CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2023-47071

    Last Modified: 21 Nov 2024

    Adobe After Effects version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 17 Nov 2023
    3.3
    Low

    CVE-2023-47072

    Last Modified: 21 Nov 2024

    Adobe After Effects version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 17 Nov 2023
    7.8
    High

    CVE-2023-47066

    Last Modified: 21 Nov 2024

    Adobe After Effects version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 17 Nov 2023
    7.8
    High

    CVE-2023-47070

    Last Modified: 21 Nov 2024

    Adobe After Effects version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 17 Nov 2023
    7.8
    High

    CVE-2023-47073

    Last Modified: 21 Nov 2024

    Adobe After Effects version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 17 Nov 2023
    7.8
    High

    CVE-2023-47069

    Last Modified: 21 Nov 2024

    Adobe After Effects version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 17 Nov 2023
    7.8
    High

    CVE-2023-47067

    Last Modified: 21 Nov 2024

    Adobe After Effects version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 17 Nov 2023
    5.4
    Medium

    CVE-2023-5445

    Last Modified: 21 Nov 2024

    An open redirect vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2, allows a remote low privileged user to modify the URL parameter for the purpose of redirecting URL request(s) to a malicious site. This impacts the dashboard area of the user interface. A user would need to be logged into ePO to trigger this vulnerability. To exploit this the attacker must change the HTTP payload post submission, prior to it reaching the ePO server.

    Published: 17 Nov 2023
    8
    High

    CVE-2023-5444

    Last Modified: 2 Dec 2024

    A Cross Site Request Forgery vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2 allows a remote low privilege user to successfully add a new user with administrator privileges to the ePO server. This impacts the dashboard area of the user interface. To exploit this the attacker must change the HTTP payload post submission, prior to it reaching the ePO server.

    Published: 17 Nov 2023
    4.3
    Medium

    CVE-2023-47757

    Last Modified: 28 Apr 2026

    Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in AWeber AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth allows Accessing Functionality Not Properly Constrained by ACLs, Cross-Site Request Forgery.This issue affects AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth: from n/a through 7.3.9.

    Published: 17 Nov 2023
    5.5
    Medium

    CVE-2023-44326

    Last Modified: 21 Nov 2024

    Adobe Dimension versions 3.4.9 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 17 Nov 2023
    5.5
    Medium

    CVE-2023-44325

    Last Modified: 21 Nov 2024

    Adobe Animate versions 23.0.2 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 17 Nov 2023
    9.6
    Critical

    CVE-2023-47797

    Last Modified: 21 Nov 2024

    Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95 allows remote attackers to inject arbitrary web script or HTML via the `p_l_back_url_title` parameter.

    Published: 17 Nov 2023
    8.8
    High

    CVE-2023-39548

    Last Modified: 2 Dec 2024

    CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.

    Published: 17 Nov 2023
    8.8
    High

    CVE-2023-39547

    Last Modified: 2 Dec 2024

    CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.

    Published: 17 Nov 2023
    8.8
    High

    CVE-2023-39546

    Last Modified: 21 Nov 2024

    CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.

    Published: 17 Nov 2023
    8.8
    High

    CVE-2023-39545

    Last Modified: 21 Nov 2024

    CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.

    Published: 17 Nov 2023
    8.8
    High

    CVE-2023-39544

    Last Modified: 21 Nov 2024

    CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.

    Published: 17 Nov 2023
    7.2
    High

    CVE-2023-47675

    Last Modified: 21 Nov 2024

    CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to execute an arbitrary OS command.

    Published: 17 Nov 2023
    4.9
    Medium

    CVE-2023-47283

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to obtain files in the system.

    Published: 17 Nov 2023
    6.5
    Medium

    CVE-2023-42428

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to delete directories and files in the system.

    Published: 17 Nov 2023
    8.1
    High

    CVE-2023-38130

    Last Modified: 6 Jan 2025

    Cross-site request forgery (CSRF) vulnerability in CubeCart prior to 6.5.3 allows a remote unauthenticated attacker to delete data in the system.

    Published: 17 Nov 2023
    5.3
    Medium

    CVE-2023-26364

    Last Modified: 21 Nov 2024

    @adobe/css-tools version 4.3.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a minor denial of service while attempting to parse CSS. Exploitation of this issue does not require user interaction or privileges.

    Published: 17 Nov 2023
    7.5
    High

    CVE-2023-38313

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenNDS Captive Portal before 10.1.2. it has a do_binauth NULL pointer dereference that can be triggered with a crafted GET HTTP request with a missing client redirect query string parameter. Triggering this issue results in crashing openNDS (a Denial-of-Service condition). The issue occurs when the client is about to be authenticated, and can be triggered only when the BinAuth option is set. Affected OpenNDS Captive Portal before version 10.1.2 fixed infixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on28. August 2023 by updating OpenNDS to version 10.1.3.

    Published: 17 Nov 2023
    7.5
    High

    CVE-2023-38315

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a try_to_authenticate NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing client token query string parameter. Triggering this issue results in crashing OpenNDS (a Denial-of-Service condition). Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.

    Published: 17 Nov 2023
    5.3
    Medium

    CVE-2023-38324

    Last Modified: 26 Nov 2024

    An issue was discovered in OpenNDS before 10.1.2. It allows users to skip the splash page sequence (and directly authenticate) when it is using the default FAS key and OpenNDS is configured as FAS. Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.

    Published: 17 Nov 2023
    4.3
    Medium

    CVE-2020-11447

    Last Modified: 21 Nov 2024

    An issue was discovered on Bell HomeHub 3000 SG48222070 devices. Remote authenticated users can retrieve the serial number via cgi/json-req - this is an information leak because the serial number is intended to prove an actor's physical access to the device.

