CVE Feed

    Dashboard / CVE

    2.6
    Low

    CVE-2023-4912

    Last Modified: 20 Nov 2025

    An issue has been discovered in GitLab EE affecting all versions starting from 10.5 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted mermaid diagram input.

    Published: 1 Dec 2023
    4.8
    Medium

    CVE-2023-5226

    Last Modified: 23 Apr 2026

    An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI.

    Published: 1 Dec 2023
    8.7
    High

    CVE-2023-6033

    Last Modified: 20 Nov 2025

    Improper neutralization of input in Jira integration configuration in GitLab CE/EE, affecting all versions from 15.10 prior to 16.6.1, 16.5 prior to 16.5.3, and 16.4 prior to 16.4.3 allows attacker to execute javascript in victim's browser.

    Published: 1 Dec 2023
    4.4
    Medium

    CVE-2023-5995

    Last Modified: 20 Nov 2025

    An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the policy bot to gain access to internal projects.

    Published: 1 Dec 2023
    5.3
    Medium

    CVE-2023-5915

    Last Modified: 21 Nov 2024

    A vulnerability of Uncontrolled Resource Consumption has been identified in STARDOM provided by Yokogawa Electric Corporation. This vulnerability may allow to a remote attacker to cause a denial-of-service condition to the FCN/FCJ controller by sending a crafted packet. While sending the packet, the maintenance homepage of the controller could not be accessed. Therefore, functions of the maintenance homepage, changing configuration, viewing logs, etc. are not available. But the controller’s operation is not stopped by the condition. The affected products and versions are as follows: STARDOM FCN/FCJ R1.01 to R4.31.

    Published: 1 Dec 2023
    4.4
    Medium

    CVE-2023-43089

    Last Modified: 21 Nov 2024

    Dell Rugged Control Center, version prior to 4.7, contains insufficient protection for the Policy folder. A local malicious standard user could potentially exploit this vulnerability to modify the content of the policy file, leading to unauthorized access to resources.

    Published: 1 Dec 2023
    7.8
    High

    CVE-2023-45252

    Last Modified: 21 Nov 2024

    DLL Hijacking vulnerability in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, due to the installation of the service in a directory that grants write privileges to standard users, allows attackers to manipulate files, execute arbitrary code, and escalate privileges.

    Published: 1 Dec 2023
    9.8
    Critical

    CVE-2023-43453

    Last Modified: 21 Nov 2024

    An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the IP parameter of the setDiagnosisCfg component.

    Published: 1 Dec 2023
    9.8
    Critical

    CVE-2023-43454

    Last Modified: 26 Nov 2024

    An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the hostName parameter of the switchOpMode component.

    Published: 1 Dec 2023
    9.8
    Critical

    CVE-2023-43455

    Last Modified: 21 Nov 2024

    An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the command parameter of the setting/setTracerouteCfg component.

    Published: 1 Dec 2023
    7.8
    High

    CVE-2023-45253

    Last Modified: 26 Nov 2024

    An issue was discovered in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, allows attackers to manipulate files and escalate privileges via RollingFileAppender.DeleteFile method performed by the log4net library.

    Published: 1 Dec 2023
    7.5
    High

    CVE-2023-48016

    Last Modified: 21 Nov 2024

    Restaurant Table Booking System V1.0 is vulnerable to SQL Injection in rtbs/admin/index.php via the username parameter.

    Published: 1 Dec 2023
    8.8
    High

    CVE-2023-48813

    Last Modified: 21 Nov 2024

    Senayan Library Management Systems (Slims) 9 Bulian v9.6.1 is vulnerable to SQL Injection via admin/modules/reporting/customs/fines_report.php.

    Published: 1 Dec 2023
    9.8
    Critical

    CVE-2023-48842

    Last Modified: 3 Jun 2025

    D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi.

    Published: 1 Dec 2023
    9.8
    Critical

    CVE-2023-48886

    Last Modified: 21 Nov 2024

    A deserialization vulnerability in NettyRpc v1.2 allows attackers to execute arbitrary commands via sending a crafted RPC request.

    Published: 1 Dec 2023
    9.8
    Critical

    CVE-2023-48887

    Last Modified: 21 Nov 2024

    A deserialization vulnerability in Jupiter v1.3.1 allows attackers to execute arbitrary commands via sending a crafted RPC request.

    Published: 1 Dec 2023
    8.8
    High

    CVE-2023-48893

    Last Modified: 21 Nov 2024

    SLiMS (aka SENAYAN Library Management System) through 9.6.1 allows admin/modules/reporting/customs/staff_act.php SQL Injection via startDate or untilDate.

