CVE Feed

    Dashboard / CVE

    4.4
    Medium

    CVE-2023-42679

    Last Modified: 21 Nov 2024

    In gpu driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

    Published: 4 Dec 2023
    5.5
    Medium

    CVE-2023-42678

    Last Modified: 21 Nov 2024

    In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 4 Dec 2023
    5.5
    Medium

    CVE-2023-42677

    Last Modified: 21 Nov 2024

    In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 4 Dec 2023
    5.5
    Medium

    CVE-2023-42676

    Last Modified: 21 Nov 2024

    In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 4 Dec 2023
    5.5
    Medium

    CVE-2023-42675

    Last Modified: 2 Dec 2024

    In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 4 Dec 2023
    5.5
    Medium

    CVE-2023-42674

    Last Modified: 21 Nov 2024

    In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 4 Dec 2023
    5.5
    Medium

    CVE-2023-42673

    Last Modified: 21 Nov 2024

    In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 4 Dec 2023
    5.5
    Medium

    CVE-2023-42672

    Last Modified: 21 Nov 2024

    In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 4 Dec 2023
    5.5
    Medium

    CVE-2023-42671

    Last Modified: 21 Nov 2024

    In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 4 Dec 2023
    6.5
    Medium

    CVE-2023-47701

    Last Modified: 13 Feb 2025

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query. IBM X-Force ID: 266166.

    Published: 4 Dec 2023
    7.2
    High

    CVE-2023-38003

    Last Modified: 29 May 2025

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a user with DATAACCESS privileges to execute routines that they should not have access to. IBM X-Force ID: 260214.

    Published: 4 Dec 2023
    5.9
    Medium

    CVE-2023-46167

    Last Modified: 13 Feb 2025

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of service when a specially crafted cursor is used. IBM X-Force ID: 269367.

    Published: 4 Dec 2023
    7.1
    High

    CVE-2023-6610

    Last Modified: 25 Aug 2026

    An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/client/smb2ops.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information.

    Published: 4 Dec 2023
    5.3
    Medium

    CVE-2023-6484

    Last Modified: 26 Jun 2026

    A log injection flaw was found in Keycloak. A text string may be injected through the authentication form when using the WebAuthn authentication mode. This issue may have a minor impact to the logs integrity.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-24049

    Last Modified: 29 May 2025

    An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges on the device via poor credential management.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-48910

    Last Modified: 21 Nov 2024

    Microcks up to 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.

    Published: 4 Dec 2023
    8.8
    High

    CVE-2023-48965

    Last Modified: 26 Nov 2024

    An issue in the component /admin/api.plugs/script of ThinkAdmin v6.1.53 allows attackers to getshell via providing a crafted URL to download a malicious PHP file.

    Published: 4 Dec 2023
    8.1
    High

    CVE-2022-46480

    Last Modified: 21 Nov 2024

    Incorrect Session Management and Credential Re-use in the Bluetooth LE stack of the Ultraloq UL3 2nd Gen Smart Lock Firmware 02.27.0012 allows an attacker to sniff the unlock code and unlock the device whilst within Bluetooth range.

    Published: 4 Dec 2023
    8.8
    High

    CVE-2023-24048

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via crafted GET request to /man_password.htm.

    Published: 4 Dec 2023
    6.8
    Medium

    CVE-2023-24047

    Last Modified: 21 Nov 2024

    An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via use of weak hashing algorithm.

    Published: 4 Dec 2023
    6.8
    Medium

    CVE-2023-24046

    Last Modified: 21 Nov 2024

    An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary commands via use of a crafted string in the ping utility.

    Published: 4 Dec 2023
    5.4
    Medium

    CVE-2023-24050

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary code via crafted string when setting the Wi-Fi password in the admin panel.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-24051

    Last Modified: 21 Nov 2024

    A client side rate limit issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via brute force style attacks.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-24052

    Last Modified: 21 Nov 2024

    An issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via the change password functionality as it does not prompt for the current password.

    Published: 4 Dec 2023
    6.5
    Medium

    CVE-2023-26941

    Last Modified: 21 Nov 2024

    Weak encryption mechanisms in RFID Tags in Yale Conexis L1 v1.1.0 allows attackers to create a cloned tag via physical proximity to the original.

    Published: 4 Dec 2023
    6.5
    Medium

    CVE-2023-26942

    Last Modified: 21 Nov 2024

    Weak encryption mechanisms in RFID Tags in Yale IA-210 Alarm v1.0 allows attackers to create a cloned tag via physical proximity to the original.

    Published: 4 Dec 2023
    6.5
    Medium

    CVE-2023-26943

    Last Modified: 21 Nov 2024

    Weak encryption mechanisms in RFID Tags in Yale Keyless Lock v1.0 allows attackers to create a cloned tag via physical proximity to the original.

    Published: 4 Dec 2023
    7.1
    High

    CVE-2023-6606

    Last Modified: 8 Nov 2025

    An out-of-bounds read vulnerability was found in smbCalcSize in fs/smb/client/netmisc.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information.

    Published: 4 Dec 2023
    7.8
    High

    CVE-2023-41613

    Last Modified: 21 Nov 2024

    EzViz Studio v2.2.0 is vulnerable to DLL hijacking.

