CVE Feed

    Dashboard / CVE

    8.3
    High

    CVE-2023-46496

    Last Modified: 21 Nov 2024

    Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the DELETE function in api/files endpoint.

    Published: 8 Dec 2023
    9.8
    Critical

    CVE-2023-46498

    Last Modified: 21 Nov 2024

    An issue in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information and execute arbitrary code via the /deleteCustomer/route.json file.

    Published: 8 Dec 2023
    7.5
    High

    CVE-2023-48122

    Last Modified: 21 Nov 2024

    An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTTP GET method.

    Published: 8 Dec 2023
    9.8
    Critical

    CVE-2023-49007

    Last Modified: 21 Nov 2024

    In Netgear Orbi RBR750 firmware before V7.2.6.21, there is a stack-based buffer overflow in /usr/sbin/httpd.

    Published: 8 Dec 2023
    6.1
    Medium

    CVE-2023-48928

    Last Modified: 27 May 2025

    Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Open Redirect. The 'path' parameter of the prefs.asp resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.

    Published: 8 Dec 2023
    9.8
    Critical

    CVE-2023-49443

    Last Modified: 21 Nov 2024

    DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords. This vulnerability allows attackers to gain access to the application via a bruteforce attack.

    Published: 8 Dec 2023
    5.4
    Medium

    CVE-2023-49444

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a crafted HTML or image file to the user avatar.

    Published: 8 Dec 2023
    5.4
    Medium

    CVE-2023-49484

    Last Modified: 21 Nov 2024

    Dreamer CMS v4.1.3 was discovered to contain a cross-site scripting (XSS) vulnerability in the article management department.

    Published: 8 Dec 2023
    5.4
    Medium

    CVE-2023-49485

    Last Modified: 27 May 2025

    JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the column management department.

    Published: 8 Dec 2023
    5.4
    Medium

    CVE-2023-49486

    Last Modified: 21 Nov 2024

    JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the model management department.

    Published: 8 Dec 2023
    5.4
    Medium

    CVE-2023-49487

    Last Modified: 21 Nov 2024

    JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the navigation management department.

    Published: 8 Dec 2023
    7.5
    High

    CVE-2023-6337

    Last Modified: 13 Feb 2025

    HashiCorp Vault and Vault Enterprise 1.12.0 and newer are vulnerable to a denial of service through memory exhaustion of the host when handling large unauthenticated and authenticated HTTP requests from a client. Vault will attempt to map the request to memory, resulting in the exhaustion of available memory on the host, which may cause Vault to crash. Fixed in Vault 1.15.4, 1.14.8, 1.13.12.

    Published: 8 Dec 2023
    4.4
    Medium

    CVE-2023-7042

    Last Modified: 21 Nov 2025

    A null pointer dereference vulnerability was found in ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev() in drivers/net/wireless/ath/ath10k/wmi-tlv.c in the Linux kernel. This issue could be exploited to trigger a denial of service.

    Published: 8 Dec 2023
    —
    Unknown

    CVE-2023-6061

    Last Modified: 12 Dec 2024

    This CVE ID has been rejected/withdrawn by its CVE Numbering Authority (Palo Alto Networks) based on discussions with Mitsubishi Electronics Corporation's PSIRT.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-5008

    Last Modified: 21 Nov 2024

    Student Information System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'regno' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.

    Published: 7 Dec 2023
    9.9
    Critical

    CVE-2023-4122

    Last Modified: 28 May 2025

    Student Information System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'photo' parameter of my-profile page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

    Published: 7 Dec 2023
    7.8
    High

    CVE-2023-5058

    Last Modified: 25 Sept 2025

    Improper Input Validation in the processing of user-supplied splash screen during system boot in Phoenix SecureCore™ Technology™ 4 potentially allows denial-of-service attacks or arbitrary code execution.

