CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2023-48424

    Last Modified: 25 Feb 2026

    U-Boot shell vulnerability resulting in Privilege escalation in a production device

    Published: 11 Dec 2023
    9.8
    Critical

    CVE-2023-48417

    Last Modified: 21 Nov 2024

    Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application

    Published: 11 Dec 2023
    6.3
    Medium

    CVE-2023-6659

    Last Modified: 2 Dec 2025

    A vulnerability, which was classified as critical, has been found in Campcodes Web-Based Student Clearance System 1.0. This issue affects some unknown processing of the file /libsystem/login.php. The manipulation of the argument student leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-247367.

    Published: 11 Dec 2023
    6.5
    Medium

    CVE-2023-6536

    Last Modified: 6 Nov 2025

    A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, causing kernel panic and a denial of service.

    Published: 11 Dec 2023
    6.5
    Medium

    CVE-2023-6356

    Last Modified: 6 Nov 2025

    A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver and causing kernel panic and a denial of service.

    Published: 11 Dec 2023
    6.2
    Medium

    CVE-2023-39804

    Last Modified: 4 Nov 2025

    In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.

    Published: 11 Dec 2023
    8.8
    High

    CVE-2020-12613

    Last Modified: 21 Nov 2024

    An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. An attacker can spawn a process with multiple users as part of the security token (prior to Avecto elevation). When Avecto elevates the process, it removes the user who is launching the process, but not the second user. Therefore this second user still retains access and can give permission to the process back to the first user.

    Published: 11 Dec 2023
    8.8
    High

    CVE-2021-3187

    Last Modified: 27 May 2025

    An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7. An authenticated, unprivileged user can elevate privileges by running a malicious script (that executes as root from a temporary directory) during install time. (This applies to macOS before 10.15.5, or Security Update 2020-003 on Mojave and High Sierra, Later versions of macOS are not vulnerable.)

    Published: 11 Dec 2023
    8.3
    High

    CVE-2023-6185

    Last Modified: 13 Feb 2025

    Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer plugins depending on what plugins are installed on the target system.

    Published: 11 Dec 2023
    6.1
    Medium

    CVE-2023-49488

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Openfiler ESA v2.99.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the nic parameter.

    Published: 11 Dec 2023
    9.8
    Critical

    CVE-2023-49417

    Last Modified: 27 May 2025

    TOTOLink A7000R V9.1.0u.6115_B20201022 has a stack overflow vulnerability via setOpModeCfg.

    Published: 11 Dec 2023
    8.8
    High

    CVE-2023-49964

    Last Modified: 21 Nov 2024

    An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restrictions and achieve RCE (Remote Code Execution). NOTE: this issue exists because of an incomplete fix for CVE-2020-12873.

    Published: 11 Dec 2023
    8.8
    High

    CVE-2023-36646

    Last Modified: 21 Nov 2024

    Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to execute privileged functions and achieve privilege escalation via REST API endpoint invocation.

    Published: 11 Dec 2023
    6.5
    Medium

    CVE-2023-6535

    Last Modified: 6 Nov 2025

    A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, causing kernel panic and a denial of service.

    Published: 11 Dec 2023
    7.5
    High

    CVE-2023-49355

    Last Modified: 21 Nov 2024

    decToString in decNumber/decNumber.c in jq 88f01a7 has a one-byte out-of-bounds write via the " []-1.2e-1111111111" input. NOTE: this is not the same as CVE-2023-50246. The CVE-2023-50246 71c2ab5 reference mentions -10E-1000010001, which is not in normalized scientific notation.

    Published: 11 Dec 2023
    9.8
    Critical

    CVE-2023-49418

    Last Modified: 21 Nov 2024

    TOTOLink A7000R V9.1.0u.6115_B20201022has a stack overflow vulnerability via setIpPortFilterRules.

    Published: 11 Dec 2023
    6.1
    Medium

    CVE-2023-49490

    Last Modified: 26 Nov 2024

    XunRuiCMS v4.5.5 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /admin.php.

    Published: 11 Dec 2023
    6.1
    Medium

    CVE-2023-49494

    Last Modified: 21 Nov 2024

    DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component select_media_post_wangEditor.php.

    Published: 11 Dec 2023
    5.4
    Medium

    CVE-2023-50465

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in Monica (aka MonicaHQ) 4.0.0 via an SVG document uploaded by an authenticated user.

    Published: 11 Dec 2023
    8.3
    High

    CVE-2023-6186

    Last Modified: 13 Feb 2025

    Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.

