CVE Feed

    Dashboard / CVE

    7.9
    High

    CVE-2023-38994

    Last Modified: 15 Apr 2025

    The 'check_univention_joinstatus' prometheus monitoring script (and other scripts) in UCS 5.0-5 revealed the LDAP plaintext password of the machine account in the process list allowing attackers with local ssh access to gain higher privileges and perform followup attacks. By default, the configuration of UCS does not allow local ssh access for regular users.

    Published: 31 Oct 2023
    7.5
    High

    CVE-2023-46978

    Last Modified: 21 Nov 2024

    TOTOLINK X6000R V9.4.0cu.852_B20230719 is vulnerable to Incorrect Access Control.Attackers can reset login password & WIFI passwords without authentication.

    Published: 31 Oct 2023
    5.4
    Medium

    CVE-2023-47094

    Last Modified: 21 Nov 2024

    A Stored Cross-Site Scripting (XSS) vulnerability in the Account Plans tab of System Settings in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the Plan name field while editing Account plan details.

    Published: 31 Oct 2023
    5
    Medium

    CVE-2023-46139

    Last Modified: 21 Nov 2024

    KernelSU is a Kernel based root solution for Android. Starting in version 0.6.1 and prior to version 0.7.0, if a KernelSU installed device is infected with a malware whose app signing block specially constructed, it can take over root privileges on the device. The vulnerable verification logic actually obtains the signature of the last block with an id of `0x7109871a`, while the verification logic during Android installation is to obtain the first one. In addition to the actual signature upgrade that has been fixed (KSU thought it was V2 but was actually V3), there is also the problem of actual signature downgrading (KSU thought it was V2 but was actually V1). Find a condition in the signature verification logic that will cause the signature not to be found error, and KernelSU does not implement the same conditions, so KSU thinks there is a V2 signature, but the APK signature verification actually uses the V1 signature. This issue is fixed in version 0.7.0. As workarounds, keep the KernelSU manager installed and avoid installing unknown apps.

    Published: 30 Oct 2023
    3.7
    Low

    CVE-2023-46138

    Last Modified: 21 Nov 2024

    JumpServer is an open source bastion host and maintenance security audit system that complies with 4A specifications. Prior to version 3.8.0, the default email for initial user admin is `admin[@]mycompany[.]com`, and users reset their passwords by sending an email. Currently, the domain `mycompany.com` has not been registered. However, if it is registered in the future, it may affect the password reset functionality. This issue has been patched in version 3.8.0 by changing the default email domain to `example.com`. Those who cannot upgrade may change the default email domain to `example.com` manually.

    Published: 30 Oct 2023
    7.5
    High

    CVE-2023-45672

    Last Modified: 21 Nov 2024

    Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, an unsafe deserialization vulnerability was identified in the endpoints used to save configurations for Frigate. This can lead to unauthenticated remote code execution. This can be performed through the UI at `/config` or through a direct call to `/api/config/save`. Exploiting this vulnerability requires the attacker to both know very specific information about a user's Frigate server and requires an authenticated user to be tricked into clicking a specially crafted link to their Frigate instance. This vulnerability could exploited by an attacker under the following circumstances: Frigate publicly exposed to the internet (even with authentication); attacker knows the address of a user's Frigate instance; attacker crafts a specialized page which links to the user's Frigate instance; attacker finds a way to get an authenticated user to visit their specialized page and click the button/link. Input is initially accepted through `http.py`. The user-provided input is then parsed and loaded by `load_config_with_no_duplicates`. However, `load_config_with_no_duplicates` does not sanitize this input by merit of using `yaml.loader.Loader` which can instantiate custom constructors. A provided payload will be executed directly at `frigate/util/builtin.py:110`. This issue may lead to pre-authenticated Remote Code Execution. Version 0.13.0 Beta 3 contains a patch.

