CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2023-37538

    Last Modified: 21 Nov 2024

    HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).

    Published: 11 Oct 2023
    7.5
    High

    CVE-2023-44108

    Last Modified: 21 Nov 2024

    Type confusion vulnerability in the distributed file module.Successful exploitation of this vulnerability may cause the device to restart.

    Published: 11 Oct 2023
    9.1
    Critical

    CVE-2023-44107

    Last Modified: 21 Nov 2024

    Vulnerability of defects introduced in the design process in the screen projection module.Successful exploitation of this vulnerability may affect service availability and integrity.

    Published: 11 Oct 2023
    9.8
    Critical

    CVE-2023-44105

    Last Modified: 21 Nov 2024

    Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this vulnerability may cause features to perform abnormally.

    Published: 11 Oct 2023
    7.5
    High

    CVE-2023-44119

    Last Modified: 21 Nov 2024

    Vulnerability of mutual exclusion management in the kernel module.Successful exploitation of this vulnerability will affect availability.

    Published: 11 Oct 2023
    9.1
    Critical

    CVE-2023-44118

    Last Modified: 21 Nov 2024

    Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confidentiality.

    Published: 11 Oct 2023
    9.8
    Critical

    CVE-2023-44116

    Last Modified: 21 Nov 2024

    Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may cause some apps to run without being authorized.

    Published: 11 Oct 2023
    7.5
    High

    CVE-2023-44114

    Last Modified: 21 Nov 2024

    Out-of-bounds array vulnerability in the dataipa module.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 11 Oct 2023
    9.8
    Critical

    CVE-2023-5521

    Last Modified: 21 Nov 2024

    Incorrect Authorization in GitHub repository tiann/kernelsu prior to v0.6.9.

    Published: 11 Oct 2023
    7.5
    High

    CVE-2023-44111

    Last Modified: 21 Nov 2024

    Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 11 Oct 2023
    4.3
    Medium

    CVE-2023-44110

    Last Modified: 21 Nov 2024

    Out-of-bounds access vulnerability in the audio module.Successful exploitation of this vulnerability may affect availability.

    Published: 11 Oct 2023
    5.3
    Medium

    CVE-2023-41304

    Last Modified: 21 Nov 2024

    Parameter verification vulnerability in the window module.Successful exploitation of this vulnerability may cause the size of an app window to be adjusted to that of a floating window.

    Published: 11 Oct 2023
    7.7
    High

    CVE-2023-5520

    Last Modified: 1 Aug 2025

    Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.

    Published: 11 Oct 2023
    9.8
    Critical

    CVE-2023-44106

    Last Modified: 21 Nov 2024

    API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vulnerability may cause features to perform abnormally.

    Published: 11 Oct 2023
    7.5
    High

    CVE-2023-44104

    Last Modified: 21 Nov 2024

    Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 11 Oct 2023
    7.5
    High

    CVE-2023-44103

    Last Modified: 21 Nov 2024

    Out-of-bounds read vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 11 Oct 2023
    5.3
    Medium

    CVE-2023-44102

    Last Modified: 21 Nov 2024

    Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability can cause the Bluetooth function to be unavailable.

    Published: 11 Oct 2023
    7.8
    High

    CVE-2023-26370

    Last Modified: 21 Nov 2024

    Adobe Photoshop versions 23.5.5 (and earlier) and 24.7 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Oct 2023
    7.5
    High

    CVE-2023-44101

    Last Modified: 21 Nov 2024

    The Bluetooth module has a vulnerability in permission control for broadcast notifications.Successful exploitation of this vulnerability may affect confidentiality.

    Published: 11 Oct 2023
    7.5
    High

    CVE-2023-44100

    Last Modified: 21 Nov 2024

    Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 11 Oct 2023
    7.5
    High

    CVE-2023-44097

    Last Modified: 21 Nov 2024

    Vulnerability of the permission to access device SNs being improperly managed.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 11 Oct 2023
    7.5
    High

    CVE-2023-44095

    Last Modified: 21 Nov 2024

    Use-After-Free (UAF) vulnerability in the surfaceflinger module.Successful exploitation of this vulnerability can cause system crash.

