CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2023-38722

    Last Modified: 21 Nov 2024

    IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 262174.

    Published: 23 Oct 2023
    5.9
    Medium

    CVE-2023-43045

    Last Modified: 21 Nov 2024

    IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized actions due to improper authentication. IBM X-Force ID: 266896.

    Published: 23 Oct 2023
    5.8
    Medium

    CVE-2023-37532

    Last Modified: 21 Nov 2024

    HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system.

    Published: 23 Oct 2023
    3.9
    Low

    CVE-2023-46122

    Last Modified: 21 Nov 2024

    sbt is a build tool for Scala, Java, and others. Given a specially crafted zip or JAR file, `IO.unzip` allows writing of arbitrary file. This would have potential to overwrite `/root/.ssh/authorized_keys`. Within sbt's main code, `IO.unzip` is used in `pullRemoteCache` task and `Resolvers.remote`; however many projects use `IO.unzip(...)` directly to implement custom tasks. This vulnerability has been patched in version 1.9.7.

    Published: 23 Oct 2023
    4.9
    Medium

    CVE-2023-43067

    Last Modified: 21 Nov 2024

    Dell Unity prior to 5.3 contains an XML External Entity injection vulnerability. An XXE attack could potentially exploit this vulnerability disclosing local files in the file system.

    Published: 23 Oct 2023
    5.1
    Medium

    CVE-2023-43066

    Last Modified: 21 Nov 2024

    Dell Unity prior to 5.3 contains a Restricted Shell Bypass vulnerability. This could allow an authenticated, local attacker to exploit this vulnerability by authenticating to the device CLI and issuing certain commands.

    Published: 23 Oct 2023
    5.5
    Medium

    CVE-2023-43065

    Last Modified: 21 Nov 2024

    Dell Unity prior to 5.3 contains a Cross-site scripting vulnerability. A low-privileged authenticated attacker can exploit these issues to obtain escalated privileges.

    Published: 23 Oct 2023
    5.2
    Medium

    CVE-2023-43074

    Last Modified: 21 Nov 2024

    Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by crafting arbitrary files through a request to the server.

    Published: 23 Oct 2023
    5.4
    Medium

    CVE-2023-46127

    Last Modified: 21 Nov 2024

    Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated client side library. A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection. This vulnerability has been patched in version 14.49.0.

    Published: 23 Oct 2023
    4.3
    Medium

    CVE-2023-5718

    Last Modified: 21 Nov 2024

    The Vue.js Devtools extension was found to leak screenshot data back to a malicious web page via the standard `postMessage()` API. By creating a malicious web page with an iFrame targeting a sensitive resource (i.e. a locally accessible file or sensitive website), and registering a listener on the web page, the extension sent messages back to the listener, containing the base64 encoded screenshot data of the sensitive resource.

    Published: 23 Oct 2023
    6.7
    Medium

    CVE-2023-28805

    Last Modified: 27 Feb 2025

    An Improper Input Validation vulnerability in Zscaler Client Connector on Linux allows Privilege Escalation. This issue affects Client Connector: before 1.4.0.105

    Published: 23 Oct 2023
    8.2
    High

    CVE-2023-28804

    Last Modified: 21 Nov 2024

    An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing binaries.This issue affects Linux Client Connector: before 1.4.0.105

    Published: 23 Oct 2023
    5.9
    Medium

    CVE-2023-28803

    Last Modified: 21 Nov 2024

    An authentication bypass by spoofing of a device with a synthetic IP address is possible in Zscaler Client Connector on Windows, allowing a functionality bypass. This issue affects Client Connector: before 3.9.

    Published: 23 Oct 2023
    6.3
    Medium

    CVE-2023-28797

    Last Modified: 27 Feb 2025

    Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside specific folders on the disk. A malicious user can replace the folder and execute code as a privileged user.

    Published: 23 Oct 2023
    7.1
    High

    CVE-2023-28796

    Last Modified: 27 Feb 2025

    Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.

    Published: 23 Oct 2023
    7.8
    High

    CVE-2023-28795

    Last Modified: 27 Feb 2025

    Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Inclusion of Code in Existing Process. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.

    Published: 23 Oct 2023
    7.8
    High

    CVE-2023-28793

    Last Modified: 27 Feb 2025

    Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.

