CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2023-42641

    Last Modified: 21 Nov 2024

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 1 Nov 2023
    5.5
    Medium

    CVE-2023-42640

    Last Modified: 21 Nov 2024

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 1 Nov 2023
    5.5
    Medium

    CVE-2023-42639

    Last Modified: 21 Nov 2024

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 1 Nov 2023
    5.5
    Medium

    CVE-2023-42638

    Last Modified: 21 Nov 2024

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 1 Nov 2023
    5.5
    Medium

    CVE-2023-42637

    Last Modified: 21 Nov 2024

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 1 Nov 2023
    5.5
    Medium

    CVE-2023-42636

    Last Modified: 21 Nov 2024

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 1 Nov 2023
    5.5
    Medium

    CVE-2023-42635

    Last Modified: 21 Nov 2024

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 1 Nov 2023
    5.5
    Medium

    CVE-2023-42634

    Last Modified: 21 Nov 2024

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 1 Nov 2023
    5.5
    Medium

    CVE-2023-42633

    Last Modified: 21 Nov 2024

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 1 Nov 2023
    5.5
    Medium

    CVE-2023-42632

    Last Modified: 21 Nov 2024

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 1 Nov 2023
    5.5
    Medium

    CVE-2023-42631

    Last Modified: 21 Nov 2024

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 1 Nov 2023
    9.6
    Critical

    CVE-2023-1720

    Last Modified: 21 Nov 2024

    Lack of mime type response header in Bitrix24 22.0.300 allows authenticated remote attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via uploading a crafted HTML file through /desktop_app/file.ajax.php?action=uploadfile.

    Published: 1 Nov 2023
    7.5
    High

    CVE-2023-1719

    Last Modified: 21 Nov 2024

    Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via overwriting uninitialised variables.

    Published: 1 Nov 2023
    7.5
    High

    CVE-2023-1718

    Last Modified: 21 Nov 2024

    Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated remote attackers to cause denial-of-service via a crafted "tmp_url".

    Published: 1 Nov 2023
    9.6
    Critical

    CVE-2023-1717

    Last Modified: 21 Nov 2024

    Prototype pollution in bitrix/templates/bitrix24/components/bitrix/menu/left_vertical/script.js in Bitrix24 22.0.300 allows remote attackers to execute arbitrary JavaScript code in the victim’s browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via polluting `__proto__[tag]` and `__proto__[text]`.

    Published: 1 Nov 2023
    9
    Critical

    CVE-2023-1716

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Invoice Edit Page in Bitrix24 22.0.300 allows attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege.

    Published: 1 Nov 2023
    9
    Critical

    CVE-2023-1715

    Last Modified: 21 Nov 2024

    A logic error when using mb_strpos() to check for potential XSS payload in Bitrix24 22.0.300 allows attackers to bypass XSS sanitisation via placing HTML tags at the begining of the payload.

    Published: 1 Nov 2023
    8.8
    High

    CVE-2023-1714

    Last Modified: 21 Nov 2024

    Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote authenticated attackers to execute arbitrary code via (1) appending arbitrary content to existing PHP files or (2) PHAR deserialization.

    Published: 1 Nov 2023
    8.8
    High

    CVE-2023-1713

    Last Modified: 21 Nov 2024

    Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apache HTTP Server allows remote authenticated attackers to execute arbitrary code via uploading a crafted ".htaccess" file.

    Published: 1 Nov 2023
    6.5
    Medium

    CVE-2023-4198

    Last Modified: 21 Nov 2024

    Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database table containing customer data

    Published: 1 Nov 2023
    7.5
    High

    CVE-2023-4197

    Last Modified: 21 Nov 2024

    Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.

    Published: 1 Nov 2023
    7.5
    High

    CVE-2023-46695

    Last Modified: 21 Nov 2024

    An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.forms.UsernameField is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.

    Published: 1 Nov 2023
    5.3
    Medium

    CVE-2023-5516

    Last Modified: 27 Feb 2025

    Poorly constructed webap requests and URI components with special characters trigger unhandled errors and exceptions, disclosing information about the underlying technology and other sensitive information details. The website unintentionally reveals sensitive information including technical details like version Info, endpoints, backend server, Internal IP. etc., which can potentially expose additional attack surface containing other interesting vulnerabilities.

    Published: 1 Nov 2023
    5.3
    Medium

    CVE-2023-5515

    Last Modified: 27 Feb 2025

    The responses for web queries with certain parameters disclose internal path of resources. This information can be used to learn internal structure of the application and to further plot attacks against web servers and deployed web applications.

    Published: 1 Nov 2023
    5.3
    Medium

    CVE-2023-5514

    Last Modified: 27 Feb 2025

    The response messages received from the eSOMS report generation using certain parameter queries with full file path can be abused for enumerating the local file system structure.

