CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2023-45331

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Nov 2023
    —
    Unknown

    CVE-2023-45330

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Nov 2023
    —
    Unknown

    CVE-2023-45329

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Nov 2023
    —
    Unknown

    CVE-2023-45328

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Nov 2023
    —
    Unknown

    CVE-2023-45327

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Nov 2023
    —
    Unknown

    CVE-2023-45326

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-45325

    Last Modified: 21 Nov 2024

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'address' parameter of the routers/add-users.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 2 Nov 2023
    —
    Unknown

    CVE-2023-45324

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-45323

    Last Modified: 21 Nov 2024

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'name' parameter of the routers/add-item.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 2 Nov 2023
    5.3
    Medium

    CVE-2023-29047

    Last Modified: 12 Jun 2025

    Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL statements. An attacker with access to the adjacent network and potentially API credentials, could read and modify database content which is accessible to the imageconverter SQL user account. None No publicly available exploits are known.

    Published: 2 Nov 2023
    4.3
    Medium

    CVE-2023-29046

    Last Modified: 21 Nov 2024

    Connections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout, instead those connections were logged. Some connections use user-controlled endpoints, which could be malicious and attempt to keep the connection open for an extended period of time. As a result users were able to trigger large amount of egress network connections, possibly exhausting network pool resources and lock up legitimate requests. A new mechanism has been introduced to cancel external connections that might access user-controlled endpoints. No publicly available exploits are known.

    Published: 2 Nov 2023
    5.4
    Medium

    CVE-2023-29045

    Last Modified: 21 Nov 2024

    Documents operations, in this case "drawing", could be manipulated to contain invalid data types, possibly script code. Script code could be injected to an operation that would be executed for users that are actively collaborating on the same document. Operation data exchanged between collaborating parties does now gets checked for validity to avoid code execution. No publicly available exploits are known.

    Published: 2 Nov 2023
    5.4
    Medium

    CVE-2023-29044

    Last Modified: 21 Nov 2024

    Documents operations could be manipulated to contain invalid data types, possibly script code. Script code could be injected to an operation that would be executed for users that are actively collaborating on the same document. Operation data exchanged between collaborating parties does now get escaped to avoid code execution. No publicly available exploits are known.

    Published: 2 Nov 2023
    6.1
    Medium

    CVE-2023-29043

    Last Modified: 3 Dec 2024

    Presentations may contain references to images, which are user-controlled, and could include malicious script code that is being processed when editing a document. Script code embedded in malicious documents could be executed in the context of the user editing the document when performing certain actions, like copying content. The relevant attribute does now get encoded to avoid the possibility of executing script code. No publicly available exploits are known.

    Published: 2 Nov 2023
    5.4
    Medium

    CVE-2023-26456

    Last Modified: 3 Dec 2024

    Users were able to set an arbitrary "product name" for OX Guard. The chosen value was not sufficiently sanitized before processing it at the user interface, allowing for indirect cross-site scripting attacks. Accounts that were temporarily taken over could be configured to trigger persistent code execution, allowing an attacker to build a foothold. Sanitization is in place for product names now. No publicly available exploits are known.

    Published: 2 Nov 2023
    5.6
    Medium

    CVE-2023-26455

    Last Modified: 21 Nov 2024

    RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse the RMI service to modify calendar items using RMI. RMI access is restricted to localhost by default. The interface has been updated to require authenticated requests. No publicly available exploits are known.

    Published: 2 Nov 2023
    7.6
    High

    CVE-2023-26454

    Last Modified: 21 Nov 2024

    Requests to fetch image metadata could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least access to adjacent networks of the imageconverter service, which is not exposed to public networks by default. Arbitrary SQL statements could be executed in the context of the services database user account. API requests are now properly checked for valid content and attempts to circumvent this check are being logged as error. No publicly available exploits are known.

    Published: 2 Nov 2023
    7.6
    High

    CVE-2023-26453

    Last Modified: 21 Nov 2024

    Requests to cache an image could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least access to adjacent networks of the imageconverter service, which is not exposed to public networks by default. Arbitrary SQL statements could be executed in the context of the services database user account. API requests are now properly checked for valid content and attempts to circumvent this check are being logged as error. No publicly available exploits are known.

    Published: 2 Nov 2023
    7.6
    High

    CVE-2023-26452

    Last Modified: 21 Nov 2024

    Requests to cache an image and return its metadata could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least access to adjacent networks of the imageconverter service, which is not exposed to public networks by default. Arbitrary SQL statements could be executed in the context of the services database user account. API requests are now properly checked for valid content and attempts to circumvent this check are being logged as error. No publicly available exploits are known.

    Published: 2 Nov 2023
    7.1
    High

    CVE-2023-5764

    Last Modified: 20 Nov 2025

    A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.

    Published: 2 Nov 2023
    7.2
    High

    CVE-2023-5860

    Last Modified: 8 Apr 2026

    The Icons Font Loader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload function in all versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 2 Nov 2023
    6.3
    Medium

    CVE-2023-5918

    Last Modified: 27 Feb 2025

    A vulnerability, which was classified as critical, was found in SourceCodester Visitor Management System 1.0. Affected is an unknown function of the file manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-244308.