    Published: 1 Dec 2023
    9.8
    Critical

    CVE-2023-49371

    Last Modified: 21 Nov 2024

    RuoYi up to v4.6 was discovered to contain a SQL injection vulnerability via /system/dept/edit.

    Published: 1 Dec 2023
    9.8
    Critical

    CVE-2023-48801

    Last Modified: 26 Nov 2024

    In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resulting in a command execution vulnerability.

    Published: 1 Dec 2023
    8.8
    High

    CVE-2023-42917

    Last Modified: 23 Oct 2025

    A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.

    Published: 30 Nov 2023
    6.5
    Medium

    CVE-2023-42916

    Last Modified: 23 Oct 2025

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-47279

    Last Modified: 3 Jun 2025

    In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an unauthenticated attacker to disclose user information through a single UDP packet, obtain plaintext credentials, or perform NTLM relaying.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-47207

    Last Modified: 21 Nov 2024

    In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with local administrator privileges.

    Published: 30 Nov 2023
    8.8
    High

    CVE-2023-46690

    Last Modified: 21 Nov 2024

    In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an attacker to write to any file to any location of the filesystem, which could lead to remote code execution.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-5909

    Last Modified: 25 Feb 2026

    KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-39226

    Last Modified: 21 Nov 2024

    In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute arbitrary code through a single UDP packet.

    Published: 30 Nov 2023
    9.1
    Critical

    CVE-2023-5908

    Last Modified: 21 Nov 2024

    KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-49735

    Last Modified: 21 Nov 2024

    ** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML definition files, leading to possible path traversal and eventually SSRF/XXE when passing user-controlled data to this key. Passing user-controlled data to this key may be relatively common, as it was also used like that to set the language in the 'tiles-test' application shipped with Tiles. This issue affects Apache Tiles from version 2 onwards. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 30 Nov 2023
    3.5
    Low

    CVE-2023-6442

    Last Modified: 21 Nov 2024

    A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file add-phlebotomist.php. The manipulation of the argument empid/fullname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-246445 was assigned to this vulnerability.

    Published: 30 Nov 2023
    3.5
    Low

    CVE-2023-6440

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Book Borrower System 1.0 and classified as problematic. This issue affects some unknown processing of the file endpoint/add-book.php. The manipulation of the argument Book Title/Book Author leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246443.

    Published: 30 Nov 2023
    3.5
    Low

    CVE-2023-6439

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic was found in ZenTao PMS 18.8. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246439.

    Published: 30 Nov 2023
    5.3
    Medium

    CVE-2023-6352

    Last Modified: 21 Nov 2024

    The default configuration of Aquaforest TIFF Server allows access to arbitrary file paths, subject to any restrictions imposed by Internet Information Services (IIS) or Microsoft Windows. Depending on how a web application uses and configures TIFF Server, a remote attacker may be able to enumerate files or directories, traverse directories, bypass authentication, or access restricted files.

    Published: 30 Nov 2023
    5.3
    Medium

    CVE-2023-6376

    Last Modified: 21 Nov 2024

    Henschen & Associates court document management software does not sufficiently randomize file names of cached documents, allowing a remote, unauthenticated attacker to access restricted documents.

    Published: 30 Nov 2023
    5.3
    Medium

    CVE-2023-6375

    Last Modified: 21 Nov 2024

    Tyler Technologies Court Case Management Plus may store backups in a location that can be accessed by a remote, unauthenticated attacker. Backups may contain sensitive information such as database credentials.

    Published: 30 Nov 2023
    5.3
    Medium

    CVE-2023-6354

    Last Modified: 21 Nov 2024

    Tyler Technologies Magistrate Court Case Management Plus allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the PDFViewer.aspx 'filename' parameter.

    Published: 30 Nov 2023
    5.3
    Medium

    CVE-2023-6353

    Last Modified: 25 Aug 2025

    Tyler Technologies Civil and Criminal Electronic Filing allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the Upload.aspx 'enky' parameter.

    Published: 30 Nov 2023
    5.3
    Medium

    CVE-2023-6344

    Last Modified: 3 Jun 2025

    Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate directories using the tiffserver/te003.aspx or te004.aspx 'ifolder' parameter. This behavior is related to the use of a deprecated version of Aquaforest TIFF Server, possibly 2.x. The vulnerable Aquaforest TIFF Server feature was removed on or around 2023-11-01. Insecure configuration issues in Aquaforest TIFF Server are identified separately as CVE-2023-6352. CVE-2023-6343 is related to or partially caused by CVE-2023-6352.

