CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2023-48268

    Last Modified: 2 Dec 2024

    Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards allowing an attacker to consume excessive resources, possibly leading to Denial of Service, by importing a board using a specially crafted zip (zip bomb).

    Published: 27 Nov 2023
    4.3
    Medium

    CVE-2023-45223

    Last Modified: 21 Nov 2024

    Mattermost fails to properly validate the "Show Full Name" option in a few endpoints in Mattermost Boards, allowing a member to get the full name of another user even if the Show Full Name option was disabled. 

    Published: 27 Nov 2023
    4.3
    Medium

    CVE-2023-47865

    Last Modified: 21 Nov 2024

    Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a post even if the Hardened Mode setting was enabled

    Published: 27 Nov 2023
    5.5
    Medium

    CVE-2023-25632

    Last Modified: 21 Nov 2024

    The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open in Whale' feature.

    Published: 27 Nov 2023
    —
    Unknown

    CVE-2023-43607

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 27 Nov 2023
    —
    Unknown

    CVE-2023-48370

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 27 Nov 2023
    —
    Unknown

    CVE-2023-43486

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 27 Nov 2023
    —
    Unknown

    CVE-2023-42778

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 27 Nov 2023
    3.5
    Low

    CVE-2023-6313

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester URL Shortener 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Long URL Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246139.

    Published: 27 Nov 2023
    4.7
    Medium

    CVE-2023-6312

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Loan Management System 1.0. It has been classified as critical. Affected is the function delete_user of the file deleteUser.php of the component Users Page. The manipulation of the argument user_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-246138 is the identifier assigned to this vulnerability.

    Published: 27 Nov 2023
    4.7
    Medium

    CVE-2023-6311

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Loan Management System 1.0 and classified as critical. This issue affects the function delete_ltype of the file delete_ltype.php of the component Loan Type Page. The manipulation of the argument ltype_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-246137 was assigned to this vulnerability.

    Published: 27 Nov 2023
    4.7
    Medium

    CVE-2023-6310

    Last Modified: 21 Nov 2024

    A vulnerability has been found in SourceCodester Loan Management System 1.0 and classified as critical. This vulnerability affects the function delete_borrower of the file deleteBorrower.php. The manipulation of the argument borrower_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-246136.

    Published: 27 Nov 2023
    5.5
    Medium

    CVE-2023-6309

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in moses-smt mosesdecoder up to 4.0. This affects an unknown part of the file contrib/iSenWeb/trans_result.php. The manipulation of the argument input1 leads to os command injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246135.

    Published: 27 Nov 2023
    6.3
    Medium

    CVE-2023-6308

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in Xiamen Four-Faith Video Surveillance Management System 2016/2017. Affected by this issue is some unknown functionality of the component Apache Struts. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-246134 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Nov 2023
    6.3
    Medium

    CVE-2023-6307

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in jeecgboot JimuReport up to 1.6.1. Affected by this vulnerability is an unknown functionality of the file /download/image. The manipulation of the argument imageUrl leads to relative path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-246133 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Nov 2023
    6.3
    Medium

    CVE-2023-6306

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in SourceCodester Free and Open Source Inventory Management System 1.0. Affected is an unknown function of the file /ample/app/ajax/member_data.php. The manipulation of the argument columns leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-246132.

    Published: 27 Nov 2023
    6.3
    Medium

    CVE-2023-6305

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file ample/app/ajax/suppliar_data.php. The manipulation of the argument columns leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246131.

    Published: 27 Nov 2023
    7.2
    High

    CVE-2023-6304

    Last Modified: 21 Nov 2024

    A vulnerability was found in Tecno 4G Portable WiFi TR118 TR118-M30E-RR-D-EnFrArSwHaPo-OP-V008-20220830. It has been declared as critical. This vulnerability affects unknown code of the file /goform/goform_get_cmd_process of the component Ping Tool. The manipulation of the argument url leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-246130 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Nov 2023
    2.4
    Low

    CVE-2023-6303

    Last Modified: 21 Nov 2024

    A vulnerability was found in CSZCMS 1.3.0. It has been classified as problematic. This affects an unknown part of the file /admin/settings/ of the component Site Settings Page. The manipulation of the argument Additional Meta Tag with the input <svg><animate onbegin=alert(1) attributeName=x dur=1s> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-246129 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Nov 2023
    4.7
    Medium

    CVE-2023-6302

    Last Modified: 21 Nov 2024

    A vulnerability was found in CSZCMS 1.3.0 and classified as critical. Affected by this issue is some unknown functionality of the file \views\templates of the component File Manager Page. The manipulation leads to permission issues. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-246128. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Nov 2023
    8.8
    High

    CVE-2023-29770

    Last Modified: 21 Nov 2024

    In Sentrifugo 3.5, the AssetsController::uploadsaveAction function allows an authenticated attacker to upload any file without extension filtering.

