CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2021-35975

    Last Modified: 21 Nov 2024

    Absolute path traversal vulnerability in the Systematica SMTP Adapter component (up to v2.0.1.101) in Systematica Radius (up to v.3.9.256.777) allows remote attackers to read arbitrary files via a full pathname in GET parameter "file" in URL. Also: affected components in same product - HTTP Adapter (up to v.1.8.0.15), MSSQL MessageBus Proxy (up to v.1.1.06), Financial Calculator (up to v.1.3.05), FIX Adapter (up to v.2.4.0.25)

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-46386

    Last Modified: 21 Nov 2024

    LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via registry.xml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-46387

    Last Modified: 26 Nov 2024

    LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Incorrect Access Control via dpal_config.zml file. This vulnerability allows remote attackers to disclose sensitive information on Loytec device data point configuration.

    Published: 30 Nov 2023
    8.8
    High

    CVE-2023-46326

    Last Modified: 21 Nov 2024

    ZStack Cloud version 3.10.38 and before allows unauthenticated API access to the list of active job UUIDs and the session ID for each of these. This leads to privilege escalation.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-46388

    Last Modified: 21 Nov 2024

    LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via dpal_config.zml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-46389

    Last Modified: 21 Nov 2024

    LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Incorrect Access Control via registry.xml file. This vulnerability allows remote attackers to disclose sensitive information on LINX configuration.

    Published: 30 Nov 2023
    7.2
    High

    CVE-2023-46956

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Packers and Movers Management System v.1.0 allows a remote attacker to execute arbitrary code via crafted payload to the /mpms/admin/?page=user/manage_user&id file.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-47307

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in /apply.cgi in Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 allows attackers to cause a denial of service via the ApCliAuthMode parameter.

    Published: 30 Nov 2023
    7.8
    High

    CVE-2023-47452

    Last Modified: 21 Nov 2024

    An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the current working directory.

    Published: 30 Nov 2023
    7.8
    High

    CVE-2023-47454

    Last Modified: 21 Nov 2024

    An Untrusted search path vulnerability in NetEase CloudMusic 2.10.4 for Windows allows local users to gain escalated privileges through the urlmon.dll file in the current working directory.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-47463

    Last Modified: 21 Nov 2024

    Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the gl_nas_sys authentication function.

    Published: 30 Nov 2023
    8.8
    High

    CVE-2023-47464

    Last Modified: 21 Nov 2024

    Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via the upload API function.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-48963

    Last Modified: 21 Nov 2024

    Tenda i6 V1.0.0.8(3856) is vulnerable to Buffer Overflow via /goform/wifiSSIDget.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-48964

    Last Modified: 21 Nov 2024

    Tenda i6 V1.0.0.8(3856) is vulnerable to Buffer Overflow via /goform/WifiMacFilterSet.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-48811

    Last Modified: 21 Nov 2024

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-48802

    Last Modified: 5 Jun 2025

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-48803

    Last Modified: 21 Nov 2024

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-48804

    Last Modified: 21 Nov 2024

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-48805

    Last Modified: 21 Nov 2024

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-48806

    Last Modified: 21 Nov 2024

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-48807

    Last Modified: 21 Nov 2024

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-48808

    Last Modified: 21 Nov 2024

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

    Published: 30 Nov 2023
    6.5
    Medium

    CVE-2023-48894

    Last Modified: 21 Nov 2024

    Incorrect Access Control vulnerability in jshERP V3.3 allows attackers to obtain sensitive information via the doFilter function.

    Published: 30 Nov 2023
    8.8
    High

    CVE-2023-48912

    Last Modified: 26 Nov 2024

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/archives/edit.

    Published: 30 Nov 2023
    8.8
    High

    CVE-2023-48913

    Last Modified: 21 Nov 2024

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/archives/delete.

    Published: 30 Nov 2023
    8.8
    High

    CVE-2023-48914

    Last Modified: 21 Nov 2024

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/archives/add.

    Published: 30 Nov 2023
    8.8
    High

    CVE-2023-49052

    Last Modified: 21 Nov 2024

    File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function in the created forms component.

    Published: 30 Nov 2023
    5.5
    Medium

    CVE-2023-6560

    Last Modified: 21 Nov 2024

    An out-of-bounds memory access flaw was found in the io_uring SQ/CQ rings functionality in the Linux kernel. This issue could allow a local user to crash the system.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-46383

    Last Modified: 4 Nov 2025

    LOYTEC electronics GmbH LINX Configurator (all versions) uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the password and gain full control of Loytec device configuration.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-46384

    Last Modified: 4 Nov 2025

    LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. Cleartext storage of credentials allows remote attackers to disclose admin password and bypass an authentication to login Loytec device.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-46385

    Last Modified: 4 Nov 2025

    LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so it allows remote attackers to steal the password and gain full control of Loytec device configuration.