    Published: 23 Oct 2023
    7.8
    High

    CVE-2021-26738

    Last Modified: 27 Feb 2025

    Zscaler Client Connector for macOS prior to 3.7 had an unquoted search path vulnerability via the PATH variable. A local adversary may be able to execute code with root privileges.

    Published: 23 Oct 2023
    5.5
    Medium

    CVE-2021-26737

    Last Modified: 21 Nov 2024

    The Zscaler Client Connector for macOS prior to 3.6 did not sufficiently validate RPC clients. A local adversary without sufficient privileges may be able to shutdown the Zscaler tunnel by exploiting a race condition.

    Published: 23 Oct 2023
    6.7
    Medium

    CVE-2021-26736

    Last Modified: 27 Feb 2025

    Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low privileged path. A local adversary may be able to execute code with SYSTEM privileges.

    Published: 23 Oct 2023
    6.7
    Medium

    CVE-2021-26735

    Last Modified: 27 Feb 2025

    The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerability. A local adversary may be able to execute code with SYSTEM privileges.

    Published: 23 Oct 2023
    4.4
    Medium

    CVE-2021-26734

    Last Modified: 21 Nov 2024

    Zscaler Client Connector Installer on Windows before version 3.4.0.124 improperly handled directory junctions during uninstallation. A local adversary may be able to delete folders in an elevated context.

    Published: 23 Oct 2023
    8.8
    High

    CVE-2023-5246

    Last Modified: 1 Jun 2026

    Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282, 1044074, 1121597, 1099832, 1051432, 1127487, 1069070, 1112296, 1044072, 1121596, 1099830 allows an unauthenticated remote attacker to potentially impact the availability, integrity and confidentiality of the gateways via an authentication bypass by capture-replay.

    Published: 23 Oct 2023
    5.5
    Medium

    CVE-2023-43624

    Last Modified: 21 Nov 2024

    CX-Designer Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4) contains an improper restriction of XML external entity reference (XXE) vulnerability. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Designer is installed may be disclosed.

    Published: 23 Oct 2023
    4.3
    Medium

    CVE-2023-5702

    Last Modified: 21 Nov 2024

    A vulnerability was found in Viessmann Vitogate 300 up to 2.1.3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/. The manipulation leads to direct request. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243140. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 23 Oct 2023
    4.3
    Medium

    CVE-2023-5701

    Last Modified: 21 Nov 2024

    A vulnerability has been found in vnotex vnote up to 3.17.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Markdown File Handler. The manipulation with the input <xss onclick="alert(1)" style=display:block>Click here</xss> leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243139. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 23 Oct 2023
    7.5
    High

    CVE-2023-33517

    Last Modified: 21 Nov 2024

    carRental 1.0 is vulnerable to Incorrect Access Control (Arbitrary File Read on the Back-end System).

    Published: 23 Oct 2023
    4.8
    Medium

    CVE-2023-46059

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Geeklog-Core geeklog v.2.2.2 allows a remote attacker to execute arbitrary code via a crafted payload to the Service, and website URL to Ping parameters of the admin/trackback.php component.

    Published: 23 Oct 2023
    9.8
    Critical

    CVE-2023-27152

    Last Modified: 21 Nov 2024

    DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication.

    Published: 23 Oct 2023
    4.8
    Medium

    CVE-2023-27148

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the Admin panel in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Role Name parameter.

    Published: 23 Oct 2023
    4.8
    Medium

    CVE-2023-27149

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Label input parameter when updating a custom list.

    Published: 23 Oct 2023
    8.8
    High

    CVE-2023-42295

    Last Modified: 21 Nov 2024

    An issue in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_rle_image function of file bifs/unquantize.c

    Published: 23 Oct 2023
    5.4
    Medium

    CVE-2023-37636

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field when creating a ticket.

    Published: 23 Oct 2023
    9.8
    Critical

    CVE-2023-37635

    Last Modified: 21 Nov 2024

    UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application.

    Published: 23 Oct 2023
    5.4
    Medium

    CVE-2023-43358

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the News Menu component.