    Published: 4 Dec 2023
    6.8
    Medium

    CVE-2023-4503

    Last Modified: 21 Nov 2024

    An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-48799

    Last Modified: 21 Nov 2024

    TOTOLINK-X6000R Firmware-V9.4.0cu.852_B20230719 is vulnerable to Command Execution.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-48800

    Last Modified: 21 Nov 2024

    In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_417338 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resulting in a command execution vulnerability.

    Published: 4 Dec 2023
    6.1
    Medium

    CVE-2023-48815

    Last Modified: 21 Nov 2024

    kkFileView v4.3.0 is vulnerable to Incorrect Access Control.

    Published: 4 Dec 2023
    7.5
    High

    CVE-2023-48863

    Last Modified: 3 Jun 2025

    SEMCMS 3.9 is vulnerable to SQL Injection. Due to the lack of security checks on the input of the application, the attacker uses the existing application to inject malicious SQL commands into the background database engine for execution, and sends some attack codes as commands or query statements to the interpreter. These malicious data can deceive the interpreter, so as to execute unplanned commands or unauthorized access to data.

    Published: 4 Dec 2023
    8.8
    High

    CVE-2023-48966

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in the component /admin/api.upload/file of ThinkAdmin v6.1.53 allows attackers to execute arbitrary code via a crafted Zip file.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-48967

    Last Modified: 21 Nov 2024

    Ssolon <= 2.6.0 and <=2.5.12 is vulnerable to Deserialization of Untrusted Data.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-49093

    Last Modified: 21 Nov 2024

    HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage. This vulnerability has been patched in version 3.9.0

    Published: 4 Dec 2023
    8.6
    High

    CVE-2023-49285

    Last Modified: 13 Feb 2025

    Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 4 Dec 2023
    8.6
    High

    CVE-2023-49286

    Last Modified: 13 Feb 2025

    Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Incorrect Check of Function Return Value bug Squid is vulnerable to a Denial of Service attack against its Helper process management. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 4 Dec 2023
    —
    Unknown

    CVE-2023-50119

    Last Modified: 21 Dec 2023

    DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-45292. Reason: This record is a reservation duplicate of CVE-2023-45292. Notes: All CVE users should reference CVE-2023-45292 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

    Published: 4 Dec 2023
    5.9
    Medium

    CVE-2023-5332

    Last Modified: 21 Nov 2024

    Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

    Published: 4 Dec 2023
    5.4
    Medium

    CVE-2023-48866

    Last Modified: 29 Sept 2025

    A Cross-Site Scripting (XSS) vulnerability in the recipe preparation component within /api/objects/recipes and note component within /api/objects/shopping_lists/ of Grocy <= 4.0.3 allows attackers to obtain the victim's cookies.

    Published: 4 Dec 2023
    7.1
    High

    CVE-2023-6481

    Last Modified: 21 Nov 2024

    A serialization vulnerability in logback receiver component part of logback version 1.4.13, 1.3.13 and 1.2.12 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.

    Published: 4 Dec 2023
    5.9
    Medium

    CVE-2023-40692

    Last Modified: 13 Feb 2025

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, 11.5 is vulnerable to denial of service under extreme stress conditions. IBM X-Force ID: 264807.

    Published: 3 Dec 2023
    3.5
    Low

    CVE-2022-4957

    Last Modified: 3 Jun 2025

    A vulnerability was found in librespeed speedtest up to 5.2.4. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file results/stats.php. The manipulation of the argument id leads to cross site scripting. The attack can be launched remotely. Upgrading to version 5.2.5 is able to address this issue. The patch is named a85f2c086f3449dffa8fe2edb5e2ef3ee72dc0e9. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-246643.

    Published: 3 Dec 2023
    6.5
    Medium

    CVE-2023-45178

    Last Modified: 13 Feb 2025

    IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 CLI is vulnerable to a denial of service when a specially crafted request is used. IBM X-Force ID: 268073.

    Published: 3 Dec 2023
    7.3
    High

    CVE-2020-36768

    Last Modified: 21 Nov 2024

    A vulnerability was found in rl-institut NESP2 Initial Release/1.0. It has been classified as critical. Affected is an unknown function of the file app/database.py. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 07c0cdf36cf6a4345086d07b54423723a496af5e. It is recommended to apply a patch to fix this issue. VDB-246642 is the identifier assigned to this vulnerability.

    Published: 3 Dec 2023
    3.5
    Low

    CVE-2018-25094

    Last Modified: 21 Nov 2024

    A vulnerability was found in ระบบบัญชีออนไลน์ Online Accounting System up to 1.4.0 and classified as problematic. This issue affects some unknown processing of the file ckeditor/filemanager/browser/default/image.php. The manipulation of the argument fid with the input ../../../etc/passwd leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. Upgrading to version 2.0.0 is able to address this issue. The identifier of the patch is 9d9618422b980335bb30be612ea90f4f56cb992c. It is recommended to upgrade the affected component. The identifier VDB-246641 was assigned to this vulnerability.

    Published: 3 Dec 2023
    6.1
    Medium

    CVE-2023-49926

    Last Modified: 21 Nov 2024

    app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget.

    Published: 3 Dec 2023
    9.1
    Critical

    CVE-2023-49946

    Last Modified: 21 Nov 2024

    In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are being checked. This allows remote attackers to read private issues, read private pull requests, delete issues, and perform other unauthorized actions.

    Published: 3 Dec 2023