CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2023-45024

    Last Modified: 21 Nov 2024

    Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.

    Published: 3 Nov 2023
    9.9
    Critical

    CVE-2023-46404

    Last Modified: 21 Nov 2024

    PCRS <= 3.11 (d0de1e) “Questions” page and “Code editor” page are vulnerable to remote code execution (RCE) by escaping Python sandboxing.

    Published: 3 Nov 2023
    9.8
    Critical

    CVE-2023-46817

    Last Modified: 21 Nov 2024

    An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote, unauthenticated attackers to inject arbitrary PHP objects into the application scope, allowing them to perform a variety of attacks, such as executing arbitrary PHP code.

    Published: 3 Nov 2023
    8.8
    High

    CVE-2023-46947

    Last Modified: 21 Nov 2024

    Subrion 4.2.1 has a remote command execution vulnerability in the backend.

    Published: 3 Nov 2023
    9.8
    Critical

    CVE-2023-46954

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in Relativity ODA LLC RelativityOne v.12.1.537.3 Patch 2 and earlier allows a remote attacker to execute arbitrary code via the name parameter.

    Published: 3 Nov 2023
    9.8
    Critical

    CVE-2023-46980

    Last Modified: 21 Nov 2024

    An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the userID parameter.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-47235

    Last Modified: 4 Nov 2025

    An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is processed, because the presence of EOR does not lead to a treat-as-withdraw outcome.

    Published: 3 Nov 2023
    5.9
    Medium

    CVE-2023-43018

    Last Modified: 21 Nov 2024

    IBM CICS TX Standard 11.1 and Advanced 10.1, 11.1 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 266163.

    Published: 2 Nov 2023
    4.8
    Medium

    CVE-2023-42029

    Last Modified: 21 Nov 2024

    IBM CICS TX Standard 11.1, Advanced 10.1, 11.1, and TXSeries for Multiplatforms 8.1, 8.2, 9.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 266059.

    Published: 2 Nov 2023
    4.3
    Medium

    CVE-2023-42027

    Last Modified: 21 Nov 2024

    IBM CICS TX Standard 11.1, Advanced 10.1, 11.1, and TXSeries for Multiplatforms 8.1, 8.2, 9.1 are vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 266057.

    Published: 2 Nov 2023
    3.5
    Low

    CVE-2023-5930

    Last Modified: 27 Feb 2025

    A vulnerability was found in Campcodes Simple Student Information System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/students/manage_academic.php. The manipulation of the argument student_id leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-244330 is the identifier assigned to this vulnerability.

    Published: 2 Nov 2023
    5.5
    Medium

    CVE-2023-5929

    Last Modified: 27 Feb 2025

    A vulnerability was found in Campcodes Simple Student Information System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/students/manage_academic.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-244329 was assigned to this vulnerability.

    Published: 2 Nov 2023
    5.5
    Medium

    CVE-2023-5928

    Last Modified: 27 Feb 2025

    A vulnerability was found in Campcodes Simple Student Information System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/departments/manage_department.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-244328.

    Published: 2 Nov 2023
    5.5
    Medium

    CVE-2023-5927

    Last Modified: 27 Feb 2025

    A vulnerability has been found in Campcodes Simple Student Information System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/courses/manage_course.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-244327.

    Published: 2 Nov 2023
    5.5
    Medium

    CVE-2023-5926

    Last Modified: 27 Feb 2025

    A vulnerability, which was classified as critical, was found in Campcodes Simple Student Information System 1.0. Affected is an unknown function of the file /admin/students/update_status.php. The manipulation of the argument student_id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-244326 is the identifier assigned to this vulnerability.

    Published: 2 Nov 2023
    5.5
    Medium

    CVE-2023-5925

    Last Modified: 27 Feb 2025

    A vulnerability, which was classified as critical, has been found in Campcodes Simple Student Information System 1.0. This issue affects some unknown processing of the file /classes/Master.php. The manipulation of the argument f leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-244325 was assigned to this vulnerability.

    Published: 2 Nov 2023
    8.2
    High

    CVE-2023-31027

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability that allows Windows users with low levels of privilege to escalate privileges when an administrator is updating GPU drivers, which may lead to escalation of privileges.

    Published: 2 Nov 2023
    6
    Medium

    CVE-2023-31026

    Last Modified: 21 Nov 2024

    NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a NULL-pointer dereference may lead to denial of service.

    Published: 2 Nov 2023
    5.5
    Medium

    CVE-2023-31023

    Last Modified: 21 Nov 2024

    NVIDIA Display Driver for Windows contains a vulnerability where an attacker may cause a pointer dereference of an untrusted value, which may lead to denial of service.

    Published: 2 Nov 2023
    5.5
    Medium

    CVE-2023-31022

    Last Modified: 27 Feb 2025

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a NULL-pointer dereference may lead to denial of service.

    Published: 2 Nov 2023
    5.5
    Medium

    CVE-2023-31021

    Last Modified: 21 Nov 2024

    NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a malicious user in the guest VM can cause a NULL-pointer dereference, which may lead to denial of service.

