CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2023-39048

    Last Modified: 21 Nov 2024

    An information leak in Tokudaya.honten v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

    Published: 2 Nov 2023
    7.5
    High

    CVE-2023-39050

    Last Modified: 21 Nov 2024

    An information leak in Daiky-value.Fukueten v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

    Published: 2 Nov 2023
    7.5
    High

    CVE-2023-39042

    Last Modified: 21 Nov 2024

    An information leak in Gyouza-newhushimi v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

    Published: 2 Nov 2023
    7.5
    High

    CVE-2023-39053

    Last Modified: 21 Nov 2024

    An information leak in Hattoriya v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

    Published: 2 Nov 2023
    7.5
    High

    CVE-2023-39054

    Last Modified: 21 Nov 2024

    An information leak in Tokudaya.ekimae_mc v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

    Published: 2 Nov 2023
    7.5
    High

    CVE-2023-39057

    Last Modified: 21 Nov 2024

    An information leak in hirochanKAKIwaiting v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

    Published: 2 Nov 2023
    5.5
    Medium

    CVE-2023-39284

    Last Modified: 21 Nov 2024

    An issue was discovered in IhisiServicesSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There are arbitrary calls to SetVariable with unsanitized arguments in the SMI handler.

    Published: 2 Nov 2023
    9.8
    Critical

    CVE-2023-42299

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_subimage_data function.

    Published: 2 Nov 2023
    6.1
    Medium

    CVE-2023-43193

    Last Modified: 21 Nov 2024

    Submitty before v22.06.00 is vulnerable to Cross Site Scripting (XSS). An attacker can create a malicious link in the forum that leads to XSS.

    Published: 2 Nov 2023
    5.3
    Medium

    CVE-2023-43194

    Last Modified: 21 Nov 2024

    Submitty before v22.06.00 is vulnerable to Incorrect Access Control. An attacker can delete any post in the forum by modifying request parameter.

    Published: 2 Nov 2023
    8.8
    High

    CVE-2023-43336

    Last Modified: 9 Jul 2026

    Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified parameter value, e.g., changing extension=self to extension=101.

    Published: 2 Nov 2023
    7.5
    High

    CVE-2023-46352

    Last Modified: 21 Nov 2024

    In the module "Pixel Plus: Events + CAPI + Pixel Catalog for Facebook Module" (facebookconversiontrackingplus) up to version 2.4.9 from Smart Modules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from ps_customer table such as name / surname / email.

    Published: 2 Nov 2023
    5.4
    Medium

    CVE-2023-46475

    Last Modified: 21 Nov 2024

    A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the name field of the project, they can inject malicious JavaScript code.

    Published: 2 Nov 2023
    4.8
    Medium

    CVE-2023-46925

    Last Modified: 21 Nov 2024

    Reportico 7.1.21 is vulnerable to Cross Site Scripting (XSS).

    Published: 2 Nov 2023
    6.5
    Medium

    CVE-2023-6277

    Last Modified: 22 Jan 2026

    An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.

    Published: 2 Nov 2023
    2.6
    Low

    CVE-2023-5910

    Last Modified: 21 Nov 2024

    A vulnerability was found in PopojiCMS 2.0.1 and classified as problematic. This issue affects some unknown processing of the file install.php of the component Web Config. The manipulation of the argument Site Title with the input <script>alert(1)</script> leads to cross site scripting. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-244229 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Nov 2023
    —
    Unknown

    CVE-2023-47170

    Last Modified: 5 Feb 2024

    This candidate was in a CNA pool that was not assigned to any issues during 2023.

    Published: 1 Nov 2023
    6.1
    Medium

    CVE-2023-45203

    Last Modified: 21 Nov 2024

    Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.

    Published: 1 Nov 2023
    6.1
    Medium

    CVE-2023-45202

    Last Modified: 21 Nov 2024

    Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the feed.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.

    Published: 1 Nov 2023
    6.1
    Medium

    CVE-2023-45201

    Last Modified: 21 Nov 2024

    Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the admin.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.

    Published: 1 Nov 2023
    5.3
    Medium

    CVE-2023-5358

    Last Modified: 21 Nov 2024

    Improper access control in Report log filters feature in Devolutions Server 2023.2.10.0 and earlier allows attackers to retrieve logs from vaults or entries they are not allowed to access via the report request url query parameters.