    Published: 7 Dec 2023
    5.5
    Medium

    CVE-2023-6581

    Last Modified: 21 Nov 2024

    A vulnerability has been found in D-Link DAR-7000 up to 20231126 and classified as critical. This vulnerability affects unknown code of the file /user/inc/workidajax.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-247162 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Dec 2023
    8.8
    High

    CVE-2023-6580

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in D-Link DIR-846 FW100A53DBR. This affects an unknown part of the file /HNAP1/ of the component QoS POST Handler. The manipulation of the argument smartqos_express_devices/smartqos_normal_devices leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247161 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Dec 2023
    7.3
    High

    CVE-2023-6579

    Last Modified: 13 Feb 2025

    A vulnerability, which was classified as critical, has been found in osCommerce 4. Affected by this issue is some unknown functionality of the file /b2b-supermarket/shopping-cart of the component POST Parameter Handler. The manipulation of the argument estimate[country_id] leads to sql injection. The attack may be launched remotely. The identifier of this vulnerability is VDB-247160. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Dec 2023
    7.3
    High

    CVE-2023-6578

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in Software AG WebMethods 10.11.x/10.15.x. Affected is an unknown function of the file wm.server/connect/. The manipulation leads to improper access controls. It is possible to launch the attack remotely. To access a file like /assets/ a popup may request username and password. By just clicking CANCEL you will be redirected to the directory. If you visited /invoke/wm.server/connect, you'll be able to see details like internal IPs, ports, and versions. In some cases if access to /assets/ is refused, you may enter /assets/x as a wrong value, then come back to /assets/ which we will show the requested data. It appears that insufficient access control is depending on referrer header data. VDB-247158 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Dec 2023
    4.8
    Medium

    CVE-2023-36880

    Last Modified: 1 Jan 2025

    Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

    Published: 7 Dec 2023
    4.3
    Medium

    CVE-2023-38174

    Last Modified: 1 Jan 2025

    Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

    Published: 7 Dec 2023
    9.6
    Critical

    CVE-2023-35618

    Last Modified: 1 Jan 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 7 Dec 2023
    4.3
    Medium

    CVE-2023-6577

    Last Modified: 21 Nov 2024

    A vulnerability was found in Byzoro PatrolFlow 2530Pro up to 20231126. It has been rated as problematic. This issue affects some unknown processing of the file /log/mailsendview.php. The manipulation of the argument file with the input /boot/phpConfig/tb_admin.txt leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247157 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Dec 2023
    6.3
    Medium

    CVE-2023-6576

    Last Modified: 21 Nov 2024

    A vulnerability was found in Byzoro S210 up to 20231123. It has been declared as critical. This vulnerability affects unknown code of the file /Tool/uploadfile.php of the component HTTP POST Request Handler. The manipulation of the argument file_upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247156. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Dec 2023
    6.3
    Medium

    CVE-2023-6575

    Last Modified: 21 Nov 2024

    A vulnerability was found in Byzoro S210 up to 20231121. It has been classified as critical. This affects an unknown part of the file /Tool/repair.php of the component HTTP POST Request Handler. The manipulation of the argument txt leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-247155. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Dec 2023
    7.5
    High

    CVE-2023-4486

    Last Modified: 28 May 2025

    Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service.

    Published: 7 Dec 2023
    6.3
    Medium

    CVE-2023-6574

    Last Modified: 21 Nov 2024

    A vulnerability was found in Byzoro Smart S20 up to 20231120 and classified as critical. Affected by this issue is some unknown functionality of the file /sysmanage/updateos.php of the component HTTP POST Request Handler. The manipulation of the argument 1_file_upload leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-247154 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Dec 2023
    7.5
    High

    CVE-2023-6333

    Last Modified: 25 Feb 2026

    The affected ControlByWeb Relay products are vulnerable to a stored cross-site scripting vulnerability, which could allow an attacker to inject arbitrary scripts into the endpoint of a web interface that could run malicious javascript code during a user's session.

    Published: 7 Dec 2023
    6.5
    Medium

    CVE-2023-6588

    Last Modified: 21 Nov 2024

    Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Workspace 2023.3.2.0 and earlier. This allows an attacker with access to the Workspace application to access credentials when offline.

    Published: 7 Dec 2023
    7.2
    High

    CVE-2023-39171

    Last Modified: 4 Nov 2025

    SENEC Storage Box V1,V2 and V3 accidentially expose a management UI accessible with publicly known admin credentials.

