CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2023-6109

    Last Modified: 8 Apr 2026

    The YOP Poll plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 6.5.26. This is due to improper restrictions on the add() function. This makes it possible for unauthenticated attackers to place multiple votes on a single poll even when the poll is set to one vote per person.

    Published: 14 Nov 2023
    6.5
    Medium

    CVE-2023-20592

    Last Modified: 21 Nov 2024

    Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.

    Published: 14 Nov 2023
    8.8
    High

    CVE-2023-47609

    Last Modified: 8 Jan 2025

    SQL injection vulnerability in OSS Calendar versions prior to v.2.0.3 allows a remote authenticated attacker to execute arbitrary code or obtain and/or alter the information stored in the database by sending a specially crafted request.

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-6006

    Last Modified: 8 Jan 2025

    This vulnerability potentially allows local attackers to escalate privileges on affected installations of PaperCut NG. An attacker must have local write access to the C Drive. In addition, Print Archiving must be enabled or the attacker needs to encounter a misconfigured system. This vulnerability does not apply to PaperCut NG installs that have Print Archiving enabled and configured as per the recommended set up procedure. This specific flaw exists within the pc-pdl-to-image process. The process loads an executable from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM Note: This CVE has been rescored with a "Privileges Required (PR)" rating of low, and “Attack Complexity (AC)” rating of low, reflecting the worst-case scenario where an Administrator has granted local login access to standard network users on the host server.

    Published: 14 Nov 2023
    5.3
    Medium

    CVE-2023-42480

    Last Modified: 21 Nov 2024

    The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an impact on confidentiality but there is no other impact on integrity or availability.

    Published: 14 Nov 2023
    5.3
    Medium

    CVE-2023-41366

    Last Modified: 21 Nov 2024

    Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.91, KERNEL 7.92, KERNEL 7.93, KERNEL 7.94, KERNEL64UC 7.22, KERNEL64UC 7.22EXT, KERNEL64UC 7.53, KERNEL64NUC 7.22, KERNEL64NUC 7.22EXT, allows an unauthenticated attacker to access the unintended data due to the lack of restrictions applied which may lead to low impact in confidentiality and no impact on the integrity and availability of the application.

    Published: 14 Nov 2023
    9.6
    Critical

    CVE-2023-31403

    Last Modified: 11 Jun 2025

    SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any malicious user can read and write to the SMB shared folder. Additionally, the files in the folder can be executed or be used by the installation process leading to considerable impact on confidentiality, integrity and availability.

    Published: 14 Nov 2023
    4.2
    Medium

    CVE-2023-47628

    Last Modified: 21 Nov 2024

    DataHub is an open-source metadata platform. DataHub Frontend's sessions are configured using Play Framework's default settings for stateless session which do not set an expiration time for a cookie. Due to this, if a session cookie were ever leaked, it would be valid forever. DataHub uses a stateless session cookie that is not invalidated on logout, it is just removed from the browser forcing the user to login again. However, if an attacker extracted a cookie from an authenticated user it would continue to be valid as there is no validation on a time window the session token is valid for due to a combination of the usage of LegacyCookiesModule from Play Framework and using default settings which do not set an expiration time. All DataHub instances prior to the patch that have removed the datahub user, but not the default policies applying to that user are affected. Users are advised to update to version 0.12.1 which addresses the issue. There are no known workarounds for this vulnerability.

    Published: 14 Nov 2023
    7.1
    High

    CVE-2023-47629

    Last Modified: 21 Nov 2024

    DataHub is an open-source metadata platform. In affected versions sign-up through an invite link does not properly restrict users from signing up as privileged accounts. If a user is given an email sign-up link they can potentially create an admin account given certain preconditions. If the default datahub user has been removed, then the user can sign up for an account that leverages the default policies giving admin privileges to the datahub user. All DataHub instances prior to the patch that have removed the datahub user, but not the default policies applying to that user are affected. Users are advised to update to version 0.12.1 which addresses the issue. There are no known workarounds for this vulnerability.

    Published: 14 Nov 2023
    9.8
    Critical

    CVE-2023-43902

    Last Modified: 28 Aug 2026

    Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.

    Published: 14 Nov 2023
    6.5
    Medium

    CVE-2023-43900

    Last Modified: 28 Aug 2026

    Insecure Direct Object References (IDOR) in eMudhra emSigner v2.8.7 allow authenticated attackers to gain unauthorized access to application content and view sensitive data of other users via manipulation of the documentID and EncryptedDocumentId parameters.