    Published: 11 Oct 2023
    5.5
    Medium

    CVE-2023-38217

    Last Modified: 27 Feb 2025

    Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by an Out-of-bounds Read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Oct 2023
    5.5
    Medium

    CVE-2023-38216

    Last Modified: 27 Feb 2025

    Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Oct 2023
    5.3
    Medium

    CVE-2023-44094

    Last Modified: 21 Nov 2024

    Type confusion vulnerability in the distributed file module.Successful exploitation of this vulnerability may cause the device to restart.

    Published: 11 Oct 2023
    7.5
    High

    CVE-2023-44109

    Last Modified: 21 Nov 2024

    Clone vulnerability in the huks ta module.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 11 Oct 2023
    7.5
    High

    CVE-2023-44096

    Last Modified: 21 Nov 2024

    Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 11 Oct 2023
    7.5
    High

    CVE-2023-44093

    Last Modified: 21 Nov 2024

    Vulnerability of package names' public keys not being verified in the security module.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 11 Oct 2023
    7.8
    High

    CVE-2023-42138

    Last Modified: 21 Nov 2024

    Out-of-bounds read vulnerability exists in KV STUDIO Ver. 11.62 and earlier and KV REPLAY VIEWER Ver. 2.62 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user of KV STUDIO PLAYER open a specially crafted file.

    Published: 11 Oct 2023
    5.4
    Medium

    CVE-2023-44997

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Nitin Rathod WP Forms Puzzle Captcha plugin <= 4.1 versions.

    Published: 11 Oct 2023
    8.3
    High

    CVE-2023-4990

    Last Modified: 1 May 2025

    Directory traversal vulnerability in MCL-Net versions prior to 4.6 Update Package (P01) may allow attackers to read arbitrary files.

    Published: 11 Oct 2023
    7.5
    High

    CVE-2023-26320

    Last Modified: 21 Nov 2024

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.

    Published: 11 Oct 2023
    6.7
    Medium

    CVE-2023-26319

    Last Modified: 21 Nov 2024

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.

    Published: 11 Oct 2023
    6.7
    Medium

    CVE-2023-26318

    Last Modified: 21 Nov 2024

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Xiaomi Xiaomi Router allows Overflow Buffers.

    Published: 11 Oct 2023
    6.5
    Medium

    CVE-2022-44757

    Last Modified: 21 Nov 2024

    BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc.

    Published: 11 Oct 2023
    6.5
    Medium

    CVE-2022-44758

    Last Modified: 21 Nov 2024

    BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized.

    Published: 11 Oct 2023
    4.6
    Medium

    CVE-2022-42451

    Last Modified: 21 Nov 2024

    Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user.

    Published: 11 Oct 2023
    —
    Unknown

    CVE-2023-5513

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 11 Oct 2023
    4.3
    Medium

    CVE-2023-45194

    Last Modified: 21 Nov 2024

    Use of default credentials vulnerability in MR-GM2 firmware Ver. 3.00.03 and earlier, and MR-GM3 (-D/-K/-S/-DK/-DKS/-M/-W) firmware Ver. 1.03.45 and earlier allows a network-adjacent unauthenticated attacker to intercept wireless LAN communication, when the affected product performs the communication without changing the pre-shared key from the factory-default configuration.

    Published: 11 Oct 2023
    4.3
    Medium

    CVE-2023-44689

    Last Modified: 21 Nov 2024

    e-Gov Client Application (Windows version) versions prior to 2.1.1.0 and e-Gov Client Application (macOS version) versions prior to 1.1.1.0 are vulnerable to improper authorization in handler for custom URL scheme. A crafted URL may direct the product to access an arbitrary website. As a result, the user may become a victim of a phishing attack.

