CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2023-36955

    Last Modified: 21 Nov 2024

    TOTOLINK CP300+ <=V5.2cu.7594_B20200910 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule.

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-40852

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to obtain sensitive information via crafted string in the admin user name field on the admin log in page.

    Published: 16 Oct 2023
    8.8
    High

    CVE-2023-43118

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, fixed in 31.7.2 and 32.5.1.5 allows attackers to run arbitrary code and cause other unspecified impacts via /jsonrpc API.

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-43119

    Last Modified: 21 Nov 2024

    An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain escalated privileges using crafted telnet commands via Redis server.

    Published: 16 Oct 2023
    8.8
    High

    CVE-2023-43120

    Last Modified: 21 Nov 2024

    An issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7 and before 31.7.1 allows attackers to gain escalated privileges via crafted HTTP request.

    Published: 16 Oct 2023
    7.5
    High

    CVE-2023-43121

    Last Modified: 21 Nov 2024

    A Directory Traversal vulnerability discovered in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7, and before 31.7.2 allows attackers to read arbitrary files.

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-44808

    Last Modified: 21 Nov 2024

    D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_4507CC function.

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-44809

    Last Modified: 21 Nov 2024

    D-Link device DIR-820L 1.05B03 is vulnerable to Insecure Permissions.

    Published: 16 Oct 2023
    6.5
    Medium

    CVE-2023-45540

    Last Modified: 21 Nov 2024

    An issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted script to the comment field of the List of Leave requests page.

    Published: 16 Oct 2023
    6.1
    Medium

    CVE-2023-45542

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in mooSocial 3.1.8 allows a remote attacker to obtain sensitive information via a crafted script to the q parameter in the Search function.

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-45572

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the fn parameter of the tgfile.htm function.

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-45574

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the fn parameter of the file.data function.

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-45575

    Last Modified: 21 Nov 2024

    Stack Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the ip parameter of the ip_position.asp function.

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-45576

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the remove_ext_proto/remove_ext_port parameter of the upnp_ctrl.asp function.

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-45578

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the pap_en/chap_en parameter of the pppoe_base.asp function.

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-45579

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the ip/type parameter of the jingx.asp function.

    Published: 16 Oct 2023
    4.8
    Medium

    CVE-2023-45669

    Last Modified: 21 Nov 2024

    WebAuthn4J Spring Security provides Web Authentication specification support for Spring applications. Affected versions are subject to improper signature counter value handling. A flaw was found in webauthn4j-spring-security-core. When an authneticator returns an incremented signature counter value during authentication, webauthn4j-spring-security-core does not properly persist the value, which means cloned authenticator detection does not work. An attacker who cloned valid authenticator in some way can use the cloned authenticator without being detected. This issue has been addressed in version `0.9.1.RELEASE`. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 16 Oct 2023
    7.1
    High

    CVE-2023-45683

    Last Modified: 21 Nov 2024

    github.com/crewjam/saml is a saml library for the go language. In affected versions the package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim’s browser loaded the SAML IdP initiated SSO link for the malicious service provider. Note: SP registration is commonly an unrestricted operation in IdPs, hence not requiring particular permissions or publicly accessible to ease the IdP interoperability. This issue is fixed in version 0.4.14. Users unable to upgrade may perform external validation of URLs provided in SAML metadata, or restrict the ability for end-users to upload arbitrary metadata.

    Published: 16 Oct 2023
    —
    Unknown

    CVE-2023-45916

    Last Modified: 29 Jan 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 16 Oct 2023
    —
    Unknown

    CVE-2023-45921

    Last Modified: 29 Jan 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 16 Oct 2023
    —
    Unknown

    CVE-2023-45923

    Last Modified: 30 Jan 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 16 Oct 2023
    —
    Unknown

    CVE-2023-45926

    Last Modified: 30 Jan 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 16 Oct 2023
    —
    Unknown

    CVE-2023-45928

    Last Modified: 30 Jan 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 16 Oct 2023
    —
    Unknown

    CVE-2023-45930

    Last Modified: 30 Jan 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 16 Oct 2023
    —
    Unknown

    CVE-2023-45932

    Last Modified: 29 Jan 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 16 Oct 2023
    0
    Low

    CVE-2023-45960

    Last Modified: 22 Nov 2023

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-45984

    Last Modified: 21 Nov 2024

    TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the lang parameter in the function setLanguageCfg.

