CVE Feed

    Dashboard / CVE

    8.5
    High

    CVE-2023-34383

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP Project Manager wedevs-project-manager allows SQL Injection.This issue affects WP Project Manager: from n/a through 2.6.0.

    Published: 3 Nov 2023
    8.2
    High

    CVE-2023-41652

    Last Modified: 29 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker rsvpmaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 10.6.6.

    Published: 3 Nov 2023
    6.1
    Medium

    CVE-2023-4592

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting vulnerability has been detected in WPN-XM Serverstack affecting version 0.8.6. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload through the /tools/webinterface/index.php parameter and retrieve the cookie session details of an authenticated user, resulting in a session hijacking.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-4591

    Last Modified: 21 Nov 2024

    A local file inclusion vulnerability has been found in WPN-XM Serverstack affecting version 0.8.6, which would allow an unauthenticated user to perform a local file inclusion (LFI) via the /tools/webinterface/index.php?page parameter by sending a GET request. This vulnerability could lead to the loading of a PHP file on the server, leading to a critical webshell exploit.

    Published: 3 Nov 2023
    6.6
    Medium

    CVE-2023-4769

    Last Modified: 21 Nov 2024

    A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerability could allow an authenticated attacker to launch targeted attacks, such as a cross-port attack, service enumeration and other attacks via HTTP requests.

    Published: 3 Nov 2023
    6.1
    Medium

    CVE-2023-4768

    Last Modified: 21 Nov 2024

    A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.pdf.

    Published: 3 Nov 2023
    6.1
    Medium

    CVE-2023-4767

    Last Modified: 21 Nov 2024

    A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.csv.

    Published: 3 Nov 2023
    6.8
    Medium

    CVE-2023-5763

    Last Modified: 21 Nov 2024

    In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote attackers to load malicious code on the server via access to insecure ORB listeners.

    Published: 3 Nov 2023
    5.5
    Medium

    CVE-2023-5948

    Last Modified: 21 Nov 2024

    Improper Authorization in GitHub repository teamamaze/amazefileutilities prior to 1.91.

    Published: 3 Nov 2023
    6.5
    Medium

    CVE-2023-41356

    Last Modified: 21 Nov 2024

    NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and read arbitrary system files.

    Published: 3 Nov 2023
    8.8
    High

    CVE-2023-41357

    Last Modified: 21 Nov 2024

    Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filtering and validation during file upload. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute scripts onto arbitrary directories to perform arbitrary system operations or disrupt service.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-41344

    Last Modified: 21 Nov 2024

    NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and read arbitrary system files.

    Published: 3 Nov 2023
    9.8
    Critical

    CVE-2023-41355

    Last Modified: 21 Nov 2024

    Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resulting in a denial of service or sensitive information leaking.

    Published: 3 Nov 2023
    4
    Medium

    CVE-2023-41354

    Last Modified: 21 Nov 2024

    Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated remote attacker can exploit this vulnerability by sending a crafted package, resulting in partially sensitive information exposed to an actor.

    Published: 3 Nov 2023
    8.8
    High

    CVE-2023-41353

    Last Modified: 21 Nov 2024

    Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user privilege can easily infer the administrator password from system information after logging system, resulting in admin access and performing arbitrary system operations or disrupt service.

    Published: 3 Nov 2023
    7.2
    High

    CVE-2023-41352

    Last Modified: 21 Nov 2024

    Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient filtering for user input. A remote attacker with administrator privilege can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services.

    Published: 3 Nov 2023
    9.8
    Critical

    CVE-2023-41351

    Last Modified: 21 Nov 2024

    Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log in as any existing users, such as an administrator, to perform arbitrary system operations or disrupt service.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-41350

    Last Modified: 21 Nov 2024

    Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very easy for bots to bypass the captcha check and more susceptible to brute force attacks.

    Published: 3 Nov 2023
    8.8
    High

    CVE-2023-41348

    Last Modified: 21 Nov 2024

    ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its code-authentication module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services.

    Published: 3 Nov 2023
    8.8
    High

    CVE-2023-41347

    Last Modified: 21 Nov 2024

    ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its check token module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services.

    Published: 3 Nov 2023
    8.8
    High

    CVE-2023-41346

    Last Modified: 21 Nov 2024

    ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-refresh module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services.

    Published: 3 Nov 2023
    8.8
    High

    CVE-2023-41345

    Last Modified: 21 Nov 2024

    ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-generated module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system, or terminate services.

    Published: 3 Nov 2023
    5.4
    Medium

    CVE-2023-41343

    Last Modified: 21 Nov 2024

    Rogic No-Code Database Builder's file uploading function has insufficient filtering for special characters. A remote attacker with regular user privilege can inject JavaScript to perform XSS (Stored Cross-Site Scripting) attack.