    Published: 2 Nov 2023
    6.5
    Medium

    CVE-2023-43076

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS 8.2.x,9.0.0.x-9.5.0.x contains a denial-of-service vulnerability. A low privilege remote attacker could potentially exploit this vulnerability to cause an out of memory (OOM) condition.

    Published: 2 Nov 2023
    2.4
    Low

    CVE-2023-5917

    Last Modified: 27 Feb 2025

    A vulnerability, which was classified as problematic, has been found in phpBB up to 3.3.10. This issue affects the function main of the file phpBB/includes/acp/acp_icons.php of the component Smiley Pack Handler. The manipulation of the argument pak leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 3.3.11 is able to address this issue. The patch is named ccf6e6c255d38692d72fcb613b113e6eaa240aac. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-244307.

    Published: 2 Nov 2023
    4.3
    Medium

    CVE-2023-5916

    Last Modified: 27 Feb 2025

    A vulnerability classified as critical has been found in Lissy93 Dashy 2.1.1. This affects an unknown part of the file /config-manager/save of the component Configuration Handler. The manipulation of the argument config leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-244305 was assigned to this vulnerability.

    Published: 2 Nov 2023
    4.3
    Medium

    CVE-2023-43087

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privileged remote attacker could potentially exploit this vulnerability to cause information disclosure.

    Published: 2 Nov 2023
    2.9
    Low

    CVE-2023-5920

    Last Modified: 27 Feb 2025

    Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input.

    Published: 2 Nov 2023
    4.4
    Medium

    CVE-2023-5606

    Last Modified: 12 May 2025

    The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ Builder in versions 4.8.6 through 4.9.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. NOTE: This vulnerability is a re-introduction of CVE-2023-4253.

    Published: 2 Nov 2023
    3.7
    Low

    CVE-2023-5875

    Last Modified: 21 Nov 2024

    Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server

    Published: 2 Nov 2023
    3.1
    Low

    CVE-2023-5876

    Last Modified: 21 Nov 2024

    Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.

    Published: 2 Nov 2023
    5.9
    Medium

    CVE-2023-46595

    Last Modified: 12 Nov 2025

    Net-NTLM leak via HTML injection in FireFlow VisualFlow workflow editor allows an attacker to obtain victim’s domain credentials and Net-NTLM hash which can lead to relay domain attacks. Fixed in A32.20 (b570 or above), A32.50 (b390 or above)

    Published: 2 Nov 2023
    5.9
    Medium

    CVE-2023-46327

    Last Modified: 21 Nov 2024

    Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents of their Address Book with encrypted form, but the encryption strength is insufficient. With the knowledge of the encryption process and the encryption key, the information such as the server credentials may be obtained from the exported Address Book data. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-45019

    Last Modified: 21 Nov 2024

    Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'category' parameter of the category.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-45018

    Last Modified: 21 Nov 2024

    Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the includes/login.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 2 Nov 2023
    —
    Unknown

    CVE-2023-45017

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Nov 2023
    —
    Unknown

    CVE-2023-45016

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-45015

    Last Modified: 21 Nov 2024

    Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'date' parameter of the bus_info.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 2 Nov 2023
    —
    Unknown

    CVE-2023-45014

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Nov 2023
    —
    Unknown

    CVE-2023-45013

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-45012

    Last Modified: 21 Nov 2024

    Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'user_email' parameter of the bus_info.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 2 Nov 2023
    —
    Unknown

    CVE-2023-45114

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Nov 2023
    —
    Unknown

    CVE-2023-45113

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Nov 2023
    —
    Unknown

    CVE-2023-45112

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-45111

    Last Modified: 21 Nov 2024

    Online Examination System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'email' parameter of the feed.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-46958

    Last Modified: 9 Jul 2026

    An issue in lmxcms v.1.41 allows a remote attacker to execute arbitrary code via a crafted script to the admin.php file.

    Published: 2 Nov 2023
    7.8
    High

    CVE-2023-39283

    Last Modified: 21 Nov 2024

    An SMM memory corruption vulnerability in the SMM driver (SMRAM write) in CsmInt10HookSmm in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to send arbitrary data to SMM which could lead to privilege escalation.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-47204

    Last Modified: 21 Nov 2024

    Unsafe YAML deserialization in yaml.Loader in transmute-core before 1.13.5 allows attackers to execute arbitrary Python code.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-31579

    Last Modified: 21 Nov 2024

    Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability allows attackers to authenticate to the application via a crafted JWT token.

    Published: 2 Nov 2023
    7.5
    High

    CVE-2023-39051

    Last Modified: 21 Nov 2024

    An information leak in VISION MEAT WORKS Track Diner 10/10mbl v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

    Published: 2 Nov 2023
    7.5
    High

    CVE-2023-39047

    Last Modified: 21 Nov 2024

    An information leak in shouzu sweets oz v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

    Published: 2 Nov 2023