CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2023-36620

    Last Modified: 21 Nov 2024

    An issue was discovered in the Boomerang Parental Control application before 13.83 for Android. The app is missing the android:allowBackup="false" attribute in the manifest. This allows the user to backup the internal memory of the app to a PC. This gives the user access to the API token that is used to authenticate requests to the API.

    Published: 3 Nov 2023
    9.1
    Critical

    CVE-2023-36621

    Last Modified: 21 Nov 2024

    An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictions temporarily or uninstall the application without the parents noticing.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2017-7252

    Last Modified: 21 Nov 2024

    bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-52356

    Last Modified: 10 Jun 2026

    A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-41259

    Last Modified: 4 Nov 2025

    Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-47234

    Last Modified: 4 Nov 2025

    An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes).

    Published: 3 Nov 2023
    7.8
    High

    CVE-2023-31102

    Last Modified: 21 Nov 2024

    Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.

    Published: 3 Nov 2023
    4.9
    Medium

    CVE-2023-34259

    Last Modified: 21 Nov 2024

    Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal to read arbitrary files on the filesystem, even files that require root privileges. NOTE: this issue exists because of an incomplete fix for CVE-2020-23575.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-34260

    Last Modified: 21 Nov 2024

    Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow a denial of service (service outage) via /wlmdeu%2f%2e%2e%2f%2e%2e followed by a directory reference such as %2fetc%00index.htm to try to read the /etc directory.

    Published: 3 Nov 2023
    5.3
    Medium

    CVE-2023-34261

    Last Modified: 21 Nov 2024

    Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow identification of valid user accounts via username enumeration because they lead to a "nicht einloggen" error rather than a falsch error.

    Published: 3 Nov 2023
    9.8
    Critical

    CVE-2023-38965

    Last Modified: 11 Nov 2025

    Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.

    Published: 3 Nov 2023
    5.9
    Medium

    CVE-2023-4043

    Last Modified: 21 Nov 2024

    In Eclipse Parsson before versions 1.1.4 and 1.0.5, Parsing JSON from untrusted sources can lead malicious actors to exploit the fact that the built-in support for parsing numbers with large scale in Java has a number of edge cases where the input text of a number can lead to much larger processing time than one would expect. To mitigate the risk, parsson put in place a size limit for the numbers as well as their scale.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-41260

    Last Modified: 4 Nov 2025

    Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls.

    Published: 3 Nov 2023
    7
    High

    CVE-2023-41914

    Last Modified: 21 Nov 2024

    SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesystem race conditions for gaining ownership of a file, overwriting a file, or deleting files.

    Published: 3 Nov 2023
    9.8
    Critical

    CVE-2023-43982

    Last Modified: 21 Nov 2024

    Bon Presta boninstagramcarousel between v5.2.1 to v7.0.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at insta_parser.php. This vulnerability allows attackers to use the vulnerable website as proxy to attack other websites or exfiltrate data via a HTTP call.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-45024

    Last Modified: 21 Nov 2024

    Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.

    Published: 3 Nov 2023
    9.9
    Critical

    CVE-2023-46404

    Last Modified: 21 Nov 2024

    PCRS <= 3.11 (d0de1e) “Questions” page and “Code editor” page are vulnerable to remote code execution (RCE) by escaping Python sandboxing.

    Published: 3 Nov 2023
    9.8
    Critical

    CVE-2023-46817

    Last Modified: 21 Nov 2024

    An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote, unauthenticated attackers to inject arbitrary PHP objects into the application scope, allowing them to perform a variety of attacks, such as executing arbitrary PHP code.

    Published: 3 Nov 2023
    8.8
    High

    CVE-2023-46947

    Last Modified: 21 Nov 2024

    Subrion 4.2.1 has a remote command execution vulnerability in the backend.

    Published: 3 Nov 2023
    9.8
    Critical

    CVE-2023-46954

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in Relativity ODA LLC RelativityOne v.12.1.537.3 Patch 2 and earlier allows a remote attacker to execute arbitrary code via the name parameter.

    Published: 3 Nov 2023
    9.8
    Critical

    CVE-2023-46980

    Last Modified: 21 Nov 2024

    An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the userID parameter.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-47235

    Last Modified: 4 Nov 2025

    An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is processed, because the presence of EOR does not lead to a treat-as-withdraw outcome.

    Published: 3 Nov 2023
    5.9
    Medium

    CVE-2023-43018

    Last Modified: 21 Nov 2024

    IBM CICS TX Standard 11.1 and Advanced 10.1, 11.1 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 266163.

    Published: 2 Nov 2023
    4.8
    Medium

    CVE-2023-42029

    Last Modified: 21 Nov 2024

    IBM CICS TX Standard 11.1, Advanced 10.1, 11.1, and TXSeries for Multiplatforms 8.1, 8.2, 9.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 266059.

    Published: 2 Nov 2023
    4.3
    Medium

    CVE-2023-42027

    Last Modified: 21 Nov 2024

    IBM CICS TX Standard 11.1, Advanced 10.1, 11.1, and TXSeries for Multiplatforms 8.1, 8.2, 9.1 are vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 266057.

    Published: 2 Nov 2023
    3.5
    Low

    CVE-2023-5930

    Last Modified: 27 Feb 2025

    A vulnerability was found in Campcodes Simple Student Information System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/students/manage_academic.php. The manipulation of the argument student_id leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-244330 is the identifier assigned to this vulnerability.

    Published: 2 Nov 2023
    5.5
    Medium

    CVE-2023-5929

    Last Modified: 27 Feb 2025

    A vulnerability was found in Campcodes Simple Student Information System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/students/manage_academic.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-244329 was assigned to this vulnerability.

