CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2023-45897

    Last Modified: 21 Nov 2024

    exfatprogs before 1.2.2 allows out-of-bounds memory access, such as in read_file_dentry_set.

    Published: 28 Oct 2023
    5.4
    Medium

    CVE-2023-46467

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted payload to the username parameter of the registration page.

    Published: 28 Oct 2023
    9.8
    Critical

    CVE-2023-46569

    Last Modified: 21 Nov 2024

    An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_fpu function of libr/arch/p/nds32/nds32-dis.h.

    Published: 28 Oct 2023
    9.8
    Critical

    CVE-2023-46570

    Last Modified: 21 Nov 2024

    An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32 function of libr/arch/p/nds32/nds32-dis.h.

    Published: 28 Oct 2023
    5.4
    Medium

    CVE-2023-46854

    Last Modified: 21 Nov 2024

    Proxmox proxmox-widget-toolkit before 4.0.9, as used in multiple Proxmox products, allows XSS via the edit notes feature.

    Published: 28 Oct 2023
    3.8
    Low

    CVE-2023-5834

    Last Modified: 21 Nov 2024

    HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fixed in Vagrant 2.4.0.

    Published: 27 Oct 2023
    8.8
    High

    CVE-2023-44480

    Last Modified: 21 Nov 2024

    Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setcasualleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 27 Oct 2023
    7.1
    High

    CVE-2023-46209

    Last Modified: 28 Apr 2026

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in G5Theme Grid Plus – Unlimited grid plugin <= 1.3.2 versions.

    Published: 27 Oct 2023
    7.3
    High

    CVE-2023-5830

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in ColumbiaSoft Document Locator. This affects an unknown part of the file /api/authentication/login of the component WebTools. The manipulation of the argument Server leads to improper authentication. It is possible to initiate the attack remotely. Upgrading to version 7.2 SP4 and 2021.1 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-243729 was assigned to this vulnerability.

    Published: 27 Oct 2023
    7.1
    High

    CVE-2023-46208

    Last Modified: 28 Apr 2026

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.6 versions.

    Published: 27 Oct 2023
    7.8
    High

    CVE-2023-40140

    Last Modified: 21 Nov 2024

    In android_view_InputDevice_create of android_view_InputDevice.cpp, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 27 Oct 2023
    5.5
    Medium

    CVE-2023-40139

    Last Modified: 21 Nov 2024

    In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 27 Oct 2023
    3.3
    Low

    CVE-2023-40138

    Last Modified: 21 Nov 2024

    In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 27 Oct 2023
    3.3
    Low

    CVE-2023-40137

    Last Modified: 21 Nov 2024

    In multiple functions of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 27 Oct 2023
    3.3
    Low

    CVE-2023-40136

    Last Modified: 21 Nov 2024

    In setHeader of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 27 Oct 2023
    3.3
    Low

    CVE-2023-40135

    Last Modified: 21 Nov 2024

    In applyCustomDescription of SaveUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 27 Oct 2023
    3.3
    Low

    CVE-2023-40134

    Last Modified: 21 Nov 2024

    In isFullScreen of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 27 Oct 2023
    5.5
    Medium

    CVE-2023-40133

    Last Modified: 21 Nov 2024

    In multiple locations of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 27 Oct 2023
    7
    High

    CVE-2023-40131

    Last Modified: 30 Apr 2025

    In GpuService of GpuService.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 27 Oct 2023
    7.8
    High

    CVE-2023-40130

    Last Modified: 17 Dec 2025

    In notifyTimeout of CallRedirectionProcessor, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege and background activity launch with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 27 Oct 2023
    8.8
    High

    CVE-2023-40129

    Last Modified: 21 Nov 2024

    In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 27 Oct 2023
    7.8
    High

    CVE-2023-40128

    Last Modified: 21 Nov 2024

    In several functions of xmlregexp.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 27 Oct 2023
    3.3
    Low

    CVE-2023-40127

    Last Modified: 21 Nov 2024

    In multiple locations, there is a possible way to access screenshots due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 27 Oct 2023
    6.5
    Medium

    CVE-2023-46211

    Last Modified: 28 Apr 2026

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder plugin <= 3.19.14 versions.

    Published: 27 Oct 2023
    7.8
    High

    CVE-2023-40125

    Last Modified: 5 May 2025

    In onCreate of ApnEditor.java, there is a possible way for a Guest user to change the APN due to a permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 27 Oct 2023
    5.5
    Medium

    CVE-2023-40123

    Last Modified: 21 Nov 2024

    In updateActionViews of PipMenuView.java, there is a possible bypass of a multi user security boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 27 Oct 2023
    5.5
    Medium

    CVE-2023-40121

    Last Modified: 21 Nov 2024

    In appendEscapedSQLString of DatabaseUtils.java, there is a possible SQL injection due to unsafe deserialization. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.

    Published: 27 Oct 2023
    7.8
    High

    CVE-2023-40120

    Last Modified: 5 May 2025

    In multiple locations, there is a possible way to bypass user notification of foreground services due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 27 Oct 2023
    7.8
    High

    CVE-2023-40117

    Last Modified: 29 Apr 2025

    In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 27 Oct 2023
    7.8
    High

    CVE-2023-40116

    Last Modified: 5 May 2025

    In onTaskAppeared of PipTaskOrganizer.java, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 27 Oct 2023
    5.9
    Medium

    CVE-2023-32738

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alkaweb Eonet Manual User Approve plugin <= 2.1.3 versions.

