CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2023-46736

    Last Modified: 21 Nov 2024

    EspoCRM is an Open Source CRM (Customer Relationship Management) software. In affected versions there is Server-Side Request Forgery (SSRF) vulnerability via the upload image from url api. Users who have access to `the /Attachment/fromImageUrl` endpoint can specify URL to point to an internal host. Even though there is check for content type, it can be bypassed by redirects in some cases. This SSRF can be leveraged to disclose internal information (in some cases), target internal hosts and bypass firewalls. This vulnerability has been addressed in commit `c536cee63` which is included in release version 8.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 5 Dec 2023
    3.3
    Low

    CVE-2023-49297

    Last Modified: 13 Feb 2025

    PyDrive2 is a wrapper library of google-api-python-client that simplifies many common Google Drive API V2 tasks. Unsafe YAML deserilization will result in arbitrary code execution. A maliciously crafted YAML file can cause arbitrary code execution if PyDrive2 is run in the same directory as it, or if it is loaded in via `LoadSettingsFile`. This is a deserilization attack that will affect any user who initializes GoogleAuth from this package while a malicious yaml file is present in the same directory. This vulnerability does not require the file to be directly loaded through the code, only present. This issue has been addressed in commit `c57355dc` which is included in release version `1.16.2`. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-5970

    Last Modified: 21 Nov 2024

    Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resulting in an MFA bypass.

    Published: 5 Dec 2023
    7.2
    High

    CVE-2023-44221

    Last Modified: 31 Oct 2025

    Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.

    Published: 5 Dec 2023
    9.8
    Critical

    CVE-2023-6448

    Last Modified: 26 Feb 2026

    Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.

    Published: 5 Dec 2023
    3.2
    Low

    CVE-2023-45085

    Last Modified: 21 Nov 2024

    An issue exists in SoftIron HyperCloud where compute nodes may come online immediately without following the correct initialization process.  In this instance, workloads may be scheduled on these nodes and deploy to a failed or erroneous state, which impacts the availability of these workloads that may be deployed during this time window. This issue impacts HyperCloud versions from 2.0.0 to before 2.0.3.

    Published: 5 Dec 2023
    7
    High

    CVE-2023-45084

    Last Modified: 2 Dec 2024

    An issue exists in SoftIron HyperCloud where drive caddy removal and reinsertion without a reboot may erroneously cause the system to recognize the caddy as new media and wipe all data on the drives due to a missing synchronization flaw, which impacts data availability and integrity. This issue only impacts SoftIron HyperCloud "density" storage nodes running HyperCloud software versions 1.0 to before 2.0.3.

    Published: 5 Dec 2023
    4.2
    Medium

    CVE-2023-45083

    Last Modified: 21 Nov 2024

    An Improper Privilege Management vulnerability exists in HyperCloud that will impact the ability for a user to authenticate against the management plane. An authenticated admin-level user may be able to delete the "admin" or "serveradmin" users, which prevents authentication from subsequently succeeding. This issue affects HyperCloud versions 1.0 to any release before 2.1.

    Published: 5 Dec 2023
    3.6
    Low

    CVE-2023-44298

    Last Modified: 21 Nov 2024

    Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information tampering, code execution, denial of service.

    Published: 5 Dec 2023
    7.1
    High

    CVE-2023-44297

    Last Modified: 21 Nov 2024

    Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information disclosure, information tampering, code execution, denial of service.

    Published: 5 Dec 2023
    5.3
    Medium

    CVE-2023-6180

    Last Modified: 21 Nov 2024

    The tokio-boring library in version 4.0.0 is affected by a memory leak issue that can lead to excessive resource consumption and potential DoS by resource exhaustion. The set_ex_data function used by the library did not deallocate memory used by pre-existing data in memory each time after completing a TLS connection causing the program to consume more resources with each new connection.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-6357

    Last Modified: 21 Nov 2024

    A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.

