CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2023-43570

    Last Modified: 21 Nov 2024

    A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacker with elevated permissions to execute arbitrary code.

    Published: 8 Nov 2023
    6.7
    Medium

    CVE-2023-43569

    Last Modified: 21 Nov 2024

    A buffer overflow was reported in the OemSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. 

    Published: 8 Nov 2023
    4.4
    Medium

    CVE-2023-43568

    Last Modified: 21 Nov 2024

    A buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.

    Published: 8 Nov 2023
    6.7
    Medium

    CVE-2023-43567

    Last Modified: 21 Nov 2024

    A buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-5079

    Last Modified: 21 Nov 2024

    Lenovo LeCloud App improper input validation allows attackers to access arbitrary components and arbitrary file downloads, which could result in information disclosure.

    Published: 8 Nov 2023
    6.7
    Medium

    CVE-2023-5078

    Last Modified: 21 Nov 2024

    A vulnerability was reported in some ThinkPad BIOS that could allow a physical or local attacker with elevated privileges to tamper with BIOS firmware.

    Published: 8 Nov 2023
    6.7
    Medium

    CVE-2023-5075

    Last Modified: 21 Nov 2024

    A buffer overflow was reported in the FmpSipoCapsuleDriver driver in the IdeaPad Duet 3-10IGL5 that may allow a local attacker with elevated privileges to execute arbitrary code.

    Published: 8 Nov 2023
    5.5
    Medium

    CVE-2023-4891

    Last Modified: 21 Nov 2024

    A potential use-after-free vulnerability was reported in the Lenovo View driver that could result in denial of service.

    Published: 8 Nov 2023
    7.3
    High

    CVE-2023-4706

    Last Modified: 21 Nov 2024

    A privilege escalation vulnerability was reported in Lenovo preloaded devices deployed using Microsoft AutoPilot under a standard user account due to incorrect default privileges.

    Published: 8 Nov 2023
    7.8
    High

    CVE-2023-4632

    Last Modified: 21 Nov 2024

    An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges.

    Published: 8 Nov 2023
    7.3
    High

    CVE-2023-47113

    Last Modified: 21 Nov 2024

    BleachBit cleans files to free disk space and to maintain privacy. BleachBit for Windows up to version 4.4.2 is vulnerable to a DLL Hijacking vulnerability. By placing a DLL in the Folder c:\DLLs, an attacker can run arbitrary code on every execution of BleachBit for Windows. This issue has been patched in version 4.5.0.

    Published: 8 Nov 2023
    4.3
    Medium

    CVE-2023-47114

    Last Modified: 21 Nov 2024

    Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in your runtime environment, and the enforcement of privacy regulations in your code. The Fides web application allows data subject users to request access to their personal data. If the request is approved by the data controller user operating the Fides web application, the data subject's personal data can then retrieved from connected systems and data stores before being bundled together as a data subject access request package for the data subject to download. Supported data formats for the package include json and csv, but the most commonly used format is a series of HTML files compressed in a ZIP file. Once downloaded and unzipped, the data subject user can browse the HTML files on their local machine. It was identified that there was no validation of input coming from e.g. the connected systems and data stores which is later reflected in the downloaded data. This can result in an HTML injection that can be abused e.g. for phishing attacks or malicious JavaScript code execution, but only in the context of the data subject's browser accessing a HTML page using the `file://` protocol. Exploitation is limited to rogue Admin UI users, malicious connected system / data store users, and the data subject user if tricked via social engineering into submitting malicious data themselves. This vulnerability has been patched in version 2.23.3.

    Published: 8 Nov 2023
    7.3
    High

    CVE-2023-47111

    Last Modified: 21 Nov 2024

    ZITADEL provides identity infrastructure. ZITADEL provides administrators the possibility to define a `Lockout Policy` with a maximum amount of failed password check attempts. On every failed password check, the amount of failed checks is compared against the configured maximum. Exceeding the limit, will lock the user and prevent further authentication. In the affected implementation it was possible for an attacker to start multiple parallel password checks, giving him the possibility to try out more combinations than configured in the `Lockout Policy`. This vulnerability has been patched in versions 2.40.5 and 2.38.3.

