CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2023-32836

    Last Modified: 25 Apr 2025

    In display, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08126725; Issue ID: ALPS08126725.

    Published: 6 Nov 2023
    6.7
    Medium

    CVE-2023-32835

    Last Modified: 24 Apr 2025

    In keyinstall, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08157918; Issue ID: ALPS08157918.

    Published: 6 Nov 2023
    6.7
    Medium

    CVE-2023-32834

    Last Modified: 29 Apr 2025

    In secmem, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08161762; Issue ID: ALPS08161762.

    Published: 6 Nov 2023
    6.7
    Medium

    CVE-2023-32818

    Last Modified: 21 Nov 2024

    In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08163896 & ALPS08013430; Issue ID: ALPS07867715.

    Published: 6 Nov 2023
    7
    High

    CVE-2023-32832

    Last Modified: 25 Apr 2025

    In video, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08235273; Issue ID: ALPS08235273.

    Published: 6 Nov 2023
    5.5
    Medium

    CVE-2023-46802

    Last Modified: 21 Nov 2024

    e-Tax software Version3.0.10 and earlier improperly restricts XML external entity references (XXE) due to the configuration of the embedded XML parser. By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.

    Published: 6 Nov 2023
    5.5
    Medium

    CVE-2018-25093

    Last Modified: 21 Nov 2024

    A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Tag Handler. The manipulation leads to improper access controls. Upgrading to version 2.10.3 is able to address this issue. The name of the patch is cc12e0be82a5d05d9f359ed8e56088f4f8b8eb69. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-244484.

    Published: 6 Nov 2023
    4.3
    Medium

    CVE-2023-6121

    Last Modified: 12 May 2026

    An out-of-bounds read vulnerability was found in the NVMe-oF/TCP subsystem in the Linux kernel. This issue may allow a remote attacker to send a crafted TCP packet, triggering a heap-based buffer overflow that results in kmalloc data being printed and potentially leaked to the kernel ring buffer (dmesg).

    Published: 6 Nov 2023
    7.2
    High

    CVE-2022-48192

    Last Modified: 21 Nov 2024

    Cross-site Scripting vulnerability in Softing smartLink SW-HT before 1.30, which allows an attacker to execute a dynamic script (JavaScript, VBScript) in the context of the application.

    Published: 6 Nov 2023
    5.9
    Medium

    CVE-2022-48193

    Last Modified: 21 Nov 2024

    Weak ciphers in Softing smartLink SW-HT before 1.30 are enabled during secure communication (SSL).

    Published: 6 Nov 2023
    5.4
    Medium

    CVE-2023-45556

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in Mybb Mybb Forums v.1.8.33 allows a local attacker to execute arbitrary code via the theme Name parameter in the theme management component.

    Published: 6 Nov 2023
    8.8
    High

    CVE-2023-44398

    Last Modified: 26 Feb 2025

    Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, `BmffImage::brotliUncompress`, is new in v0.28.0, so earlier versions of Exiv2 are _not_ affected. The out-of-bounds write is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to gain code execution, if they can trick the victim into running Exiv2 on a crafted image file. This bug is fixed in version v0.28.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 6 Nov 2023
    8.8
    High

    CVE-2023-47004

    Last Modified: 29 Apr 2025

    Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code via the code logic after valid authentication.

    Published: 6 Nov 2023
    9.8
    Critical

    CVE-2023-47253

    Last Modified: 7 Jul 2025

    Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValoresPopHidden parameter.

    Published: 6 Nov 2023
    —
    Unknown

    CVE-2023-47357

    Last Modified: 23 Apr 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 6 Nov 2023
    5.5
    Medium

    CVE-2018-25092

    Last Modified: 21 Nov 2024

    A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Command Mention Handler. The manipulation leads to improper access controls. Upgrading to version 2.10.3 is able to address this issue. The patch is named cc12e0be82a5d05d9f359ed8e56088f4f8b8eb69. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-244483.

