CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2023-49967

    Last Modified: 21 Nov 2024

    Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-50000

    Last Modified: 21 Nov 2024

    Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formResetMeshNode.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-50001

    Last Modified: 21 Nov 2024

    Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formUpgradeMeshOnline.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-50002

    Last Modified: 21 Nov 2024

    Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formRebootMeshNode.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-50164

    Last Modified: 14 Mar 2025

    An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.

    Published: 7 Dec 2023
    7.5
    High

    CVE-2023-33411

    Last Modified: 26 Nov 2024

    A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions up to 3.17.02, allows remote unauthenticated users to perform directory traversal, potentially disclosing sensitive information.

    Published: 7 Dec 2023
    7.7
    High

    CVE-2023-49096

    Last Modified: 28 May 2025

    Jellyfin is a Free Software Media System for managing and streaming media. In affected versions there is an argument injection in the VideosController, specifically the `/Videos/<itemId>/stream` and `/Videos/<itemId>/stream.<container>` endpoints which are present in the current Jellyfin version. Additional endpoints in the AudioController might also be vulnerable, as they differ only slightly in execution. Those endpoints are reachable by an unauthenticated user. In order to exploit this vulnerability an unauthenticated attacker has to guess an itemId, which is a completely random GUID. It’s a very unlikely case even for a large media database with lots of items. Without an additional information leak, this vulnerability shouldn’t be directly exploitable, even if the instance is reachable from the Internet. There are a lot of query parameters that get accepted by the method. At least two of those, videoCodec and audioCodec are vulnerable to the argument injection. The values can be traced through a lot of code and might be changed in the process. However, the fallback is to always use them as-is, which means we can inject our own arguments. Those arguments land in the command line of FFmpeg. Because UseShellExecute is always set to false, we can’t simply terminate the FFmpeg command and execute our own. It should only be possible to add additional arguments to FFmpeg, which is powerful enough as it stands. There is probably a way of overwriting an arbitrary file with malicious content. This vulnerability has been addressed in version 10.8.13. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-39538

    Last Modified: 25 Feb 2026

    AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a BMP Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability. 

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-39539

    Last Modified: 16 Dec 2025

    AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability. 

    Published: 6 Dec 2023
    7.8
    High

    CVE-2023-6288

    Last Modified: 21 Nov 2024

    Code injection in Remote Desktop Manager 2023.3.9.3 and earlier on macOS allows an attacker to execute code via the DYLIB_INSERT_LIBRARIES environment variable.

    Published: 6 Dec 2023
    7.2
    High

    CVE-2023-32268

    Last Modified: 21 Nov 2024

    Exposure of Proxy Administrator Credentials An authenticated administrator equivalent Filr user can access the credentials of proxy administrators.

    Published: 6 Dec 2023
    5.3
    Medium

    CVE-2023-6273

    Last Modified: 21 Nov 2024

    Permission management vulnerability in the module for disabling Sound Booster. Successful exploitation of this vulnerability may cause features to perform abnormally.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-49240

    Last Modified: 21 Nov 2024

    Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-49239

    Last Modified: 2 Dec 2024

    Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-49246

    Last Modified: 28 May 2025

    Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-49245

    Last Modified: 21 Nov 2024

    Unauthorized access vulnerability in the Huawei Share module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-49244

    Last Modified: 21 Nov 2024

    Permission management vulnerability in the multi-user module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-49243

    Last Modified: 21 Nov 2024

    Vulnerability of unauthorized access to email attachments in the email module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-49242

    Last Modified: 21 Nov 2024

    Free broadcast vulnerability in the running management module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-49241

    Last Modified: 21 Nov 2024

    API permission control vulnerability in the network management module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-44113

    Last Modified: 21 Nov 2024

    Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Dec 2023
    5.4
    Medium

    CVE-2023-34439

    Last Modified: 21 Nov 2024

    Pleasanter 1.3.47.0 and earlier contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the user's web browser.

    Published: 6 Dec 2023
    6.1
    Medium

    CVE-2023-46688

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in Pleasanter 1.3.47.0 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL.

    Published: 6 Dec 2023
    4.3
    Medium

    CVE-2023-45210

    Last Modified: 28 May 2025

    Pleasanter 1.3.47.0 and earlier contains an improper access control vulnerability, which may allow a remote authenticated attacker to view the temporary files uploaded by other users who are not permitted to access.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-44099

    Last Modified: 21 Nov 2024

    Vulnerability of data verification errors in the kernel module. Successful exploitation of this vulnerability may cause WLAN interruption.

    Published: 6 Dec 2023
    5.5
    Medium

    CVE-2023-49248

    Last Modified: 21 Nov 2024

    Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause unauthorized file access.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-49247

    Last Modified: 21 Nov 2024

    Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Dec 2023
    9.8
    Critical

    CVE-2023-46773

    Last Modified: 21 Nov 2024

    Permission management vulnerability in the PMS module. Successful exploitation of this vulnerability may cause privilege escalation.

    Published: 6 Dec 2023
    8.8
    High

    CVE-2023-6514

    Last Modified: 21 Nov 2024

    The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability. Successful exploitation of this vulnerability may allow attackers to access restricted functions.  Successful exploitation of this vulnerability may allow attackers to access restricted functions.