    Published: 17 Nov 2023
    9.8
    Critical

    CVE-2023-45387

    Last Modified: 21 Nov 2024

    In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 5.0.0 from MyPrestaModules for PrestaShop, a guest can perform SQL injection via `exportProduct::_addDataToDb().`

    Published: 17 Nov 2023
    6.1
    Medium

    CVE-2020-11448

    Last Modified: 21 Nov 2024

    An issue was discovered on Bell HomeHub 3000 SG48222070 devices. There is XSS related to the email field and the login page.

    Published: 17 Nov 2023
    6.5
    Medium

    CVE-2023-38314

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a NULL pointer dereference in preauthenticated() that can be triggered with a crafted GET HTTP request with a missing redirect query string parameter. Triggering this issue results in crashing OpenNDS (a Denial-of-Service condition). Affected OpenNDS Captive Portal before version 10.1.2 fixed infixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on28. August 2023 by updating OpenNDS to version 10.1.3.

    Published: 17 Nov 2023
    9.8
    Critical

    CVE-2023-38316

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrary OS commands by inserting them into the URL portion of HTTP GET requests. Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.

    Published: 17 Nov 2023
    7.5
    High

    CVE-2023-38320

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a show_preauthpage NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing User-Agent header. Triggering this issue results in crashing OpenNDS (a Denial-of-Service condition). This problem was fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.

    Published: 17 Nov 2023
    7.5
    High

    CVE-2023-38322

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a do_binauth NULL pointer dereference that be triggered with a crafted GET HTTP request with a missing User-Agent HTTP header. Triggering this issue results in crashing OpenNDS (a Denial-of-Service condition). The issue occurs when the client is about to be authenticated, and can be triggered only when the BinAuth option is set. Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.

    Published: 17 Nov 2023
    9.8
    Critical

    CVE-2023-41101

    Last Modified: 21 Nov 2024

    An issue was discovered in the captive portal in OpenNDS before version 10.1.3. get_query in http_microhttpd.c does not validate the length of the query string of GET requests. This leads to a stack-based buffer overflow in versions 9.x and earlier, and to a heap-based buffer overflow in versions 10.x and later. Attackers may exploit the issue to crash OpenNDS (Denial-of-Service condition) or to inject and execute arbitrary bytecode (Remote Code Execution). Affected OpenNDS before version 10.1.3 fixed in OpenWrt master and OpenWrt 23.05 on 23. November by updating OpenNDS to version 10.2.0.

    Published: 17 Nov 2023
    7.5
    High

    CVE-2023-41102

    Last Modified: 21 Nov 2024

    An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory. Affected OpenNDS before version 10.1.3 fixed in OpenWrt master and OpenWrt 23.05 on 23. November by updating OpenNDS to version 10.2.0.

    Published: 17 Nov 2023
    9.8
    Critical

    CVE-2023-43177

    Last Modified: 21 Nov 2024

    CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.

    Published: 17 Nov 2023
    5.4
    Medium

    CVE-2023-44796

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate privileges via a crafted script to the _generaloptions_panel.php component.

    Published: 17 Nov 2023
    7.5
    High

    CVE-2023-45382

    Last Modified: 21 Nov 2024

    In the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a path traversal to view all files on the information system.

    Published: 17 Nov 2023
    7.5
    High

    CVE-2023-46402

    Last Modified: 21 Nov 2024

    git-urls 1.0.0 allows ReDOS (Regular Expression Denial of Service) in urls.go.

    Published: 17 Nov 2023
    7.5
    High

    CVE-2023-48185

    Last Modified: 21 Nov 2024

    Directory Traversal vulnerability in TerraMaster v.s1.0 through v.2.295 allows a remote attacker to obtain sensitive information via a crafted GET request.

    Published: 17 Nov 2023
    6.5
    Medium

    CVE-2023-48024

    Last Modified: 21 Nov 2024

    Liblisp through commit 4c65969 was discovered to contain a use-after-free vulnerability in void hash_destroy(hash_table_t *h) at hash.c

    Published: 17 Nov 2023
    8.1
    High

    CVE-2023-48025

    Last Modified: 21 Nov 2024

    Liblisp through commit 4c65969 was discovered to contain a out-of-bounds-read vulnerability in unsigned get_length(lisp_cell_t * x) at eval.c

    Published: 17 Nov 2023
    9.8
    Critical

    CVE-2023-48648

    Last Modified: 21 Nov 2024

    Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creation functions (such as the Mkdir() function) gives universal access (0777) to created folders by default. Excessive permissions can be granted when creating a directory with permissions greater than 0755 or when the permissions argument is not specified.

    Published: 17 Nov 2023
    3.5
    Low

    CVE-2023-48649

    Last Modified: 21 Nov 2024

    Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows stored XSS on the Admin page via an uploaded file name.

    Published: 17 Nov 2023
    9.8
    Critical

    CVE-2023-48655

    Last Modified: 21 Nov 2024

    An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.

    Published: 17 Nov 2023
    9.8
    Critical

    CVE-2023-48656

    Last Modified: 26 Nov 2024

    An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses.

    Published: 17 Nov 2023
    9.8
    Critical

    CVE-2023-48657

    Last Modified: 21 Nov 2024

    An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.

    Published: 17 Nov 2023
    9.8
    Critical

    CVE-2023-48658

    Last Modified: 21 Nov 2024

    An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, underscore, dash, period, and space.

    Published: 17 Nov 2023
    9.8
    Critical

    CVE-2023-48659

    Last Modified: 21 Nov 2024

    An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.

    Published: 17 Nov 2023
    9.8
    Critical

    CVE-2023-48028

    Last Modified: 29 Sept 2025

    kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack.

    Published: 17 Nov 2023