    Published: 5 Nov 2023
    3.5
    Low

    CVE-2017-20187

    Last Modified: 21 Nov 2024

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as problematic. Affected is the function formatEmailString of the file src/Magnesium/Message/Base.php. The manipulation of the argument email/name leads to injection. Upgrading to version 0.3.1 is able to address this issue. The patch is identified as 500d340e1f6421007413cc08a8383475221c2604. It is recommended to upgrade the affected component. VDB-244482 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 5 Nov 2023
    6.1
    Medium

    CVE-2023-47258

    Last Modified: 21 Nov 2024

    Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter.

    Published: 5 Nov 2023
    6.1
    Medium

    CVE-2023-47259

    Last Modified: 21 Nov 2024

    Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in the Textile formatter.

    Published: 5 Nov 2023
    6.1
    Medium

    CVE-2023-47260

    Last Modified: 21 Nov 2024

    Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails.

    Published: 5 Nov 2023
    5.3
    Medium

    CVE-2023-47271

    Last Modified: 26 Nov 2024

    PKP-WAL (aka PKP Web Application Library or pkp-lib) before 3.3.0-16, as used in Open Journal Systems (OJS) and other products, does not verify that the file named in an XML document (used for the native import/export plugin) is an image file, before trying to use it for an issue cover image.

    Published: 5 Nov 2023
    6.1
    Medium

    CVE-2023-47272

    Last Modified: 21 Nov 2024

    Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).

    Published: 5 Nov 2023
    9.8
    Critical

    CVE-2023-40922

    Last Modified: 21 Nov 2024

    kerawen before v2.5.1 was discovered to contain a SQL injection vulnerability via the ocs_id_cart parameter at KerawenDeliveryModuleFrontController::initContent().

    Published: 4 Nov 2023
    7.5
    High

    CVE-2023-46382

    Last Modified: 4 Nov 2025

    LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) use cleartext HTTP for login.

    Published: 4 Nov 2023
    5.3
    Medium

    CVE-2023-46963

    Last Modified: 21 Nov 2024

    An issue in Beijing Yunfan Internet Technology Co., Ltd, Yunfan Learning Examination System v.6.5 allows a remote attacker to obtain sensitive information via the password parameter in the login function.

    Published: 4 Nov 2023
    6.1
    Medium

    CVE-2023-46964

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Hillstone Next Generation FireWall SG-6000-e3960 v.5.5 allows a remote attacker to execute arbitrary code via the use front-end filtering instead of back-end filtering.

    Published: 4 Nov 2023
    9.8
    Critical

    CVE-2023-46981

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Novel-Plus v.4.2.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /common/log/list.

    Published: 4 Nov 2023
    6.5
    Medium

    CVE-2023-47249

    Last Modified: 21 Nov 2024

    In International Color Consortium DemoIccMAX 79ecb74, a CIccXmlArrayType:::ParseText function (for unsigned short) in IccUtilXml.cpp in libIccXML.a has an out-of-bounds read.

    Published: 4 Nov 2023
    7.5
    High

    CVE-2023-46380

    Last Modified: 4 Nov 2025

    LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) send password-change requests via cleartext HTTP.

    Published: 4 Nov 2023
    8.2
    High

    CVE-2023-46381

    Last Modified: 4 Nov 2025

    LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) lack authentication for the preinstalled version of LWEB-802 via an lweb802_pre/ URI. An unauthenticated attacker can edit any project (or create a new project) and control its GUI.

    Published: 4 Nov 2023
    7.6
    High

    CVE-2023-40215

    Last Modified: 29 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Demonisblack demon image annotation allows SQL Injection.This issue affects demon image annotation: from n/a through 5.1.

    Published: 3 Nov 2023
    8.5
    High

    CVE-2023-35910

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nucleus_genius Quasar form free – Contact Form Builder for WordPress allows SQL Injection.This issue affects Quasar form free – Contact Form Builder for WordPress: from n/a through 6.0.

    Published: 3 Nov 2023
    6.7
    Medium

    CVE-2023-38391

    Last Modified: 29 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themesgrove Onepage Builder allows SQL Injection.This issue affects Onepage Builder: from n/a through 2.4.1.