    Published: 3 Nov 2023
    —
    Unknown

    CVE-2023-46702

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 3 Nov 2023
    —
    Unknown

    CVE-2023-47206

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 3 Nov 2023
    —
    Unknown

    CVE-2023-46710

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 3 Nov 2023
    —
    Unknown

    CVE-2023-42432

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 3 Nov 2023
    5.4
    Medium

    CVE-2023-35896

    Last Modified: 21 Nov 2024

    IBM Content Navigator 3.0.13 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 259247.

    Published: 3 Nov 2023
    —
    Unknown

    CVE-2023-5947

    Last Modified: 27 Feb 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-7247. Reason: This candidate is a duplicate of CVE-2023-7247. Notes: All CVE users should reference CVE-2023-7247 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 3 Nov 2023
    6.6
    Medium

    CVE-2023-36022

    Last Modified: 9 Oct 2025

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

    Published: 3 Nov 2023
    4.3
    Medium

    CVE-2023-36029

    Last Modified: 8 Oct 2025

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

    Published: 3 Nov 2023
    7.3
    High

    CVE-2023-36034

    Last Modified: 8 Oct 2025

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

    Published: 3 Nov 2023
    6.7
    Medium

    CVE-2023-46176

    Last Modified: 21 Nov 2024

    IBM MQ Appliance 9.3 CD could allow a local attacker to gain elevated privileges on the system, caused by improper validation of security keys. IBM X-Force ID: 269535.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-52355

    Last Modified: 2 Oct 2026

    An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

    Published: 3 Nov 2023
    4.3
    Medium

    CVE-2023-47233

    Last Modified: 12 May 2026

    The brcm80211 component in the Linux kernel through 6.5.10 has a brcmf_cfg80211_detach use-after-free in the device unplugging (disconnect the USB by hotplug) code. For physically proximate attackers with local access, this "could be exploited in a real world scenario." This is related to brcmf_cfg80211_escan_timeout_worker in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c.

    Published: 3 Nov 2023
    4.6
    Medium

    CVE-2023-36620

    Last Modified: 21 Nov 2024

    An issue was discovered in the Boomerang Parental Control application before 13.83 for Android. The app is missing the android:allowBackup="false" attribute in the manifest. This allows the user to backup the internal memory of the app to a PC. This gives the user access to the API token that is used to authenticate requests to the API.

    Published: 3 Nov 2023
    9.1
    Critical

    CVE-2023-36621

    Last Modified: 21 Nov 2024

    An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictions temporarily or uninstall the application without the parents noticing.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2017-7252

    Last Modified: 21 Nov 2024

    bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-52356

    Last Modified: 10 Jun 2026

    A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-41259

    Last Modified: 4 Nov 2025

    Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-47234

    Last Modified: 4 Nov 2025

    An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes).

    Published: 3 Nov 2023
    7.8
    High

    CVE-2023-31102

    Last Modified: 21 Nov 2024

    Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.

    Published: 3 Nov 2023
    4.9
    Medium

    CVE-2023-34259

    Last Modified: 21 Nov 2024

    Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal to read arbitrary files on the filesystem, even files that require root privileges. NOTE: this issue exists because of an incomplete fix for CVE-2020-23575.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-34260

    Last Modified: 21 Nov 2024

    Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow a denial of service (service outage) via /wlmdeu%2f%2e%2e%2f%2e%2e followed by a directory reference such as %2fetc%00index.htm to try to read the /etc directory.

    Published: 3 Nov 2023
    5.3
    Medium

    CVE-2023-34261

    Last Modified: 21 Nov 2024

    Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow identification of valid user accounts via username enumeration because they lead to a "nicht einloggen" error rather than a falsch error.

    Published: 3 Nov 2023
    9.8
    Critical

    CVE-2023-38965

    Last Modified: 11 Nov 2025

    Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.

    Published: 3 Nov 2023
    5.9
    Medium

    CVE-2023-4043

    Last Modified: 21 Nov 2024

    In Eclipse Parsson before versions 1.1.4 and 1.0.5, Parsing JSON from untrusted sources can lead malicious actors to exploit the fact that the built-in support for parsing numbers with large scale in Java has a number of edge cases where the input text of a number can lead to much larger processing time than one would expect. To mitigate the risk, parsson put in place a size limit for the numbers as well as their scale.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-41260

    Last Modified: 4 Nov 2025

    Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls.

    Published: 3 Nov 2023
    7
    High

    CVE-2023-41914

    Last Modified: 21 Nov 2024

    SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesystem race conditions for gaining ownership of a file, overwriting a file, or deleting files.

    Published: 3 Nov 2023
    9.8
    Critical

    CVE-2023-43982

    Last Modified: 21 Nov 2024

    Bon Presta boninstagramcarousel between v5.2.1 to v7.0.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at insta_parser.php. This vulnerability allows attackers to use the vulnerable website as proxy to attack other websites or exfiltrate data via a HTTP call.

    Published: 3 Nov 2023