CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2023-4218

    Last Modified: 21 Nov 2024

    In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review a foreign repository or patch).

    Published: 9 Nov 2023
    9.8
    Critical

    CVE-2023-47248

    Last Modified: 13 Feb 2025

    Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (for example user-supplied input files). This vulnerability only affects PyArrow, not other Apache Arrow implementations or bindings. It is recommended that users of PyArrow upgrade to 14.0.1. Similarly, it is recommended that downstream libraries upgrade their dependency requirements to PyArrow 14.0.1 or later. PyPI packages are already available, and we hope that conda-forge packages will be available soon. If it is not possible to upgrade, we provide a separate package `pyarrow-hotfix` that disables the vulnerability on older PyArrow versions. See https://pypi.org/project/pyarrow-hotfix/ for instructions.

    Published: 9 Nov 2023
    4.4
    Medium

    CVE-2023-47613

    Last Modified: 21 Nov 2024

    A CWE-23: Relative Path Traversal vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow a local, low privileged attacker to escape from virtual directories and get read/write access to protected files on the targeted system.

    Published: 9 Nov 2023
    5.6
    Medium

    CVE-2023-26156

    Last Modified: 21 Nov 2024

    Versions of the package chromedriver before 119.0.1 are vulnerable to Command Injection when setting the chromedriver.path to an arbitrary system binary. This could lead to unauthorized access and potentially malicious actions on the host system. **Note:** An attacker must have access to the system running the vulnerable chromedriver library to exploit it. The success of exploitation also depends on the permissions and privileges of the process running chromedriver.

    Published: 9 Nov 2023
    —
    Unknown

    CVE-2023-41371

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 9 Nov 2023
    —
    Unknown

    CVE-2023-45739

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 9 Nov 2023
    5.9
    Medium

    CVE-2023-20902

    Last Modified: 21 Nov 2024

    A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below,  Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with network access to create jobs/stop job tasks and retrieve job task information.

    Published: 9 Nov 2023
    4.3
    Medium

    CVE-2023-5868

    Last Modified: 23 Jun 2026

    A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.

    Published: 9 Nov 2023
    6.5
    Medium

    CVE-2023-47363

    Last Modified: 21 Nov 2024

    The leakage of channel access token in F.B.P members Line 13.6.1 allows remote attackers to send malicious notifications to victims.

    Published: 9 Nov 2023
    6.5
    Medium

    CVE-2023-47364

    Last Modified: 26 Nov 2024

    The leakage of channel access token in nagaoka taxi Line 13.6.1 allows remote attackers to send malicious notifications to victims

    Published: 9 Nov 2023
    6.5
    Medium

    CVE-2023-47366

    Last Modified: 21 Nov 2024

    The leakage of channel access token in craft_members Line 13.6.1 allows remote attackers to send malicious notifications to victims.

    Published: 9 Nov 2023
    6.5
    Medium

    CVE-2023-47367

    Last Modified: 21 Nov 2024

    The leakage of channel access token in platinum clinic Line 13.6.1 allows remote attackers to send malicious notifications to victims.

    Published: 9 Nov 2023
    6.5
    Medium

    CVE-2023-47368

    Last Modified: 21 Nov 2024

    The leakage of channel access token in taketorinoyu Line 13.6.1 allows remote attackers to send malicious notifications to victims.

    Published: 9 Nov 2023
    6.5
    Medium

    CVE-2023-47369

    Last Modified: 21 Nov 2024

    The leakage of channel access token in best_training_member Line 13.6.1 allows remote attackers to send malicious notifications.

    Published: 9 Nov 2023
    6.5
    Medium

    CVE-2023-47365

    Last Modified: 21 Nov 2024

    The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notifications to victims.

    Published: 9 Nov 2023
    7.2
    High

    CVE-2023-29975

    Last Modified: 21 Nov 2024

    An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.

    Published: 9 Nov 2023
    2.2
    Low

    CVE-2023-5870

    Last Modified: 2 Mar 2026

    A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-45885

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to run arbitrary code via the new component feature in the flexibleLayout plugin.

    Published: 9 Nov 2023
    6.5
    Medium

    CVE-2023-45884

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.

    Published: 9 Nov 2023
    6.1
    Medium

    CVE-2023-46492

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in MLDB.ai v.2017.04.17.0 allows a remote attacker to execute arbitrary code via a crafted payload to the public_html/doc/index.html.

    Published: 9 Nov 2023
    7.5
    High

    CVE-2023-46894

    Last Modified: 21 Nov 2024

    An issue discovered in esptool 4.6.2 allows attackers to view sensitive information via weak cryptographic algorithm.

    Published: 9 Nov 2023
    6.5
    Medium

    CVE-2023-47370

    Last Modified: 21 Nov 2024

    The leakage of channel access token in bluetrick Line 13.6.1 allows remote attackers to send malicious notifications to victims.

    Published: 9 Nov 2023
    6.5
    Medium

    CVE-2023-47372

    Last Modified: 21 Nov 2024

    The leakage of channel access token in UPDATESALON C-LOUNGE Line 13.6.1 allows remote attackers to send malicious notifications to victims.

    Published: 9 Nov 2023
    6.5
    Medium

    CVE-2023-47373

    Last Modified: 21 Nov 2024

    The leakage of channel access token in DRAGON FAMILY Line 13.6.1 allows remote attackers to send malicious notifications to victims.

