CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2023-48691

    Last Modified: 21 Nov 2024

    Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause an out-of-bounds write in Azure RTOS NETX Duo, that could lead to remote code execution. The affected components include process related to IGMP protocol in RTOS v6.2.1 and below. The fix has been included in NetX Duo release 6.3.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 5 Dec 2023
    9.8
    Critical

    CVE-2023-48316

    Last Modified: 21 Nov 2024

    Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include processes/functions related to snmp, smtp, ftp and dtls in RTOS v6.2.1 and below. The fixes have been included in NetX Duo release 6.3.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-48315

    Last Modified: 27 Nov 2024

    Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include processes/functions related to ftp and sntp in RTOS v6.2.1 and below. The fixes have been included in NetX Duo release 6.3.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 5 Dec 2023
    6
    Medium

    CVE-2023-46674

    Last Modified: 21 Nov 2024

    An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration properties that could have been modified by authenticated users. Elastic would like to thank Yakov Shafranovich, with Amazon Web Services for reporting this issue.

    Published: 5 Dec 2023
    7.5
    High

    CVE-2023-37572

    Last Modified: 21 Nov 2024

    Softing OPC Suite version 5.25 and before has Incorrect Access Control, allows attackers to obtain sensitive information via weak permissions in OSF_discovery service. The service executable could be changed or the service could be deleted.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2022-47531

    Last Modified: 21 Nov 2024

    An issue was discovered in Ericsson Evolved Packet Gateway (EPG) versions 3.x before 3.25 and 2.x before 2.16, allows authenticated users to bypass system CLI and execute commands they are authorized to execute directly in the UNIX shell.

    Published: 5 Dec 2023
    7.5
    High

    CVE-2023-43472

    Last Modified: 21 Nov 2024

    An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.

    Published: 5 Dec 2023
    5.9
    Medium

    CVE-2023-43628

    Last Modified: 4 Nov 2025

    An integer underflow vulnerability exists in the NTRIP Stream Parsing functionality of GPSd 3.25.1~dev. A specially crafted network packet can lead to memory corruption. An attacker can send a malicious packet to trigger this vulnerability.

    Published: 5 Dec 2023
    7.5
    High

    CVE-2023-45287

    Last Modified: 13 Feb 2025

    Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.

    Published: 5 Dec 2023
    7.8
    High

    CVE-2023-47304

    Last Modified: 21 Nov 2024

    An issue was discovered in Vonage Box Telephone Adapter VDV23 version VDV21-3.2.11-0.5.1, allows local attackers to bypass UART authentication controls and read/write arbitrary values to the memory of the device.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-49379

    Last Modified: 21 Nov 2024

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /admin/friend_link/save.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-49395

    Last Modified: 21 Nov 2024

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/update.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-49396

    Last Modified: 21 Nov 2024

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/save.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-49397

    Last Modified: 21 Nov 2024

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/updateStatus.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-49398

    Last Modified: 21 Nov 2024

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/delete.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-49447

    Last Modified: 21 Nov 2024

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/update.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-49448

    Last Modified: 21 Nov 2024

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/nav/delete.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-49372

    Last Modified: 21 Nov 2024

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/slide/save.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-49373

    Last Modified: 21 Nov 2024

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/slide/delete.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-49374

    Last Modified: 21 Nov 2024

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/slide/update.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-49375

    Last Modified: 21 Nov 2024

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/update.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-49376

    Last Modified: 21 Nov 2024

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/delete.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-49377

    Last Modified: 21 Nov 2024

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/update.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-49378

    Last Modified: 21 Nov 2024

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/form/save.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-49380

    Last Modified: 21 Nov 2024

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/delete.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-49381

    Last Modified: 21 Nov 2024

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/update.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-49382

    Last Modified: 21 Nov 2024

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/delete.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-49383

    Last Modified: 21 Nov 2024

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/save.

    Published: 5 Dec 2023
    8.8
    High

    CVE-2023-49446

    Last Modified: 21 Nov 2024

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/save.

    Published: 5 Dec 2023
    7.5
    High

    CVE-2023-41835

    Last Modified: 4 Nov 2025

    When a Multipart request is performed but some of the fields exceed the maxStringLength  limit, the upload files will remain in struts.multipart.saveDir  even if the request has been denied. Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts 6.3.0.1 or greater, which fixe this issue.

    Published: 5 Dec 2023
    7.6
    High

    CVE-2023-5808

    Last Modified: 21 Nov 2024

    SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be barred to that specific administrative role.

    Published: 4 Dec 2023
    6.3
    Medium

    CVE-2023-49289

    Last Modified: 21 Nov 2024

    Ajax.NET Professional (AjaxPro) is an AJAX framework for Microsoft ASP.NET which will create proxy JavaScript classes that are used on client-side to invoke methods on the web server. Affected versions of this package are vulnerable cross site scripting attacks. Releases before version 21.12.22.1 are affected. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 4 Dec 2023
    3.9
    Low

    CVE-2023-49284

    Last Modified: 13 Feb 2025

    fish is a smart and user-friendly command line shell for macOS, Linux, and the rest of the family. fish shell uses certain Unicode non-characters internally for marking wildcards and expansions. It will incorrectly allow these markers to be read on command substitution output, rather than transforming them into a safe internal representation. While this may cause unexpected behavior with direct input (for example, echo \UFDD2HOME has the same output as echo $HOME), this may become a minor security problem if the output is being fed from an external program into a command substitution where this output may not be expected. This design flaw was introduced in very early versions of fish, predating the version control system, and is thought to be present in every version of fish released in the last 15 years or more, although with different characters. Code execution does not appear to be possible, but denial of service (through large brace expansion) or information disclosure (such as variable expansion) is potentially possible under certain circumstances. fish shell 3.6.2 has been released to correct this issue. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 4 Dec 2023
    5.3
    Medium

