CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2023-46845

    Last Modified: 21 Nov 2024

    EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an arbitrary code execution vulnerability due to improper settings of the template engine Twig included in the product. As a result, arbitrary code may be executed on the server where the product is running by a user with an administrative privilege.

    Published: 7 Nov 2023
    6.4
    Medium

    CVE-2023-5076

    Last Modified: 8 Apr 2026

    The Ziteboard Online Whiteboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ziteboard' shortcode in versions up to, and including, 2.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Nov 2023
    4.3
    Medium

    CVE-2023-38548

    Last Modified: 6 Mar 2025

    A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service.

    Published: 7 Nov 2023
    5.4
    Medium

    CVE-2023-38549

    Last Modified: 21 Nov 2024

    A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service. Note: The criticality of this vulnerability is reduced as it requires interaction by a user with the Veeam ONE Administrator role.

    Published: 7 Nov 2023
    9.8
    Critical

    CVE-2023-38547

    Last Modified: 6 Mar 2025

    A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead to remote code execution on the SQL server hosting the Veeam ONE configuration database.

    Published: 7 Nov 2023
    4.3
    Medium

    CVE-2023-41723

    Last Modified: 21 Nov 2024

    A vulnerability in Veeam ONE allows a user with the Veeam ONE Read-Only User role to view the Dashboard Schedule. Note: The criticality of this vulnerability is reduced because the user with the Read-Only role is only able to view the schedule and cannot make changes.

    Published: 7 Nov 2023
    3.5
    Low

    CVE-2019-25156

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic was found in dstar2018 Agency up to 61. Affected by this vulnerability is an unknown functionality of the file search.php. The manipulation of the argument QSType/QuickSearch leads to cross site scripting. The attack can be launched remotely. The patch is named 975b56953efabb434519d9feefcc53685fb8d0ab. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-244495.

    Published: 7 Nov 2023
    8.4
    High

    CVE-2023-33074

    Last Modified: 16 Dec 2025

    Memory corruption in Audio when SSR event is triggered after music playback is stopped.

    Published: 7 Nov 2023
    7.5
    High

    CVE-2023-33061

    Last Modified: 21 Nov 2024

    Transient DOS in WLAN Firmware while parsing WLAN beacon or probe-response frame.

    Published: 7 Nov 2023
    7.8
    High

    CVE-2023-33059

    Last Modified: 16 Dec 2025

    Memory corruption in Audio while processing the VOC packet data from ADSP.

    Published: 7 Nov 2023
    7.5
    High

    CVE-2023-33056

    Last Modified: 21 Nov 2024

    Transient DOS in WLAN Firmware when firmware receives beacon including T2LM IE.

    Published: 7 Nov 2023
    7.8
    High

    CVE-2023-33055

    Last Modified: 16 Dec 2025

    Memory Corruption in Audio while invoking callback function in driver from ADSP.

    Published: 7 Nov 2023
    7.5
    High

    CVE-2023-33048

    Last Modified: 21 Nov 2024

    Transient DOS in WLAN Firmware while parsing t2lm buffers.

    Published: 7 Nov 2023
    7.5
    High

    CVE-2023-33047

    Last Modified: 11 Aug 2025

    Transient DOS in WLAN Firmware while parsing no-inherit IES.

    Published: 7 Nov 2023
    9.8
    Critical

    CVE-2023-33045

    Last Modified: 21 Nov 2024

    Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.

    Published: 7 Nov 2023
    7.8
    High

    CVE-2023-33031

    Last Modified: 16 Dec 2025

    Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer.

    Published: 7 Nov 2023
    9
    Critical

    CVE-2023-28574

    Last Modified: 21 Nov 2024

    Memory corruption in core services when Diag handler receives a command to configure event listeners.

    Published: 7 Nov 2023
    6.6
    Medium

    CVE-2023-28572

    Last Modified: 21 Nov 2024

    Memory corruption in WLAN HOST while processing the WLAN scan descriptor list.

    Published: 7 Nov 2023
    6.7
    Medium

    CVE-2023-28570

    Last Modified: 11 Aug 2025

    Memory corruption while processing audio effects.