    Published: 9 Nov 2023
    7.8
    High

    CVE-2023-47489

    Last Modified: 29 Sept 2025

    CSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute arbitrary code via a crafted script to the export-v2.php and ajax.render.php components.

    Published: 9 Nov 2023
    5.9
    Medium

    CVE-2023-5954

    Last Modified: 13 Feb 2025

    HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory. A large number of these requests may lead to denial-of-service. Fixed in Vault 1.15.2, 1.14.6, and 1.13.10.

    Published: 9 Nov 2023
    6.1
    Medium

    CVE-2023-47488

    Last Modified: 29 Sept 2025

    Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted script to the attrib_manager_id parameter in the General Information page and the id parameter in the contact page.

    Published: 9 Nov 2023
    8.8
    High

    CVE-2023-5869

    Last Modified: 11 Mar 2026

    A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data. This enables the execution of arbitrary code on the target system, allowing users to write arbitrary bytes to memory and extensively read the server's memory.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-37533

    Last Modified: 21 Nov 2024

    HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which contains the malicious script code. This may allow the attacker to steal cookie-based authentication credentials and comprise a user's account then launch other attacks.

    Published: 8 Nov 2023
    9.8
    Critical

    CVE-2023-3959

    Last Modified: 16 Jan 2025

    Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While processing XML elements from incoming network requests, the product does not sufficiently check or validate allocated buffer size. This may lead to remote code execution.

    Published: 8 Nov 2023
    9.8
    Critical

    CVE-2023-45225

    Last Modified: 16 Jan 2025

    Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras  with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While parsing certain XML elements from incoming network requests, the product does not sufficiently check or validate allocated buffer size. This may lead to remote code execution.

    Published: 8 Nov 2023
    9.8
    Critical

    CVE-2023-43755

    Last Modified: 16 Jan 2025

    Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. During the processing and parsing of certain fields in XML elements from incoming network requests, the product does not sufficiently check or validate allocated buffer size. This may lead to remote code execution.

    Published: 8 Nov 2023
    8.8
    High

    CVE-2023-39435

    Last Modified: 16 Jan 2025

    Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to stack-based overflows. During the process of updating certain settings sent from incoming network requests, the product does not sufficiently check or validate allocated buffer size. This may lead to remote code execution.

    Published: 8 Nov 2023
    8.8
    High

    CVE-2023-4249

    Last Modified: 16 Jan 2025

    Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 has a command injection vulnerability in their implementation of their binaries and handling of network requests.

    Published: 8 Nov 2023
    6.7
    Medium

    CVE-2023-43577

    Last Modified: 21 Nov 2024

    A buffer overflow was reported in the ReFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

    Published: 8 Nov 2023
    6.7
    Medium

    CVE-2023-43576

    Last Modified: 21 Nov 2024

    A buffer overflow was reported in the WMISwSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

    Published: 8 Nov 2023
    6.7
    Medium

    CVE-2023-43575

    Last Modified: 21 Nov 2024

    A buffer overflow was reported in the UltraFunctionTable module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

    Published: 8 Nov 2023
    4.4
    Medium

    CVE-2023-43574

    Last Modified: 21 Nov 2024

    A buffer over-read was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.

    Published: 8 Nov 2023
    6.7
    Medium

    CVE-2023-43573

    Last Modified: 21 Nov 2024

    A buffer overflow was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

    Published: 8 Nov 2023
    4.4
    Medium

    CVE-2023-43572

    Last Modified: 21 Nov 2024

    A buffer over-read was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.

    Published: 8 Nov 2023
    6.7
    Medium

    CVE-2023-45079

    Last Modified: 21 Nov 2024

    A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

    Published: 8 Nov 2023
    6.7
    Medium

    CVE-2023-45078

    Last Modified: 21 Nov 2024

    A memory leakage vulnerability was reported in the DustFilterAlertSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

    Published: 8 Nov 2023
    6.7
    Medium

    CVE-2023-45077

    Last Modified: 21 Nov 2024

    A memory leakage vulnerability was reported in the 534D0740 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

    Published: 8 Nov 2023
    6.7
    Medium

    CVE-2023-45076

    Last Modified: 21 Nov 2024

    A memory leakage vulnerability was reported in the 534D0140 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

    Published: 8 Nov 2023
    6.7
    Medium

    CVE-2023-45075

    Last Modified: 21 Nov 2024

    A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

    Published: 8 Nov 2023
    6.7
    Medium

    CVE-2023-43581

    Last Modified: 21 Nov 2024

    A buffer overflow was reported in the Update_WMI module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

    Published: 8 Nov 2023
    6.7
    Medium

    CVE-2023-43580

    Last Modified: 21 Nov 2024

    A buffer overflow was reported in the SmuV11DxeVMR module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

    Published: 8 Nov 2023
    6.7
    Medium

    CVE-2023-43579

    Last Modified: 21 Nov 2024

    A buffer overflow was reported in the SmuV11Dxe driver in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

    Published: 8 Nov 2023
    6.7
    Medium

    CVE-2023-43578

    Last Modified: 21 Nov 2024

    A buffer overflow was reported in the SmiFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

    Published: 8 Nov 2023
    6.7
    Medium

    CVE-2023-43571

    Last Modified: 21 Nov 2024

    A buffer overflow was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

    Published: 8 Nov 2023