CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2023-49245

    Last Modified: 21 Nov 2024

    Unauthorized access vulnerability in the Huawei Share module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-49244

    Last Modified: 21 Nov 2024

    Permission management vulnerability in the multi-user module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-49243

    Last Modified: 21 Nov 2024

    Vulnerability of unauthorized access to email attachments in the email module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-49242

    Last Modified: 21 Nov 2024

    Free broadcast vulnerability in the running management module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-49241

    Last Modified: 21 Nov 2024

    API permission control vulnerability in the network management module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-44113

    Last Modified: 21 Nov 2024

    Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Dec 2023
    5.4
    Medium

    CVE-2023-34439

    Last Modified: 21 Nov 2024

    Pleasanter 1.3.47.0 and earlier contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the user's web browser.

    Published: 6 Dec 2023
    6.1
    Medium

    CVE-2023-46688

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in Pleasanter 1.3.47.0 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL.

    Published: 6 Dec 2023
    4.3
    Medium

    CVE-2023-45210

    Last Modified: 28 May 2025

    Pleasanter 1.3.47.0 and earlier contains an improper access control vulnerability, which may allow a remote authenticated attacker to view the temporary files uploaded by other users who are not permitted to access.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-44099

    Last Modified: 21 Nov 2024

    Vulnerability of data verification errors in the kernel module. Successful exploitation of this vulnerability may cause WLAN interruption.

    Published: 6 Dec 2023
    5.5
    Medium

    CVE-2023-49248

    Last Modified: 21 Nov 2024

    Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause unauthorized file access.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-49247

    Last Modified: 21 Nov 2024

    Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Dec 2023
    9.8
    Critical

    CVE-2023-46773

    Last Modified: 21 Nov 2024

    Permission management vulnerability in the PMS module. Successful exploitation of this vulnerability may cause privilege escalation.

    Published: 6 Dec 2023
    8.8
    High

    CVE-2023-6514

    Last Modified: 21 Nov 2024

    The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability. Successful exploitation of this vulnerability may allow attackers to access restricted functions.  Successful exploitation of this vulnerability may allow attackers to access restricted functions.

    Published: 6 Dec 2023
    5.3
    Medium

    CVE-2023-6459

    Last Modified: 16 Dec 2024

    Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs.

    Published: 6 Dec 2023
    7.1
    High

    CVE-2023-6458

    Last Modified: 21 Nov 2024

    Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traversal.

    Published: 6 Dec 2023
    5.3
    Medium

    CVE-2023-46219

    Last Modified: 12 May 2026

    When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.

    Published: 6 Dec 2023
    6.5
    Medium

    CVE-2023-46218

    Last Modified: 12 May 2026

    This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.

    Published: 6 Dec 2023
    8.8
    High

    CVE-2023-49897

    Last Modified: 24 Oct 2025

    An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

    Published: 6 Dec 2023
    7
    High

    CVE-2023-6531

    Last Modified: 6 Nov 2025

    A use-after-free flaw was found in the Linux Kernel due to a race problem in the unix garbage collector's deletion of SKB races with unix_stream_read_generic() on the socket that the SKB is queued on.

    Published: 6 Dec 2023
    8.8
    High

    CVE-2023-22522

    Last Modified: 25 Feb 2026

    This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page. Using this approach, an attacker is able to achieve Remote Code Execution (RCE) on an affected instance. Publicly accessible Confluence Data Center and Server versions as listed below are at risk and require immediate attention. See the advisory for additional details Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

    Published: 6 Dec 2023
    5.9
    Medium

    CVE-2023-26154

    Last Modified: 21 Nov 2024

    Versions of the package pubnub before 7.4.0; all versions of the package com.pubnub:pubnub; versions of the package pubnub before 6.19.0; all versions of the package github.com/pubnub/go; versions of the package github.com/pubnub/go/v7 before 7.2.0; versions of the package pubnub before 7.3.0; versions of the package pubnub/pubnub before 6.1.0; versions of the package pubnub before 5.3.0; versions of the package pubnub before 0.4.0; versions of the package pubnub/c-core before 4.5.0; versions of the package com.pubnub:pubnub-kotlin before 7.7.0; versions of the package pubnub/swift before 6.2.0; versions of the package pubnub before 5.2.0; versions of the package pubnub before 4.3.0 are vulnerable to Insufficient Entropy via the getKey function, due to inefficient implementation of the AES-256-CBC cryptographic algorithm. The provided encrypt function is less secure when hex encoding and trimming are applied, leaving half of the bits in the key always the same for every encoded message or file. **Note:** In order to exploit this vulnerability, the attacker needs to invest resources in preparing the attack and brute-force the encryption.