    Published: 2 Nov 2023
    6.1
    Medium

    CVE-2023-31020

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause improper access control, which may lead to denial of service or data tampering.

    Published: 2 Nov 2023
    7.8
    High

    CVE-2023-31019

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation does not restrict or incorrectly restricts access from the named pipe server to a connecting client, which may lead to potential impersonation to the client's secure context.

    Published: 2 Nov 2023
    6.5
    Medium

    CVE-2023-31018

    Last Modified: 27 Feb 2025

    NVIDIA GPU Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a NULL-pointer dereference, which may lead to denial of service.

    Published: 2 Nov 2023
    7.8
    High

    CVE-2023-31017

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may be able to write arbitrary data to privileged locations by using reparse points. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

    Published: 2 Nov 2023
    7.3
    High

    CVE-2023-31016

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability where an uncontrolled search path element may allow an attacker to execute arbitrary code, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

    Published: 2 Nov 2023
    5.5
    Medium

    CVE-2023-5924

    Last Modified: 27 Feb 2025

    A vulnerability classified as critical was found in Campcodes Simple Student Information System 1.0. This vulnerability affects unknown code of the file /admin/courses/view_course.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-244324.

    Published: 2 Nov 2023
    5.5
    Medium

    CVE-2023-5923

    Last Modified: 27 Feb 2025

    A vulnerability classified as critical has been found in Campcodes Simple Student Information System 1.0. This affects an unknown part of the file /admin/index.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-244323.

    Published: 2 Nov 2023
    8.3
    High

    CVE-2023-5846

    Last Modified: 21 Nov 2024

    Franklin Fueling System TS-550 versions prior to 1.9.23.8960 are vulnerable to attackers decoding admin credentials, resulting in unauthenticated access to the device.

    Published: 2 Nov 2023
    3.1
    Low

    CVE-2023-5035

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in PT-G503 Series firmware versions prior to v5.2, where the Secure attribute for sensitive cookies in HTTPS sessions is not set, which could cause the cookie to be transmitted in plaintext over an HTTP session. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and manipulation.

    Published: 2 Nov 2023
    3.1
    Low

    CVE-2023-4217

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and manipulation.

    Published: 2 Nov 2023
    8.1
    High

    CVE-2023-46725

    Last Modified: 21 Nov 2024

    FoodCoopShop is open source software for food coops and local shops. Versions starting with 3.2.0 prior to 3.6.1 are vulnerable to server-side request forgery. In the Network module, a manufacturer account can use the `/api/updateProducts.json` endpoint to make the server send a request to an arbitrary host. This means that the server can be used as a proxy into the internal network where the server is. Furthermore, the checks on a valid image are not adequate, leading to a time of check time of use issue. For example, by using a custom server that returns 200 on HEAD requests, then return a valid image on first GET request and then a 302 redirect to final target on second GET request, the server will copy whatever file is at the redirect destination, making this a full SSRF. Version 3.6.1 fixes this vulnerability.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-45347

    Last Modified: 21 Nov 2024

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_verified' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-45346

    Last Modified: 21 Nov 2024

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_role' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-45345

    Last Modified: 21 Nov 2024

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_deleted' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-45338

    Last Modified: 21 Nov 2024

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the routers/add-ticket.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-45343

    Last Modified: 21 Nov 2024

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'ticket_id' parameter of the routers/ticket-message.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-45341

    Last Modified: 12 Jun 2025

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_price' parameter of the routers/menu-router.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-45344

    Last Modified: 21 Nov 2024

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_balance' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-45342

    Last Modified: 21 Nov 2024

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'phone' parameter of the routers/register-router.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-45340

    Last Modified: 21 Nov 2024

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'phone' parameter of the routers/details-router.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 2 Nov 2023
    —
    Unknown

    CVE-2023-45339

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Nov 2023
    10
    Critical

    CVE-2023-42802

    Last Modified: 21 Nov 2024

    GLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation allows one to upload malicious PHP files to unwanted directories. Depending on web server configuration and available system libraries, malicious PHP files can then be executed through a web server request. Version 10.0.10 fixes this issue. As a workaround, remove write access on `/ajax` and `/front` files to the web server.

    Published: 2 Nov 2023
    4.7
    Medium

    CVE-2023-5919

    Last Modified: 27 Feb 2025

    A vulnerability was found in SourceCodester Company Website CMS 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /dashboard/createblog of the component Create Blog Page. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-244310 is the identifier assigned to this vulnerability.

    Published: 2 Nov 2023
    —
    Unknown

    CVE-2023-45337

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-45336

    Last Modified: 21 Nov 2024

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'password' parameter of the routers/router.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 2 Nov 2023
    —
    Unknown

    CVE-2023-45335

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-45334

    Last Modified: 21 Nov 2024

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'status' parameter of the routers/edit-orders.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 2 Nov 2023
    —
    Unknown

    CVE-2023-45333

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Nov 2023
    —
    Unknown

    CVE-2023-45332

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Nov 2023