    Published: 11 Oct 2023
    8.8
    High

    CVE-2023-5511

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) in GitHub repository snipe/snipe-it prior to v.6.2.3.

    Published: 11 Oct 2023
    3.7
    Low

    CVE-2023-38546

    Last Modified: 12 May 2026

    This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met. libcurl performs transfers. In its API, an application creates "easy handles" that are the individual handles for single transfers. libcurl provides a function call that duplicates en easy handle called [curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html). If a transfer has cookies enabled when the handle is duplicated, the cookie-enable state is also cloned - but without cloning the actual cookies. If the source handle did not read any cookies from a specific file on disk, the cloned version of the handle would instead store the file name as `none` (using the four ASCII letters, no quotes). Subsequent use of the cloned handle that does not explicitly set a source to load cookies from would then inadvertently load cookies from a file named `none` - if such a file exists and is readable in the current directory of the program using libcurl. And if using the correct file format of course.

    Published: 11 Oct 2023
    9.8
    Critical

    CVE-2023-38545

    Last Modified: 12 May 2026

    This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255 bytes. If the host name is detected to be longer, curl switches to local name resolving and instead passes on the resolved address only. Due to this bug, the local variable that means "let the host resolve the name" could get the wrong value during a slow SOCKS5 handshake, and contrary to the intention, copy the too long host name to the target buffer instead of copying just the resolved address there. The target buffer being a heap based buffer, and the host name coming from the URL that curl has been told to operate with.

    Published: 11 Oct 2023
    8.8
    High

    CVE-2023-43960

    Last Modified: 21 Nov 2024

    An issue in DLINK DPH-400SE FRU 2.2.15.8 allows a remote attacker to escalate privileges via the User Modify function in the Maintenance/Access function component.

    Published: 11 Oct 2023
    7.5
    High

    CVE-2023-44961

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in Koha Library Software 23.0.5.04 and before allows a remote attacker to obtain sensitive information via the intranet/cgi bin/cataloging/ysearch.pl. component.

    Published: 11 Oct 2023
    5.3
    Medium

    CVE-2023-44962

    Last Modified: 21 Nov 2024

    File Upload vulnerability in Koha Library Software 23.05.04 and before allows a remote attacker to read arbitrary files via the upload-cover-image.pl component.

    Published: 11 Oct 2023
    6.5
    Medium

    CVE-2023-45396

    Last Modified: 21 Nov 2024

    An Insecure Direct Object Reference (IDOR) vulnerability leads to events profiles access in Elenos ETG150 FM transmitter running on version 3.12.

    Published: 11 Oct 2023
    8.2
    High

    CVE-2023-37536

    Last Modified: 13 Feb 2025

    An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.

    Published: 11 Oct 2023
    7.8
    High

    CVE-2023-38817

    Last Modified: 21 Nov 2024

    An issue in Inspect Element Ltd Echo.ac v.5.2.1.0 allows a local attacker to gain privileges via a crafted command to the echo_driver.sys component. NOTE: the vendor's position is that the reported ability for user-mode applications to execute code as NT AUTHORITY\SYSTEM was "deactivated by Microsoft itself."

    Published: 11 Oct 2023
    9.1
    Critical

    CVE-2023-44981

    Last Modified: 23 Apr 2025

    Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in zoo.cfg server list. The instance part in SASL auth ID is optional and if it's missing, like '[email protected]', the authorization check will be skipped. As a result an arbitrary endpoint could join the cluster and begin propagating counterfeit changes to the leader, essentially giving it complete read-write access to the data tree. Quorum Peer authentication is not enabled by default. Users are recommended to upgrade to version 3.9.1, 3.8.3, 3.7.2, which fixes the issue. Alternately ensure the ensemble election/quorum communication is protected by a firewall as this will mitigate the issue. See the documentation for more details on correct cluster administration.

    Published: 11 Oct 2023