Dec 2023
    5.4
    Medium

    CVE-2023-6762

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in Thecosy IceCMS 2.0.1. Affected is an unknown function of the file /article/DelectArticleById/ of the component Article Handler. The manipulation leads to permission issues. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-247890 is the identifier assigned to this vulnerability.

    Published: 13 Dec 2023
    4.3
    Medium

    CVE-2023-6761

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, has been found in Thecosy IceCMS up to 2.0.1. This issue affects some unknown processing of the component User Data Handler. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247889 was assigned to this vulnerability.

    Published: 13 Dec 2023
    6.3
    Medium

    CVE-2023-6760

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in Thecosy IceCMS up to 2.0.1. This vulnerability affects unknown code. The manipulation leads to manage user sessions. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247888.

    Published: 13 Dec 2023
    5.3
    Medium

    CVE-2023-6759

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in Thecosy IceCMS 2.0.1. This affects an unknown part of the file /WebResource/resource of the component Love Handler. The manipulation leads to improper enforcement of a single, unique action. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-247887.

    Published: 13 Dec 2023
    5.3
    Medium

    CVE-2023-6758

    Last Modified: 21 Nov 2024

    A vulnerability was found in Thecosy IceCMS 2.0.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /adplanet/PlanetCommentList of the component API. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-247886 is the identifier assigned to this vulnerability.

    Published: 13 Dec 2023
    5.3
    Medium

    CVE-2023-6757

    Last Modified: 22 May 2025

    A vulnerability was found in Thecosy IceCMS 2.0.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /adplanet/PlanetUser of the component API. The manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247885 was assigned to this vulnerability.

    Published: 13 Dec 2023
    5.5
    Medium

    CVE-2023-48638

    Last Modified: 21 Nov 2024

    Adobe Substance 3D Designer versions 13.0.0 (and earlier) and 13.1.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Dec 2023
    7.8
    High

    CVE-2023-48639

    Last Modified: 21 Nov 2024

    Adobe Substance 3D Designer versions 13.0.0 (and earlier) and 13.1.0 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Dec 2023
    5.5
    Medium

    CVE-2023-48637

    Last Modified: 21 Nov 2024

    Adobe Substance 3D Designer versions 13.0.0 (and earlier) and 13.1.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Dec 2023
    5.5
    Medium

    CVE-2023-48636

    Last Modified: 21 Nov 2024

    Adobe Substance 3D Designer versions 13.0.0 (and earlier) and 13.1.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Dec 2023
    5.3
    Medium

    CVE-2023-6756

    Last Modified: 21 Nov 2024

    A vulnerability was found in Thecosy IceCMS 2.0.1. It has been classified as problematic. Affected is an unknown function of the file /login of the component Captcha Handler. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247884.

    Published: 13 Dec 2023