    Published: 5 Dec 2023
    4.3
    Medium

    CVE-2022-24403

    Last Modified: 21 Nov 2024

    The TETRA TA61 identity encryption function internally uses a 64-bit value derived exclusively from the SCK (Class 2 networks) or CCK (Class 3 networks). The structure of TA61 allows for efficient recovery of this 64-bit value, allowing an adversary to encrypt or decrypt arbitrary identities given only three known encrypted/unencrypted identity pairs.

    Published: 5 Dec 2023
    —
    Unknown

    CVE-2023-50182

    Last Modified: 17 Mar 2025

    Not used

    Published: 5 Dec 2023
    —
    Unknown

    CVE-2023-50183

    Last Modified: 17 Mar 2025

    Not used

    Published: 5 Dec 2023
    —
    Unknown

    CVE-2023-50184

    Last Modified: 17 Mar 2025

    Not used

    Published: 5 Dec 2023
    —
    Unknown

    CVE-2023-50185

    Last Modified: 17 Mar 2025

    Not used

    Published: 5 Dec 2023
    8.1
    High

    CVE-2023-45842

    Last Modified: 4 Nov 2025

    Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `mxsldr` package.

    Published: 5 Dec 2023
    8.1
    High

    CVE-2023-45841

    Last Modified: 4 Nov 2025

    Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `versal-firmware` package.

    Published: 5 Dec 2023
    8.1
    High

    CVE-2023-45840

    Last Modified: 4 Nov 2025

    Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `riscv64-elf-toolchain` package.

    Published: 5 Dec 2023
    8.1
    High

    CVE-2023-45839

    Last Modified: 4 Nov 2025

    Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `aufs-util` package.

    Published: 5 Dec 2023
    8.1
    High

    CVE-2023-45838

    Last Modified: 4 Nov 2025

    Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `aufs` package.

    Published: 5 Dec 2023
    8.1
    High

    CVE-2023-43608

    Last Modified: 4 Nov 2025

    A data integrity vulnerability exists in the BR_NO_CHECK_HASH_FOR functionality of Buildroot 2023.08.1 and dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.

    Published: 5 Dec 2023
    9.8
    Critical

    CVE-2023-49070

    Last Modified: 13 Feb 2025

    Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Users are recommended to upgrade to version 18.12.10

    Published: 5 Dec 2023
    10
    Critical

    CVE-2023-6269

    Last Modified: 13 Feb 2025

    An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versions V10R10.12.00 and V10R11.05.02. This allows an unauthenticated attacker to gain root access to the appliance via SSH (scope change) and also bypass authentication for the administrative interface and gain access as an arbitrary (administrative) user.

    Published: 5 Dec 2023
    7.5
    High

    CVE-2023-5188

    Last Modified: 21 Nov 2024

    The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol Configurator is vulnerable to malformed packets. An remote unauthenticated attacker could send specifically crafted packets that lead to a denial-of-service condition until restart of the affected device.

    Published: 5 Dec 2023
    7.5
    High

    CVE-2023-39248

    Last Modified: 28 May 2025

    Dell OS10 Networking Switches running 10.5.2.x and above contain an Uncontrolled Resource Consumption (Denial of Service) vulnerability, when switches are configured with VLT and VRRP. A remote unauthenticated user can cause the network to be flooded leading to Denial of Service for actual network users. This is a high severity vulnerability as it allows an attacker to cause an outage of network. Dell recommends customers to upgrade at the earliest opportunity.

    Published: 5 Dec 2023
    6.3
    Medium

    CVE-2023-44295

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to loss of information, and information disclosure.

    Published: 5 Dec 2023
    7.5
    High

    CVE-2023-44288

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS, 8.2.2.x through 9.6.0.x, contains an improper control of a resource through its lifetime vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, leading to denial of service.