    Published: 27 Nov 2023
    5.3
    Medium

    CVE-2023-34053

    Last Modified: 13 Feb 2025

    In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses Spring MVC or Spring WebFlux * io.micrometer:micrometer-core is on the classpath * an ObservationRegistry is configured in the application to record observations Typically, Spring Boot applications need the org.springframework.boot:spring-boot-actuator dependency to meet all conditions.

    Published: 27 Nov 2023
    5.3
    Medium

    CVE-2023-34055

    Last Modified: 13 Feb 2025

    In Spring Boot versions 2.7.0 - 2.7.17, 3.0.0-3.0.12 and 3.1.0-3.1.5, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses Spring MVC or Spring WebFlux * org.springframework.boot:spring-boot-actuator is on the classpath

    Published: 27 Nov 2023
    5.5
    Medium

    CVE-2023-42363

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.

    Published: 27 Nov 2023
    5.5
    Medium

    CVE-2023-42366

    Last Modified: 6 Dec 2024

    A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159.

    Published: 27 Nov 2023
    9.8
    Critical

    CVE-2023-46349

    Last Modified: 26 Nov 2024

    In the module "Product Catalog (CSV, Excel) Export/Update" (updateproducts) < 3.8.5 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method `productsUpdateModel::getExportIds()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

    Published: 27 Nov 2023
    5.3
    Medium

    CVE-2023-46355

    Last Modified: 21 Nov 2024

    In the module "CSV Feeds PRO" (csvfeeds) < 2.6.1 from Bl Modules for PrestaShop, a guest can download personal information without restriction. Due to too permissive access control which does not force administrator to use password on feeds, a guest can access exports from the module which can lead to leaks of personal information from ps_customer / ps_order table such as name / surname / email / phone number / postal address.

    Published: 27 Nov 2023
    9.8
    Critical

    CVE-2023-46480

    Last Modified: 5 Jun 2025

    An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the indieauth function.

    Published: 27 Nov 2023
    5.4
    Medium

    CVE-2023-47437

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Pachno 1.0.6 allowing an authenticated attacker to execute a cross-site scripting (XSS) attack. The vulnerability exists due to inadequate input validation in the Project Description and comments, which enables an attacker to inject malicious java script.

    Published: 27 Nov 2023
    6.1
    Medium

    CVE-2023-48034

    Last Modified: 21 Nov 2024

    An issue discovered in Acer Wireless Keyboard SK-9662 allows attacker in physical proximity to both decrypt wireless keystrokes and inject arbitrary keystrokes via use of weak encryption.

    Published: 27 Nov 2023
    9.8
    Critical

    CVE-2023-48188

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in PrestaShop opartdevis v.4.5.18 thru v.4.6.12 allows a remote attacker to execute arbitrary code via a crafted script to the getModuleTranslation function.

    Published: 27 Nov 2023
    5.4
    Medium

    CVE-2023-49028

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in smpn1smg absis v.2017-10-19 and before allows a remote attacker to execute arbitrary code via the user parameter in the lock/lock.php file.

    Published: 27 Nov 2023
    6.1
    Medium

    CVE-2023-49029

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in smpn1smg absis v.2017-10-19 and before allows a remote attacker to execute arbitrary code via the nama parameter in the lock/lock.php file.

    Published: 27 Nov 2023
    7.5
    High

    CVE-2023-49030

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in32ns KLive v.2019-1-19 and before allows a remote attacker to obtain sensitive information via a crafted script to the web/user.php component.

    Published: 27 Nov 2023
    9.8
    Critical

    CVE-2023-49040

    Last Modified: 21 Nov 2024

    An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the adslPwd parameter in the form_fast_setting_internet_set function.

