CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2023-45587

    Last Modified: 8 Jul 2026

    An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions allows attacker to execute unauthorized code or commands via crafted HTTP requests

    Published: 13 Dec 2023
    8.3
    High

    CVE-2022-27488

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.0 through 6.2.7, 6.0.x, FortiMail version 7.0.0 through 7.0.3, 6.4.0 through 6.4.6, 6.2.x, 6.0.x FortiRecorder version 6.4.0 through 6.4.2, 6.0.x, 2.7.x, 2.6.x, FortiNDR version 1.x.x allows a remote unauthenticated attacker to execute commands on the CLI via tricking an authenticated administrator to execute malicious GET requests.

    Published: 13 Dec 2023
    8.8
    High

    CVE-2023-48782

    Last Modified: 25 Feb 2026

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters

    Published: 13 Dec 2023
    7.5
    High

    CVE-2023-45801

    Last Modified: 21 Nov 2024

    Improper Authentication vulnerability in Nadatel DVR allows Information Elicitation.This issue affects DVR: from 3.0.0 before 9.9.0.

    Published: 13 Dec 2023
    7.5
    High

    CVE-2023-45800

    Last Modified: 21 Nov 2024

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hanbiro Hanbiro groupware allows Information Elicitation.This issue affects Hanbiro groupware: from V3.8.79 before V3.8.81.1.

    Published: 13 Dec 2023
    8.8
    High

    CVE-2023-6753

    Last Modified: 21 Nov 2024

    Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2.

    Published: 13 Dec 2023
    7.5
    High

    CVE-2023-50781

    Last Modified: 16 Sept 2026

    A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

    Published: 13 Dec 2023
    7.6
    High

    CVE-2023-6478

    Last Modified: 23 Jun 2026

    A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.

    Published: 13 Dec 2023
    7.8
    High

    CVE-2023-6377

    Last Modified: 23 Jun 2026

    A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.

    Published: 13 Dec 2023
    5.5
    Medium

    CVE-2023-50440

    Last Modified: 3 Jun 2025

    ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before 2023.5; ZEDMAIL for Windows before 2023.5; ZED! for Windows, Mac, Linux before 2023.5; ZEDFREE for Windows, Mac, Linux before 2023.5; or ZEDPRO for Windows, Mac, Linux before 2023.5 can be modified by an unauthenticated attacker to include a UNC reference so that it could trigger network access to an attacker-controlled computer when opened by the victim.

    Published: 13 Dec 2023
    8.8
    High

    CVE-2023-47322

    Last Modified: 21 Nov 2024

    The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the CSRF with execute making the attacker an administrator user in the application.

    Published: 13 Dec 2023
    4.8
    Medium

    CVE-2023-43122

    Last Modified: 21 Nov 2024

    Samsung Mobile Processor and Wearable Processor (Exynos 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, and W920) allow Information Disclosure in the Bootloader.

    Published: 13 Dec 2023
    6.3
    Medium

    CVE-2023-42483

    Last Modified: 21 Nov 2024

    A TOCTOU race condition in Samsung Mobile Processor Exynos 9820, Exynos 980, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, and Exynos 1380 can cause unexpected termination of a system.

    Published: 13 Dec 2023
    9.8
    Critical

    CVE-2023-40921

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to obtain sensitive information via the lat and lng parameters.

    Published: 13 Dec 2023
    6.1
    Medium

    CVE-2023-46750

    Last Modified: 3 Nov 2025

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.

    Published: 13 Dec 2023
    4.3
    Medium

    CVE-2023-47327

    Last Modified: 26 Nov 2024

    The "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the correct URL.

    Published: 13 Dec 2023
    8.8
    High

    CVE-2023-47578

    Last Modified: 21 Nov 2024

    Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices are susceptible to Cross Site Request Forgery (CSRF) attacks due to the absence of CSRF protection in the web interface.

    Published: 13 Dec 2023
    4
    Medium

    CVE-2023-45864

    Last Modified: 22 May 2025

    A race condition issue discovered in Samsung Mobile Processor Exynos 9820, 980, 1080, 2100, 2200, 1280, and 1380 allows unintended modifications of values within certain areas.

    Published: 13 Dec 2023
    4.6
    Medium

    CVE-2023-50443

    Last Modified: 21 Nov 2024

    Encrypted disks created by PRIMX CRYHOD for Windows before Q.2020.4 (ANSSI qualification submission) or CRYHOD for Windows before 2023.5 can be modified by an unauthenticated attacker to include a UNC reference so that it could trigger outbound network traffic from computers on which disks are opened.

    Published: 13 Dec 2023
    7.5
    High

    CVE-2023-34194

    Last Modified: 4 Nov 2025

    StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML through 2.6.2 has a reachable assertion (and application exit) via a crafted XML document with a '\0' located after whitespace.

    Published: 13 Dec 2023
    8.8
    High

    CVE-2023-47326

    Last Modified: 21 Nov 2024

    Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) via the Domain SQL Create function.

