CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2023-5593

    Last Modified: 21 Nov 2024

    The out-of-bounds write vulnerability in the Windows-based SecuExtender SSL VPN Client software version 4.0.4.0 could allow an authenticated local user to gain a privilege escalation by sending a crafted CREATE message.

    Published: 20 Nov 2023
    4
    Medium

    CVE-2023-47217

    Last Modified: 21 Nov 2024

    in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through buffer overflow.

    Published: 20 Nov 2023
    6.2
    Medium

    CVE-2023-46100

    Last Modified: 21 Nov 2024

    in OpenHarmony v3.2.2 and prior versions allow a local attacker get sensitive buffer information through use of uninitialized resource.

    Published: 20 Nov 2023
    6.2
    Medium

    CVE-2023-42774

    Last Modified: 21 Nov 2024

    in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information through incorrect default permissions.

    Published: 20 Nov 2023
    5.9
    Medium

    CVE-2023-6045

    Last Modified: 21 Nov 2024

    in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through type confusion.

    Published: 20 Nov 2023
    6.2
    Medium

    CVE-2023-46705

    Last Modified: 21 Nov 2024

    in OpenHarmony v3.2.2 and prior versions allow a local attacker causes system information leak through type confusion.

    Published: 20 Nov 2023
    8.4
    High

    CVE-2023-43612

    Last Modified: 21 Nov 2024

    in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary file read and write through improper preservation of permissions.

    Published: 20 Nov 2023
    7.3
    High

    CVE-2023-3116

    Last Modified: 21 Nov 2024

    in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information or rewrite sensitive file through incorrect default permissions.

    Published: 20 Nov 2023
    9.8
    Critical

    CVE-2022-46337

    Last Modified: 10 Jun 2025

    A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this could let an attacker fill up the disk by creating junk Derby databases. In LDAP-authenticated Derby installations, this could also allow the attacker to execute malware which was visible to and executable by the account which booted the Derby server. In LDAP-protected databases which weren't also protected by SQL GRANT/REVOKE authorization, this vulnerability could also let an attacker view and corrupt sensitive data and run sensitive database functions and procedures. Mitigation: Users should upgrade to Java 21 and Derby 10.17.1.0. Alternatively, users who wish to remain on older Java versions should build their own Derby distribution from one of the release families to which the fix was backported: 10.16, 10.15, and 10.14. Those are the releases which correspond, respectively, with Java LTS versions 17, 11, and 8.

    Published: 20 Nov 2023
    9.8
    Critical

    CVE-2023-46302

    Last Modified: 21 Nov 2024

    Apache Software Foundation Apache Submarine has a bug when serializing against yaml. The bug is caused by snakeyaml https://nvd.nist.gov/vuln/detail/CVE-2022-1471 . Apache Submarine uses JAXRS to define REST endpoints. In order to handle YAML requests (using application/yaml content-type), it defines a YamlEntityProvider entity provider that will process all incoming YAML requests. In order to unmarshal the request, the readFrom method is invoked, passing the entityStream containing the user-supplied data in `submarine-server/server-core/src/main/java/org/apache/submarine/server/utils/YamlUtils.java`. We have now fixed this issue in the new version by replacing to `jackson-dataformat-yaml`. This issue affects Apache Submarine: from 0.7.0 before 0.8.0. Users are recommended to upgrade to version 0.8.0, which fixes this issue. If using the version smaller than 0.8.0 and not want to upgrade, you can try cherry-pick PR https://github.com/apache/submarine/pull/1054 and rebuild the submart-server image to fix this.

    Published: 20 Nov 2023
    5.3
    Medium

    CVE-2023-3379

    Last Modified: 21 Nov 2024

    Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.

    Published: 20 Nov 2023
    6.1
    Medium

    CVE-2023-47175

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the product.

    Published: 20 Nov 2023
    9.8
    Critical

    CVE-2023-46700

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary SQL command by sending a crafted request, and obtain or alter information stored in the database.

