CVE-2023-46845
Last Modified: 21 Nov 2024EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an arbitrary code execution vulnerability due to improper settings of the template engine Twig included in the product. As a result, arbitrary code may be executed on the server where the product is running by a user with an administrative privilege.
CVE-2023-5076
Last Modified: 8 Apr 2026The Ziteboard Online Whiteboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ziteboard' shortcode in versions up to, and including, 2.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2023-38548
Last Modified: 6 Mar 2025A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service.
CVE-2023-38549
Last Modified: 21 Nov 2024A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service. Note: The criticality of this vulnerability is reduced as it requires interaction by a user with the Veeam ONE Administrator role.
CVE-2023-38547
Last Modified: 6 Mar 2025A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead to remote code execution on the SQL server hosting the Veeam ONE configuration database.
CVE-2023-41723
Last Modified: 21 Nov 2024A vulnerability in Veeam ONE allows a user with the Veeam ONE Read-Only User role to view the Dashboard Schedule. Note: The criticality of this vulnerability is reduced because the user with the Read-Only role is only able to view the schedule and cannot make changes.
CVE-2019-25156
Last Modified: 21 Nov 2024A vulnerability classified as problematic was found in dstar2018 Agency up to 61. Affected by this vulnerability is an unknown functionality of the file search.php. The manipulation of the argument QSType/QuickSearch leads to cross site scripting. The attack can be launched remotely. The patch is named 975b56953efabb434519d9feefcc53685fb8d0ab. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-244495.
CVE-2023-33074
Last Modified: 16 Dec 2025Memory corruption in Audio when SSR event is triggered after music playback is stopped.
CVE-2023-33061
Last Modified: 21 Nov 2024Transient DOS in WLAN Firmware while parsing WLAN beacon or probe-response frame.
CVE-2023-33059
Last Modified: 16 Dec 2025Memory corruption in Audio while processing the VOC packet data from ADSP.
CVE-2023-33056
Last Modified: 21 Nov 2024Transient DOS in WLAN Firmware when firmware receives beacon including T2LM IE.
CVE-2023-33055
Last Modified: 16 Dec 2025Memory Corruption in Audio while invoking callback function in driver from ADSP.
CVE-2023-33048
Last Modified: 21 Nov 2024Transient DOS in WLAN Firmware while parsing t2lm buffers.
CVE-2023-33047
Last Modified: 11 Aug 2025Transient DOS in WLAN Firmware while parsing no-inherit IES.
CVE-2023-33045
Last Modified: 21 Nov 2024Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.
CVE-2023-33031
Last Modified: 16 Dec 2025Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer.
CVE-2023-28574
Last Modified: 21 Nov 2024Memory corruption in core services when Diag handler receives a command to configure event listeners.
CVE-2023-28572
Last Modified: 21 Nov 2024Memory corruption in WLAN HOST while processing the WLAN scan descriptor list.
CVE-2023-28570
Last Modified: 11 Aug 2025Memory corruption while processing audio effects.
CVE-2023-28569
Last Modified: 11 Aug 2025Information disclosure in WLAN HAL while handling command through WMI interfaces.
CVE-2023-28568
Last Modified: 21 Nov 2024Information disclosure in WLAN HAL when reception status handler is called.
CVE-2023-28566
Last Modified: 11 Aug 2025Information disclosure in WLAN HAL while handling the WMI state info command.
CVE-2023-28563
Last Modified: 11 Aug 2025Information disclosure in IOE Firmware while handling WMI command.
CVE-2023-28556
Last Modified: 11 Aug 2025Cryptographic issue in HLOS during key management.
CVE-2023-28554
Last Modified: 11 Aug 2025Information Disclosure in Qualcomm IPC while reading values from shared memory in VM.
CVE-2023-28553
Last Modified: 21 Nov 2024Information Disclosure in WLAN Host when processing WMI event command.
CVE-2023-28545
Last Modified: 11 Aug 2025Memory corruption in TZ Secure OS while loading an app ELF.
CVE-2023-24852
Last Modified: 11 Aug 2025Memory Corruption in Core due to secure memory access by user while loading modem image.
CVE-2023-22388
Last Modified: 16 Dec 2025Memory Corruption in Multi-mode Call Processor while processing bit mask API.
CVE-2023-21671
Last Modified: 11 Aug 2025Memory Corruption in Core during syscall for Sectools Fuse comparison feature.
CVE-2023-35140
Last Modified: 21 Nov 2024The improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an authenticated local user with read-only access to modify system settings on a vulnerable device.
