CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2023-46587

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in XnView Classic v.2.51.5 allows a local attacker to execute arbitrary code via a crafted TIF file.

    Published: 27 Oct 2023
    7
    High

    CVE-2023-46813

    Last Modified: 25 Feb 2026

    An issue was discovered in the Linux kernel before 6.5.9, exploitable by local users with userspace access to MMIO registers. Incorrect access checking in the #VC handler and instruction emulation of the SEV-ES emulation of MMIO accesses could lead to arbitrary write access to kernel memory (and thus privilege escalation). This depends on a race condition through which userspace can replace an instruction before the #VC handler reads it.

    Published: 27 Oct 2023
    8.8
    High

    CVE-2023-46815

    Last Modified: 21 Nov 2024

    An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. An Unrestricted File Upload vulnerability has been identified in the Notes module. By using a crafted request, custom PHP code can be injected via the Notes module because of missing input validation. An attacker with regular user privileges can exploit this.

    Published: 27 Oct 2023
    8.8
    High

    CVE-2023-46816

    Last Modified: 21 Nov 2024

    An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. A Server Site Template Injection (SSTI) vulnerability has been identified in the GecControl action. By using a crafted request, custom PHP code can be injected via the GetControl action because of missing input validation. An attacker with regular user privileges can exploit this.

    Published: 27 Oct 2023
    7.5
    High

    CVE-2023-46852

    Last Modified: 21 Nov 2024

    In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "get" substring.

    Published: 27 Oct 2023
    —
    Unknown

    CVE-2023-43737

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 26 Oct 2023
    —
    Unknown

    CVE-2023-44268

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 26 Oct 2023
    6.3
    Medium

    CVE-2023-5805

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Simple Real Estate Portal System 1.0. It has been classified as critical. Affected is an unknown function of the file view_estate.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-243618 is the identifier assigned to this vulnerability.

    Published: 26 Oct 2023
    9.8
    Critical

    CVE-2023-46665

    Last Modified: 16 Jan 2025

    Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying passwords in a POST request and gain unauthorized access to the affected device with administrative privileges.

    Published: 26 Oct 2023
    8.8
    High

    CVE-2023-46748

    Last Modified: 27 Oct 2025

    An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Published: 26 Oct 2023
    9.8
    Critical

    CVE-2023-46747

    Last Modified: 27 Oct 2025

    Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Published: 26 Oct 2023
    7.5
    High

    CVE-2023-46664

    Last Modified: 16 Jan 2025

    Sielco PolyEco1000 is vulnerable to an improper access control vulnerability when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability attackers can bypass authorization and access resources behind protected pages.

    Published: 26 Oct 2023
    7.5
    High

    CVE-2023-46663

    Last Modified: 16 Jan 2025

    Sielco PolyEco1000 is vulnerable to an attacker bypassing authorization and accessing resources behind protected pages. The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests.

    Published: 26 Oct 2023
    7.3
    High

    CVE-2023-5804

    Last Modified: 21 Nov 2024

    A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0 and classified as critical. This issue affects some unknown processing of the file login.php. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The identifier VDB-243617 was assigned to this vulnerability.

    Published: 26 Oct 2023
    7.5
    High

    CVE-2023-46662

    Last Modified: 16 Jan 2025

    Sielco PolyEco1000 is vulnerable to an information disclosure vulnerability due to improper access control enforcement. An unauthenticated remote attacker can exploit this via a specially crafted request to gain access to sensitive information.

    Published: 26 Oct 2023
    9.8
    Critical

    CVE-2023-46661

    Last Modified: 16 Jan 2025

    Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests.

    Published: 26 Oct 2023
    9.1
    Critical

    CVE-2023-5754

    Last Modified: 16 Jan 2025

    Sielco PolyEco1000 uses a weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system.

    Published: 26 Oct 2023
    8.8
    High

    CVE-2023-0897

    Last Modified: 16 Jan 2025

    Sielco PolyEco1000 is vulnerable to a session hijack vulnerability due to the cookie being vulnerable to a brute force attack, lack of SSL, and the session being visible in requests.

    Published: 26 Oct 2023
    7.8
    High

    CVE-2023-39427

    Last Modified: 8 Aug 2025

    In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share v12 SP0 Build (1204.77), the affected applications lack proper validation of user-supplied data when parsing XE files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.

