CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2023-41114

    Last Modified: 21 Nov 2024

    An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contains the functions get_url_as_text and get_url_as_bytea that are publicly executable, thus permitting an authenticated user to read any file from the local filesystem or remote system regardless of that user's permissions.

    Published: 12 Dec 2023
    6.5
    Medium

    CVE-2023-41115

    Last Modified: 21 Nov 2024

    An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. When using UTL_ENCODE, an authenticated user can read any large object, regardless of that user's permissions.

    Published: 12 Dec 2023
    4.3
    Medium

    CVE-2023-41116

    Last Modified: 21 Nov 2024

    An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It allows an authenticated user to refresh any materialized view, regardless of that user's permissions.

    Published: 12 Dec 2023
    8.8
    High

    CVE-2023-41117

    Last Modified: 27 May 2025

    An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contain packages, standalone packages, and functions that run SECURITY DEFINER but are inadequately secured against search_path attacks.

    Published: 12 Dec 2023
    8.8
    High

    CVE-2023-41119

    Last Modified: 21 Nov 2024

    An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contains the function _dbms_aq_move_to_exception_queue that may be used to elevate a user's privileges to superuser. This function accepts the OID of a table, and then accesses that table as the superuser by using SELECT and DML commands.

    Published: 12 Dec 2023
    6.5
    Medium

    CVE-2023-41120

    Last Modified: 21 Nov 2024

    An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It permits an authenticated user to use DBMS_PROFILER to remove all accumulated profiling data on a system-wide basis, regardless of that user's permissions.

    Published: 12 Dec 2023
    7.2
    High

    CVE-2023-41623

    Last Modified: 21 Nov 2024

    Emlog version pro2.1.14 was discovered to contain a SQL injection vulnerability via the uid parameter at /admin/media.php.

    Published: 12 Dec 2023
    8.8
    High

    CVE-2023-42890

    Last Modified: 13 Feb 2025

    The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2. Processing web content may lead to arbitrary code execution.

    Published: 12 Dec 2023
    9.8
    Critical

    CVE-2023-43364

    Last Modified: 21 Nov 2024

    main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.

    Published: 12 Dec 2023
    9.8
    Critical

    CVE-2023-46454

    Last Modified: 21 Nov 2024

    In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package information functionality.

    Published: 12 Dec 2023
    9.8
    Critical

    CVE-2023-46456

    Last Modified: 21 Nov 2024

    In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality.

    Published: 12 Dec 2023
    7.5
    High

    CVE-2023-48641

    Last Modified: 21 Nov 2024

    Archer Platform 6.x before 6.14 P1 HF2 (6.14.0.1.2) contains an insecure direct object reference vulnerability. An authenticated malicious user in a multi-instance installation could potentially exploit this vulnerability by manipulating application resource references in user requests to bypass authorization checks, in order to gain execute access to AWF application resources.

    Published: 12 Dec 2023
    5.4
    Medium

    CVE-2023-48642

    Last Modified: 21 Nov 2024

    Archer Platform 6.x before 6.13 P2 (6.13.0.2) contains an authenticated HTML content injection vulnerability. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. 6.14 (6.14.0) is also a fixed release.

    Published: 12 Dec 2023
    6.1
    Medium

    CVE-2023-49563

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in Voltronic Power SNMP Web Pro v.1.1 allows an attacker to execute arbitrary code via a crafted script within a request to the webserver.

    Published: 12 Dec 2023
    5.2
    Medium

    CVE-2023-49921

    Last Modified: 21 Nov 2024

    An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw contents of documents stored in Elasticsearch to be printed in logs. Elastic has released 8.11.2 and 7.17.16 that resolves this issue by removing this excessive logging. This issue only affects users that use Watcher and have a Watch defined that uses the search input and additionally have set the search input’s logger to DEBUG or finer, for example using: org.elasticsearch.xpack.watcher.input.search, org.elasticsearch.xpack.watcher.input, org.elasticsearch.xpack.watcher, or wider, since the loggers are hierarchical.