    Published: 16 Oct 2023
    —
    Unknown

    CVE-2023-46050

    Last Modified: 29 Jan 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 16 Oct 2023
    5.3
    Medium

    CVE-2023-7250

    Last Modified: 6 Nov 2025

    A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-45573

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the n parameter of the mrclfile_del.asp function.

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-45577

    Last Modified: 21 Nov 2024

    Stack Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the wanid parameter of the H5/speedlimit.data function.

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-45580

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the wild/mx and other parameters of the ddns.asp function

    Published: 16 Oct 2023
    3.3
    Low

    CVE-2023-35018

    Last Modified: 21 Nov 2024

    IBM Security Verify Governance 10.0 could allow a privileged use to upload arbitrary files due to improper file validation. IBM X-Force ID: 259382.

    Published: 15 Oct 2023
    2.3
    Low

    CVE-2023-35013

    Last Modified: 21 Nov 2024

    IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain sensitive information from source code. IBM X-Force ID: 257769.

    Published: 15 Oct 2023
    7.3
    High

    CVE-2023-5589

    Last Modified: 16 Jun 2025

    A vulnerability was found in SourceCodester Judging Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-242188.

    Published: 15 Oct 2023
    7.5
    High

    CVE-2023-5590

    Last Modified: 21 Nov 2024

    NULL Pointer Dereference in GitHub repository seleniumhq/selenium prior to 4.14.0.

    Published: 15 Oct 2023
    2.6
    Low

    CVE-2023-5588

    Last Modified: 21 Nov 2024

    A vulnerability was found in kphrx pleroma. It has been classified as problematic. This affects the function Pleroma.Emoji.Pack of the file lib/pleroma/emoji/pack.ex. The manipulation of the argument name leads to path traversal. The complexity of an attack is rather high. The exploitability is told to be difficult. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The patch is named 2c795094535537a8607cc0d3b7f076a609636f40. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-242187.

    Published: 15 Oct 2023
    6.3
    Medium

    CVE-2023-5587

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /vm/admin/doctors.php of the component Parameter Handler. The manipulation of the argument search leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-242186 is the identifier assigned to this vulnerability.

    Published: 15 Oct 2023
    4.9
    Medium

    CVE-2023-40378

    Last Modified: 21 Nov 2024

    IBM Directory Server for IBM i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain component access to the host operating system. IBM X-Force ID: 263584.

    Published: 15 Oct 2023
    7.8
    High

    CVE-2023-5586

    Last Modified: 21 Nov 2024

    NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3.0-DEV.

    Published: 15 Oct 2023
    7.5
    High

    CVE-2023-38312

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability in Valve Counter-Strike 8684 allows a client (with remote control access to a game server) to read arbitrary files from the underlying server via the motdfile console variable.

    Published: 15 Oct 2023
    8.8
    High

    CVE-2023-5178

    Last Modified: 24 Mar 2026

    A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation.

    Published: 15 Oct 2023
    6.1
    Medium

    CVE-2018-25091

    Last Modified: 21 Nov 2024

    urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).

    Published: 15 Oct 2023
    2.4
    Low

    CVE-2023-5585

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Online Motorcycle Rental System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/?page=bike of the component Bike List. The manipulation of the argument Model with the input "><script>confirm (document.cookie)</script> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-242170 is the identifier assigned to this vulnerability.

    Published: 14 Oct 2023
    5.4
    Medium

    CVE-2023-30994

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 254138

    Published: 14 Oct 2023
    5.4
    Medium

    CVE-2023-40367

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 263376.

    Published: 14 Oct 2023
    6.2
    Medium

    CVE-2023-45176

    Last Modified: 21 Nov 2024

    IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.10.0 and IBM Integration Bus 10.1 through 10.1.0.1 are vulnerable to a denial of service for integration nodes on Windows. IBM X-Force ID: 247998.

    Published: 14 Oct 2023
    5.3
    Medium

    CVE-2022-43868

    Last Modified: 21 Nov 2024

    IBM Security Verify Access OIDC Provider could disclose directory information that could aid attackers in further attacks against the system. IBM X-Force ID: 239445.

    Published: 14 Oct 2023
    7.5
    High

    CVE-2022-43740

    Last Modified: 21 Nov 2024

    IBM Security Verify Access OIDC Provider could allow a remote user to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 238921.

    Published: 14 Oct 2023
    4.6
    Medium

    CVE-2023-35024

    Last Modified: 21 Nov 2024

    IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 258349.

    Published: 14 Oct 2023