    CVE-2023-49290

    Last Modified: 29 May 2025

    lestrrat-go/jwx is a Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. A p2c parameter set too high in JWE's algorithm PBES2-* could lead to a denial of service. The JWE key management algorithms based on PBKDF2 require a JOSE Header Parameter called p2c (PBES2 Count). This parameter dictates the number of PBKDF2 iterations needed to derive a CEK wrapping key. Its primary purpose is to intentionally slow down the key derivation function, making password brute-force and dictionary attacks more resource- intensive. Therefore, if an attacker sets the p2c parameter in JWE to a very large number, it can cause a lot of computational consumption, resulting in a denial of service. This vulnerability has been addressed in commit `64f2a229b` which has been included in release version 1.2.27 and 2.0.18. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 4 Dec 2023
    9.3
    Critical

    CVE-2023-49291

    Last Modified: 21 Nov 2024

    tj-actions/branch-names is a Github action to retrieve branch or tag names with support for all events. The `tj-actions/branch-names` GitHub Actions improperly references the `github.event.pull_request.head.ref` and `github.head_ref` context variables within a GitHub Actions `run` step. The head ref variable is the branch name and can be used to execute arbitrary code using a specially crafted branch name. As a result an attacker can use this vulnerability to steal secrets from or abuse `GITHUB_TOKEN` permissions. This vulnerability has been addressed in version 7.0.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 4 Dec 2023
    4.9
    Medium

    CVE-2023-49292

    Last Modified: 21 Nov 2024

    ecies is an Elliptic Curve Integrated Encryption Scheme for secp256k1 in Golang. If funcations Encapsulate(), Decapsulate() and ECDH() could be called by an attacker, they could recover any private key that interacts with it. This vulnerability was patched in 2.0.8. Users are advised to upgrade.

    Published: 4 Dec 2023
    7.8
    High

    CVE-2023-5944

    Last Modified: 21 Nov 2024

    Delta Electronics DOPSoft is vulnerable to a stack-based buffer overflow, which may allow for arbitrary code execution if an attacker can lead a legitimate user to execute a specially crafted file.

    Published: 4 Dec 2023
    6.1
    Medium

    CVE-2023-49293

    Last Modified: 29 May 2025

    Vite is a website frontend framework. When Vite's HTML transformation is invoked manually via `server.transformIndexHtml`, the original request URL is passed in unmodified, and the `html` being transformed contains inline module scripts (`<script type="module">...</script>`), it is possible to inject arbitrary HTML into the transformed output by supplying a malicious URL query string to `server.transformIndexHtml`. Only apps using `appType: 'custom'` and using the default Vite HTML middleware are affected. The HTML entry must also contain an inline script. The attack requires a user to click on a malicious URL while running the dev server. Restricted files aren't exposed to the attacker. This issue has been addressed in [email protected], [email protected], and [email protected]. There are no known workarounds for this vulnerability.

    Published: 4 Dec 2023
    8.3
    High

    CVE-2023-40465

    Last Modified: 21 Nov 2024

    Several versions of ALEOS, including ALEOS 4.16.0, include an opensource third-party component which can be exploited from the local area network, resulting in a Denial of Service condition for the captive portal.

    Published: 4 Dec 2023
    8.1
    High

    CVE-2023-40464

    Last Modified: 25 Feb 2026

    Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items could potentially perform a man in the middle attack between the ACEManager client and ACEManager server.

    Published: 4 Dec 2023
    8.1
    High

    CVE-2023-40463

    Last Modified: 29 May 2025

    When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and earlier store the SHA512 hash of the common root password for that version in a directory accessible to a user with root privileges or equivalent access.

    Published: 4 Dec 2023
    7.5
    High

    CVE-2023-40462

    Last Modified: 13 Feb 2025

    The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable.

    Published: 4 Dec 2023
    8.1
    High

    CVE-2023-40461

    Last Modified: 25 Feb 2026

    The ACEManager component of ALEOS 4.16 and earlier allows an authenticated user with Administrator privileges to access a file upload field which does not fully validate the file name, creating a Stored Cross-Site Scripting condition.

    Published: 4 Dec 2023
    7.1
    High

    CVE-2023-40460

    Last Modified: 25 Feb 2026

    The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which could potentially allow an authenticated user to perform client-side script execution within ACEManager, altering the device functionality until the device is restarted.

    Published: 4 Dec 2023
    8.6
    High

    CVE-2023-49288

    Last Modified: 13 Feb 2025

    Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with "collapsed_forwarding on" are vulnerable. Configurations with "collapsed_forwarding off" or without a "collapsed_forwarding" directive are not vulnerable. This bug is fixed by Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should remove all collapsed_forwarding lines from their squid.conf.

    Published: 4 Dec 2023
    7.5
    High

    CVE-2023-40459

    Last Modified: 29 May 2025

    The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable.

    Published: 4 Dec 2023
    5.5
    Medium

    CVE-2023-45781

    Last Modified: 21 Nov 2024

    In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    7.8
    High

    CVE-2023-45779

    Last Modified: 21 Nov 2024

    In the APEX module framework of AOSP, there is a possible malicious update to platform components due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. More details on this can be found in the referenced links.

    Published: 4 Dec 2023
    7.8
    High

    CVE-2023-45777

    Last Modified: 21 Nov 2024

    In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to launch arbitrary activities using system privileges due to Parcel Mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    7.8
    High

    CVE-2023-45776

    Last Modified: 21 Nov 2024

    In CreateAudioBroadcast of broadcaster.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023