    Published: 7 Dec 2023
    —
    Unknown

    CVE-2023-39170

    Last Modified: 13 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it's a duplicate of CVE-2023-39169.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-39169

    Last Modified: 4 Nov 2025

    The affected devices use publicly available default credentials with administrative privileges.

    Published: 7 Dec 2023
    7.5
    High

    CVE-2023-39167

    Last Modified: 4 Nov 2025

    In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensitive data.

    Published: 7 Dec 2023
    9.1
    Critical

    CVE-2023-39172

    Last Modified: 4 Nov 2025

    The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture and modify network traffic.

    Published: 7 Dec 2023
    4.7
    Medium

    CVE-2023-45762

    Last Modified: 28 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Michael Uno (miunosoft) Responsive Column Widgets.This issue affects Responsive Column Widgets: from n/a through 1.2.7.

    Published: 7 Dec 2023
    4.7
    Medium

    CVE-2023-47548

    Last Modified: 28 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SoftLab Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site.This issue affects Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site: from n/a through 1.3.2.

    Published: 7 Dec 2023
    4.7
    Medium

    CVE-2023-47779

    Last Modified: 28 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks. Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms.This issue affects Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through 1.1.4.

    Published: 7 Dec 2023
    4.7
    Medium

    CVE-2023-48325

    Last Modified: 28 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in PluginOps Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages.This issue affects Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages: from n/a through 1.5.1.5.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-35039

    Last Modified: 28 Apr 2026

    Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset with Code for WordPress REST API allows Authentication Abuse.This issue affects Password Reset with Code for WordPress REST API: from n/a through 0.0.15.

    Published: 7 Dec 2023
    5.3
    Medium

    CVE-2023-35909

    Last Modified: 28 Apr 2026

    Uncontrolled Resource Consumption vulnerability in Saturday Drive Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress leading to DoS.This issue affects Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress: from n/a through 3.6.25.

    Published: 7 Dec 2023
    7.2
    High

    CVE-2022-45362

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Paytm Paytm Payment Gateway.This issue affects Paytm Payment Gateway: from n/a through 2.7.0.

    Published: 7 Dec 2023
    7.1
    High

    CVE-2023-41804

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4.

    Published: 7 Dec 2023
    4.9
    Medium

    CVE-2023-46641

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Code for Recovery 12 Step Meeting List.This issue affects 12 Step Meeting List: from n/a through 3.14.24.

    Published: 7 Dec 2023
    4.9
    Medium

    CVE-2023-49746

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Softaculous Team SpeedyCache – Cache, Optimization, Performance.This issue affects SpeedyCache – Cache, Optimization, Performance: from n/a through 1.1.2.

    Published: 7 Dec 2023
    7
    High

    CVE-2024-0646

    Last Modified: 6 Nov 2025

    An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate their privileges on the system.

    Published: 7 Dec 2023
    6.1
    Medium

    CVE-2023-49225

    Last Modified: 22 Aug 2025

    A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in the product. As for the affected products/models/versions, see the information provided by the vendor listed under [References] section or the list under [Product Status] section.

    Published: 7 Dec 2023
    6.1
    Medium

    CVE-2023-6568

    Last Modified: 21 Nov 2024

    A reflected Cross-Site Scripting (XSS) vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the Content-Type header in POST requests. An attacker can inject malicious JavaScript code into the Content-Type header, which is then improperly reflected back to the user without adequate sanitization or escaping, leading to arbitrary JavaScript execution in the context of the victim's browser. The vulnerability is present in the mlflow/server/auth/__init__.py file, where the user-supplied Content-Type header is directly injected into a Python formatted string and returned to the user, facilitating the XSS attack.

    Published: 7 Dec 2023
    5.4
    Medium

    CVE-2023-28017

    Last Modified: 2 Dec 2024

    HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which leads to executing malicious script code. This may let the attacker steal cookie-based authentication credentials and comprise a user's account then launch other attacks.

    Published: 7 Dec 2023