    Published: 26 Oct 2023
    7.8
    High

    CVE-2023-39936

    Last Modified: 21 Nov 2024

    In Ashlar-Vellum Graphite v13.0.48, the affected application lacks proper validation of user-supplied data when parsing VC6 files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.

    Published: 26 Oct 2023
    9.8
    Critical

    CVE-2023-44267

    Last Modified: 21 Nov 2024

    Online Art Gallery v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'lnm' parameter of the header.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 26 Oct 2023
    5.3
    Medium

    CVE-2023-31416

    Last Modified: 21 Nov 2024

    Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.

    Published: 26 Oct 2023
    6.3
    Medium

    CVE-2023-5796

    Last Modified: 21 Nov 2024

    A vulnerability was found in CodeAstro POS System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /setting of the component Logo Handler. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-243602 is the identifier assigned to this vulnerability.

    Published: 26 Oct 2023
    6.3
    Medium

    CVE-2023-5795

    Last Modified: 21 Nov 2024

    A vulnerability was found in CodeAstro POS System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /profil of the component Profile Picture Handler. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243601 was assigned to this vulnerability.

    Published: 26 Oct 2023
    7.3
    High

    CVE-2023-5794

    Last Modified: 21 Nov 2024

    A vulnerability was found in PHPGurukul Online Railway Catering System 1.0. It has been classified as critical. Affected is an unknown function of the file index.php of the component Login. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-243600.

    Published: 26 Oct 2023
    3.5
    Low

    CVE-2023-5793

    Last Modified: 29 Jan 2026

    A vulnerability was found in flusity CMS and classified as problematic. This issue affects the function loadCustomBlocCreateForm of the file /core/tools/customblock.php of the component Dashboard. The manipulation of the argument customblock_place leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The patch is named 81252bc764e1de2422e79e36194bba1289e7a0a5. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-243599.

    Published: 26 Oct 2023
    7.2
    High

    CVE-2023-5624

    Last Modified: 21 Nov 2024

    Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow an admin user to alter parameters that could potentially allow a blindSQL injection.

    Published: 26 Oct 2023
    6.3
    Medium

    CVE-2023-5792

    Last Modified: 21 Nov 2024

    A vulnerability has been found in SourceCodester Sticky Notes App 1.0 and classified as critical. This vulnerability affects unknown code of the file endpoint/delete-note.php. The manipulation of the argument note leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-243598 is the identifier assigned to this vulnerability.

    Published: 26 Oct 2023
    3.5
    Low

    CVE-2023-5791

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, was found in SourceCodester Sticky Notes App 1.0. This affects an unknown part of the file endpoint/add-note.php. The manipulation of the argument noteTitle/noteContent leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243597 was assigned to this vulnerability.

    Published: 26 Oct 2023
    7
    High

    CVE-2023-5623

    Last Modified: 21 Nov 2024

    NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary code with SYSTEM privileges where NNM is installed to a non-standard location

    Published: 26 Oct 2023
    6.5
    Medium

    CVE-2023-41966

    Last Modified: 16 Jan 2025

    The application suffers from a privilege escalation vulnerability. A user with read permissions can elevate privileges by sending a HTTP POST to set a parameter.

    Published: 26 Oct 2023
    6.5
    Medium

    CVE-2023-45228

    Last Modified: 16 Jan 2025

    The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissions by sending a single HTTP POST request with modified parameters.

    Published: 26 Oct 2023
    7.1
    High

    CVE-2023-5622

    Last Modified: 21 Nov 2024

    Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows hosts by replacing a specially crafted file.

    Published: 26 Oct 2023
    8.8
    High

    CVE-2023-45317

    Last Modified: 16 Jan 2025

    The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.

    Published: 26 Oct 2023
    5.3
    Medium

    CVE-2023-46666

    Last Modified: 21 Nov 2024

    An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all content on the Sharepoint site through Elasticsearch.

    Published: 26 Oct 2023
    9.8
    Critical

    CVE-2023-42769

    Last Modified: 16 Jan 2025

    The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.