    Published: 1 Nov 2023
    8.6
    High

    CVE-2023-20083

    Last Modified: 11 Aug 2026

    A vulnerability in ICMPv6 inspection when configured with the Snort 2 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the CPU of an affected device to spike to 100 percent, which could stop all traffic processing and result in a denial of service (DoS) condition. FTD management traffic is not affected by this vulnerability. This vulnerability is due to improper error checking when parsing fields within the ICMPv6 header. An attacker could exploit this vulnerability by sending a crafted ICMPv6 packet through an affected device. A successful exploit could allow the attacker to cause the device to exhaust CPU resources and stop processing traffic, resulting in a DoS condition. Note: To recover from the DoS condition, the Snort 2 Detection Engine or the Cisco FTD device may need to be restarted.

    Published: 1 Nov 2023
    4
    Medium

    CVE-2023-20267

    Last Modified: 11 Aug 2026

    A vulnerability in the IP geolocation rules of Snort 3 could allow an unauthenticated, remote attacker to potentially bypass IP address restrictions. This vulnerability exists because the configuration for IP geolocation rules is not parsed properly. An attacker could exploit this vulnerability by spoofing an IP address until they bypass the restriction. A successful exploit could allow the attacker to bypass location-based IP address restrictions.

    Published: 1 Nov 2023
    5
    Medium

    CVE-2023-20247

    Last Modified: 11 Aug 2026

    A vulnerability in the remote access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to bypass a configured multiple certificate authentication policy and connect using only a valid username and password. This vulnerability is due to improper error handling during remote access VPN authentication. An attacker could exploit this vulnerability by sending crafted requests during remote access VPN session establishment. A successful exploit could allow the attacker to bypass the configured multiple certificate authentication policy while retaining the privileges and permissions associated with the original connection profile.

    Published: 1 Nov 2023
    8.6
    High

    CVE-2023-20095

    Last Modified: 11 Aug 2026

    A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of HTTPS requests. An attacker could exploit this vulnerability by sending crafted HTTPS requests to an affected system. A successful exploit could allow the attacker to cause resource exhaustion, resulting in a DoS condition.

    Published: 1 Nov 2023
    4.3
    Medium

    CVE-2023-5859

    Last Modified: 13 Feb 2025

    Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted local HTML page. (Chromium security severity: Low)

    Published: 1 Nov 2023
    4.3
    Medium

    CVE-2023-5858

    Last Modified: 12 Jun 2025

    Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)

    Published: 1 Nov 2023
    8.8
    High

    CVE-2023-5857

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially execute arbitrary code via a malicious file. (Chromium security severity: Medium)

    Published: 1 Nov 2023
    8.8
    High

    CVE-2023-5856

    Last Modified: 29 Apr 2025

    Use after free in Side Panel in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Nov 2023
    8.8
    High

    CVE-2023-5855

    Last Modified: 29 Apr 2025

    Use after free in Reading Mode in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)

    Published: 1 Nov 2023
    8.8
    High

    CVE-2023-5854

    Last Modified: 29 Apr 2025

    Use after free in Profiles in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)

    Published: 1 Nov 2023
    4.3
    Medium

    CVE-2023-5853

    Last Modified: 13 Feb 2025

    Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Nov 2023
    8.8
    High

    CVE-2023-5852

    Last Modified: 29 Apr 2025

    Use after free in Printing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)

    Published: 1 Nov 2023
    4.3
    Medium

    CVE-2023-5851

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Nov 2023
    4.3
    Medium

    CVE-2023-5850

    Last Modified: 13 Feb 2025

    Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)

    Published: 1 Nov 2023
    8.8
    High

    CVE-2023-5849

    Last Modified: 29 Apr 2025

    Integer overflow in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Nov 2023
    8.8
    High

    CVE-2023-5482

    Last Modified: 30 Apr 2025

    Insufficient data validation in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Nov 2023
    6.1
    Medium

    CVE-2023-5480

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Payments in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to bypass XSS preventions via a malicious file. (Chromium security severity: High)

    Published: 1 Nov 2023
    5.8
    Medium

    CVE-2023-20246

    Last Modified: 11 Aug 2026

    Multiple Cisco products are affected by a vulnerability in Snort access control policies that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a logic error that occurs when the access control policies are being populated. An attacker could exploit this vulnerability by establishing a connection to an affected device. A successful exploit could allow the attacker to bypass configured access control rules on the affected system.

    Published: 1 Nov 2023
    8.8
    High

    CVE-2023-20175

    Last Modified: 16 Dec 2025

    A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid Read-only-level privileges or higher on the affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted CLI command. A successful exploit could allow the attacker to elevate privileges to root.

