CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2022-32755

    Last Modified: 21 Nov 2024

    IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 228505.

    Published: 14 Oct 2023
    6.8
    Medium

    CVE-2022-33165

    Last Modified: 21 Nov 2024

    IBM Security Directory Server 6.4.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 228582.

    Published: 14 Oct 2023
    5.3
    Medium

    CVE-2022-33161

    Last Modified: 21 Nov 2024

    IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. X-Force ID: 228569.

    Published: 14 Oct 2023
    3.5
    Low

    CVE-2023-5582

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, has been found in ZZZCMS 2.2.0. This issue affects some unknown processing of the component Personal Profile Page. The manipulation leads to basic cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-242147.

    Published: 14 Oct 2023
    3.5
    Low

    CVE-2023-5581

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic was found in SourceCodester Medicine Tracker System 1.0. This vulnerability affects unknown code of the file index.php. The manipulation of the argument page leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-242146 is the identifier assigned to this vulnerability.

    Published: 14 Oct 2023
    6.3
    Medium

    CVE-2023-5580

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in SourceCodester Library System 1.0. This affects an unknown part of the file index.php. The manipulation of the argument category leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-242145 was assigned to this vulnerability.

    Published: 14 Oct 2023
    3.5
    Low

    CVE-2023-5579

    Last Modified: 21 Nov 2024

    A vulnerability was found in yhz66 Sandbox 6.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /im/user/ of the component User Data Handler. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-242144.

    Published: 14 Oct 2023
    4.4
    Medium

    CVE-2023-1259

    Last Modified: 8 Apr 2026

    The Hotjar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the hotjar_site_id in versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 14 Oct 2023
    2
    Low

    CVE-2023-5578

    Last Modified: 15 Sept 2026

    A vulnerability was detected in Portábilis i-Educar up to 2.7.5. Affected is an unknown function of the file \intranet\agenda_imprimir.php of the component HTTP GET Request Handler. The manipulation of the argument cod_agenda with the input ");'> <script>alert(document.cookie)</script> results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. Upgrading the affected component is recommended. The vendor explains: "This endpoint and the associated functionality are no longer present in the current i-Educar codebase, as the affected area was removed from the product. As a result, the previously reported attack vector (...) is no longer applicable to versions in which this functionality has been removed."

    Published: 14 Oct 2023
    6.5
    Medium

    CVE-2023-42663

    Last Modified: 13 Feb 2025

    Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs. Users of Apache Airflow are advised to upgrade to version 2.7.2 or newer to mitigate the risk associated with this vulnerability.

    Published: 14 Oct 2023
    6.5
    Medium

    CVE-2023-42792

    Last Modified: 13 Feb 2025

    Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to craft a request that could give the user write access to various DAG resources for DAGs that the user had no access to, thus, enabling the user to clear DAGs they shouldn't. Users of Apache Airflow are strongly advised to upgrade to version 2.7.2 or newer to mitigate the risk associated with this vulnerability.

    Published: 14 Oct 2023
    4.3
    Medium

    CVE-2023-45348

    Last Modified: 13 Feb 2025

    Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the "expose_config" option is set to "non-sensitive-only". The `expose_config` option is False by default. It is recommended to upgrade to a version that is not affected.

    Published: 14 Oct 2023
    6.5
    Medium

    CVE-2023-42780

    Last Modified: 21 Nov 2024

    Apache Airflow, versions prior to 2.7.2, contains a security vulnerability that allows authenticated users of Airflow to list warnings for all DAGs, even if the user had no permission to see those DAGs. It would reveal the dag_ids and the stack-traces of import errors for those DAGs with import errors. Users of Apache Airflow are advised to upgrade to version 2.7.2 or newer to mitigate the risk associated with this vulnerability.

    Published: 14 Oct 2023
    7.3
    High

    CVE-2023-26155

    Last Modified: 21 Nov 2024

    All versions of the package node-qpdf are vulnerable to Command Injection such that the package-exported method encrypt() fails to sanitize its parameter input, which later flows into a sensitive command execution API. As a result, attackers may inject malicious commands once they can specify the input pdf file path.

    Published: 14 Oct 2023
    9.8
    Critical

    CVE-2023-45853

    Last Modified: 14 Jul 2026

    MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.

    Published: 14 Oct 2023
    9.8
    Critical

    CVE-2023-45856

    Last Modified: 21 Nov 2024

    qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.

    Published: 14 Oct 2023
    9.8
    Critical

    CVE-2023-30154

    Last Modified: 21 Nov 2024

    Multiple improper neutralization of SQL parameters in module AfterMail (aftermailpresta) for PrestaShop, before version 2.2.1, allows remote attackers to perform SQL injection attacks via `id_customer`, `id_conf`, `id_product` and `token` parameters in `aftermailajax.php via the 'id_product' parameter in hooks DisplayRightColumnProduct and DisplayProductButtons.