    Published: 30 Oct 2023
    4.7
    Medium

    CVE-2023-45671

    Last Modified: 21 Nov 2024

    Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, there is a reflected cross-site scripting vulnerability in any API endpoints reliant on the `/<camera_name>` base path as values provided for the path are not sanitized. Exploiting this vulnerability requires the attacker to both know very specific information about a user's Frigate server and requires an authenticated user to be tricked into clicking a specially crafted link to their Frigate instance. This vulnerability could exploited by an attacker under the following circumstances: Frigate publicly exposed to the internet (even with authentication); attacker knows the address of a user's Frigate instance; attacker crafts a specialized page which links to the user's Frigate instance; attacker finds a way to get an authenticated user to visit their specialized page and click the button/link. As the reflected values included in the URL are not sanitized or escaped, this permits execution arbitrary Javascript payloads. Version 0.13.0 Beta 3 contains a patch for this issue.

    Published: 30 Oct 2023
    7.5
    High

    CVE-2023-45670

    Last Modified: 21 Nov 2024

    Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, the `config/save` and `config/set` endpoints of Frigate do not implement any CSRF protection. This makes it possible for a request sourced from another site to update the configuration of the Frigate server (e.g. via "drive-by" attack). Exploiting this vulnerability requires the attacker to both know very specific information about a user's Frigate server and requires an authenticated user to be tricked into clicking a specially crafted link to their Frigate instance. This vulnerability could exploited by an attacker under the following circumstances: Frigate publicly exposed to the internet (even with authentication); attacker knows the address of a user's Frigate instance; attacker crafts a specialized page which links to the user's Frigate instance; attacker finds a way to get an authenticated user to visit their specialized page and click the button/link. This issue can lead to arbitrary configuration updates for the Frigate server, resulting in denial of service and possible data exfiltration. Version 0.13.0 Beta 3 contains a patch.

    Published: 30 Oct 2023
    7.5
    High

    CVE-2023-44397

    Last Modified: 21 Nov 2024

    CloudExplorer Lite is an open source, lightweight cloud management platform. Prior to version 1.4.1, the gateway filter of CloudExplorer Lite uses a controller with path starting with `matching/API/`, which can cause a permission bypass. Version 1.4.1 contains a patch for this issue.

    Published: 30 Oct 2023
    5.6
    Medium

    CVE-2023-43798

    Last Modified: 21 Nov 2024

    BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable to Server-Side Request Forgery (SSRF). This issue is a bypass of CVE-2023-33176. A patch in versions 2.6.12 and 2.7.0-rc.1 disabled follow redirect at `httpclient.execute` since the software no longer has to follow it when using `finalUrl`. There are no known workarounds. We recommend upgrading to a patched version of BigBlueButton.

    Published: 30 Oct 2023
    6.3
    Medium

    CVE-2023-43797

    Last Modified: 21 Nov 2024

    BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable to cross-site scripting when users wait to enter the meeting due to inserting unsanitized messages to the element using unsafe innerHTML. Text sanitizing was added for lobby messages starting in versions 2.6.11 and 2.7.0-beta.3. There are no known workarounds.

    Published: 30 Oct 2023
    9.8
    Critical

    CVE-2023-43792

    Last Modified: 21 Nov 2024

    baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. As of time of publication, no known patched versions are available.

    Published: 30 Oct 2023
    4.7
    Medium

    CVE-2023-43649

    Last Modified: 21 Nov 2024

    baserCMS is a website development framework. Prior to version 4.8.0, there is a cross site request forgery vulnerability in the content preview feature of baserCMS. Version 4.8.0 contains a patch for this issue.

    Published: 30 Oct 2023
    4.9
    Medium

    CVE-2023-43648

    Last Modified: 21 Nov 2024

    baserCMS is a website development framework. Prior to version 4.8.0, there is a Directory Traversal Vulnerability in the form submission data management feature of baserCMS. Version 4.8.0 contains a patch for this issue.

    Published: 30 Oct 2023
    6.1
    Medium

    CVE-2023-43647

    Last Modified: 21 Nov 2024

    baserCMS is a website development framework. Prior to version 4.8.0, there is a cross-site scripting vulnerability in the file upload feature of baserCMS. Version 4.8.0 contains a patch for this issue.

    Published: 30 Oct 2023
    3.1
    Low

    CVE-2023-42804

    Last Modified: 21 Nov 2024

    BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vulnerability that allows an attacker with a valid starting folder path, to traverse and read other files without authentication, assuming the files have certain extensions (txt, swf, svg, png). In version 2.6.0-beta.1, input validation was added on the parameters being passed and dangerous characters are stripped. There are no known workarounds.