    Published: 27 Oct 2023
    5.9
    Medium

    CVE-2023-46200

    Last Modified: 28 Apr 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Stephen Darlington, Wandle Software Limited Smart App Banner plugin <= 1.1.3 versions.

    Published: 27 Oct 2023
    6.3
    Medium

    CVE-2023-5829

    Last Modified: 21 Nov 2024

    A vulnerability was found in code-projects Admission Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file student_avatar.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243728.

    Published: 27 Oct 2023
    6.1
    Medium

    CVE-2022-3702

    Last Modified: 21 Nov 2024

    A denial of service vulnerability was reported in Lenovo Vantage HardwareScan Plugin version 1.3.0.5 and earlier that could allow a local attacker to delete contents of an arbitrary directory under certain conditions.

    Published: 27 Oct 2023
    7.8
    High

    CVE-2022-3701

    Last Modified: 21 Nov 2024

    A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlier that could allow a local attacker to execute arbitrary code with elevated privileges.

    Published: 27 Oct 2023
    6.1
    Medium

    CVE-2022-3700

    Last Modified: 21 Nov 2024

    A Time of Check Time of Use (TOCTOU) vulnerability was reported in the Lenovo Vantage SystemUpdate Plugin version 2.0.0.212 and earlier that could allow a local attacker to delete arbitrary files.

    Published: 27 Oct 2023
    7.3
    High

    CVE-2023-5828

    Last Modified: 21 Nov 2024

    A vulnerability was found in Nanning Ontall Longxing Industrial Development Zone Project Construction and Installation Management System up to 20231026. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.aspx. The manipulation of the argument tbxUserName leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243727.

    Published: 27 Oct 2023
    6.1
    Medium

    CVE-2023-29009

    Last Modified: 21 Nov 2024

    baserCMS is a website development framework with WebAPI that runs on PHP8 and CakePHP4. There is a XSS Vulnerability in Favorites Feature to baserCMS. This issue has been patched in version 4.8.0.

    Published: 27 Oct 2023
    6.5
    Medium

    CVE-2022-3681

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless network to successfully brute force the WPS pin, potentially allowing them unauthorized access to a wireless network.

    Published: 27 Oct 2023
    7.6
    High

    CVE-2022-3611

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability has been identified in the Lenovo App Store which may allow some applications to gain unauthorized access to sensitive user data used by other unrelated applications.

    Published: 27 Oct 2023
    7.8
    High

    CVE-2023-27858

    Last Modified: 17 Dec 2024

    Rockwell Automation Arena Simulation contains an arbitrary code execution vulnerability that could potentially allow a malicious user to commit unauthorized code to the software by using an uninitialized pointer in the application.  The threat-actor could then execute malicious code on the system affecting the confidentiality, integrity, and availability of the product.  The user would need to open a malicious file provided to them by the attacker for the code to execute.

    Published: 27 Oct 2023
    6.5
    Medium

    CVE-2022-3429

    Last Modified: 21 Nov 2024

    A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malformed strings to an open port, triggering a denial of service that causes a display error and prevents the printer from functioning properly.

    Published: 27 Oct 2023
    7.8
    High

    CVE-2023-27854

    Last Modified: 17 Dec 2024

    An arbitrary code execution vulnerability was reported to Rockwell Automation in Arena Simulation that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buffer overflow.  The threat-actor could then execute malicious code on the system affecting the confidentiality, integrity, and availability of the product.  The user would need to open a malicious file provided to them by the attacker for the code to execute.

    Published: 27 Oct 2023
    4.3
    Medium

    CVE-2022-34887

    Last Modified: 21 Nov 2024

    Standard users can directly operate and set printer configuration information , such as IP, in some Lenovo Printers without having to authenticate with the administrator password.

    Published: 27 Oct 2023
    8.8
    High

    CVE-2022-34886

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was found in the firmware used in some Lenovo printers, which can be caused by a remote user pushing an illegal string to the server-side interface via a script, resulting in a stack overflow.

    Published: 27 Oct 2023
    7.5
    High

    CVE-2023-46289

    Last Modified: 27 Feb 2025

    Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. If exploited, the product would become unavailable and require a restart to recover resulting in a denial-of-service condition.

    Published: 27 Oct 2023
    8.1
    High

    CVE-2023-46290

    Last Modified: 27 Feb 2025

    Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into FactoryTalk® Services Platform . This vulnerability can only be exploited if the authorized user did not previously log in into the FactoryTalk® Services Platform web service.

    Published: 27 Oct 2023
    8.2
    High

    CVE-2023-4967

    Last Modified: 27 Feb 2025

    Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server

    Published: 27 Oct 2023
    5.5
    Medium

    CVE-2023-5827

    Last Modified: 12 Jun 2025

    A vulnerability was found in Shanghai CTI Navigation CTI Monitoring and Early Warning System 2.2. It has been classified as critical. This affects an unknown part of the file /Web/SysManage/UserEdit.aspx. The manipulation of the argument ID leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-243717 was assigned to this vulnerability.

    Published: 27 Oct 2023
    5.5
    Medium

    CVE-2023-5826

    Last Modified: 21 Nov 2024

    A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/list_onlineuser.php. The manipulation of the argument SessionId leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243716. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.

    Published: 27 Oct 2023