    Published: 13 Dec 2023
    9.8
    Critical

    CVE-2023-49363

    Last Modified: 21 Nov 2024

    Rockoa <2.3.3 is vulnerable to SQL Injection. The problem exists in the indexAction method in reimpAction.php.

    Published: 13 Dec 2023
    6.1
    Medium

    CVE-2023-41618

    Last Modified: 26 Nov 2024

    Emlog Pro v2.1.14 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /admin/article.php?active_savedraft.

    Published: 13 Dec 2023
    6.1
    Medium

    CVE-2023-41621

    Last Modified: 26 Nov 2024

    A Cross Site Scripting (XSS) vulnerability was discovered in Emlog Pro v2.1.14 via the component /admin/store.php.

    Published: 13 Dec 2023
    7.5
    High

    CVE-2023-47323

    Last Modified: 21 Nov 2024

    The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other users; including those sent only to administrators.

    Published: 13 Dec 2023
    5.4
    Medium

    CVE-2023-47324

    Last Modified: 21 Nov 2024

    Silverpeas Core 6.3.1 is vulnerable to Cross Site Scripting (XSS) via the message/notification feature.

    Published: 13 Dec 2023
    5.4
    Medium

    CVE-2023-47325

    Last Modified: 22 May 2025

    Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces.

    Published: 13 Dec 2023
    8.1
    High

    CVE-2023-47320

    Last Modified: 22 May 2025

    Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the application unavailable to all users. This affects Silverpeas Core 6.3.1 and below.

    Published: 13 Dec 2023
    4.9
    Medium

    CVE-2023-47321

    Last Modified: 26 Nov 2024

    Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control via the "Porlet Deployer" which allows administrators to deploy .WAR portlets.

    Published: 13 Dec 2023
    9.8
    Critical

    CVE-2023-47577

    Last Modified: 21 Nov 2024

    An issue discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 allows for unauthorized password changes due to no check for current password.

    Published: 13 Dec 2023
    8.8
    High

    CVE-2023-47573

    Last Modified: 26 Nov 2024

    An issue discovered in Relyum RELY-PCIe 22.2.1 devices. The authorization mechanism is not enforced in the web interface, allowing a low-privileged user to execute administrative functions.

    Published: 13 Dec 2023
    5.9
    Medium

    CVE-2023-47574

    Last Modified: 21 Nov 2024

    An issue was discovered on Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices. There is a Weak SMB configuration with signing disabled.

    Published: 13 Dec 2023
    6.1
    Medium

    CVE-2023-47575

    Last Modified: 21 Nov 2024

    An issue was discovered on Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices. The web interfaces of the Relyum devices are susceptible to reflected XSS.

    Published: 13 Dec 2023
    8.8
    High

    CVE-2023-47576

    Last Modified: 21 Nov 2024

    An issue was discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices, allowing authenticated command injection through the web interface.

    Published: 13 Dec 2023
    7.5
    High

    CVE-2023-47579

    Last Modified: 21 Nov 2024

    Relyum RELY-PCIe 22.2.1 devices suffer from a system group misconfiguration, allowing read access to the central password hash file of the operating system.

    Published: 13 Dec 2023
    6.2
    Medium

    CVE-2023-50268

    Last Modified: 13 Feb 2025

    jq is a command-line JSON processor. Version 1.7 is vulnerable to stack-based buffer overflow in builds using decNumber. Version 1.7.1 contains a patch for this issue.

    Published: 13 Dec 2023
    6.2
    Medium

    CVE-2023-50246

    Last Modified: 25 Apr 2025

    jq is a command-line JSON processor. Version 1.7 is vulnerable to heap-based buffer overflow. Version 1.7.1 contains a patch for this issue.

    Published: 13 Dec 2023
    5.3
    Medium

    CVE-2023-50439

    Last Modified: 21 Nov 2024

    ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission), ZED! for Windows before Q.2021.2 (ANSSI qualification submission), ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission), ZONECENTRAL for Windows before 2023.5, or ZEDMAIL for Windows before 2023.5 disclose the original path in which the containers were created, which allows an unauthenticated attacker to obtain some information regarding the context of use (project name, etc.).

    Published: 13 Dec 2023
    5.5
    Medium

    CVE-2023-50441

    Last Modified: 21 Nov 2024

    Encrypted folders created by PRIMX ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission) or ZONECENTRAL for Windows before 2023.5 can be modified by an unauthenticated attacker to include a UNC reference so that it could trigger outbound network traffic from computers on which folders are opened.

    Published: 13 Dec 2023
    5.5
    Medium

    CVE-2023-50442

    Last Modified: 21 Nov 2024

    Encrypted folders created by PRIMX ZONECENTRAL through 2023.5 can be modified by a local attacker (with appropriate privileges) so that specific file types are excluded from encryption temporarily. (This modification can, however, be detected, as described in the Administrator Guide.)