    Published: 3 Nov 2023
    7.6
    High

    CVE-2023-32741

    Last Modified: 29 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in IT Path Solutions PVT LTD Contact Form to Any API allows SQL Injection.This issue affects Contact Form to Any API: from n/a through 1.1.2.

    Published: 3 Nov 2023
    8.3
    High

    CVE-2023-36677

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager allows SQL Injection.This issue affects SP Project & Document Manager: from n/a through 4.67.

    Published: 3 Nov 2023
    6.5
    Medium

    CVE-2023-45189

    Last Modified: 21 Nov 2024

    A vulnerability in IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.10, 23.0.0 through 23.0.10 may result in access to client vault credentials. This difficult to exploit vulnerability could allow a low privileged attacker to programmatically access client vault credentials. IBM X-Force ID: 268752.

    Published: 3 Nov 2023
    7.8
    High

    CVE-2023-41726

    Last Modified: 21 Nov 2024

    Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability

    Published: 3 Nov 2023
    7.8
    High

    CVE-2023-41725

    Last Modified: 21 Nov 2024

    Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability

    Published: 3 Nov 2023
    7.8
    High

    CVE-2022-43554

    Last Modified: 21 Nov 2024

    Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability

    Published: 3 Nov 2023
    7.8
    High

    CVE-2022-43555

    Last Modified: 21 Nov 2024

    Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability

    Published: 3 Nov 2023
    7.8
    High

    CVE-2022-44569

    Last Modified: 21 Nov 2024

    A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.

    Published: 3 Nov 2023
    9.9
    Critical

    CVE-2023-36529

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme allows SQL Injection.This issue affects Houzez - Real Estate WordPress Theme: from n/a through 1.3.4.

    Published: 3 Nov 2023
    7.6
    High

    CVE-2023-34179

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Groundhogg Inc. Groundhogg allows SQL Injection.This issue affects Groundhogg: from n/a through 2.7.11.

    Published: 3 Nov 2023
    8.2
    High

    CVE-2023-25700

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.1.10.

    Published: 3 Nov 2023
    4.3
    Medium

    CVE-2023-39301

    Last Modified: 21 Nov 2024

    A server-side request forgery (SSRF) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to read application data via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2514 build 20230906 and later QTS 5.1.1.2491 build 20230815 and later QuTS hero h5.0.1.2515 build 20230907 and later QuTS hero h5.1.1.2488 build 20230812 and later QuTScloud c5.1.0.2498 and later

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-39299

    Last Modified: 21 Nov 2024

    A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: Music Station 4.8.11 and later Music Station 5.1.16 and later Music Station 5.3.23 and later

    Published: 3 Nov 2023
    9
    Critical

    CVE-2023-23369

    Last Modified: 27 Feb 2025

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: Multimedia Console 2.1.2 ( 2023/05/04 ) and later Multimedia Console 1.4.8 ( 2023/05/05 ) and later QTS 5.1.0.2399 build 20230515 and later QTS 4.3.6.2441 build 20230621 and later QTS 4.3.4.2451 build 20230621 and later QTS 4.3.3.2420 build 20230621 and later QTS 4.2.6 build 20230621 and later Media Streaming add-on 500.1.1.2 ( 2023/06/12 ) and later Media Streaming add-on 500.0.0.11 ( 2023/06/16 ) and later

    Published: 3 Nov 2023
    9.8
    Critical

    CVE-2023-23368

    Last Modified: 27 Feb 2025

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build 20230421 and later QTS 4.5.4.2374 build 20230416 and later QuTS hero h5.0.1.2376 build 20230421 and later QuTS hero h4.5.4.2374 build 20230417 and later QuTScloud c5.0.1.2374 and later

    Published: 3 Nov 2023
    8.1
    High

    CVE-2023-25800

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.2.0.

    Published: 3 Nov 2023
    7.1
    High

    CVE-2023-25990

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.1.10.

    Published: 3 Nov 2023