CVE-2023-5977
Last Modified: 14 Nov 2023Accidental Request.
CVE-2023-5976
Last Modified: 21 Nov 2024Improper Access Control in GitHub repository microweber/microweber prior to 2.0.
CVE-2023-47455
Last Modified: 21 Nov 2024Tenda AX1806 V1.0.0.1 contains a heap overflow vulnerability in setSchedWifi function, in which the src and v12 are directly obtained from http request parameter schedStartTime and schedEndTime without checking their size.
CVE-2023-46737
Last Modified: 21 Nov 2024Cosign is a sigstore signing tool for OCI containers. Cosign is susceptible to a denial of service by an attacker controlled registry. An attacker who controls a remote registry can return a high number of attestations and/or signatures to Cosign and cause Cosign to enter a long loop resulting in an endless data attack. The root cause is that Cosign loops through all attestations fetched from the remote registry in pkg/cosign.FetchAttestations. The attacker needs to compromise the registry or make a request to a registry they control. When doing so, the attacker must return a high number of attestations in the response to Cosign. The result will be that the attacker can cause Cosign to go into a long or infinite loop that will prevent other users from verifying their data. In Kyvernos case, an attacker whose privileges are limited to making requests to the cluster can make a request with an image reference to their own registry, trigger the infinite loop and deny other users from completing their admission requests. Alternatively, the attacker can obtain control of the registry used by an organization and return a high number of attestations instead the expected number of attestations. The issue can be mitigated rather simply by setting a limit to the limit of attestations that Cosign will loop through. The limit does not need to be high to be within the vast majority of use cases and still prevent the endless data attack. This issue has been patched in version 2.2.1 and users are advised to upgrade.
CVE-2023-33480
Last Modified: 21 Nov 2024RemoteClinic 2.0 contains a critical vulnerability chain that can be exploited by a remote attacker with low-privileged user credentials to create admin users, escalate privileges, and execute arbitrary code on the target system via a PHP shell. The vulnerabilities are caused by a lack of input validation and access control in the staff/register.php endpoint and the edit-my-profile.php page. By sending a series of specially crafted requests to the RemoteClinic application, an attacker can create admin users with more privileges than their own, upload a PHP file containing arbitrary code, and execute arbitrary commands via the PHP shell.
CVE-2023-33481
Last Modified: 21 Nov 2024RemoteClinic 2.0 is vulnerable to a time-based blind SQL injection attack in the 'start' GET parameter of patients/index.php.
CVE-2021-43419
Last Modified: 21 Nov 2024An Information Disclosure vulnerability exists in Opay Mobile application 1.5.1.26 and maybe be higher in the logcat app.
CVE-2023-47359
Last Modified: 28 May 2026Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption.
CVE-2023-47360
Last Modified: 3 Jun 2025Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length.
CVE-2023-41425
Last Modified: 24 Apr 2025Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.
CVE-2023-42283
Last Modified: 21 Nov 2024Blind SQL injection in api_id parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.
CVE-2023-42284
Last Modified: 21 Nov 2024Blind SQL injection in api_version parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.
CVE-2023-42361
Last Modified: 21 Nov 2024Local File Inclusion vulnerability in Midori-global Better PDF Exporter for Jira Server and Jira Data Center v.10.3.0 and before allows an attacker to view arbitrary files and cause other impacts via use of crafted image during PDF export.
CVE-2023-43885
Last Modified: 21 Nov 2024Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attackers to arbitrarily lock the device.
CVE-2023-43886
Last Modified: 21 Nov 2024A buffer overflow in the HTTP server component of Tenda RX9 Pro v22.03.02.20 might allow an authenticated attacker to overwrite memory.
CVE-2023-43984
Last Modified: 21 Nov 2024Insecure permissions in Smart Soft advancedexport before v4.4.7 allow unauthenticated attackers to arbitrarily download user information from the ps_customer table.
CVE-2023-45380
Last Modified: 21 Nov 2024In the module "Order Duplicator " Clone and Delete Existing Order" (orderduplicate) in version <= 1.1.7 from Silbersaiten for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can download personal information from ps_customer/ps_address tables such as name / surname / phone number / full postal address.
CVE-2023-46001
Last Modified: 21 Nov 2024Buffer Overflow vulnerability in gpac MP4Box v.2.3-DEV-rev573-g201320819-master allows a local attacker to cause a denial of service via the gpac/src/isomedia/isom_read.c:2807:51 function in gf_isom_get_user_data.
CVE-2023-46501
Last Modified: 21 Nov 2024An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin password function.