    Published: 1 Nov 2023
    2.7
    Low

    CVE-2023-2622

    Last Modified: 27 Feb 2025

    Authenticated clients can read arbitrary files on the MAIN Computer system using the remote procedure call (RPC) of the InspectSetup service endpoint. The low privilege client is then allowed to read arbitrary files that they do not have authorization to read.

    Published: 1 Nov 2023
    6.5
    Medium

    CVE-2023-2621

    Last Modified: 27 Feb 2025

    The McFeeder server (distributed as part of SSW package), is susceptible to an arbitrary file write vulnerability on the MAIN computer system. This vulnerability stems from the use of an outdated version of a third-party library, which is used to extract archives uploaded to McFeeder server. An authenticated malicious client can exploit this vulnerability by uploading a crafted ZIP archive via the network to McFeeder’s service endpoint.

    Published: 1 Nov 2023
    5.4
    Medium

    CVE-2023-5904

    Last Modified: 27 Feb 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

    Published: 1 Nov 2023
    5.4
    Medium

    CVE-2023-5903

    Last Modified: 27 Feb 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

    Published: 1 Nov 2023
    3.5
    Low

    CVE-2023-5900

    Last Modified: 3 Dec 2024

    Cross-Site Request Forgery in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

    Published: 1 Nov 2023
    3.5
    Low

    CVE-2023-5901

    Last Modified: 21 Nov 2024

    Cross-site Scripting in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

    Published: 1 Nov 2023
    8.8
    High

    CVE-2023-5897

    Last Modified: 27 Feb 2025

    Cross-Site Request Forgery (CSRF) in GitHub repository pkp/customLocale prior to 1.2.0-1.

    Published: 1 Nov 2023
    8.8
    High

    CVE-2023-5898

    Last Modified: 27 Feb 2025

    Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

    Published: 1 Nov 2023
    4.3
    Medium

    CVE-2023-5902

    Last Modified: 27 Feb 2025

    Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

    Published: 1 Nov 2023
    5.4
    Medium

    CVE-2023-5896

    Last Modified: 27 Feb 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.4.0-4.

    Published: 1 Nov 2023
    8.8
    High

    CVE-2023-5899

    Last Modified: 27 Feb 2025

    Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

    Published: 1 Nov 2023
    5.4
    Medium

    CVE-2023-5895

    Last Modified: 27 Feb 2025

    Cross-site Scripting (XSS) - DOM in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

    Published: 1 Nov 2023
    5.4
    Medium

    CVE-2023-5894

    Last Modified: 27 Feb 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository pkp/ojs prior to 3.3.0-16.

    Published: 1 Nov 2023
    8.2
    High

    CVE-2023-5889

    Last Modified: 21 Nov 2024

    Insufficient Session Expiration in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

    Published: 1 Nov 2023
    5.4
    Medium

    CVE-2023-5891

    Last Modified: 27 Feb 2025

    Cross-site Scripting (XSS) - Reflected in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

    Published: 1 Nov 2023
    5.4
    Medium

    CVE-2023-5892

    Last Modified: 27 Feb 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

    Published: 1 Nov 2023
    8.8
    High

    CVE-2023-5893

    Last Modified: 27 Feb 2025

    Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

    Published: 1 Nov 2023
    5.4
    Medium

    CVE-2023-5890

    Last Modified: 27 Feb 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

    Published: 1 Nov 2023
    9.8
    Critical

    CVE-2023-46482

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/database/admin/index.php component.

    Published: 1 Nov 2023
    8.6
    High

    CVE-2023-46724

    Last Modified: 13 Feb 2025

    Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.

    Published: 1 Nov 2023
    9.8
    Critical

    CVE-2023-39281

    Last Modified: 21 Nov 2024

    A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to run arbitrary code execution during the DXE phase.

    Published: 1 Nov 2023
    9.8
    Critical

    CVE-2023-44025

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in addify Addifyfreegifts v.1.0.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the getrulebyid function in the AddifyfreegiftsModel.php component.

    Published: 1 Nov 2023
    5.4
    Medium

    CVE-2023-44954

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in BigTree CMS v.4.5.7 allows a remote attacker to execute arbitrary code via the ID parameter in the Developer Settings functions.

    Published: 1 Nov 2023
    6.1
    Medium

    CVE-2023-46448

    Last Modified: 21 Nov 2024

    Reflected Cross-Site Scripting (XSS) vulnerability in dmpop Mejiro Commit Versions Prior To 3096393 allows attackers to run arbitrary code via crafted string in metadata of uploaded images.

    Published: 1 Nov 2023
    5.5
    Medium

    CVE-2023-46931

    Last Modified: 21 Nov 2024

    GPAC 2.3-DEV-rev605-gfc9e29089-master contains a heap-buffer-overflow in ffdmx_parse_side_data /afltest/gpac/src/filters/ff_dmx.c:202:14 in gpac/MP4Box.

    Published: 1 Nov 2023