    Published: 30 Nov 2023
    5.3
    Medium

    CVE-2023-6343

    Last Modified: 25 Aug 2025

    Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate and access sensitive files using the tiffserver/tssp.aspx 'FN' and 'PN' parameters. This behavior is related to the use of a deprecated version of Aquaforest TIFF Server, possibly 2.x. The vulnerable Aquaforest TIFF Server feature was removed on or around 2023-11-01. Insecure configuration issues in Aquaforest TIFF Server are identified separately as CVE-2023-6352. CVE-2023-6343 is similar to CVE-2020-9323. CVE-2023-6343 is related to or partially caused by CVE-2023-6352.

    Published: 30 Nov 2023
    5.3
    Medium

    CVE-2023-6341

    Last Modified: 21 Nov 2024

    Catalis (previously Icon Software) CMS360 allows a remote, unauthenticated attacker to view sensitive court documents by modifying document and other identifiers in URLs. The impact varies based on the intention and configuration of a specific CMS360 installation.

    Published: 30 Nov 2023
    5.3
    Medium

    CVE-2023-6342

    Last Modified: 21 Nov 2024

    Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at least the 'CmWebSearchPfp/Login.aspx?xyzldk=' and 'payforprint_CM/Redirector.ashx?userid=' parameters. The vulnerable "pay for print" feature was removed on or around 2023-11-01.

    Published: 30 Nov 2023
    5.7
    Medium

    CVE-2023-47870

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Accessing Functionality Not Properly Constrained by ACLs leading to forced all users log out.This issue affects wpForo Forum: from n/a through 2.2.6.

    Published: 30 Nov 2023
    5.9
    Medium

    CVE-2023-34018

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoundCloud Inc. SoundCloud Shortcode allows Stored XSS.This issue affects SoundCloud Shortcode: from n/a through 3.1.0.

    Published: 30 Nov 2023
    4.3
    Medium

    CVE-2023-6438

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in Thecosy IceCMS 2.0.1. Affected is an unknown function of the file /WebArticle/articles/ of the component Like Handler. The manipulation leads to improper enforcement of a single, unique action. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-246438 is the identifier assigned to this vulnerability.

    Published: 30 Nov 2023
    7.1
    High

    CVE-2023-47521

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Max Bond, AndreSC Q2W3 Post Order allows Reflected XSS.This issue affects Q2W3 Post Order: from n/a through 1.2.8.

    Published: 30 Nov 2023
    4.3
    Medium

    CVE-2023-2267

    Last Modified: 21 Nov 2024

    An Improper Input Validation vulnerability in Schweitzer Engineering Laboratories SEL-411L could allow an attacker to perform reflection attacks against an authorized and authenticated user. See product Instruction Manual Appendix A dated 20230830 for more details.

    Published: 30 Nov 2023
    4.3
    Medium

    CVE-2023-2266

    Last Modified: 21 Nov 2024

    An Improper neutralization of input during web page generation in the Schweitzer Engineering Laboratories SEL-411L could allow an attacker to generate cross-site scripting based attacks against an authorized and authenticated user. See product Instruction Manual Appendix A dated 20230830 for more details.

    Published: 30 Nov 2023
    7.1
    High

    CVE-2023-38400

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold - Responsive Multi-Purpose Theme allows Reflected XSS.This issue affects Enfold - Responsive Multi-Purpose Theme: from n/a through 5.6.4.

    Published: 30 Nov 2023
    4.3
    Medium

    CVE-2023-2265

    Last Modified: 21 Nov 2024

    An Improper Restriction of Rendered UI Layers or Frames in the Schweitzer Engineering Laboratories SEL-411L could allow an unauthenticated attacker to perform clickjacking based attacks against an authenticated and authorized user. See product Instruction Manual Appendix A dated 20230830 for more details.

    Published: 30 Nov 2023
    4
    Medium

    CVE-2023-2264

    Last Modified: 3 Jun 2025

    An improper input validation vulnerability in the Schweitzer Engineering Laboratories SEL-411L could allow a malicious actor to manipulate authorized users to click on a link that could allow undesired behavior. See product Instruction Manual Appendix A dated 20230830 for more details.

    Published: 30 Nov 2023
    4.5
    Medium

    CVE-2023-34390

    Last Modified: 21 Nov 2024

    An input validation vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote authenticated attacker to create a denial of service against the system and locking out services. See product Instruction Manual Appendix A dated 20230830 for more details.

    Published: 30 Nov 2023