    Published: 11 Dec 2023
    5.5
    Medium

    CVE-2023-6658

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in SourceCodester Simple Student Attendance System 1.0. This vulnerability affects unknown code of the file ajax-api.php?action=save_attendance. The manipulation of the argument class_id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-247366 is the identifier assigned to this vulnerability.

    Published: 10 Dec 2023
    5.5
    Medium

    CVE-2023-6657

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in SourceCodester Simple Student Attendance System 1.0. This affects an unknown part of the file /modals/student_form.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-247365 was assigned to this vulnerability.

    Published: 10 Dec 2023
    5
    Medium

    CVE-2023-6656

    Last Modified: 21 Nov 2024

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22. It has been rated as critical. Affected by this issue is some unknown functionality of the file DFLIMG/DFLJPG.py. The manipulation leads to deserialization. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The identifier of this vulnerability is VDB-247364. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 10 Dec 2023
    7.3
    High

    CVE-2023-6655

    Last Modified: 27 May 2025

    A vulnerability, which was classified as critical, has been found in Hongjing e-HR 2020. Affected by this issue is some unknown functionality of the file /w_selfservice/oauthservlet/%2e./.%2e/general/inform/org/loadhistroyorgtree of the component Login Interface. The manipulation of the argument parentid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-247358 is the identifier assigned to this vulnerability.

    Published: 10 Dec 2023
    6.3
    Medium

    CVE-2023-6654

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in PHPEMS 6.x/7.x/8.x/9.0. Affected by this vulnerability is an unknown functionality in the library lib/session.cls.php of the component Session Data Handler. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247357 was assigned to this vulnerability.

    Published: 10 Dec 2023
    4.3
    Medium

    CVE-2023-6653

    Last Modified: 21 Nov 2024

    A vulnerability was found in PHPGurukul Teacher Subject Allocation Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/subject.php of the component Create a new Subject. The manipulation of the argument cid leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-247346 is the identifier assigned to this vulnerability.

    Published: 10 Dec 2023
    7.3
    High

    CVE-2023-6652

    Last Modified: 21 Nov 2024

    A vulnerability was found in code-projects Matrimonial Site 1.0. It has been declared as critical. Affected by this vulnerability is the function register of the file /register.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247345 was assigned to this vulnerability.

    Published: 10 Dec 2023
    7.3
    High

    CVE-2023-6651

    Last Modified: 21 Nov 2024

    A vulnerability was found in code-projects Matrimonial Site 1.0. It has been classified as critical. Affected is an unknown function of the file /auth/auth.php?user=1. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247344.

    Published: 10 Dec 2023
    4.3
    Medium

    CVE-2023-6650

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Simple Invoice Generator System 1.0 and classified as problematic. This issue affects some unknown processing of the file login.php. The manipulation of the argument cashier leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-247343.

    Published: 10 Dec 2023
    4.3
    Medium

    CVE-2023-6649

    Last Modified: 21 Nov 2024

    A vulnerability has been found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file index.php. The manipulation of the argument searchdata with the input <script>alert(5)</script> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-247342 is the identifier assigned to this vulnerability.

    Published: 10 Dec 2023
    6.9
    Medium

    CVE-2023-6648

    Last Modified: 2 Oct 2025

    A vulnerability, which was classified as critical, was found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file password-recovery.php. The manipulation of the argument username/contactno leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 10 Dec 2023
    7.3
    High

    CVE-2023-6647

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in AMTT HiBOS 1.0. Affected by this issue is some unknown functionality. The manipulation of the argument Type leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247340. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Dec 2023
    6.1
    Medium

    CVE-2022-48614

    Last Modified: 21 Nov 2024

    Special:Ask in Semantic MediaWiki before 4.0.2 allows Reflected XSS.

    Published: 10 Dec 2023
    6.5
    Medium

    CVE-2023-50463

    Last Modified: 21 Nov 2024

    The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows attackers to spoof their source IP address via an X-Forwarded-For header, which may bypass a protection mechanism (trusted_proxy directive in reverse_proxy or IP address range restrictions).

    Published: 10 Dec 2023
    7.5
    High

    CVE-2023-50449

    Last Modified: 21 Nov 2024

    JFinalCMS 5.0.0 could allow a remote attacker to read files via ../ Directory Traversal in the /common/down/file fileKey parameter.

    Published: 10 Dec 2023
    7.8
    High

    CVE-2023-50446

    Last Modified: 21 Nov 2024

    An issue was discovered in Mullvad VPN Windows app before 2023.6-beta1. Insufficient permissions on a directory allow any local unprivileged user to escalate privileges to SYSTEM.

    Published: 10 Dec 2023
    5.3
    Medium

    CVE-2023-50453

    Last Modified: 21 Nov 2024

    An issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This endpoint returns internal configuration data of user object attributes, such as selectable values, which should not be visible to the public.