    Published: 6 Dec 2023
    8.8
    High

    CVE-2023-22523

    Last Modified: 25 Feb 2026

    This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets Discovery agent.

    Published: 6 Dec 2023
    9.8
    Critical

    CVE-2023-22524

    Last Modified: 25 Feb 2026

    Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code.

    Published: 6 Dec 2023
    6.1
    Medium

    CVE-2023-6527

    Last Modified: 8 Apr 2026

    The Email Subscription Popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the HTTP_REFERER header in all versions up to, and including, 1.2.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 6 Dec 2023
    5.3
    Medium

    CVE-2023-41268

    Last Modified: 2 Dec 2024

    Improper input validation vulnerability in Samsung Open Source Escargot allows stack overflow and segmentation fault. This issue affects Escargot: from 3.0.0 through 4.0.0.

    Published: 6 Dec 2023
    5
    Medium

    CVE-2023-40053

    Last Modified: 21 Nov 2024

    A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file share function feature of Serv-U, which could be used maliciously.

    Published: 6 Dec 2023
    6.5
    Medium

    CVE-2023-6512

    Last Modified: 28 May 2025

    Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the contents of an iframe dialog context menu via a crafted HTML page. (Chromium security severity: Low)

    Published: 6 Dec 2023
    4.3
    Medium

    CVE-2023-6511

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 6 Dec 2023
    8.8
    High

    CVE-2023-6510

    Last Modified: 13 Feb 2025

    Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)

    Published: 6 Dec 2023
    8.8
    High

    CVE-2023-6509

    Last Modified: 13 Feb 2025

    Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: High)

    Published: 6 Dec 2023
    8.8
    High

    CVE-2023-6508

    Last Modified: 13 Feb 2025

    Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 6 Dec 2023
    6.4
    Medium

    CVE-2021-27795

    Last Modified: 21 Nov 2024

    Brocade Fabric OS (FOS) hardware platforms running any version of Brocade Fabric OS software, which supports the license string format; contain cryptographic issues that could allow for the installation of forged or fraudulent license keys. This would allow attackers or a malicious party to forge a counterfeit license key that the Brocade Fabric OS platform would authenticate and activate as if it were a legitimate license key.

    Published: 6 Dec 2023
    8.8
    High

    CVE-2023-48859

    Last Modified: 21 Nov 2024

    TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows attackers to bypass front-end security restrictions and execute arbitrary code.

    Published: 6 Dec 2023
    9.8
    Critical

    CVE-2023-36655

    Last Modified: 21 Nov 2024

    The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login and obtain an authentication token by specifying a username with different uppercase/lowercase character combination.

    Published: 6 Dec 2023
    5.4
    Medium

    CVE-2023-28875

    Last Modified: 21 Nov 2024

    A Stored XSS issue in shared files download terms in Filerun Update 20220202 allows attackers to inject JavaScript code that is executed when a user follows the crafted share link.

    Published: 6 Dec 2023
    4.3
    Medium

    CVE-2023-28876

    Last Modified: 21 Nov 2024

    A Broken Access Control issue in comments to uploaded files in Filerun through Update 20220202 allows attackers to delete comments on files uploaded by other users.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-45285

    Last Modified: 13 Feb 2025

    Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the module is unavailable via the secure "https://" and "git+ssh://" protocols, even if GOINSECURE is not set for said module. This only affects users who are not using the module proxy and are fetching modules directly (i.e. GOPROXY=off).

    Published: 6 Dec 2023
    9.8
    Critical

    CVE-2023-46353

    Last Modified: 26 Nov 2024

    In the module "Product Tag Icons Pro" (ticons) before 1.8.4 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The method TiconProduct::getTiconByProductAndTicon() has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-46354

    Last Modified: 21 Nov 2024

    In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from ps_customer/ps_address tables such as name / surname / email / phone number / full postal address.