    Published: 12 Dec 2023
    5.3
    Medium

    CVE-2023-49993

    Last Modified: 4 Nov 2025

    Espeak-ng 1.52-dev was discovered to contain a Buffer Overflow via the function ReadClause at readclause.c.

    Published: 12 Dec 2023
    5.3
    Medium

    CVE-2023-49990

    Last Modified: 4 Nov 2025

    Espeak-ng 1.52-dev was discovered to contain a buffer-overflow via the function SetUpPhonemeTable at synthdata.c.

    Published: 12 Dec 2023
    5.3
    Medium

    CVE-2023-49992

    Last Modified: 4 Nov 2025

    Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Overflow via the function RemoveEnding at dictionary.c.

    Published: 12 Dec 2023
    5.3
    Medium

    CVE-2023-49991

    Last Modified: 4 Nov 2025

    Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Underflow via the function CountVowelPosition at synthdata.c.

    Published: 12 Dec 2023
    5.5
    Medium

    CVE-2023-49994

    Last Modified: 4 Nov 2025

    Espeak-ng 1.52-dev was discovered to contain a Floating Point Exception via the function PeaksToHarmspect at wavegen.c.

    Published: 12 Dec 2023
    6.5
    Medium

    CVE-2023-50495

    Last Modified: 4 Nov 2025

    NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().

    Published: 12 Dec 2023
    7.5
    High

    CVE-2023-5379

    Last Modified: 25 Feb 2026

    A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user could to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS).

    Published: 12 Dec 2023
    7.5
    High

    CVE-2009-4123

    Last Modified: 21 Nov 2024

    The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation.

    Published: 12 Dec 2023
    5.4
    Medium

    CVE-2023-6710

    Last Modified: 20 Nov 2025

    A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By adding a script on the alias parameter on the URL, it adds a new virtual host and adds the script to the cluster-manager page.

    Published: 12 Dec 2023
    7.5
    High

    CVE-2023-28465

    Last Modified: 27 May 2025

    The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain directories via directory traversal, if an allowed directory name is a substring of the directory name chosen by the attacker. NOTE: this issue exists because of an incomplete fix for CVE-2023-24057.

    Published: 12 Dec 2023
    4.3
    Medium

    CVE-2023-41113

    Last Modified: 21 Nov 2024

    An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It allows an authenticated user to to obtain information about whether certain files exist on disk, what errors if any occur when attempting to read them, and some limited information about their contents (regardless of permissions). This can occur when a superuser has configured one or more directories for filesystem access via CREATE DIRECTORY and adopted certain non-default settings for log_line_prefix and log_connections.

    Published: 12 Dec 2023
    8.8
    High

    CVE-2023-41118

    Last Modified: 26 Nov 2024

    An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It may allow an authenticated user to bypass authorization requirements and access underlying implementation functions. When a superuser has configured file locations using CREATE DIRECTORY, these functions allow users to take a wide range of actions, including read, write, copy, rename, and delete.

    Published: 12 Dec 2023
    8.6
    High

    CVE-2023-49803

    Last Modified: 21 Nov 2024

    @koa/cors npm provides Cross-Origin Resource Sharing (CORS) for koa, a web framework for Node.js. Prior to version 5.0.0, the middleware operates in a way that if an allowed origin is not provided, it will return an `Access-Control-Allow-Origin` header with the value of the origin from the request. This behavior completely disables one of the most crucial elements of browsers - the Same Origin Policy (SOP), this could cause a very serious security threat to the users of this middleware. If such behavior is expected, for instance, when middleware is used exclusively for prototypes and not for production applications, it should be heavily emphasized in the documentation along with an indication of the risks associated with such behavior, as many users may not be aware of it. Version 5.0.0 fixes this vulnerability.

