CVE Feed

    Dashboard / CVE

    5.7
    Medium

    CVE-2023-3104

    Last Modified: 21 Nov 2024

    Lack of authentication vulnerability. An unauthenticated local user is able to see through the cameras using the web server due to the lack of any form of authentication.

    Published: 22 Nov 2023
    7.5
    High

    CVE-2023-5983

    Last Modified: 20 May 2026

    Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Botanik Software Pharmacy Automation allows Retrieve Embedded Sensitive Data. This issue affects Pharmacy Automation: before 2.1.133.0.

    Published: 22 Nov 2023
    8
    High

    CVE-2023-3103

    Last Modified: 21 Nov 2024

    Authentication bypass vulnerability, the exploitation of which could allow a local attacker to perform a Man-in-the-Middle (MITM) attack on the robot's camera video stream. In addition, if a MITM attack is carried out, it is possible to consume the robot's resources, which could lead to a denial-of-service (DOS) condition.

    Published: 22 Nov 2023
    6
    Medium

    CVE-2023-6253

    Last Modified: 13 Feb 2025

    A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.

    Published: 22 Nov 2023
    9.8
    Critical

    CVE-2023-5047

    Last Modified: 21 May 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DRD Fleet Leasing DRDrive allows SQL Injection. This issue affects DRDrive: before 20231006.

    Published: 22 Nov 2023
    4.3
    Medium

    CVE-2023-6189

    Last Modified: 23 Feb 2026

    Missing access permissions checks in the M-Files server before 23.11.13156.0 allow attackers to perform data write and export jobs using the M-Files API methods.

    Published: 22 Nov 2023
    5.7
    Medium

    CVE-2023-6117

    Last Modified: 23 Feb 2026

    A possibility of unwanted server memory consumption was detected through the obsolete functionalities in the Rest API methods of the M-Files server before 23.11.13156.0 which allows attackers to execute DoS attacks.

    Published: 22 Nov 2023
    9.8
    Critical

    CVE-2023-37924

    Last Modified: 21 Nov 2024

    Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can result in unauthorized login. Now we have fixed this issue and now user must have the correct login to access workbench. This issue affects Apache Submarine: from 0.7.0 before 0.8.0. We recommend that all submarine users with 0.7.0 upgrade to 0.8.0, which not only fixes the issue, supports the oidc authentication mode, but also removes the case of unauthenticated logins. If using the version lower than 0.8.0 and not want to upgrade, you can try cherry-pick PR https://github.com/apache/submarine/pull/1037 https://github.com/apache/submarine/pull/1054 and rebuild the submarine-server image to fix this.

    Published: 22 Nov 2023
    5.4
    Medium

    CVE-2023-6011

    Last Modified: 20 May 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DECE Software Geodi allows Stored XSS. This issue affects Geodi: before 8.0.0.27396.

    Published: 22 Nov 2023
    7.1
    High

    CVE-2023-5921

    Last Modified: 20 May 2026

    Improper Enforcement of Behavioral Workflow vulnerability in DECE Software Geodi allows Functionality Bypass. This issue affects Geodi: before 8.0.0.27396.

    Published: 22 Nov 2023
    6.5
    Medium

    CVE-2023-2446

    Last Modified: 8 Apr 2026

    The UserPro plugin for WordPress is vulnerable to sensitive information disclosure via the 'userpro' shortcode in versions up to, and including 5.1.1. This is due to insufficient restriction on sensitive user meta values that can be called via that shortcode. This makes it possible for authenticated attackers, with subscriber-level permissions, and above to retrieve sensitive user meta that can be used to gain access to a high privileged user account.

    Published: 22 Nov 2023
    6.1
    Medium

    CVE-2023-2447

    Last Modified: 8 Apr 2026

    The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on the 'export_users' function. This makes it possible for unauthenticated attackers to export the users to a csv file, granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 22 Nov 2023
    4.3
    Medium

    CVE-2023-41146

    Last Modified: 21 Nov 2024

    Autodesk Customer Support Portal allows cases created by users under an account to see cases created by other users on the same account.

    Published: 22 Nov 2023
    5.3
    Medium

    CVE-2023-41145

    Last Modified: 21 Nov 2024

    Autodesk users who no longer have an active license for an account can still access cases for that account.

    Published: 22 Nov 2023
    7.8
    High

    CVE-2023-29069

    Last Modified: 21 Nov 2024

    A maliciously crafted DLL file can be forced to install onto a non-default location, and attacker can overwrite parts of the product with malicious DLLs. These files may then have elevated privileges leading to a Privilege Escalation vulnerability.

    Published: 22 Nov 2023
    4.3
    Medium

    CVE-2022-35638

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230824.