    Published: 30 Oct 2023
    5.3
    Medium

    CVE-2023-42803

    Last Modified: 21 Nov 2024

    BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the insertDocument API call does not validate the given file extension before saving the file, and does not remove it in case of validation failures. BigBlueButton 2.6.0-beta.2 contains a patch. There are no known workarounds.

    Published: 30 Oct 2023
    3.5
    Low

    CVE-2023-41891

    Last Modified: 21 Nov 2024

    FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. Prior to version 1.1.124, list endpoints on FlyteAdmin have a SQL vulnerability where a malicious user can send a REST request with custom SQL statements as list filters. The attacker needs to have access to the FlyteAdmin installation, typically either behind a VPN or authentication. Version 1.1.124 contains a patch for this issue.

    Published: 30 Oct 2023
    7.3
    High

    CVE-2023-45780

    Last Modified: 8 Apr 2026

    In Print Service, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-40101

    Last Modified: 21 Nov 2024

    In collapse of canonicalize_md.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21398

    Last Modified: 21 Nov 2024

    In sdksandbox, there is a possible strandhogg style overlay attack due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21397

    Last Modified: 21 Nov 2024

    In Setup Wizard, there is a possible way to save a WiFi network due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21396

    Last Modified: 21 Nov 2024

    In Activity Manager, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    6.5
    Medium

    CVE-2023-21395

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21394

    Last Modified: 21 Nov 2024

    In registerPhoneAccount of TelecomServiceImpl.java, there is a possible way to reveal images from another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21393

    Last Modified: 21 Nov 2024

    In Settings, there is a possible way for the user to change SIM due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    8.8
    High

    CVE-2023-21392

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege when connecting to a Bluetooth device with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.5
    High

    CVE-2023-21391

    Last Modified: 21 Nov 2024

    In Messaging, there is a possible way to disable the messaging application due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21390

    Last Modified: 21 Nov 2024

    In Sim, there is a possible way to evade mobile preference restrictions due to a permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21389

    Last Modified: 21 Nov 2024

    In Settings, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21388

    Last Modified: 21 Nov 2024

    In Settings, there is a possible restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    4.4
    Medium

    CVE-2023-21387

    Last Modified: 21 Nov 2024

    In User Backup Manager, there is a possible way to leak a token to bypass user confirmation for backup due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21385

    Last Modified: 21 Nov 2024

    In Whitechapel, there is a possible out of bounds read due to memory corruption. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21384

    Last Modified: 21 Nov 2024

    In Package Manager, there is a possible possible permissions bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21383

    Last Modified: 21 Nov 2024

    In Settings, there is a possible way for the user to unintentionally send extra data due to an unclear prompt. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21382

    Last Modified: 21 Nov 2024

    In Content Resolver, there is a possible method to access metadata about existing content providers on the device due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21381

    Last Modified: 21 Nov 2024

    In Media Resource Manager, there is a possible local arbitrary code execution due to use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    6.7
    Medium

    CVE-2023-21380

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    4.4
    Medium

    CVE-2023-21379

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21378

    Last Modified: 21 Nov 2024

    In Telecomm, there is a possible way to silence the ring for calls of secondary users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21377

    Last Modified: 21 Nov 2024

    In SELinux Policy, there is a possible restriction bypass due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21376

    Last Modified: 6 Mar 2025

    In Telephony, there is a possible way to retrieve the ICCID due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21375

    Last Modified: 21 Nov 2024

    In Sysproxy, there is a possible out of bounds write due to an integer underflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21374

    Last Modified: 21 Nov 2024

    In System UI, there is a possible factory reset protection bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21373

    Last Modified: 21 Nov 2024

    In Telephony, there is a possible way for a guest user to change the preferred SIM due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21372

    Last Modified: 21 Nov 2024

    In libdexfile, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    6.7
    Medium

    CVE-2023-21371

    Last Modified: 21 Nov 2024

    In Secure Element, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    6.7
    Medium

    CVE-2023-21370

    Last Modified: 21 Nov 2024

    In the Security Element API, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21369

    Last Modified: 21 Nov 2024

    In Usage Access, there is a possible way to display a Settings usage access restriction toggle screen due to a permissions bypass. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21368

    Last Modified: 21 Nov 2024

    In Audio, there is a possible out of bounds read due to missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023