    Published: 8 Nov 2023
    5.5
    Medium

    CVE-2023-47109

    Last Modified: 21 Nov 2024

    PrestaShop blockreassurance adds an information block aimed at offering helpful information to reassure customers that the store is trustworthy. When adding a block in blockreassurance module, a BO user can modify the http request and give the path of any file in the project instead of an image. When deleting the block from the BO, the file will be deleted. It is possible to make the website completely unavailable by removing index.php for example. This issue has been patched in version 5.1.4.

    Published: 8 Nov 2023
    6.7
    Medium

    CVE-2023-0392

    Last Modified: 21 Nov 2024

    The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execution.

    Published: 8 Nov 2023
    5
    Medium

    CVE-2023-26221

    Last Modified: 21 Nov 2024

    The Spotfire Connectors component of TIBCO Software Inc.'s Spotfire Analyst, Spotfire Server, and Spotfire for AWS Marketplace contains an easily exploitable vulnerability that allows a low privileged attacker with read/write access to craft malicious Analyst files. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s Spotfire Analyst: versions 12.3.0, 12.4.0, and 12.5.0, Spotfire Server: versions 12.3.0, 12.4.0, and 12.5.0, and Spotfire for AWS Marketplace: version 12.5.0.

    Published: 8 Nov 2023
    8.8
    High

    CVE-2023-5996

    Last Modified: 13 Feb 2025

    Use after free in WebAudio in Google Chrome prior to 119.0.6045.123 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Nov 2023
    6.5
    Medium

    CVE-2023-47231

    Last Modified: 28 Apr 2026

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Bainternet ShortCodes UI plugin <= 1.9.8 versions.

    Published: 8 Nov 2023
    6.5
    Medium

    CVE-2023-47229

    Last Modified: 28 Apr 2026

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Vyas Dipen Top 25 Social Icons plugin <= 3.1 versions.

    Published: 8 Nov 2023
    5.9
    Medium

    CVE-2023-47228

    Last Modified: 28 Apr 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Muneeb Layer Slider plugin <= 1.1.9.7 versions.

    Published: 8 Nov 2023
    5.9
    Medium

    CVE-2023-47227

    Last Modified: 28 Apr 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Web-Settler Social Feed | All social media in one place plugin <= 1.5.4.6 versions.

    Published: 8 Nov 2023
    5.9
    Medium

    CVE-2023-47226

    Last Modified: 28 Apr 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Post Sliders & Post Grids plugin <= 1.0.20 versions.

    Published: 8 Nov 2023
    5.9
    Medium

    CVE-2023-47223

    Last Modified: 28 Apr 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Map Plugins Basic Interactive World Map plugin <= 2.0 versions.

    Published: 8 Nov 2023
    6.5
    Medium

    CVE-2023-47190

    Last Modified: 29 Apr 2026

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Apollo13Themes Apollo13 Framework Extensions plugin <= 1.9.0 versions.

    Published: 8 Nov 2023
    5.9
    Medium

    CVE-2023-47181

    Last Modified: 28 Apr 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Gibson IdeaPush plugin <= 8.52 versions.

    Published: 8 Nov 2023
    6.4
    Medium

    CVE-2023-3282

    Last Modified: 21 Nov 2024

    A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system enables a local attacker to execute programs with elevated privileges if the attacker has shell access to the engine.

    Published: 8 Nov 2023
    8.2
    High

    CVE-2023-5913

    Last Modified: 21 Nov 2024

    Incorrect Privilege Assignment vulnerability in opentext Fortify ScanCentral DAST. The vulnerability could be exploited to gain elevated privileges.This issue affects Fortify ScanCentral DAST versions 21.1, 21.2, 21.2.1, 22.1, 22.1.1, 22.2, 23.1.

    Published: 8 Nov 2023
    8.2
    High

    CVE-2023-5760

    Last Modified: 21 Nov 2024

    A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain full local privilege escalation on the system.This issue affects Avast/Avg Antivirus: 23.8.

    Published: 8 Nov 2023
    7.1
    High

    CVE-2023-46643

    Last Modified: 28 Apr 2026

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GARY JEZORSKI CloudNet360 plugin <= 3.2.0 versions.

    Published: 8 Nov 2023
    5.9
    Medium

    CVE-2023-46642

    Last Modified: 28 Apr 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in sahumedia SAHU TikTok Pixel for E-Commerce plugin <= 1.2.2 versions.