    Published: 26 Oct 2023
    6.3
    Medium

    CVE-2023-5790

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in SourceCodester File Manager App 1.0. Affected by this vulnerability is an unknown functionality of the file endpoint/add-file.php. The manipulation of the argument uploadedFileName leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243595.

    Published: 26 Oct 2023
    2.4
    Low

    CVE-2023-5789

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in Dragon Path 707GR1 up to 20231022. Affected is an unknown function of the component Ping Diagnostics. The manipulation of the argument Host Address with the input >><img/src/onerror=alert(1)> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-243594 is the identifier assigned to this vulnerability.

    Published: 26 Oct 2023
    7.3
    High

    CVE-2023-5787

    Last Modified: 21 Nov 2024

    A vulnerability was found in Shaanxi Chanming Education Technology Score Query System 5.0. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument stuIdCard leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243593 was assigned to this vulnerability.

    Published: 26 Oct 2023
    5.3
    Medium

    CVE-2023-5786

    Last Modified: 21 Nov 2024

    A vulnerability was found in GeoServer GeoWebCache up to 1.15.1. It has been declared as problematic. This vulnerability affects unknown code of the file /geoserver/gwc/rest.html. The manipulation leads to direct request. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243592.

    Published: 26 Oct 2023
    5.5
    Medium

    CVE-2023-5785

    Last Modified: 21 Nov 2024

    A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This affects an unknown part of the file /protocol/firewall/addaddress_interpret.php. The manipulation of the argument messagecontent leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243591. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 26 Oct 2023
    6.8
    Medium

    CVE-2023-5056

    Last Modified: 20 Nov 2025

    A flaw was found in the Skupper operator, which may permit a certain configuration to create a service account that would allow an authenticated attacker in the adjacent cluster to view deployments in all namespaces in the cluster. This issue permits unauthorized viewing of information outside of the user's purview.

    Published: 26 Oct 2023
    5.5
    Medium

    CVE-2023-5784

    Last Modified: 21 Nov 2024

    A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by this issue is some unknown functionality of the file /protocol/firewall/uploadfirewall.php. The manipulation of the argument messagecontent leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-243590 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 26 Oct 2023
    8.7
    High

    CVE-2023-46238

    Last Modified: 21 Nov 2024

    ZITADEL is an identity infrastructure management system. ZITADEL users can upload their own avatar image using various image types including SVG. SVG can include scripts, such as javascript, which can be executed during rendering. Due to a missing security header, an attacker could inject code to an SVG to gain access to the victim’s account in certain scenarios. A victim would need to directly open the malicious image in the browser, where a single session in ZITADEL needs to be active for this exploit to work. If the possible victim had multiple or no active sessions in ZITADEL, the attack would not succeed. This issue has been patched in version 2.39.2 and 2.38.2.

    Published: 26 Oct 2023
    6.3
    Medium

    CVE-2023-5783

    Last Modified: 12 Jun 2025

    A vulnerability has been found in Tongda OA 2017 up to 11.9 and classified as critical. Affected by this vulnerability is an unknown functionality of the file general/system/approve_center/flow_sort/flow/delete.php. The manipulation of the argument id/sort_parent leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-243589 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 26 Oct 2023
    5.5
    Medium

    CVE-2023-5782

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.10. Affected is an unknown function of the file /manage/delete_query.php of the component General News. The manipulation of the argument NEWS_ID leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243588. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 26 Oct 2023
    7.1
    High

    CVE-2023-46090

    Last Modified: 28 Apr 2026

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WebDorado WDSocialWidgets plugin <= 1.0.15 versions.

    Published: 26 Oct 2023
    6.8
    Medium

    CVE-2023-41096

    Last Modified: 21 Nov 2024

    Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue affects Silicon Labs Ember ZNet SDK: 7.3.1 and earlier.

    Published: 26 Oct 2023
    6.8
    Medium

    CVE-2023-41095

    Last Modified: 21 Nov 2024

    Missing Encryption of Security Keys vulnerability in Silicon Labs OpenThread SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue affects Silicon Labs OpenThread SDK: 2.3.1 and earlier.

    Published: 26 Oct 2023
    6.3
    Medium

    CVE-2023-5781

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in Tongda OA 2017 11.10. This issue affects the function DELETE_STR of the file general/system/res_manage/monitor/delete_webmail.php. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243587. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 26 Oct 2023