    Published: 22 Nov 2023
    5.9
    Medium

    CVE-2021-37937

    Last Modified: 21 Nov 2024

    An issue was found with how API keys are created with the Fleet-Server service account. When an API key is created with a service account, it is possible that the API key could be created with higher privileges than intended. Using this vulnerability, a compromised Fleet-Server service account could escalate themselves to a super-user.

    Published: 22 Nov 2023
    7
    High

    CVE-2021-37942

    Last Modified: 21 Nov 2024

    A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious plugin to an application running the APM Java agent. By using this vulnerability, an attacker could execute code at a potentially higher level of permissions than their user typically has access to.

    Published: 22 Nov 2023
    2.1
    Low

    CVE-2021-22143

    Last Modified: 21 Nov 2024

    The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application error. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application error it is possible the headers will not be sanitized before being sent.

    Published: 22 Nov 2023
    7.8
    High

    CVE-2023-35127

    Last Modified: 21 Nov 2024

    Stack-based buffer overflow may occur when Fuji Electric Tellus Lite V-Simulator parses a specially-crafted input file.

    Published: 22 Nov 2023
    7.8
    High

    CVE-2023-40152

    Last Modified: 21 Nov 2024

    When Fuji Electric Tellus Lite V-Simulator parses a specially-crafted input file an out of bounds write may occur.

    Published: 22 Nov 2023
    7.3
    High

    CVE-2023-5299

    Last Modified: 21 Nov 2024

    A user with a standard account in Fuji Electric Tellus Lite may overwrite files in the system.

    Published: 22 Nov 2023
    3.1
    Low

    CVE-2021-22151

    Last Modified: 21 Nov 2024

    It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension.

    Published: 22 Nov 2023
    6.6
    Medium

    CVE-2021-22150

    Last Modified: 2 Dec 2024

    It was discovered that a user with Fleet admin permissions could upload a malicious package. Due to using an older version of the js-yaml library, this package would be loaded in an insecure manner, allowing an attacker to execute commands on the Kibana server.

    Published: 22 Nov 2023
    3.6
    Low

    CVE-2023-48706

    Last Modified: 17 Sept 2026

    Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` command for the very first time and using a sub-replace-special atom inside the substitution part, it is possible that the recursive `:s` call causes free-ing of memory which may later then be accessed by the initial `:s` command. The user must intentionally execute the payload and the whole process is a bit tricky to do since it seems to work only reliably for the very first :s command. It may also cause a crash of Vim. Version 9.0.2121 contains a fix for this issue.

    Published: 22 Nov 2023
    6.5
    Medium

    CVE-2023-47014

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) vulnerability in Sourcecodester Sticky Notes App Using PHP with Source Code v.1.0 allows a local attacker to obtain sensitive information via a crafted payload to add-note.php.

    Published: 22 Nov 2023
    7.5
    High

    CVE-2023-47016

    Last Modified: 21 Nov 2024

    radare2 5.8.9 has an out-of-bounds read in r_bin_object_set_items in libr/bin/bobj.c, causing a crash in r_read_le32 in libr/include/r_endian.h.

    Published: 22 Nov 2023
    8.8
    High

    CVE-2023-47350

    Last Modified: 26 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in SwiftyEdit Content Management System prior to v1.2.0, allows remote attackers to escalate privileges via the user password update functionality.

    Published: 22 Nov 2023
    8.1
    High

    CVE-2023-43887

    Last Modified: 26 Nov 2024

    Libde265 v1.0.12 was discovered to contain multiple buffer overflows via the num_tile_columns and num_tile_row parameters in the function pic_parameter_set::dump.

    Published: 22 Nov 2023
    9.8
    Critical

    CVE-2023-45377

    Last Modified: 10 Jun 2025

    In the module "Chronopost Official" (chronopost) for PrestaShop, a guest can perform SQL injection. The script PHP `cancelSkybill.php` own a sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

    Published: 22 Nov 2023
    6.5
    Medium

    CVE-2023-46673

    Last Modified: 21 Nov 2024

    It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.

    Published: 22 Nov 2023
    7.8
    High

    CVE-2023-46814

    Last Modified: 21 Nov 2024

    A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as SYSTEM.

    Published: 22 Nov 2023
    6.5
    Medium

    CVE-2023-47251

    Last Modified: 21 Nov 2024

    In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, a Directory Traversal in the print function of the VNC service allows authenticated attackers (with access to a VNC session) to automatically transfer malicious PDF documents by moving them into the .spool directory, and then sending a signal to the VNC service, which automatically transfers them to the connected VNC client's filesystem.

    Published: 22 Nov 2023
    6.5
    Medium

    CVE-2023-47312

    Last Modified: 21 Nov 2024

    Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to Login Credential Leakage via Audit Entries.