    Published: 8 Nov 2023
    6.5
    Medium

    CVE-2023-46640

    Last Modified: 29 Apr 2026

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in D. Relton Medialist plugin <= 1.3.9 versions.

    Published: 8 Nov 2023
    7.1
    High

    CVE-2023-46627

    Last Modified: 28 Apr 2026

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ashish Ajani WordPress Simple HTML Sitemap plugin <= 2.1 versions.

    Published: 8 Nov 2023
    7.1
    High

    CVE-2023-32298

    Last Modified: 28 Apr 2026

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kathy Darling Simple User Listing plugin <= 1.9.2 versions.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-5759

    Last Modified: 21 Nov 2024

    In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the buffer was identified. Reported by Jason Geffner.  

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-45319

    Last Modified: 21 Nov 2024

    In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the commit function was identified. Reported by Jason Geffner. 

    Published: 8 Nov 2023
    9
    Critical

    CVE-2023-45849

    Last Modified: 21 Nov 2024

    An arbitrary code execution which results in privilege escalation was discovered in Helix Core versions prior to 2023.2. Reported by Jason Geffner.

    Published: 8 Nov 2023
    8.8
    High

    CVE-2023-47107

    Last Modified: 21 Nov 2024

    PILOS is an open source front-end for BigBlueButton servers with a built-in load balancer. The password reset component deployed within PILOS uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to PILOS users when so that it points to the attackers server thereby disclosing the password reset token if/when the link is followed. This only affects local user accounts and requires the password reset option to be enabled. This issue has been patched in version 2.3.0.

    Published: 8 Nov 2023
    7.1
    High

    CVE-2023-46626

    Last Modified: 29 Apr 2026

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FLOWFACT WP Connector plugin <= 2.1.7 versions.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-35767

    Last Modified: 21 Nov 2024

    In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Jason Geffner.  

    Published: 8 Nov 2023
    4.8
    Medium

    CVE-2023-45140

    Last Modified: 21 Nov 2024

    The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. SCP and SFTP plugins don't honor group-based JIT MFA. Establishing a SCP/SFTP connection through The Bastion via a group access where MFA is enforced does not ask for additional factor. This abnormal behavior only applies to per-group-based JIT MFA. Other MFA setup types, such as Immediate MFA, JIT MFA on a per-plugin basis and JIT MFA on a per-account basis are not affected. This issue has been patched in version 3.14.15.

    Published: 8 Nov 2023
    5.5
    Medium

    CVE-2023-5136

    Last Modified: 11 Jun 2025

    An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An attacker could exploit this vulnerability by getting a user to open a specially crafted data file.

    Published: 8 Nov 2023
    —
    Unknown

    CVE-2023-6034

    Last Modified: 14 Nov 2023

    Accidental request.

    Published: 8 Nov 2023
    7.1
    High

    CVE-2023-46621

    Last Modified: 28 Apr 2026

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Enej Bajgoric / Gagan Sandhu / CTLT DEV User Avatar plugin <= 1.4.11 versions.

    Published: 8 Nov 2023
    6.5
    Medium

    CVE-2023-46613

    Last Modified: 28 Apr 2026

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Jens Kuerschner Add to Calendar Button plugin <= 1.5.1 versions.

    Published: 8 Nov 2023
    8.3
    High

    CVE-2023-6012

    Last Modified: 21 Nov 2024

    An improper input validation vulnerability has been found in Lanaccess ONSAFE MonitorHM affecting version 3.7.0. This vulnerability could lead a remote attacker to exploit the checkbox element and perform remote code execution, compromising the entire infrastructure.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-46759

    Last Modified: 21 Nov 2024

    Permission control vulnerability in the call module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-46758

    Last Modified: 21 Nov 2024

    Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-46757

    Last Modified: 21 Nov 2024

    The remote PIN module has a vulnerability that causes incorrect information storage locations.Successful exploitation of this vulnerability may affect confidentiality.

    Published: 8 Nov 2023
    5.3
    Medium

    CVE-2023-46756

    Last Modified: 21 Nov 2024

    Permission control vulnerability in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up windows.

    Published: 8 Nov 2023
    5.3
    Medium

    CVE-2023-46755

    Last Modified: 21 Nov 2024

    Vulnerability of input parameters being not strictly verified in the input. Successful exploitation of this vulnerability may cause the launcher to restart.

    Published: 8 Nov 2023