    Published: 1 Nov 2023
    6
    Medium

    CVE-2023-20170

    Last Modified: 16 Dec 2025

    A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted CLI command. A successful exploit could allow the attacker to elevate privileges to root.

    Published: 1 Nov 2023
    9.8
    Critical

    CVE-2023-5765

    Last Modified: 21 Nov 2024

    Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to bypass permissions via data source switching.

    Published: 1 Nov 2023
    8.2
    High

    CVE-2023-20063

    Last Modified: 11 Aug 2026

    A vulnerability in the inter-device communication mechanisms between devices that are running Cisco Firepower Threat Defense (FTD) Software and devices that are running Cisco Firepower Management (FMC) Software could allow an authenticated, local attacker to execute arbitrary commands with root permissions on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by accessing the expert mode of an affected device and submitting specific commands to a connected system. A successful exploit could allow the attacker to execute arbitrary code in the context of an FMC device if the attacker has administrative privileges on an associated FTD device. Alternatively, a successful exploit could allow the attacker to execute arbitrary code in the context of an FTD device if the attacker has administrative privileges on an associated FMC device.

    Published: 1 Nov 2023
    6.8
    Medium

    CVE-2023-20042

    Last Modified: 11 Aug 2026

    A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an implementation error within the SSL/TLS session handling process that can prevent the release of a session handler under specific conditions. An attacker could exploit this vulnerability by sending crafted SSL/TLS traffic to an affected device, increasing the probability of session handler leaks. A successful exploit could allow the attacker to eventually deplete the available session handler pool, preventing new sessions from being established and causing a DoS condition.

    Published: 1 Nov 2023
    6.1
    Medium

    CVE-2023-20264

    Last Modified: 11 Aug 2026

    A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to intercept the SAML assertion of a user who is authenticating to a remote access VPN session. This vulnerability is due to insufficient validation of the login URL. An attacker could exploit this vulnerability by persuading a user to access a site that is under the control of the attacker, allowing the attacker to modify the login URL. A successful exploit could allow the attacker to intercept a successful SAML assertion and use that assertion to establish a remote access VPN session toward the affected device with the identity and permissions of the hijacked user, resulting in access to the protected network.

    Published: 1 Nov 2023
    7.2
    High

    CVE-2023-20220

    Last Modified: 26 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. To exploit these vulnerabilities, the attacker must have valid device credentials, but does not need Administrator privileges. These vulnerabilities are due to insufficient validation of user-supplied input for certain configuration options. An attacker could exploit these vulnerabilities by using crafted input within the device configuration GUI. A successful exploit could allow the attacker to execute arbitrary commands on the device, including on the underlying operating system, which could also affect the availability of the device.

    Published: 1 Nov 2023
    7.2
    High

    CVE-2023-20219

    Last Modified: 26 Nov 2024

    Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The attacker would need valid device credentials but does not require administrator privileges to exploit this vulnerability. These vulnerabilities are due to insufficient validation of user-supplied input for certain configuration options. An attacker could exploit these vulnerabilities by using crafted input within the device configuration GUI. A successful exploit could allow the attacker to execute arbitrary commands on the device including the underlying operating system which could also affect the availability of the device.

    Published: 1 Nov 2023
    4
    Medium

    CVE-2023-20070

    Last Modified: 11 Aug 2026

    A vulnerability in the TLS 1.3 implementation of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to unexpectedly restart. This vulnerability is due to a logic error in how memory allocations are handled during a TLS 1.3 session. Under specific, time-based constraints, an attacker could exploit this vulnerability by sending a crafted TLS 1.3 message sequence through an affected device. A successful exploit could allow the attacker to cause the Snort 3 detection engine to reload, resulting in a denial of service (DoS) condition. While the Snort detection engine reloads, packets going through the FTD device that are sent to the Snort detection engine will be dropped. The Snort detection engine will restart automatically. No manual intervention is required.

    Published: 1 Nov 2023
    9.8
    Critical

    CVE-2023-5766

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute code from another windows user session on the same host via a specially crafted TCP packet.

    Published: 1 Nov 2023
    5.8
    Medium

    CVE-2023-20071

    Last Modified: 11 Aug 2026

    Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a flaw in the FTP module of the Snort detection engine. An attacker could exploit this vulnerability by sending crafted FTP traffic through an affected device. A successful exploit could allow the attacker to bypass FTP inspection and deliver a malicious payload.

    Published: 1 Nov 2023