CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2023-5102

    Last Modified: 9 Dec 2024

    Insufficient Control Flow Management in RDT400 in SICK APU allows an unprivileged remote attacker to potentially enable hidden functionality via HTTP requests.

    Published: 9 Oct 2023
    5.3
    Medium

    CVE-2023-5101

    Last Modified: 9 Dec 2024

    Files or Directories Accessible to External Parties in RDT400 in SICK APU allows an unprivileged remote attacker to download various files from the server via HTTP requests.

    Published: 9 Oct 2023
    5.9
    Medium

    CVE-2023-5100

    Last Modified: 21 Nov 2024

    Cleartext Transmission of Sensitive Information in RDT400 in SICK APU allows an unprivileged remote attacker to retrieve potentially sensitive information via intercepting network traffic that is not encrypted.

    Published: 9 Oct 2023
    6.5
    Medium

    CVE-2023-43697

    Last Modified: 9 Dec 2024

    Modification of Assumed-Immutable Data (MAID) in RDT400 in SICK APU allows an unprivileged remote attacker to make the site unable to load necessary strings via changing file paths using HTTP requests.

    Published: 9 Oct 2023
    7.1
    High

    CVE-2023-43698

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (’Cross-site Scripting’) in RDT400 in SICK APU allows an unprivileged remote attacker to run arbitrary code in the clients browser via injecting code into the website.

    Published: 9 Oct 2023
    7.5
    High

    CVE-2023-43699

    Last Modified: 9 Dec 2024

    Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU allows an unprivileged remote attacker to guess the password via trial-and-error as the login attempts are not limited.

    Published: 9 Oct 2023
    7.7
    High

    CVE-2023-43700

    Last Modified: 21 Nov 2024

    Missing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that no not require authentication.

    Published: 9 Oct 2023
    8.2
    High

    CVE-2023-43696

    Last Modified: 21 Nov 2024

    Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous access to the FTP server.

    Published: 9 Oct 2023
    7.1
    High

    CVE-2023-45247

    Last Modified: 16 Jun 2025

    Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 36497, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39169.

    Published: 9 Oct 2023
    7.3
    High

    CVE-2023-45248

    Last Modified: 16 Jun 2025

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 36497, Acronis Cyber Protect 16 (Windows) before build 37391.

    Published: 9 Oct 2023
    4.3
    Medium

    CVE-2023-5333

    Last Modified: 21 Nov 2024

    Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sending a specially crafted request to /api/v4/users/ids with multiple identical IDs.

    Published: 9 Oct 2023
    4.3
    Medium

    CVE-2023-5331

    Last Modified: 21 Nov 2024

    Mattermost fails to properly check the creator of an attached file when adding the file to a draft post, potentially exposing unauthorized file information.

    Published: 9 Oct 2023
    4.3
    Medium

    CVE-2023-5330

    Last Modified: 21 Nov 2024

    Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a specially crafted request to the /api/v4/opengraph filling the cache and turning the server unavailable.

    Published: 9 Oct 2023
    6.8
    Medium

    CVE-2023-45613

    Last Modified: 21 Nov 2024

    In JetBrains Ktor before 2.3.5 server certificates were not verified

    Published: 9 Oct 2023
    8.6
    High

    CVE-2023-45612

    Last Modified: 21 Nov 2024

    In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE

    Published: 9 Oct 2023
    4.3
    Medium

    CVE-2023-44993

    Last Modified: 12 May 2025

    Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.7.8 versions.

    Published: 9 Oct 2023
    5.4
    Medium

    CVE-2023-44473

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Michael Tran Table of Contents Plus plugin <= 2302 versions.

    Published: 9 Oct 2023
    4.3
    Medium

    CVE-2023-44240

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Peter Butler Timthumb Vulnerability Scanner plugin <= 1.54 versions.

    Published: 9 Oct 2023
    4.3
    Medium

    CVE-2023-44246

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Matias s Shockingly Simple Favicon plugin <= 1.8.2 versions.

    Published: 9 Oct 2023
    4.3
    Medium

    CVE-2023-44238

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Joakim Ling Remove slug from custom post type plugin <= 1.0.3 versions.