    Published: 6 Dec 2023
    7.5
    High

    CVE-2023-46751

    Last Modified: 21 Nov 2024

    An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows remote attackers to crash the application via a dangling pointer.

    Published: 6 Dec 2023
    8.8
    High

    CVE-2023-48123

    Last Modified: 21 Nov 2024

    An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.

    Published: 6 Dec 2023
    9.8
    Critical

    CVE-2023-48849

    Last Modified: 21 Nov 2024

    Ruijie EG Series Routers version EG_3.0(1)B11P216 and before allows unauthenticated attackers to remotely execute arbitrary code due to incorrect filtering.

    Published: 6 Dec 2023
    9.8
    Critical

    CVE-2023-48930

    Last Modified: 26 Nov 2024

    xinhu xinhuoa 2.2.1 contains a File upload vulnerability.

    Published: 6 Dec 2023
    5.4
    Medium

    CVE-2023-48940

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in /admin.php of DaiCuo v2.5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 6 Dec 2023
    7.2
    High

    CVE-2023-5384

    Last Modified: 20 Nov 2025

    A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.

    Published: 6 Dec 2023
    5.3
    Medium

    CVE-2023-39326

    Last Modified: 13 Feb 2025

    A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read many more bytes from the network than are in the body. A malicious HTTP client can further exploit this to cause a server to automatically read a large amount of data (up to about 1GiB) when a handler fails to read the entire body of a request. Chunk extensions are a little-used HTTP feature which permit including additional metadata in a request or response body sent using the chunked encoding. The net/http chunked encoding reader discards this metadata. A sender can exploit this by inserting a large metadata segment with each byte transferred. The chunk reader now produces an error if the ratio of real body to encoded bytes grows too small.

    Published: 6 Dec 2023
    5.9
    Medium

    CVE-2023-24547

    Last Modified: 28 May 2025

    On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in clear text that can be revealed in local logs or remote logging servers by authenticated users, as well as appear in clear text in the device’s running config.

    Published: 5 Dec 2023
    5.4
    Medium

    CVE-2023-49283

    Last Modified: 21 Nov 2024

    microsoft-graph-core the Microsoft Graph Library for PHP. The Microsoft Graph Beta PHP SDK published packages which contained test code that enabled the use of the phpInfo() function from any application that could access and execute the file at `vendor/microsoft/microsoft-graph-core/tests/GetPhpInfo.php`. The phpInfo function exposes system information. The vulnerability affects the GetPhpInfo.php script of the PHP SDK which contains a call to the phpinfo() function. This vulnerability requires a misconfiguration of the server to be present so it can be exploited. For example, making the PHP application’s /vendor directory web accessible. The combination of the vulnerability and the server misconfiguration would allow an attacker to craft an HTTP request that executes the phpinfo() method. The attacker would then be able to get access to system information like configuration, modules, and environment variables and later on use the compromised secrets to access additional data. This problem has been patched in version 2.0.2. If an immediate deployment with the updated vendor package is not available, you can perform the following temporary workarounds: delete the `vendor/microsoft/microsoft-graph-core/tests/GetPhpInfo.php` file, remove access to the /vendor directory, or disable the phpinfo function

    Published: 5 Dec 2023
    5.4
    Medium

    CVE-2023-49282

    Last Modified: 21 Nov 2024

    msgraph-sdk-php is the Microsoft Graph Library for PHP. The Microsoft Graph PHP SDK published packages which contained test code that enabled the use of the phpInfo() function from any application that could access and execute the file at vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php. The phpInfo function exposes system information. The vulnerability affects the GetPhpInfo.php script of the PHP SDK which contains a call to the phpinfo() function. This vulnerability requires a misconfiguration of the server to be present so it can be exploited. For example, making the PHP application’s /vendor directory web accessible. The combination of the vulnerability and the server misconfiguration would allow an attacker to craft an HTTP request that executes the phpinfo() method. The attacker would then be able to get access to system information like configuration, modules, and environment variables and later on use the compromised secrets to access additional data. This problem has been patched in versions 1.109.1 and 2.0.0-RC5. If an immediate deployment with the updated vendor package is not available, you can perform the following temporary workarounds: delete the `vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php` file, remove access to the `/vendor` directory, or disable the phpinfo function.

    Published: 5 Dec 2023