    Published: 14 Oct 2023
    6.1
    Medium

    CVE-2023-30148

    Last Modified: 12 Jun 2026

    Multiple Stored Cross Site Scripting (XSS) vulnerabilities in Opart opartmultihtmlblock before version 2.0.12 and Opart multihtmlblock* version 1.0.0, allows remote authenticated users to inject arbitrary web script or HTML via the body_text or body_text_rude field in /sourcefiles/BlockhtmlClass.php and /sourcefiles/blockhtml.php.

    Published: 14 Oct 2023
    7.5
    High

    CVE-2023-44037

    Last Modified: 21 Nov 2024

    An issue in ZPE Systems, Inc Nodegrid OS v.5.8.10 thru v.5.8.13 and v.5.10.3 thru v.5.10.5 allows a remote attacker to obtain sensitive information via the TACACS+ server component.

    Published: 14 Oct 2023
    9.8
    Critical

    CVE-2023-45852

    Last Modified: 21 Nov 2024

    In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr params JSON data for the put method.

    Published: 14 Oct 2023
    7.5
    High

    CVE-2023-45855

    Last Modified: 21 Nov 2024

    qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.

    Published: 14 Oct 2023
    7.7
    High

    CVE-2023-45674

    Last Modified: 21 Nov 2024

    Farmbot-Web-App is a web control interface for the Farmbot farm automation platform. An SQL injection vulnerability was found in FarmBot's web app that allows authenticated attackers to extract arbitrary data from its database (including the user table). This issue may lead to Information Disclosure. This issue has been patched in version 15.8.4. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 13 Oct 2023
    —
    Unknown

    CVE-2023-5584

    Last Modified: 6 Feb 2024

    We have rejected this CVE as it was determined a non-security issue by the vendor.

    Published: 13 Oct 2023
    7.6
    High

    CVE-2023-4257

    Last Modified: 13 Feb 2025

    Unchecked user input length in /subsys/net/l2/wifi/wifi_shell.c can cause buffer overflows.

    Published: 13 Oct 2023
    7.6
    High

    CVE-2023-4263

    Last Modified: 13 Feb 2025

    Potential buffer overflow vulnerability in the Zephyr IEEE 802.15.4 nRF 15.4 driver

    Published: 13 Oct 2023
    4.2
    Medium

    CVE-2023-36559

    Last Modified: 14 Apr 2025

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

    Published: 13 Oct 2023
    4.6
    Medium

    CVE-2023-34977

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.0 ( 2023/07/27 ) and later

    Published: 13 Oct 2023
    10
    Critical

    CVE-2023-34976

    Last Modified: 12 Jan 2026

    A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.0 ( 2023/07/27 ) and later

    Published: 13 Oct 2023
    6.6
    Medium

    CVE-2023-34975

    Last Modified: 12 Jan 2026

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. QuTScloud is not affected. We have already fixed the vulnerability in the following versions: QuTS hero h4.5.4.2626 build 20231225 and later QTS 4.5.4.2627 build 20231225 and later

    Published: 13 Oct 2023
    6.6
    Medium

    CVE-2023-32976

    Last Modified: 21 Nov 2024

    An OS command injection vulnerability has been reported to affect Container Station. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following version: Container Station 2.6.7.44 and later

    Published: 13 Oct 2023
    7.5
    High

    CVE-2023-32974

    Last Modified: 21 Nov 2024

    A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.0.2444 build 20230629 and later QuTS hero h5.1.0.2424 build 20230609 and later QuTScloud c5.1.0.2498 and later

    Published: 13 Oct 2023
    3.8
    Low

    CVE-2023-32973

    Last Modified: 21 Nov 2024

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444 build 20230629 and later QTS 4.5.4.2467 build 20230718 and later QuTS hero h5.0.1.2515 build 20230907 and later QuTS hero h5.1.0.2424 build 20230609 and later QuTS hero h4.5.4.2476 build 20230728 and later QuTScloud c5.1.0.2498 and later

    Published: 13 Oct 2023
    4.9
    Medium

    CVE-2023-32970

    Last Modified: 21 Nov 2024

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to launch a denial-of-service (DoS) attack via a network. QES is not affected. We have already fixed the vulnerability in the following versions: QuTS hero h5.0.1.2515 build 20230907 and later QuTS hero h5.1.0.2453 build 20230708 and later QuTS hero h4.5.4.2476 build 20230728 and later QuTScloud c5.1.0.2498 and later QTS 5.1.0.2444 build 20230629 and later QTS 4.5.4.2467 build 20230718 and later

    Published: 13 Oct 2023
    7.5
    High

    CVE-2023-4499

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) which may lead to information disclosure. HP is releasing mitigation for the potential vulnerability.