    Published: 2 Nov 2023
    5.5
    Medium

    CVE-2023-5928

    Last Modified: 27 Feb 2025

    A vulnerability was found in Campcodes Simple Student Information System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/departments/manage_department.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-244328.

    Published: 2 Nov 2023
    5.5
    Medium

    CVE-2023-5927

    Last Modified: 27 Feb 2025

    A vulnerability has been found in Campcodes Simple Student Information System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/courses/manage_course.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-244327.

    Published: 2 Nov 2023
    5.5
    Medium

    CVE-2023-5926

    Last Modified: 27 Feb 2025

    A vulnerability, which was classified as critical, was found in Campcodes Simple Student Information System 1.0. Affected is an unknown function of the file /admin/students/update_status.php. The manipulation of the argument student_id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-244326 is the identifier assigned to this vulnerability.

    Published: 2 Nov 2023
    5.5
    Medium

    CVE-2023-5925

    Last Modified: 27 Feb 2025

    A vulnerability, which was classified as critical, has been found in Campcodes Simple Student Information System 1.0. This issue affects some unknown processing of the file /classes/Master.php. The manipulation of the argument f leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-244325 was assigned to this vulnerability.

    Published: 2 Nov 2023
    8.2
    High

    CVE-2023-31027

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability that allows Windows users with low levels of privilege to escalate privileges when an administrator is updating GPU drivers, which may lead to escalation of privileges.

    Published: 2 Nov 2023
    6
    Medium

    CVE-2023-31026

    Last Modified: 21 Nov 2024

    NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a NULL-pointer dereference may lead to denial of service.

    Published: 2 Nov 2023
    5.5
    Medium

    CVE-2023-31023

    Last Modified: 21 Nov 2024

    NVIDIA Display Driver for Windows contains a vulnerability where an attacker may cause a pointer dereference of an untrusted value, which may lead to denial of service.

    Published: 2 Nov 2023
    5.5
    Medium

    CVE-2023-31022

    Last Modified: 27 Feb 2025

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a NULL-pointer dereference may lead to denial of service.

    Published: 2 Nov 2023
    5.5
    Medium

    CVE-2023-31021

    Last Modified: 21 Nov 2024

    NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a malicious user in the guest VM can cause a NULL-pointer dereference, which may lead to denial of service.

    Published: 2 Nov 2023
    6.1
    Medium

    CVE-2023-31020

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause improper access control, which may lead to denial of service or data tampering.

    Published: 2 Nov 2023
    7.8
    High

    CVE-2023-31019

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation does not restrict or incorrectly restricts access from the named pipe server to a connecting client, which may lead to potential impersonation to the client's secure context.

    Published: 2 Nov 2023
    6.5
    Medium

    CVE-2023-31018

    Last Modified: 27 Feb 2025

    NVIDIA GPU Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a NULL-pointer dereference, which may lead to denial of service.

    Published: 2 Nov 2023
    7.8
    High

    CVE-2023-31017

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may be able to write arbitrary data to privileged locations by using reparse points. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

    Published: 2 Nov 2023
    7.3
    High

    CVE-2023-31016

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability where an uncontrolled search path element may allow an attacker to execute arbitrary code, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

    Published: 2 Nov 2023
    5.5
    Medium

    CVE-2023-5924

    Last Modified: 27 Feb 2025

    A vulnerability classified as critical was found in Campcodes Simple Student Information System 1.0. This vulnerability affects unknown code of the file /admin/courses/view_course.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-244324.

    Published: 2 Nov 2023
    5.5
    Medium

    CVE-2023-5923

    Last Modified: 27 Feb 2025

    A vulnerability classified as critical has been found in Campcodes Simple Student Information System 1.0. This affects an unknown part of the file /admin/index.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-244323.

    Published: 2 Nov 2023
    8.3
    High

    CVE-2023-5846

    Last Modified: 21 Nov 2024

    Franklin Fueling System TS-550 versions prior to 1.9.23.8960 are vulnerable to attackers decoding admin credentials, resulting in unauthenticated access to the device.

    Published: 2 Nov 2023
    3.1
    Low

    CVE-2023-5035

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in PT-G503 Series firmware versions prior to v5.2, where the Secure attribute for sensitive cookies in HTTPS sessions is not set, which could cause the cookie to be transmitted in plaintext over an HTTP session. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and manipulation.

    Published: 2 Nov 2023
    3.1
    Low

    CVE-2023-4217

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and manipulation.

    Published: 2 Nov 2023
    8.1
    High

    CVE-2023-46725

    Last Modified: 21 Nov 2024

    FoodCoopShop is open source software for food coops and local shops. Versions starting with 3.2.0 prior to 3.6.1 are vulnerable to server-side request forgery. In the Network module, a manufacturer account can use the `/api/updateProducts.json` endpoint to make the server send a request to an arbitrary host. This means that the server can be used as a proxy into the internal network where the server is. Furthermore, the checks on a valid image are not adequate, leading to a time of check time of use issue. For example, by using a custom server that returns 200 on HEAD requests, then return a valid image on first GET request and then a 302 redirect to final target on second GET request, the server will copy whatever file is at the redirect destination, making this a full SSRF. Version 3.6.1 fixes this vulnerability.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-45347

    Last Modified: 21 Nov 2024

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_verified' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-45346

    Last Modified: 21 Nov 2024

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_role' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-45345

    Last Modified: 21 Nov 2024

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_deleted' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 2 Nov 2023