    Published: 20 Nov 2023
    9.8
    Critical

    CVE-2023-38880

    Last Modified: 21 Nov 2024

    The Community Edition version 9.0 of OS4ED's openSIS Classic has a broken access control vulnerability in the database backup functionality. Whenever an admin generates a database backup, the backup is stored in the web root while the file name has a format of "opensisBackup<date>.sql" (e.g. "opensisBackup07-20-2023.sql"), i.e. can easily be guessed. This file can be accessed by any unauthenticated actor and contains a dump of the whole database including password hashes.

    Published: 20 Nov 2023
    7.5
    High

    CVE-2023-48110

    Last Modified: 21 Nov 2024

    Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the urls parameter in the function saveParentControlInfo . This vulnerability allows attackers to cause a Denial of Service (DoS) attack

    Published: 20 Nov 2023
    7.5
    High

    CVE-2023-48111

    Last Modified: 21 Nov 2024

    Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo . This vulnerability allows attackers to cause a Denial of Service (DoS) attack

    Published: 20 Nov 2023
    9.8
    Critical

    CVE-2023-38823

    Last Modified: 10 Jun 2025

    Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to execute arbitrary code via the formSetCfm function in bin/httpd.

    Published: 20 Nov 2023
    7.5
    High

    CVE-2023-38879

    Last Modified: 21 Nov 2024

    The Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a directory traversal vulnerability in the 'filename' parameter of 'DownloadWindow.php'.

    Published: 20 Nov 2023
    6.1
    Medium

    CVE-2023-38881

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into any of the 'calendar_id', 'school_date', 'month' or 'year' parameters in 'CalendarModal.php'.

    Published: 20 Nov 2023
    6.1
    Medium

    CVE-2023-38882

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'include' parameter in 'ForExport.php'

    Published: 20 Nov 2023
    6.1
    Medium

    CVE-2023-38883

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'ajax' parameter in 'ParentLookup.php'.

    Published: 20 Nov 2023
    7.5
    High

    CVE-2023-38884

    Last Modified: 21 Nov 2024

    An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's files by visiting '/assets/studentfiles/<studentId>-<filename>'

    Published: 20 Nov 2023
    8.8
    High

    CVE-2023-38885

    Last Modified: 21 Nov 2024

    OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole app. This may allow an attacker to trick an authenticated user into performing any kind of state changing request.

    Published: 20 Nov 2023
    7.1
    High

    CVE-2023-48090

    Last Modified: 21 Nov 2024

    GPAC 2.3-DEV-rev617-g671976fcc-master is vulnerable to memory leaks in extract_attributes media_tools/m3u8.c:329.

    Published: 20 Nov 2023
    5.4
    Medium

    CVE-2023-46470

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via crafted telecommand in the timeline view of the ArchiveBrowser.

    Published: 20 Nov 2023
    5.4
    Medium

    CVE-2023-46471

    Last Modified: 10 Jun 2025

    Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via the text variable scriptContainer of the ScriptViewer.

    Published: 20 Nov 2023
    9.8
    Critical

    CVE-2023-46990

    Last Modified: 21 Nov 2024

    Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeReplace function.

    Published: 20 Nov 2023
    7.8
    High

    CVE-2023-47172

    Last Modified: 21 Nov 2024

    Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, and WithSecure Elements Endpoint Protection 17 and later.

    Published: 20 Nov 2023
    6.1
    Medium

    CVE-2023-47311

    Last Modified: 21 Nov 2024

    An issue in Yamcs 5.8.6 allows attackers to send aribitrary telelcommands in a Command Stack via Clickjacking.

    Published: 20 Nov 2023
    6.1
    Medium

    CVE-2023-47417

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in the component /shells/embedder.html of DZSlides after v2011.07.25 allows attackers to execute arbitrary code via a crafted payload.

    Published: 20 Nov 2023
    5.5
    Medium

    CVE-2023-48039

    Last Modified: 21 Nov 2024

    GPAC 2.3-DEV-rev617-g671976fcc-master is vulnerable to memory leak in gf_mpd_parse_string media_tools/mpd.c:75.