    Published: 7 Nov 2023
    6.1
    Medium

    CVE-2023-28569

    Last Modified: 11 Aug 2025

    Information disclosure in WLAN HAL while handling command through WMI interfaces.

    Published: 7 Nov 2023
    6.1
    Medium

    CVE-2023-28568

    Last Modified: 21 Nov 2024

    Information disclosure in WLAN HAL when reception status handler is called.

    Published: 7 Nov 2023
    6.1
    Medium

    CVE-2023-28566

    Last Modified: 11 Aug 2025

    Information disclosure in WLAN HAL while handling the WMI state info command.

    Published: 7 Nov 2023
    6.1
    Medium

    CVE-2023-28563

    Last Modified: 11 Aug 2025

    Information disclosure in IOE Firmware while handling WMI command.

    Published: 7 Nov 2023
    7.1
    High

    CVE-2023-28556

    Last Modified: 11 Aug 2025

    Cryptographic issue in HLOS during key management.

    Published: 7 Nov 2023
    6.1
    Medium

    CVE-2023-28554

    Last Modified: 11 Aug 2025

    Information Disclosure in Qualcomm IPC while reading values from shared memory in VM.

    Published: 7 Nov 2023
    6.1
    Medium

    CVE-2023-28553

    Last Modified: 21 Nov 2024

    Information Disclosure in WLAN Host when processing WMI event command.

    Published: 7 Nov 2023
    8.2
    High

    CVE-2023-28545

    Last Modified: 11 Aug 2025

    Memory corruption in TZ Secure OS while loading an app ELF.

    Published: 7 Nov 2023
    8.4
    High

    CVE-2023-24852

    Last Modified: 11 Aug 2025

    Memory Corruption in Core due to secure memory access by user while loading modem image.

    Published: 7 Nov 2023
    9.8
    Critical

    CVE-2023-22388

    Last Modified: 16 Dec 2025

    Memory Corruption in Multi-mode Call Processor while processing bit mask API.

    Published: 7 Nov 2023
    9.3
    Critical

    CVE-2023-21671

    Last Modified: 11 Aug 2025

    Memory Corruption in Core during syscall for Sectools Fuse comparison feature.

    Published: 7 Nov 2023
    5.5
    Medium

    CVE-2023-35140

    Last Modified: 21 Nov 2024

    The improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an authenticated local user with read-only access to modify system settings on a vulnerable device.

    Published: 7 Nov 2023
    —
    Unknown

    CVE-2023-5977

    Last Modified: 14 Nov 2023

    Accidental Request.

    Published: 7 Nov 2023
    4.3
    Medium

    CVE-2023-5976

    Last Modified: 21 Nov 2024

    Improper Access Control in GitHub repository microweber/microweber prior to 2.0.

    Published: 7 Nov 2023
    9.1
    Critical

    CVE-2023-47455

    Last Modified: 21 Nov 2024

    Tenda AX1806 V1.0.0.1 contains a heap overflow vulnerability in setSchedWifi function, in which the src and v12 are directly obtained from http request parameter schedStartTime and schedEndTime without checking their size.

    Published: 7 Nov 2023
    3.1
    Low

    CVE-2023-46737

    Last Modified: 21 Nov 2024

    Cosign is a sigstore signing tool for OCI containers. Cosign is susceptible to a denial of service by an attacker controlled registry. An attacker who controls a remote registry can return a high number of attestations and/or signatures to Cosign and cause Cosign to enter a long loop resulting in an endless data attack. The root cause is that Cosign loops through all attestations fetched from the remote registry in pkg/cosign.FetchAttestations. The attacker needs to compromise the registry or make a request to a registry they control. When doing so, the attacker must return a high number of attestations in the response to Cosign. The result will be that the attacker can cause Cosign to go into a long or infinite loop that will prevent other users from verifying their data. In Kyvernos case, an attacker whose privileges are limited to making requests to the cluster can make a request with an image reference to their own registry, trigger the infinite loop and deny other users from completing their admission requests. Alternatively, the attacker can obtain control of the registry used by an organization and return a high number of attestations instead the expected number of attestations. The issue can be mitigated rather simply by setting a limit to the limit of attestations that Cosign will loop through. The limit does not need to be high to be within the vast majority of use cases and still prevent the endless data attack. This issue has been patched in version 2.2.1 and users are advised to upgrade.

