CVE Feed

    Dashboard / CVE

    4.7
    Medium

    CVE-2021-36806

    Last Modified: 2 Dec 2024

    A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on Sophos Email Appliance older than version 4.5.3.4.

    Published: 30 Nov 2023
    6.5
    Medium

    CVE-2023-49620

    Last Modified: 13 Feb 2025

    Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), with unauthorized access vulnerability (IDOR), but after version 3.1.0 we fixed this issue. We mark this cve as moderate level because it still requires user login to operate, please upgrade to version 3.1.0 to avoid this vulnerability

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2022-45135

    Last Modified: 13 Feb 2025

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.

    Published: 30 Nov 2023
    7.2
    High

    CVE-2023-49701

    Last Modified: 21 Nov 2024

    Memory Corruption in SIM management while USIMPhase2init

    Published: 30 Nov 2023
    8.3
    High

    CVE-2023-49077

    Last Modified: 21 Nov 2024

    Mailcow: dockerized is an open source groupware/email suite based on docker. A Cross-Site Scripting (XSS) vulnerability has been identified within the Quarantine UI of the system. This vulnerability poses a significant threat to administrators who utilize the Quarantine feature. An attacker can send a carefully crafted email containing malicious JavaScript code. This issue has been patched in version 2023-11.

    Published: 30 Nov 2023
    6.7
    Medium

    CVE-2023-49700

    Last Modified: 21 Nov 2024

    Security best practices violations, a string operation in Streamingmedia will write past the end of fixed-size destination buffer if the source buffer is too large.

    Published: 30 Nov 2023
    8.6
    High

    CVE-2023-49095

    Last Modified: 27 Nov 2024

    nexkey is a microblogging platform. Insufficient validation of ActivityPub requests received in inbox could allow any user to impersonate another user in certain circumstances. This issue has been patched in version 12.122.2.

    Published: 30 Nov 2023
    6.7
    Medium

    CVE-2023-49699

    Last Modified: 21 Nov 2024

    Memory Corruption in IMS while calling VoLTE Streamingmedia Interface

    Published: 30 Nov 2023
    4.3
    Medium

    CVE-2023-49076

    Last Modified: 5 Jun 2025

    Customer-data-framework allows management of customer data within Pimcore. There are no tokens or headers to prevent CSRF attacks from occurring, therefore an attacker could abuse this vulnerability to create new customers. This issue has been patched in version 4.0.5.

    Published: 30 Nov 2023
    4.3
    Medium

    CVE-2023-49094

    Last Modified: 5 Jun 2025

    Symbolicator is a symbolication service for native stacktraces and minidumps with symbol server support. An attacker could make Symbolicator send arbitrary GET HTTP requests to internal IP addresses by using a specially crafted HTTP endpoint. The response could be reflected to the attacker if they have an account on Sentry instance. The issue has been fixed in the release 23.11.2.

    Published: 30 Nov 2023
    8.1
    High

    CVE-2023-49097

    Last Modified: 27 Nov 2024

    ZITADEL is an identity infrastructure system. ZITADEL uses the notification triggering requests Forwarded or X-Forwarded-Host header to build the button link sent in emails for confirming a password reset with the emailed code. If this header is overwritten and a user clicks the link to a malicious site in the email, the secret code can be retrieved and used to reset the users password and take over his account. Accounts with MFA or Passwordless enabled can not be taken over by this attack. This issue has been patched in versions 2.41.6, 2.40.10 and 2.39.9.

    Published: 30 Nov 2023
    —
    Unknown

    CVE-2023-47214

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 30 Nov 2023
    —
    Unknown

    CVE-2023-49605

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 30 Nov 2023
    —
    Unknown

    CVE-2023-42777

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 30 Nov 2023
    —
    Unknown

    CVE-2023-46101

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 30 Nov 2023
    —
    Unknown

    CVE-2023-46709

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 30 Nov 2023
    —
    Unknown

    CVE-2023-48337

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 30 Nov 2023
    —
    Unknown

    CVE-2023-49116

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 30 Nov 2023
    —
    Unknown

    CVE-2023-41083

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 30 Nov 2023
    —
    Unknown

    CVE-2023-49592

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 30 Nov 2023
    7.8
    High

    CVE-2023-5247

    Last Modified: 2 Dec 2024

    Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software Products allows a malicious attacker to execute a malicious code by having legitimate users open a specially crafted project file, which could result in information disclosure, tampering and deletion, or a denial-of-service (DoS) condition.