    Published: 13 Dec 2023
    7.5
    High

    CVE-2023-50444

    Last Modified: 26 Nov 2024

    By default, .ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before 2023.5; ZEDMAIL for Windows before 2023.5; and ZED! for Windows, Mac, Linux before 2023.5 include an encrypted version of sensitive user information, which could allow an unauthenticated attacker to obtain it via brute force.

    Published: 13 Dec 2023
    7.5
    High

    CVE-2023-50782

    Last Modified: 24 Mar 2026

    A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

    Published: 13 Dec 2023
    8.5
    High

    CVE-2023-3517

    Last Modified: 21 Nov 2024

    Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.

    Published: 12 Dec 2023
    3.7
    Low

    CVE-2023-50263

    Last Modified: 21 Nov 2024

    Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. In Nautobot 1.x and 2.0.x prior to 1.6.7 and 2.0.6, the URLs `/files/get/?name=...` and `/files/download/?name=...` are used to provide admin access to files that have been uploaded as part of a run request for a Job that has FileVar inputs. Under normal operation these files are ephemeral and are deleted once the Job in question runs. In the default implementation used in Nautobot, as provided by `django-db-file-storage`, these URLs do not by default require any user authentication to access; they should instead be restricted to only users who have permissions to view Nautobot's `FileProxy` model instances. Note that no URL mechanism is provided for listing or traversal of the available file `name` values, so in practice an unauthenticated user would have to guess names to discover arbitrary files for download, but if a user knows the file name/path value, they can access it without authenticating, so we are considering this a vulnerability. Fixes are included in Nautobot 1.6.7 and Nautobot 2.0.6. No known workarounds are available other than applying the patches included in those versions.

    Published: 12 Dec 2023
    —
    Unknown

    CVE-2023-6752

    Last Modified: 2 Jan 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-6747. Reason: This candidate is a reservation duplicate of CVE-2023-6747. Notes: All CVE users should reference CVE-2023-6747 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 12 Dec 2023
    8.3
    High

    CVE-2023-50252

    Last Modified: 21 Nov 2024

    php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when handling `<use>` tag that references an `<image>` tag, it merges the attributes from the `<use>` tag to the `<image>` tag. The problem pops up especially when the `href` attribute from the `<use>` tag has not been sanitized. This can lead to an unsafe file read that can cause PHAR Deserialization vulnerability in PHP prior to version 8. Version 0.5.1 contains a patch for this issue.

    Published: 12 Dec 2023
    5.3
    Medium

    CVE-2023-50251

    Last Modified: 22 May 2025

    php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when parsing the attributes passed to a `use` tag inside an svg document, an attacker can cause the system to go to an infinite recursion. Depending on the system configuration and attack pattern this could exhaust the memory available to the executing process and/or to the server itself. An attacker sending multiple request to a system to render the above payload can potentially cause resource exhaustion to the point that the system is unable to handle incoming request. Version 0.5.1 contains a patch for this issue.

    Published: 12 Dec 2023
    8.9
    High

    CVE-2023-48225

    Last Modified: 21 Nov 2024

    Laf is a cloud development platform. Prior to version 1.0.0-beta.13, the control of LAF app enV is not strict enough, and in certain scenarios of privatization environment, it may lead to sensitive information leakage in secret and configmap. In ES6 syntax, if an obj directly references another obj, the name of the obj itself will be used as the key, and the entire object structure will be integrated intact. When constructing the deployment instance of the app, env was found from the database and directly inserted into the template, resulting in controllability here. Sensitive information in the secret and configmap can be read through the k8s envFrom field. In a privatization environment, when `namespaceConf. fixed` is marked, it may lead to the leakage of sensitive information in the system. As of time of publication, it is unclear whether any patches or workarounds exist.

    Published: 12 Dec 2023
    3.7
    Low

    CVE-2023-50247

    Last Modified: 21 Nov 2024

    h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. The QUIC stack (quicly), as used by H2O up to commit 43f86e5 (in version 2.3.0-beta and prior), is susceptible to a state exhaustion attack. When H2O is serving HTTP/3, a remote attacker can exploit this vulnerability to progressively increase the memory retained by the QUIC stack. This can eventually cause H2O to abort due to memory exhaustion. The vulnerability has been resolved in commit d67e81d03be12a9d53dc8271af6530f40164cd35. HTTP/1 and HTTP/2 are not affected by this vulnerability as they do not use QUIC. Administrators looking to mitigate this issue without upgrading can disable HTTP/3 support.

    Published: 12 Dec 2023
    4.6
    Medium

    CVE-2023-34064

    Last Modified: 21 Nov 2024

    Workspace ONE Launcher contains a Privilege Escalation Vulnerability. A malicious actor with physical access to Workspace ONE Launcher could utilize the Edge Panel feature to bypass setup to gain access to sensitive information.

    Published: 12 Dec 2023