    Published: 14 Nov 2023
    7.5
    High

    CVE-2023-43901

    Last Modified: 28 Aug 2026

    Incorrect access control in the AdHoc User creation form of eMudhra emSigner v2.8.7 allows unauthenticated attackers to arbitrarily modify usernames and privileges by using the email address of a registered user.

    Published: 14 Nov 2023
    7.6
    High

    CVE-2023-36049

    Last Modified: 9 Oct 2025

    .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability

    Published: 14 Nov 2023
    5.5
    Medium

    CVE-2023-46581

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary code via the name, uname and email parameters in the registration.php component.

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-46582

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary SQL commands via the id paramter in the deleteProduct.php component.

    Published: 14 Nov 2023
    8.8
    High

    CVE-2022-45781

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in Tenda AX1803 v1.0.0.1_2994 and earlier allows attackers to run arbitrary code via /goform/SetOnlineDevName.

    Published: 14 Nov 2023
    4.8
    Medium

    CVE-2023-31754

    Last Modified: 21 Nov 2024

    Optimizely CMS UI before v12.16.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Admin panel.

    Published: 14 Nov 2023
    5.3
    Medium

    CVE-2023-41570

    Last Modified: 21 Nov 2024

    MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.

    Published: 14 Nov 2023
    7.5
    High

    CVE-2023-45558

    Last Modified: 21 Nov 2024

    An issue in Golden v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.

    Published: 14 Nov 2023
    5.4
    Medium

    CVE-2023-42325

    Last Modified: 26 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page.

    Published: 14 Nov 2023
    8.8
    High

    CVE-2023-42326

    Last Modified: 21 Nov 2024

    An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.

    Published: 14 Nov 2023
    5.4
    Medium

    CVE-2023-42327

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-44444

    Last Modified: 4 Nov 2025

    GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PSP files. Crafted data in a PSP file can trigger an off-by-one error when calculating a location to write within a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-22097.

    Published: 14 Nov 2023
    7.5
    High

    CVE-2023-45560

    Last Modified: 21 Nov 2024

    An issue in Yasukawa memberscard v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.

    Published: 14 Nov 2023
    7.5
    High

    CVE-2023-45684

    Last Modified: 21 Nov 2024

    Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earliest affected version is 3.6.0. The issue is in the Mission Portal login page in the CFEngine hub.

    Published: 14 Nov 2023
    5.4
    Medium

    CVE-2023-45879

    Last Modified: 21 Nov 2024

    GibbonEdu Gibbon version 25.0.0 allows HTML Injection via an IFRAME element to the Messager component.

    Published: 14 Nov 2023
    6.1
    Medium

    CVE-2023-45881

    Last Modified: 21 Nov 2024

    GibbonEdu Gibbon through version 25.0.0 allows /modules/Planner/resources_addQuick_ajaxProcess.php file upload with resultant XSS. The imageAsLinks parameter must be set to Y to return HTML code. The filename attribute of the bodyfile1 parameter is reflected in the response.

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-46022

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in delete.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via the 'bid' parameter.

    Published: 14 Nov 2023
    6.5
    Medium

    CVE-2023-46023

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in addTask.php in Code-Projects Simple Task List 1.0 allows attackers to obtain sensitive information via the 'status' parameter.

    Published: 14 Nov 2023
    7.5
    High

    CVE-2023-46024

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in index.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to run arbitrary SQL commands and obtain sensitive information via the 'searchdata' parameter.

    Published: 14 Nov 2023
    4.9
    Medium

    CVE-2023-46025

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in teacher-info.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to obtain sensitive information via the 'editid' parameter.

    Published: 14 Nov 2023
    4.8
    Medium

    CVE-2023-46026

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in profile.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to run arbitrary code via the 'adminname' and 'email' parameters.

    Published: 14 Nov 2023
    5.4
    Medium

    CVE-2023-46580

    Last Modified: 21 Nov 2024

    Cross-Site Scripting (XSS) vulnerability in Inventory Management V1.0 allows attackers to execute arbitrary code via the pname parameter of the editProduct.php component.

    Published: 14 Nov 2023
    8
    High

    CVE-2023-46671

    Last Modified: 21 Nov 2024

    An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error. Elastic has released Kibana 8.11.1 which resolves this issue. The error message recorded in the log may contain account credentials for the kibana_system user, API Keys, and credentials of Kibana end-users. The issue occurs infrequently, only if an error is returned from an Elasticsearch cluster, in cases where there is user interaction and an unhealthy cluster (for example, when returning circuit breaker or no shard exceptions).

    Published: 14 Nov 2023
    5.2
    Medium

    CVE-2023-47262

    Last Modified: 26 Nov 2024

    The startup process and device configurations of the Abbott ID NOW device, before v7.1, can be interrupted and/or modified via physical access to an internal serial port. Direct physical access is required to exploit.