    Published: 7 Nov 2023
    8.8
    High

    CVE-2023-33480

    Last Modified: 21 Nov 2024

    RemoteClinic 2.0 contains a critical vulnerability chain that can be exploited by a remote attacker with low-privileged user credentials to create admin users, escalate privileges, and execute arbitrary code on the target system via a PHP shell. The vulnerabilities are caused by a lack of input validation and access control in the staff/register.php endpoint and the edit-my-profile.php page. By sending a series of specially crafted requests to the RemoteClinic application, an attacker can create admin users with more privileges than their own, upload a PHP file containing arbitrary code, and execute arbitrary commands via the PHP shell.

    Published: 7 Nov 2023
    9.8
    Critical

    CVE-2023-33481

    Last Modified: 21 Nov 2024

    RemoteClinic 2.0 is vulnerable to a time-based blind SQL injection attack in the 'start' GET parameter of patients/index.php.

    Published: 7 Nov 2023
    7.5
    High

    CVE-2021-43419

    Last Modified: 21 Nov 2024

    An Information Disclosure vulnerability exists in Opay Mobile application 1.5.1.26 and maybe be higher in the logcat app.

    Published: 7 Nov 2023
    9.8
    Critical

    CVE-2023-47359

    Last Modified: 28 May 2026

    Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption.

    Published: 7 Nov 2023
    7.5
    High

    CVE-2023-47360

    Last Modified: 3 Jun 2025

    Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length.

    Published: 7 Nov 2023
    6.1
    Medium

    CVE-2023-41425

    Last Modified: 24 Apr 2025

    Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.

    Published: 7 Nov 2023
    9.8
    Critical

    CVE-2023-42283

    Last Modified: 21 Nov 2024

    Blind SQL injection in api_id parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.

    Published: 7 Nov 2023
    9.8
    Critical

    CVE-2023-42284

    Last Modified: 21 Nov 2024

    Blind SQL injection in api_version parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.

    Published: 7 Nov 2023
    7.8
    High

    CVE-2023-42361

    Last Modified: 21 Nov 2024

    Local File Inclusion vulnerability in Midori-global Better PDF Exporter for Jira Server and Jira Data Center v.10.3.0 and before allows an attacker to view arbitrary files and cause other impacts via use of crafted image during PDF export.

    Published: 7 Nov 2023
    8.1
    High

    CVE-2023-43885

    Last Modified: 21 Nov 2024

    Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attackers to arbitrarily lock the device.

    Published: 7 Nov 2023
    7.1
    High

    CVE-2023-43886

    Last Modified: 21 Nov 2024

    A buffer overflow in the HTTP server component of Tenda RX9 Pro v22.03.02.20 might allow an authenticated attacker to overwrite memory.

    Published: 7 Nov 2023
    7.5
    High

    CVE-2023-43984

    Last Modified: 21 Nov 2024

    Insecure permissions in Smart Soft advancedexport before v4.4.7 allow unauthenticated attackers to arbitrarily download user information from the ps_customer table.

    Published: 7 Nov 2023
    8.8
    High

    CVE-2023-45380

    Last Modified: 21 Nov 2024

    In the module "Order Duplicator " Clone and Delete Existing Order" (orderduplicate) in version <= 1.1.7 from Silbersaiten for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can download personal information from ps_customer/ps_address tables such as name / surname / phone number / full postal address.

    Published: 7 Nov 2023
    5.5
    Medium

    CVE-2023-46001

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in gpac MP4Box v.2.3-DEV-rev573-g201320819-master allows a local attacker to cause a denial of service via the gpac/src/isomedia/isom_read.c:2807:51 function in gf_isom_get_user_data.

    Published: 7 Nov 2023
    9.1
    Critical

    CVE-2023-46501

    Last Modified: 21 Nov 2024

    An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin password function.

    Published: 7 Nov 2023