    Published: 22 Nov 2023
    5.4
    Medium

    CVE-2023-47313

    Last Modified: 21 Nov 2024

    Headwind MDM Web panel 5.22.1 is vulnerable to Directory Traversal. The application uses an API call to move the uploaded temporary file to the file directory during the file upload process. This API call receives two input parameters, such as path and localPath. The first one refers to the temporary file with an absolute path without validating it. Attackers may modify this API call by referring to arbitrary files. As a result, arbitrary files can be moved to the files directory and so they can be downloaded.

    Published: 22 Nov 2023
    8.8
    High

    CVE-2023-47315

    Last Modified: 21 Nov 2024

    Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to a hard-coded JWT Secret. The secret is hardcoded into the source code available to anyone on Git Hub. This secret is used to sign the application’s JWT token and verify the incoming user-supplied tokens.

    Published: 22 Nov 2023
    5.4
    Medium

    CVE-2023-47316

    Last Modified: 21 Nov 2024

    Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control. The Web panel allows users to gain access to potentially sensitive API calls such as listing users and their data, file management API calls and audit-related API calls.

    Published: 22 Nov 2023
    6.1
    Medium

    CVE-2023-47380

    Last Modified: 21 Nov 2024

    Admidio v4.2.12 and below is vulnerable to Cross Site Scripting (XSS).

    Published: 22 Nov 2023
    5.3
    Medium

    CVE-2023-47392

    Last Modified: 21 Nov 2024

    An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the carts of other users via sending a crafted add order request.

    Published: 22 Nov 2023
    5.3
    Medium

    CVE-2023-47393

    Last Modified: 21 Nov 2024

    An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the maintenance orders of other users and access sensitive user information via unspecified vectors.

    Published: 22 Nov 2023
    7.5
    High

    CVE-2023-48105

    Last Modified: 26 Nov 2024

    An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of service via the wasm_loader_prepare_bytecode function in core/iwasm/interpreter/wasm_loader.c.

    Published: 22 Nov 2023
    8.8
    High

    CVE-2023-48106

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the mz_path_resolve function in the mz_os.c file.

    Published: 22 Nov 2023
    7.2
    High

    CVE-2023-48646

    Last Modified: 21 Nov 2024

    Zoho ManageEngine RecoveryManager Plus before 6070 allows admin users to execute arbitrary commands via proxy settings.

    Published: 22 Nov 2023
    8.8
    High

    CVE-2023-49102

    Last Modified: 21 Nov 2024

    NZBGet 21.1 allows authenticated remote code execution because the unarchive programs (7za and unrar) preserve executable file permissions. An attacker with the Control capability can execute a file by setting the value of SevenZipCommand or UnrarCmd. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 22 Nov 2023
    6.1
    Medium

    CVE-2023-49146

    Last Modified: 21 Nov 2024

    DOMSanitizer (aka dom-sanitizer) before 1.0.7 allows XSS via an SVG document because of mishandling of comments and greedy regular expressions.

    Published: 22 Nov 2023
    5.5
    Medium

    CVE-2023-50431

    Last Modified: 30 May 2025

    sec_attest_info in drivers/accel/habanalabs/common/habanalabs_ioctl.c in the Linux kernel through 6.6.5 allows an information leak to user space because info->pad0 is not initialized.

    Published: 22 Nov 2023
    8.8
    High

    CVE-2023-48107

    Last Modified: 4 Nov 2025

    Buffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the mz_path_has_slash function in the mz_os.c file.

    Published: 22 Nov 2023
    9.8
    Critical

    CVE-2023-46357

    Last Modified: 21 Nov 2024

    In the module "Cross Selling in Modal Cart" (motivationsale) < 3.5.0 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method `motivationsaleDataModel::getProductsByIds()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

    Published: 22 Nov 2023
    8.8
    High

    CVE-2023-47250

    Last Modified: 21 Nov 2024

    In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, broken Access Control on X11 server sockets allows authenticated attackers (with access to a VNC session) to access the X11 desktops of other users by specifying their DISPLAY ID. This allows complete control of their desktop, including the ability to inject keystrokes and perform a keylogging attack.

    Published: 22 Nov 2023
    5.4
    Medium

    CVE-2023-47314

    Last Modified: 21 Nov 2024

    Headwind MDM Web panel 5.22.1 is vulnerable to cross-site scripting (XSS). The file upload function allows APK and arbitrary files to be uploaded. By exploiting this issue, attackers may upload HTML files and share the download URL pointing to these files with the victims. As the file download function returns the file in inline mode, the victim’s browser will immediately render the content of the HTML file as a web page. As a result, the uploaded client-side code will be evaluated and executed in the victim’s browser, allowing attackers to perform common XSS attacks.

    Published: 22 Nov 2023