    Published: 30 Nov 2023
    7.2
    High

    CVE-2023-49081

    Last Modified: 23 Jun 2026

    aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create a new HTTP request if the attacker controls the HTTP version. The vulnerability only occurs if the attacker can control the HTTP version of the request. This issue has been patched in version 3.9.0.

    Published: 30 Nov 2023
    7.8
    High

    CVE-2023-47453

    Last Modified: 26 Nov 2024

    An Untrusted search path vulnerability in Sohu Video Player 7.0.15.0 allows local users to gain escalated privileges through the version.dll file in the current working directory.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-48810

    Last Modified: 21 Nov 2024

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-48812

    Last Modified: 26 Nov 2024

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability.

    Published: 30 Nov 2023
    6.8
    Medium

    CVE-2023-49087

    Last Modified: 21 Nov 2024

    xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verification that the hash value of the related XML-document matches a specific DigestValue-value, but also that the cryptographic signature on the SignedInfo-tree (the one that contains the DigestValue) verifies and matches a trusted public key. If an attacker somehow (i.e. by exploiting a bug in PHP's canonicalization function) manages to manipulate the canonicalized version's DigestValue, it would be possible to forge the signature. This issue has been patched in version 1.6.12 and 5.0.0-alpha.13.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-40458

    Last Modified: 21 Nov 2024

    Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc ALEOS could potentially allow a remote attacker to trigger a Denial of Service (DoS) condition for ACEManager without impairing other router functions. This condition is cleared by restarting the device.

    Published: 29 Nov 2023
    7.8
    High

    CVE-2023-49694

    Last Modified: 21 Nov 2024

    A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed can create arbitrary JSP files in a Tomcat web application directory. The user can then execute the JSP files under the security context of SYSTEM.

    Published: 29 Nov 2023
    9.8
    Critical

    CVE-2023-49693

    Last Modified: 21 Nov 2024

    NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticated users, allowing attackers to execute arbitrary code.

    Published: 29 Nov 2023
    9.8
    Critical

    CVE-2022-42541

    Last Modified: 5 Jun 2025

    Remote code execution

    Published: 29 Nov 2023
    9.8
    Critical

    CVE-2022-42540

    Last Modified: 21 Nov 2024

    Elevation of privilege

    Published: 29 Nov 2023
    7.5
    High

    CVE-2022-42539

    Last Modified: 21 Nov 2024

    Information disclosure

    Published: 29 Nov 2023
    9.8
    Critical

    CVE-2022-42538

    Last Modified: 21 Nov 2024

    Elevation of privilege

    Published: 29 Nov 2023
    9.8
    Critical

    CVE-2022-42537

    Last Modified: 21 Nov 2024

    Remote code execution

    Published: 29 Nov 2023
    9.8
    Critical

    CVE-2022-42536

    Last Modified: 21 Nov 2024

    Remote code execution

    Published: 29 Nov 2023
    5.4
    Medium

    CVE-2023-44383

    Last Modified: 5 Jun 2025

    October is a Content Management System (CMS) and web platform to assist with development workflow. A user with access to the media manager that stores SVG files could create a stored XSS attack against themselves and any other user with access to the media manager when SVG files are supported. This issue has been patched in version 3.5.2.

    Published: 29 Nov 2023
    8.8
    High

    CVE-2023-49091

    Last Modified: 11 Apr 2025

    Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Cosmos-server is vulnerable due to to the authorization header used for user login remaining valid and not expiring after log out. This vulnerability allows an attacker to use the token to gain unauthorized access to the application/system even after the user has logged out. This issue has been patched in version 0.13.1.

    Published: 29 Nov 2023
    9.3
    Critical

    CVE-2023-49079

    Last Modified: 21 Nov 2024

    Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary users to impersonate any remote user. This issue has been patched in version 2023.11.1-beta.1.

    Published: 29 Nov 2023
    7.2
    High

    CVE-2023-6218

    Last Modified: 21 Nov 2024

    In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a privilege escalation path associated with group administrators has been identified.  It is possible for a group administrator to elevate a group members permissions to the role of an organization administrator.

    Published: 29 Nov 2023
    7.1
    High

    CVE-2023-6217

    Last Modified: 21 Nov 2024

    In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a reflected cross-site scripting (XSS) vulnerability has been identified when MOVEit Gateway is used in conjunction with MOVEit Transfer.  An attacker could craft a malicious payload targeting the system which comprises a MOVEit Gateway and MOVEit Transfer deployment. If a MOVEit user interacts with the crafted payload, the attacker would be able to execute malicious JavaScript within the context of the victim’s browser.

    Published: 29 Nov 2023