    Published: 30 Nov 2023
    4.3
    Medium

    CVE-2023-5772

    Last Modified: 8 Apr 2026

    The Debug Log Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the clear_log() function. This makes it possible for unauthenticated attackers to clear the debug log via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-4474

    Last Modified: 16 Dec 2025

    The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-4473

    Last Modified: 16 Dec 2025

    A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

    Published: 30 Nov 2023
    8.8
    High

    CVE-2023-37928

    Last Modified: 13 Feb 2025

    A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

    Published: 30 Nov 2023
    8.8
    High

    CVE-2023-37927

    Last Modified: 13 Feb 2025

    The improper neutralization of special elements in the CGI program of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-35138

    Last Modified: 21 Nov 2024

    A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-35137

    Last Modified: 21 Nov 2024

    An improper authentication vulnerability in the authentication module of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to obtain system information by sending a crafted URL to a vulnerable device.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-3741

    Last Modified: 2 Dec 2024

    An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execute any command on the device.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2024-9779

    Last Modified: 15 Apr 2026

    A flaw was found in Open Cluster Management (OCM) when a user has access to the worker nodes which contain the cluster-manager or klusterlet deployments. The cluster-manager deployment uses a service account with the same name "cluster-manager" which is bound to a ClusterRole also named "cluster-manager", which includes the permission to create Pod resources. If this deployment runs a pod on an attacker-controlled node, the attacker can obtain the cluster-manager's token and steal any service account token by creating and mounting the target service account to control the whole cluster.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-47418

    Last Modified: 21 Nov 2024

    Remote Code Execution (RCE) vulnerability in o2oa version 8.1.2 and before, allows attackers to create a new interface in the service management function to execute JavaScript.

    Published: 30 Nov 2023
    5.3
    Medium

    CVE-2021-35975

    Last Modified: 21 Nov 2024

    Absolute path traversal vulnerability in the Systematica SMTP Adapter component (up to v2.0.1.101) in Systematica Radius (up to v.3.9.256.777) allows remote attackers to read arbitrary files via a full pathname in GET parameter "file" in URL. Also: affected components in same product - HTTP Adapter (up to v.1.8.0.15), MSSQL MessageBus Proxy (up to v.1.1.06), Financial Calculator (up to v.1.3.05), FIX Adapter (up to v.2.4.0.25)

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-46386

    Last Modified: 21 Nov 2024

    LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via registry.xml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-46387

    Last Modified: 26 Nov 2024

    LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Incorrect Access Control via dpal_config.zml file. This vulnerability allows remote attackers to disclose sensitive information on Loytec device data point configuration.

    Published: 30 Nov 2023
    8.8
    High

    CVE-2023-46326

    Last Modified: 21 Nov 2024

    ZStack Cloud version 3.10.38 and before allows unauthenticated API access to the list of active job UUIDs and the session ID for each of these. This leads to privilege escalation.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-46388

    Last Modified: 21 Nov 2024

    LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via dpal_config.zml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-46389

    Last Modified: 21 Nov 2024

    LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Incorrect Access Control via registry.xml file. This vulnerability allows remote attackers to disclose sensitive information on LINX configuration.

    Published: 30 Nov 2023
    7.2
    High

    CVE-2023-46956

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Packers and Movers Management System v.1.0 allows a remote attacker to execute arbitrary code via crafted payload to the /mpms/admin/?page=user/manage_user&id file.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-47307

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in /apply.cgi in Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 allows attackers to cause a denial of service via the ApCliAuthMode parameter.

    Published: 30 Nov 2023
    7.8
    High

    CVE-2023-47452

    Last Modified: 21 Nov 2024

    An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the current working directory.

    Published: 30 Nov 2023
    7.8
    High

    CVE-2023-47454

    Last Modified: 21 Nov 2024

    An Untrusted search path vulnerability in NetEase CloudMusic 2.10.4 for Windows allows local users to gain escalated privileges through the urlmon.dll file in the current working directory.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-47463

    Last Modified: 21 Nov 2024

    Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the gl_nas_sys authentication function.

    Published: 30 Nov 2023
    8.8
    High

    CVE-2023-47464

    Last Modified: 21 Nov 2024

    Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via the upload API function.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-48963

    Last Modified: 21 Nov 2024

    Tenda i6 V1.0.0.8(3856) is vulnerable to Buffer Overflow via /goform/wifiSSIDget.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-48964

    Last Modified: 21 Nov 2024

    Tenda i6 V1.0.0.8(3856) is vulnerable to Buffer Overflow via /goform/WifiMacFilterSet.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-48811

    Last Modified: 21 Nov 2024

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-48802

    Last Modified: 5 Jun 2025

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-48803

    Last Modified: 21 Nov 2024

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-48804

    Last Modified: 21 Nov 2024

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-48805

    Last Modified: 21 Nov 2024

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

    Published: 30 Nov 2023