    Published: 10 Dec 2023
    5.9
    Medium

    CVE-2023-50454

    Last Modified: 21 Nov 2024

    An issue was discovered in Zammad before 6.2.0. In several subsystems, SSL/TLS was used to establish connections to external services without proper validation of hostname and certificate authority. This is exploitable by man-in-the-middle attackers.

    Published: 10 Dec 2023
    7.5
    High

    CVE-2023-50455

    Last Modified: 21 Nov 2024

    An issue was discovered in Zammad before 6.2.0. Due to lack of rate limiting in the "email address verification" feature, an attacker could send many requests for a known address to cause Denial Of Service (generation of many emails, which would also spam the victim).

    Published: 10 Dec 2023
    5.3
    Medium

    CVE-2023-50456

    Last Modified: 27 May 2025

    An issue was discovered in Zammad before 6.2.0. An attacker can trigger phishing links in generated notification emails via a crafted first or last name.

    Published: 10 Dec 2023
    4.3
    Medium

    CVE-2023-50457

    Last Modified: 21 Nov 2024

    An issue was discovered in Zammad before 6.2.0. When listing tickets linked to a knowledge base answer, or knowledge base answers of a ticket, a user could see entries for which they lack permissions.

    Published: 10 Dec 2023
    3.5
    Low

    CVE-2023-6646

    Last Modified: 27 May 2025

    A vulnerability classified as problematic has been found in linkding 1.23.0. Affected is an unknown function. The manipulation of the argument q leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.23.1 is able to address this issue. It is recommended to upgrade the affected component. VDB-247338 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early, responded in a very professional manner and immediately released a fixed version of the affected product.

    Published: 9 Dec 2023
    4.1
    Medium

    CVE-2023-6120

    Last Modified: 8 Apr 2026

    The Welcart e-Commerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.6 via the upload_certificate_file function. This makes it possible for administrators to upload .pem or .crt files to arbitrary locations on the server.

    Published: 9 Dec 2023
    5.4
    Medium

    CVE-2023-5756

    Last Modified: 8 Apr 2026

    The Digital Publications by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.6. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes it possible for unauthenticated attackers to execute AJAX actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 9 Dec 2023
    6.2
    Medium

    CVE-2023-47722

    Last Modified: 21 Nov 2024

    IBM API Connect V10.0.5.3 and V10.0.6.0 stores user credentials in browser cache which can be read by a local user. IBM X-Force ID: 271912.

    Published: 9 Dec 2023
    8.4
    High

    CVE-2023-28523

    Last Modified: 27 May 2025

    IBM Informix Dynamic Server 12.10 and 14.10 onsmsync is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 250753.

    Published: 9 Dec 2023
    6.2
    Medium

    CVE-2023-28526

    Last Modified: 21 Nov 2024

    IBM Informix Dynamic Server 12.10 and 14.10 archecker is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a local user to cause a segmentation fault. IBM X-Force ID: 251204.

    Published: 9 Dec 2023
    6.2
    Medium

    CVE-2023-28527

    Last Modified: 21 Nov 2024

    IBM Informix Dynamic Server 12.10 and 14.10 cdr is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a local user to cause a segmentation fault. IBM X-Force ID: 251206.

    Published: 9 Dec 2023
    5.9
    Medium

    CVE-2020-25835

    Last Modified: 21 Nov 2024

    A potential vulnerability has been identified in Micro Focus ArcSight Management Center. The vulnerability could be remotely exploited resulting in stored Cross-Site Scripting (XSS).

    Published: 9 Dec 2023
    8.8
    High

    CVE-2023-49797

    Last Modified: 13 Feb 2025

    PyInstaller bundles a Python application and all its dependencies into a single package. A PyInstaller built application, elevated as a privileged process, may be tricked by an unprivileged attacker into deleting files the unprivileged user does not otherwise have access to. A user is affected if **all** the following are satisfied: 1. The user runs an application containing either `matplotlib` or `win32com`. 2. The application is ran as administrator (or at least a user with higher privileges than the attacker). 3. The user's temporary directory is not locked to that specific user (most likely due to `TMP`/`TEMP` environment variables pointing to an unprotected, arbitrary, non default location). Either: A. The attacker is able to very carefully time the replacement of a temporary file with a symlink. This switch must occur exactly between `shutil.rmtree()`'s builtin symlink check and the deletion itself B: The application was built with Python 3.7.x or earlier which has no protection against Directory Junctions links. The vulnerability has been addressed in PR #7827 which corresponds to `pyinstaller >= 5.13.1`. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 9 Dec 2023