    Published: 20 Nov 2023
    7.5
    High

    CVE-2023-48051

    Last Modified: 21 Nov 2024

    An issue in /upydev/keygen.py in upydev v0.4.3 allows attackers to decrypt sensitive information via weak encryption padding.

    Published: 20 Nov 2023
    7.5
    High

    CVE-2023-48109

    Last Modified: 21 Nov 2024

    Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the deviceId parameter in the function saveParentControlInfo . This vulnerability allows attackers to cause a Denial of Service (DoS) attack

    Published: 20 Nov 2023
    9.8
    Critical

    CVE-2023-48176

    Last Modified: 26 Nov 2024

    An Insecure Permissions issue in WebsiteGuide v.0.2 allows a remote attacker to gain escalated privileges via crafted jwt (JSON web token).

    Published: 20 Nov 2023
    7.8
    High

    CVE-2023-48192

    Last Modified: 21 Nov 2024

    An issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary code via the setTracerouteCfg function.

    Published: 20 Nov 2023
    —
    Unknown

    CVE-2023-48938

    Last Modified: 23 Apr 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 20 Nov 2023
    —
    Unknown

    CVE-2023-48939

    Last Modified: 23 Apr 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 20 Nov 2023
    6.5
    Medium

    CVE-2023-28780

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Yoast Yoast Local Premium.This issue affects Yoast Local Premium: from n/a through 14.8.

    Published: 18 Nov 2023
    5.4
    Medium

    CVE-2023-31075

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Arshid Easy Hide Login.This issue affects Easy Hide Login: from n/a through 1.0.8.

    Published: 18 Nov 2023
    4.3
    Medium

    CVE-2023-31089

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Tradebooster Video XML Sitemap Generator.This issue affects Video XML Sitemap Generator: from n/a through 1.0.0.

    Published: 18 Nov 2023
    5.4
    Medium

    CVE-2023-32245

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WPDeveloper Essential Addons for Elementor Pro.This issue affects Essential Addons for Elementor Pro: from n/a through 5.4.8.

    Published: 18 Nov 2023
    5.4
    Medium

    CVE-2023-32504

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Kainex Wise Chat.This issue affects Wise Chat: from n/a through 3.1.3.

    Published: 18 Nov 2023
    5.4
    Medium

    CVE-2023-32514

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Himanshu Parashar Google Site Verification plugin using Meta Tag.This issue affects Google Site Verification plugin using Meta Tag: from n/a through 1.2.

    Published: 18 Nov 2023
    4.3
    Medium

    CVE-2023-25985

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Tomas | Docs | FAQ | Premium Support WordPress Tooltips.This issue affects WordPress Tooltips: from n/a through 8.2.5.

    Published: 18 Nov 2023
    4.3
    Medium

    CVE-2023-41129

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Patreon Patreon WordPress.This issue affects Patreon WordPress: from n/a through 1.8.6.

    Published: 18 Nov 2023
    5.4
    Medium

    CVE-2023-47243

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in CodeMShop 코드엠샵 마이사이트 – MSHOP MY SITE.This issue affects 코드엠샵 마이사이트 – MSHOP MY SITE: from n/a through 1.1.6.

    Published: 18 Nov 2023
    4.3
    Medium

    CVE-2023-47519

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WC Product Table WooCommerce Product Table Lite.This issue affects WooCommerce Product Table Lite: from n/a through 2.6.2.

    Published: 18 Nov 2023
    4.3
    Medium

    CVE-2023-47531

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in DroitThemes Droit Dark Mode.This issue affects Droit Dark Mode: from n/a through 1.1.2.

    Published: 18 Nov 2023
    5.4
    Medium

    CVE-2023-47551

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in RedNao Donations Made Easy – Smart Donations.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12.

    Published: 18 Nov 2023
    5.4
    Medium

    CVE-2023-47552

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Labib Ahmed Image Hover Effects – WordPress Plugin.This issue affects Image Hover Effects – WordPress Plugin: from n/a through 5.5.

    Published: 18 Nov 2023