    Published: 6 Dec 2023
    5.3
    Medium

    CVE-2023-6459

    Last Modified: 16 Dec 2024

    Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs.

    Published: 6 Dec 2023
    7.1
    High

    CVE-2023-6458

    Last Modified: 21 Nov 2024

    Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traversal.

    Published: 6 Dec 2023
    5.3
    Medium

    CVE-2023-46219

    Last Modified: 12 May 2026

    When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.

    Published: 6 Dec 2023
    6.5
    Medium

    CVE-2023-46218

    Last Modified: 12 May 2026

    This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.

    Published: 6 Dec 2023
    8.8
    High

    CVE-2023-49897

    Last Modified: 24 Oct 2025

    An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

    Published: 6 Dec 2023
    7
    High

    CVE-2023-6531

    Last Modified: 6 Nov 2025

    A use-after-free flaw was found in the Linux Kernel due to a race problem in the unix garbage collector's deletion of SKB races with unix_stream_read_generic() on the socket that the SKB is queued on.

    Published: 6 Dec 2023
    8.8
    High

    CVE-2023-22522

    Last Modified: 25 Feb 2026

    This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page. Using this approach, an attacker is able to achieve Remote Code Execution (RCE) on an affected instance. Publicly accessible Confluence Data Center and Server versions as listed below are at risk and require immediate attention. See the advisory for additional details Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

    Published: 6 Dec 2023
    5.9
    Medium

    CVE-2023-26154

    Last Modified: 21 Nov 2024

    Versions of the package pubnub before 7.4.0; all versions of the package com.pubnub:pubnub; versions of the package pubnub before 6.19.0; all versions of the package github.com/pubnub/go; versions of the package github.com/pubnub/go/v7 before 7.2.0; versions of the package pubnub before 7.3.0; versions of the package pubnub/pubnub before 6.1.0; versions of the package pubnub before 5.3.0; versions of the package pubnub before 0.4.0; versions of the package pubnub/c-core before 4.5.0; versions of the package com.pubnub:pubnub-kotlin before 7.7.0; versions of the package pubnub/swift before 6.2.0; versions of the package pubnub before 5.2.0; versions of the package pubnub before 4.3.0 are vulnerable to Insufficient Entropy via the getKey function, due to inefficient implementation of the AES-256-CBC cryptographic algorithm. The provided encrypt function is less secure when hex encoding and trimming are applied, leaving half of the bits in the key always the same for every encoded message or file. **Note:** In order to exploit this vulnerability, the attacker needs to invest resources in preparing the attack and brute-force the encryption.

    Published: 6 Dec 2023
    8.8
    High

    CVE-2023-22523

    Last Modified: 25 Feb 2026

    This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets Discovery agent.

    Published: 6 Dec 2023
    9.8
    Critical

    CVE-2023-22524

    Last Modified: 25 Feb 2026

    Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code.

    Published: 6 Dec 2023
    6.1
    Medium

    CVE-2023-6527

    Last Modified: 8 Apr 2026

    The Email Subscription Popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the HTTP_REFERER header in all versions up to, and including, 1.2.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 6 Dec 2023
    5.3
    Medium

    CVE-2023-41268

    Last Modified: 2 Dec 2024

    Improper input validation vulnerability in Samsung Open Source Escargot allows stack overflow and segmentation fault. This issue affects Escargot: from 3.0.0 through 4.0.0.

    Published: 6 Dec 2023
    5
    Medium

    CVE-2023-40053

    Last Modified: 21 Nov 2024

    A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file share function feature of Serv-U, which could be used maliciously.

    Published: 6 Dec 2023
    6.5
    Medium

    CVE-2023-6512

    Last Modified: 28 May 2025

    Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the contents of an iframe dialog context menu via a crafted HTML page. (Chromium security severity: Low)

    Published: 6 Dec 2023
    4.3
    Medium

    CVE-2023-6511

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 6 Dec 2023
    8.8
    High

    CVE-2023-6510

    Last Modified: 13 Feb 2025

    Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)

    Published: 6 Dec 2023
    8.8
    High

    CVE-2023-6509

    Last Modified: 13 Feb 2025

    Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: High)

    Published: 6 Dec 2023
    8.8
    High

    CVE-2023-6508

    Last Modified: 13 Feb 2025

    Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 6 Dec 2023
    6.4
    Medium

    CVE-2021-27795

    Last Modified: 21 Nov 2024

    Brocade Fabric OS (FOS) hardware platforms running any version of Brocade Fabric OS software, which supports the license string format; contain cryptographic issues that could allow for the installation of forged or fraudulent license keys. This would allow attackers or a malicious party to forge a counterfeit license key that the Brocade Fabric OS platform would authenticate and activate as if it were a legitimate license key.

    Published: 6 Dec 2023
    8.8
    High

    CVE-2023-48859

    Last Modified: 21 Nov 2024

    TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows attackers to bypass front-end security restrictions and execute arbitrary code.

    Published: 6 Dec 2023
    9.8
    Critical

    CVE-2023-36655

    Last Modified: 21 Nov 2024

    The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login and obtain an authentication token by specifying a username with different uppercase/lowercase character combination.

    Published: 6 Dec 2023