    Published: 13 Oct 2023
    3.3
    Low

    CVE-2023-5449

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified in certain HP Displays supporting the Theft Deterrence feature which may allow a monitor’s Theft Deterrence to be deactivated.

    Published: 13 Oct 2023
    6.8
    Medium

    CVE-2023-5409

    Last Modified: 21 Nov 2024

    HP is aware of a potential security vulnerability in HP t430 and t638 Thin Client PCs. These models may be susceptible to a physical attack, allowing an untrusted source to tamper with the system firmware using a publicly disclosed private key. HP is providing recommended guidance for customers to reduce exposure to the potential vulnerability.

    Published: 13 Oct 2023
    4.4
    Medium

    CVE-2023-40682

    Last Modified: 21 Nov 2024

    IBM App Connect Enterprise 12.0.1.0 through 12.0.8.0 contains an unspecified vulnerability that could allow a local privileged user to obtain sensitive information from API logs. IBM X-Force ID: 263833.

    Published: 13 Oct 2023
    4.3
    Medium

    CVE-2023-45270

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in PINPOINT.WORLD Pinpoint Booking System plugin <= 2.9.9.4.0 versions.

    Published: 13 Oct 2023
    5.4
    Medium

    CVE-2023-45276

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in automatededitor.Com Automated Editor plugin <= 1.3 versions.

    Published: 13 Oct 2023
    5.4
    Medium

    CVE-2023-45269

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO plugin <= 2.0.25 versions.

    Published: 13 Oct 2023
    4.3
    Medium

    CVE-2023-45268

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Hitsteps Hitsteps Web Analytics plugin <= 5.86 versions.

    Published: 13 Oct 2023
    3.5
    Low

    CVE-2023-41836

    Last Modified: 14 Jan 2026

    An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0, FortiSandbox 4.2.1 through 4.2.4, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0.4 through 3.0.7 allows attacker to execute unauthorized code or commands via crafted HTTP requests.

    Published: 13 Oct 2023
    7.5
    High

    CVE-2023-41843

    Last Modified: 14 Jan 2026

    A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, FortiSandbox 4.2.1 through 4.2.5, FortiSandbox 4.0.0 through 4.0.3, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandbox 2.5 all versions, FortiSandbox 2.4.1 allows attacker to execute unauthorized code or commands via crafted HTTP requests.

    Published: 13 Oct 2023
    7.5
    High

    CVE-2023-41680

    Last Modified: 14 Jan 2026

    A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, FortiSandbox 4.2.1 through 4.2.5, FortiSandbox 4.0.0 through 4.0.3, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandbox 2.5 all versions, FortiSandbox 2.4.1 allows attacker to execute unauthorized code or commands via crafted HTTP requests.

    Published: 13 Oct 2023
    7.5
    High

    CVE-2023-41681

    Last Modified: 14 Jan 2026

    A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, FortiSandbox 4.2.1 through 4.2.5, FortiSandbox 4.0.0 through 4.0.3, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandbox 2.5 all versions, FortiSandbox 2.4.1 allows attacker to execute unauthorized code or commands via crafted HTTP requests.

    Published: 13 Oct 2023
    8.1
    High

    CVE-2023-41682

    Last Modified: 14 Jan 2026

    A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0, FortiSandbox 4.2.1 through 4.2.5, FortiSandbox 4.0.0 through 4.0.3, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandbox 2.5 all versions, FortiSandbox 2.4 all versions allows attacker to denial of service via crafted http requests.

    Published: 13 Oct 2023
    4.3
    Medium

    CVE-2023-45267

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Zizou1988 IRivYou plugin <= 2.2.1 versions.

    Published: 13 Oct 2023
    8.1
    High

    CVE-2023-33303

    Last Modified: 16 Dec 2025

    A insufficient session expiration in Fortinet FortiEDR version 5.0.0 through 5.0.1 allows attacker to execute unauthorized code or commands via api request

    Published: 13 Oct 2023
    5.4
    Medium

    CVE-2023-45109

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ZAKSTAN WhitePage plugin <= 1.1.5 versions.

    Published: 13 Oct 2023
    8.2
    High

    CVE-2023-29464

    Last Modified: 21 Nov 2024

    FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage of data from memory resulting in an information disclosure. If the size is large enough, it causes communications over the common industrial protocol to become unresponsive to any type of packet, resulting in a denial-of-service to FactoryTalk Linx over the common industrial protocol.

    Published: 13 Oct 2023