    Published: 11 Dec 2023
    9.8
    Critical

    CVE-2023-50245

    Last Modified: 21 Nov 2024

    OpenEXR-viewer is a viewer for OpenEXR files with detailed metadata probing. Versions prior to 0.6.1 have a memory overflow vulnerability. This issue is fixed in version 0.6.1.

    Published: 11 Dec 2023
    6
    Medium

    CVE-2023-49805

    Last Modified: 21 Nov 2024

    Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, the application uses WebSocket (with Socket.io), but it does not verify that the source of communication is valid. This allows third-party website to access the application on behalf of their client. When connecting to the server using Socket.IO, the server does not validate the `Origin` header leading to other site being able to open connections to the server and communicate with it. Other websites still need to authenticate to access most features, however this can be used to circumvent firewall protections made in place by people deploying the application. Without origin validation, Javascript executed from another origin would be allowed to connect to the application without any user interaction. Without login credentials, such a connection is unable to access protected endpoints containing sensitive data of the application. However, such a connection may allow attacker to further exploit unseen vulnerabilities of the application. Users with "No-auth" mode configured who are relying on a reverse proxy or firewall to provide protection to the application would be especially vulnerable as it would grant the attacker full access to the application. In version 1.23.9, additional verification of the HTTP Origin header has been added to the socket.io connection handler. By default, if the `Origin` header is present, it would be checked against the Host header. Connection would be denied if the hostnames do not match, which would indicate that the request is cross-origin. Connection would be allowed if the `Origin` header is not present. Users can override this behavior by setting environment variable `UPTIME_KUMA_WS_ORIGIN_CHECK=bypass`.

    Published: 11 Dec 2023
    6.7
    Medium

    CVE-2023-49804

    Last Modified: 21 Nov 2024

    Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, when a user changes their login password in Uptime Kuma, a previously logged-in user retains access without being logged out. This behavior persists consistently, even after system restarts or browser restarts. This vulnerability allows unauthorized access to user accounts, compromising the security of sensitive information. The same vulnerability was partially fixed in CVE-2023-44400, but logging existing users out of their accounts was forgotten. To mitigate the risks associated with this vulnerability, the maintainers made the server emit a `refresh` event (clients handle this by reloading) and then disconnecting all clients except the one initiating the password change. It is recommended to update Uptime Kuma to version 1.23.9.

    Published: 11 Dec 2023
    5.3
    Medium

    CVE-2023-45292

    Last Modified: 21 Nov 2024

    When using the default implementation of Verify to check a Captcha, verification can be bypassed. For example, if the first parameter is a non-existent id, the second parameter is an empty string, and the third parameter is true, the function will always consider the Captcha to be correct.

    Published: 11 Dec 2023
    6.7
    Medium

    CVE-2023-49802

    Last Modified: 21 Nov 2024

    The LinkedCustomFields plugin for MantisBT allows users to link values between two custom fields, creating linked drop-downs. Prior to version 2.0.1, cross-site scripting in the MantisBT LinkedCustomFields plugin allows Javascript execution, when a crafted Custom Field is linked via the plugin and displayed when reporting a new Issue or editing an existing one. This issue is fixed in version 2.0.1. As a workaround, one may utilize MantisBT's default Content Security Policy, which blocks script execution.

    Published: 11 Dec 2023
    5.3
    Medium

    CVE-2023-49796

    Last Modified: 21 Nov 2024

    MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a limited file write vulnerability in `file.py` Users should use MindsDB's `staging` branch or v23.11.4.1, which contain a fix for the issue.