    Published: 27 Nov 2023
    9.8
    Critical

    CVE-2023-49042

    Last Modified: 21 Nov 2024

    Heap Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the schedStartTime parameter or the schedEndTime parameter in the function setSchedWifi.

    Published: 27 Nov 2023
    9.8
    Critical

    CVE-2023-49043

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the wpapsk_crypto parameter in the function fromSetWirelessRepeat.

    Published: 27 Nov 2023
    9.8
    Critical

    CVE-2023-49044

    Last Modified: 21 Nov 2024

    Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the ssid parameter in the function form_fast_setting_wifi_set.

    Published: 27 Nov 2023
    9.8
    Critical

    CVE-2023-49046

    Last Modified: 26 Nov 2024

    Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the devName parameter in the function formAddMacfilterRule.

    Published: 27 Nov 2023
    7.5
    High

    CVE-2023-49047

    Last Modified: 21 Nov 2024

    Tenda AX1803 v1.0.0.1 contains a stack overflow via the devName parameter in the function formSetDeviceName.

    Published: 27 Nov 2023
    7.5
    High

    CVE-2023-49316

    Last Modified: 21 Nov 2024

    In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively large degrees can lead to a denial of service.

    Published: 27 Nov 2023
    5.5
    Medium

    CVE-2023-42365

    Last Modified: 3 Nov 2025

    A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function.

    Published: 27 Nov 2023
    5.5
    Medium

    CVE-2023-42364

    Last Modified: 3 Nov 2025

    A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function.

    Published: 27 Nov 2023
    3.5
    Low

    CVE-2023-6301

    Last Modified: 21 Nov 2024

    A vulnerability has been found in SourceCodester Best Courier Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file parcel_list.php of the component GET Parameter Handler. The manipulation of the argument id with the input </TiTlE><ScRiPt>alert(1)</ScRiPt> leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246127.

    Published: 26 Nov 2023
    3.5
    Low

    CVE-2023-6300

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, was found in SourceCodester Best Courier Management System 1.0. Affected is an unknown function. The manipulation of the argument page with the input </TiTlE><ScRiPt>alert(1)</ScRiPt> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-246126 is the identifier assigned to this vulnerability.

    Published: 26 Nov 2023
    4.3
    Medium

    CVE-2023-6299

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, has been found in Apryse iText 8.0.1. This issue affects some unknown processing of the file PdfDocument.java of the component Reference Table Handler. The manipulation leads to memory leak. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 8.0.2 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-246125 was assigned to this vulnerability. NOTE: The vendor was contacted early about this vulnerability. The fix was introduced in the iText 8.0.2 release on October 25th 2023, prior to the disclosure.

    Published: 26 Nov 2023
    4.3
    Medium

    CVE-2023-6298

    Last Modified: 13 Feb 2025

    A vulnerability classified as problematic was found in Apryse iText 8.0.2. This vulnerability affects the function main of the file PdfDocument.java. The manipulation leads to improper validation of array index. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The identifier of this vulnerability is VDB-246124. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. A statement published afterwards explains that the exception is not a vulnerability and the identified CWEs might not apply to the software.

    Published: 26 Nov 2023
    4.3
    Medium

    CVE-2023-6297

    Last Modified: 3 Jun 2025

    A vulnerability classified as problematic has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file patient-search-report.php of the component Search Report Page. The manipulation of the argument Search By Patient Name with the input <script>alert(document.cookie)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246123.

    Published: 26 Nov 2023
    4.3
    Medium

    CVE-2023-6296

    Last Modified: 13 Feb 2025

    A vulnerability was found in osCommerce 4. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /catalog/compare of the component Instant Message Handler. The manipulation of the argument compare with the input 40dz4iq"><script>alert(1)</script>zohkx leads to cross site scripting. The attack may be launched remotely. VDB-246122 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 26 Nov 2023
    9.1
    Critical

    CVE-2023-49312

    Last Modified: 21 Nov 2024

    Precision Bridge PrecisionBridge.exe (aka the thick client) before 7.3.21 allows an integrity violation in which the same license key is used on multiple systems, via vectors involving a Process Hacker memory dump, error message inspection, and modification of a MAC address.

    Published: 26 Nov 2023