    Published: 23 Oct 2023
    4.8
    Medium

    CVE-2023-44760

    Last Modified: 21 Nov 2024

    Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS v.9.2.1 allow an attacker to execute arbitrary code via a crafted script to the Header and Footer Tracking Codes of the SEO & Statistics. NOTE: the vendor disputes this because these header/footer changes can only be made by an admin, and allowing an admin to place JavaScript there is an intentional customization feature. Also, the exploitation method claimed by "sromanhu" does not provide any access to a Concrete CMS session, because the Concrete CMS session cookie is configured as HttpOnly.

    Published: 23 Oct 2023
    7.5
    High

    CVE-2023-45966

    Last Modified: 21 Nov 2024

    umputun remark42 version 1.12.1 and before has a Blind Server-Side Request Forgery (SSRF) vulnerability.

    Published: 23 Oct 2023
    5.4
    Medium

    CVE-2023-45998

    Last Modified: 21 Nov 2024

    kodbox 1.44 is vulnerable to Cross Site Scripting (XSS). Customizing global HTML results in storing XSS.

    Published: 23 Oct 2023
    4.8
    Medium

    CVE-2023-46058

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Geeklog-Core geeklog v.2.2.2 allows a remote attacker to execute arbitrary code via a crafted payload to the grp_desc parameter of the admin/group.php component.

    Published: 23 Oct 2023
    4.9
    Medium

    CVE-2023-46118

    Last Modified: 13 Feb 2025

    RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making it vulnerable for denial of service (DoS) attacks with very large messages. An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. This vulnerability has been patched in versions 3.11.24 and 3.12.7.

    Published: 23 Oct 2023
    5.5
    Medium

    CVE-2023-46331

    Last Modified: 21 Nov 2024

    WebAssembly wabt 1.0.33 has an Out-of-Bound Memory Read in in DataSegment::IsValidRange(), which lead to segmentation fault.

    Published: 23 Oct 2023
    5.5
    Medium

    CVE-2023-46332

    Last Modified: 21 Nov 2024

    WebAssembly wabt 1.0.33 contains an Out-of-Bound Memory Write in DataSegment::Drop(), which lead to segmentation fault.

    Published: 23 Oct 2023
    —
    Unknown

    CVE-2023-46377

    Last Modified: 21 Nov 2023

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 23 Oct 2023
    —
    Unknown

    CVE-2023-46517

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 23 Oct 2023
    8.8
    High

    CVE-2023-46602

    Last Modified: 21 Nov 2024

    In International Color Consortium DemoIccMAX 79ecb74, there is a stack-based buffer overflow in the icFixXml function in IccXML/IccLibXML/IccUtilXml.cpp in libIccXML.a.

    Published: 23 Oct 2023
    8.8
    High

    CVE-2023-46603

    Last Modified: 21 Nov 2024

    In International Color Consortium DemoIccMAX 79ecb74, there is an out-of-bounds read in the CIccPRMG::GetChroma function in IccProfLib/IccPrmg.cpp in libSampleICC.a.

    Published: 23 Oct 2023
    7.5
    High

    CVE-2023-46324

    Last Modified: 21 Nov 2024

    pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated. An attacker can send arbitrary SUCIs to the UDM, which tries to decrypt them via both its private key and the attacker's public key.

    Published: 23 Oct 2023
    5.5
    Medium

    CVE-2023-5700

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected is an unknown function of the file /protocol/iscgwtunnel/uploadiscgwrouteconf.php. The manipulation of the argument GWLinkId leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-243138 is the identifier assigned to this vulnerability.

    Published: 22 Oct 2023
    3.5
    Low

    CVE-2023-5699

    Last Modified: 12 Jun 2025

    A vulnerability, which was classified as problematic, has been found in CodeAstro Internet Banking System 1.0. This issue affects some unknown processing of the file pages_view_client.php. The manipulation of the argument acc_name with the input Johnnie Reyes'"()&%<zzz><ScRiPt >alert(5646)</ScRiPt> leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243137 was assigned to this vulnerability.

    Published: 22 Oct 2023
    3.5
    Low

    CVE-2023-5698

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. This vulnerability affects unknown code of the file pages_deposit_money.php. The manipulation of the argument account_number with the input 421873905--><ScRiPt%20>alert(9523)</ScRiPt><!-- leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243136.

    Published: 22 Oct 2023