    Published: 11 Dec 2023
    4.8
    Medium

    CVE-2023-5955

    Last Modified: 21 Nov 2024

    The Contact Form Email WordPress plugin before 1.3.44 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 11 Dec 2023
    6.1
    Medium

    CVE-2023-5749

    Last Modified: 21 Nov 2024

    The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 11 Dec 2023
    4.8
    Medium

    CVE-2023-5757

    Last Modified: 21 Nov 2024

    The WP Crowdfunding WordPress plugin before 2.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 11 Dec 2023
    4.8
    Medium

    CVE-2023-5940

    Last Modified: 21 Nov 2024

    The WP Not Login Hide (WPNLH) WordPress plugin through 1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 11 Dec 2023
    6.1
    Medium

    CVE-2023-5750

    Last Modified: 21 Nov 2024

    The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape a parameter before outputting it back in the page containing a specific content, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 11 Dec 2023
    8.8
    High

    CVE-2023-6035

    Last Modified: 21 Nov 2024

    The EazyDocs WordPress plugin before 2.3.4 does not properly sanitize and escape "data" parameter before using it in an SQL statement via an AJAX action, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks.

    Published: 11 Dec 2023
    6.5
    Medium

    CVE-2023-5907

    Last Modified: 27 May 2025

    The File Manager WordPress plugin before 6.3 does not restrict the file managers root directory, allowing an administrator to set a root outside of the WordPress root directory, giving access to system files and directories even in a multisite setup, where site administrators should not be allowed to modify the sites files.

    Published: 11 Dec 2023
    6.5
    Medium

    CVE-2023-49795

    Last Modified: 21 Nov 2024

    MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a server-side request forgery vulnerability in `file.py`. This can lead to limited information disclosure. Users should use MindsDB's `staging` branch or v23.11.4.1, which contain a fix for the issue.

    Published: 11 Dec 2023
    5.4
    Medium

    CVE-2023-48715

    Last Modified: 21 Nov 2024

    Tuleap is an open source suite to improve management of software developments and collaboration. Prior to version 15.2.99.103 of Tuleap Community Edition and prior to versions 15.2-4 and 15.1-8 of Tuleap Enterprise Edition, the name of the releases are not properly escaped on the edition page of a release. A malicious user with the ability to create a FRS release could force a victim having write permissions in the FRS to execute uncontrolled code. Tuleap Community Edition 15.2.99.103, Tuleap Enterprise Edition 15.2-4, and Tuleap Enterprise Edition 15.1-8 contain a fix for this issue.

    Published: 11 Dec 2023
    7.6
    High

    CVE-2023-6538

    Last Modified: 21 Nov 2024

    SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Server or combined Server+Storage administrative roles are able to access SMU configuration backup, that would normally be barred to those specific administrative roles.

    Published: 11 Dec 2023
    2.8
    Low

    CVE-2023-6194

    Last Modified: 21 Nov 2024

    In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document type definition (DTD) references to external entities. This means that if a user chooses to use a malicious report definition XML file containing an external entity reference to generate a report then Eclipse Memory Analyzer may access external files or URLs defined via a DTD in the report definition.

    Published: 11 Dec 2023
    6.3
    Medium

    CVE-2023-6671

    Last Modified: 21 Nov 2024

    A vulnerability has been discovered on OJS, that consists in a CSRF (Cross-Site Request Forgery) attack that forces an end user to execute unwanted actions on a web application in which they're currently authenticated.

    Published: 11 Dec 2023
    5.5
    Medium

    CVE-2023-6679

    Last Modified: 21 Nov 2025

    A null pointer dereference vulnerability was found in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c in the Digital Phase Locked Loop (DPLL) subsystem in the Linux kernel. This issue could be exploited to trigger a denial of service.

    Published: 11 Dec 2023
    8.8
    High

    CVE-2023-5500

    Last Modified: 21 Nov 2024

    This vulnerability allows an remote attacker with low privileges to misuse Improper Control of Generation of Code ('Code Injection') to gain full control of the affected device.

    Published: 11 Dec 2023
    9.8
    Critical

    CVE-2023-6181

    Last Modified: 21 Nov 2024

    An oversight in BCB handling of reboot reason that allows for persistent code execution

    Published: 11 Dec 2023
    9.8
    Critical

    CVE-2023-48425

    Last Modified: 27 May 2025

    U-Boot vulnerability resulting in persistent Code Execution 

    Published: 11 Dec 2023