    Published: 14 Nov 2023
    5.5
    Medium

    CVE-2023-47384

    Last Modified: 21 Nov 2024

    MP4Box GPAC v2.3-DEV-rev617-g671976fcc-master was discovered to contain a memory leak in the function gf_isom_add_chapter at /isomedia/isom_write.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.

    Published: 14 Nov 2023
    8.8
    High

    CVE-2023-48020

    Last Modified: 21 Nov 2024

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/task/changeStatus.

    Published: 14 Nov 2023
    8.8
    High

    CVE-2023-48021

    Last Modified: 21 Nov 2024

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/task/update.

    Published: 14 Nov 2023
    6.2
    Medium

    CVE-2023-36558

    Last Modified: 9 Oct 2025

    ASP.NET Core Security Feature Bypass Vulnerability

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-6111

    Last Modified: 20 Mar 2025

    A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The function nft_trans_gc_catchall did not remove the catchall set element from the catchall_list when the argument sync is true, making it possible to free a catchall set element many times. We recommend upgrading past commit 93995bf4af2c5a99e2a87f0cd5ce547d31eb7630.

    Published: 14 Nov 2023
    3.4
    Low

    CVE-2023-47641

    Last Modified: 3 Nov 2025

    aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Affected versions of aiohttp have a security vulnerability regarding the inconsistent interpretation of the http protocol. HTTP/1.1 is a persistent protocol, if both Content-Length(CL) and Transfer-Encoding(TE) header values are present it can lead to incorrect interpretation of two entities that parse the HTTP and we can poison other sockets with this incorrect interpretation. A possible Proof-of-Concept (POC) would be a configuration with a reverse proxy(frontend) that accepts both CL and TE headers and aiohttp as backend. As aiohttp parses anything with chunked, we can pass a chunked123 as TE, the frontend entity will ignore this header and will parse Content-Length. The impact of this vulnerability is that it is possible to bypass any proxy rule, poisoning sockets to other users like passing Authentication Headers, also if it is present an Open Redirect an attacker could combine it to redirect random users to another website and log the request. This vulnerability has been addressed in release 3.8.0 of aiohttp. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-44441

    Last Modified: 4 Nov 2025

    GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DDS files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-22093.

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-44442

    Last Modified: 4 Nov 2025

    GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PSD files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current process. Was ZDI-CAN-22094.

    Published: 14 Nov 2023
    4.6
    Medium

    CVE-2023-6134

    Last Modified: 25 Feb 2026

    A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could allow an attacker to submit a specially crafted request leading to cross-site scripting (XSS) or further attacks. This flaw is the result of an incomplete fix for CVE-2020-10748.

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-44443

    Last Modified: 14 Aug 2025

    GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PSP files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-22096.

    Published: 14 Nov 2023
    9.8
    Critical

    CVE-2023-45878

    Last Modified: 8 Jan 2025

    GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The endpoint accepts the img, path, and gibbonPersonID parameters. The img parameter is expected to be a base64 encoded image. If the path parameter is set, the defined path is used as the destination folder, concatenated with the absolute path of the installation directory. The content of the img parameter is base64 decoded and written to the defined file path. This allows creation of PHP files that permit Remote Code Execution (unauthenticated).

    Published: 14 Nov 2023
    7.2
    High

    CVE-2023-45880

    Last Modified: 21 Nov 2024

    GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can create a new Asset Component. The templateFileDestination parameter can be set to an arbitrary pathname (and extension). This allows creation of PHP files outside of the uploads directory, directly in the webroot.

    Published: 14 Nov 2023
    6.1
    Medium

    CVE-2023-48094

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in CesiumJS v1.111 allows attackers to execute arbitrary code in the context of the victim's browser via sending a crafted payload to /container_files/public_html/doc/index.html. NOTE: the vendor’s position is that Apps/Sandcastle/standalone.html is part of the CesiumGS/cesium GitHub repository, but is demo code that is not part of the CesiumJS JavaScript library product.

    Published: 14 Nov 2023
    8.8
    High

    CVE-2023-23583

    Last Modified: 16 Dec 2025

    Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.

    Published: 14 Nov 2023
    5.9
    Medium

    CVE-2023-47657

    Last Modified: 8 Jan 2025

    Auth. (ShopManager+) Stored Cross-Site Scripting (XSS) vulnerability in GrandPlugins Direct Checkout – Quick View – Buy Now For WooCommerce plugin <= 1.5.8 versions.

    Published: 13 Nov 2023