    Published: 5 Dec 2023
    8.4
    High

    CVE-2023-33107

    Last Modified: 28 Oct 2025

    Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

    Published: 5 Dec 2023
    8.4
    High

    CVE-2023-33106

    Last Modified: 28 Oct 2025

    Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.

    Published: 5 Dec 2023
    7.5
    High

    CVE-2023-33098

    Last Modified: 11 Aug 2025

    Transient DOS while parsing WPA IES, when it is passed with length more than expected size.

    Published: 5 Dec 2023
    7.5
    High

    CVE-2023-33097

    Last Modified: 21 Nov 2024

    Transient DOS in WLAN Firmware while processing a FTMR frame.

    Published: 5 Dec 2023
    8.4
    High

    CVE-2023-33092

    Last Modified: 11 Aug 2025

    Memory corruption while processing pin reply in Bluetooth, when pin code received from APP layer is greater than expected size.

    Published: 5 Dec 2023
    7.5
    High

    CVE-2023-33089

    Last Modified: 11 Aug 2025

    Transient DOS when processing a NULL buffer while parsing WLAN vdev.

    Published: 5 Dec 2023
    8.4
    High

    CVE-2023-33088

    Last Modified: 11 Aug 2025

    Memory corruption when processing cmd parameters while parsing vdev.

    Published: 5 Dec 2023
    7.8
    High

    CVE-2023-33087

    Last Modified: 11 Aug 2025

    Memory corruption in Core while processing RX intent request.

    Published: 5 Dec 2023
    9.8
    Critical

    CVE-2023-33083

    Last Modified: 2 Dec 2024

    Memory corruption in WLAN Host while processing RRM beacon on the AP.

    Published: 5 Dec 2023
    9.8
    Critical

    CVE-2023-33082

    Last Modified: 25 Feb 2026

    Memory corruption while sending an Assoc Request having BTM Query or BTM Response containing MBO IE.

    Published: 5 Dec 2023
    7.5
    High

    CVE-2023-33081

    Last Modified: 21 Nov 2024

    Transient DOS while converting TWT (Target Wake Time) frame parameters in the OTA broadcast.

    Published: 5 Dec 2023
    7.5
    High

    CVE-2023-33080

    Last Modified: 11 Aug 2025

    Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.

    Published: 5 Dec 2023
    7.8
    High

    CVE-2023-33079

    Last Modified: 11 Aug 2025

    Memory corruption in Audio while running invalid audio recording from ADSP.

    Published: 5 Dec 2023
    8.4
    High

    CVE-2023-33071

    Last Modified: 25 Feb 2026

    Memory corruption in Automotive OS whenever untrusted apps try to access HAb for graphics functionalities.

    Published: 5 Dec 2023
    7.1
    High

    CVE-2023-33070

    Last Modified: 11 Aug 2025

    Transient DOS in Automotive OS due to improper authentication to the secure IO calls.

    Published: 5 Dec 2023
    7.8
    High

    CVE-2023-33063

    Last Modified: 27 Oct 2025

    Memory corruption in DSP Services during a remote call from HLOS to DSP.

    Published: 5 Dec 2023
    9.1
    Critical

    CVE-2023-33054

    Last Modified: 11 Aug 2025

    Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.

    Published: 5 Dec 2023
    8.4
    High

    CVE-2023-33053

    Last Modified: 11 Aug 2025

    Memory corruption in Kernel while parsing metadata.

    Published: 5 Dec 2023
    7.5
    High

    CVE-2023-33044

    Last Modified: 11 Aug 2025

    Transient DOS in Data modem while handling TLB control messages from the Network.

    Published: 5 Dec 2023
    7.5
    High

    CVE-2023-33043

    Last Modified: 11 Aug 2025

    Transient DOS in Modem when a Beam switch request is made with a non-configured BWP.

    Published: 5 Dec 2023
    7.5
    High

    CVE-2023-33042

    Last Modified: 11 Aug 2025

    Transient DOS in Modem after RRC Setup message is received.

    Published: 5 Dec 2023