    Published: 9 Oct 2023
    4.3
    Medium

    CVE-2023-44237

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Moriyan Jay WP Site Protector plugin <= 2.0 versions.

    Published: 9 Oct 2023
    5.4
    Medium

    CVE-2023-44236

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Devnath verma WP Captcha plugin <= 2.0.0 versions.

    Published: 9 Oct 2023
    6.8
    Medium

    CVE-2023-3589

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x could allow with some very specific conditions an attacker to send a specifically crafted query to the server.

    Published: 9 Oct 2023
    4.3
    Medium

    CVE-2023-44232

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Huseyin Berberoglu WP Hide Pages plugin <= 1.0 versions.

    Published: 9 Oct 2023
    4.3
    Medium

    CVE-2023-44231

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in NickDuncan Contact Form plugin <= 2.0.10 versions.

    Published: 9 Oct 2023
    4.3
    Medium

    CVE-2023-44260

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Mikk Mihkel Nurges, Rebing OÜ Woocommerce ESTO plugin <= 2.23.1 versions.

    Published: 9 Oct 2023
    —
    Unknown

    CVE-2023-45589

    Last Modified: 17 Mar 2025

    Not used

    Published: 9 Oct 2023
    8.8
    High

    CVE-2023-43641

    Last Modified: 16 Dec 2025

    libcue provides an API for parsing and extracting data from CUE sheets. Versions 2.2.1 and prior are vulnerable to out-of-bounds array access. A user of the GNOME desktop environment can be exploited by downloading a cue sheet from a malicious webpage. Because the file is saved to `~/Downloads`, it is then automatically scanned by tracker-miners. And because it has a .cue filename extension, tracker-miners use libcue to parse the file. The file exploits the vulnerability in libcue to gain code execution. This issue is patched in version 2.3.0.

    Published: 9 Oct 2023
    5.9
    Medium

    CVE-2023-5568

    Last Modified: 2 Sept 2025

    A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remote, authenticated attacker to exploit this vulnerability to cause a denial of service.

    Published: 9 Oct 2023
    9.8
    Critical

    CVE-2023-43899

    Last Modified: 21 Nov 2024

    hansun CMS v1.0 was discovered to contain a SQL injection vulnerability via the component /ajax/ajax_login.ashx.

    Published: 9 Oct 2023
    7.5
    High

    CVE-2023-45371

    Last Modified: 21 Nov 2024

    An issue was discovered in the Wikibase extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. There is no rate limit for merging items.

    Published: 9 Oct 2023
    5.3
    Medium

    CVE-2023-45372

    Last Modified: 21 Nov 2024

    An issue was discovered in the Wikibase extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. During item merging, ItemMergeInteractor does not have an edit filter running (e.g., AbuseFilter).

    Published: 9 Oct 2023
    6.5
    Medium

    CVE-2023-39854

    Last Modified: 21 Nov 2024

    The web interface of ATX Ucrypt through 3.5 allows authenticated users (or attackers using default credentials for the admin, master, or user account) to include files via a URL in the /hydra/view/get_cc_url url parameter. There can be resultant SSRF.

    Published: 9 Oct 2023
    9.1
    Critical

    CVE-2023-43271

    Last Modified: 21 Nov 2024

    Incorrect access control in 70mai a500s v1.2.119 allows attackers to directly access and delete the video files of the driving recorder through ftp and other protocols.

    Published: 9 Oct 2023
    9.8
    Critical

    CVE-2023-44467

    Last Modified: 21 Nov 2024

    langchain_experimental (aka LangChain Experimental) in LangChain before 0.0.306 allows an attacker to bypass the CVE-2023-36258 fix and execute arbitrary code via __import__ in Python code, which is not prohibited by pal_chain/base.py.

    Published: 9 Oct 2023
    8.8
    High

    CVE-2023-44811

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) vulnerability in MooSocial v.3.1.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the admin Password Change Function.

    Published: 9 Oct 2023
    6.1
    Medium

    CVE-2023-44812

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a crafted payload to the admin_redirect_url parameter of the user login function.

    Published: 9 Oct 2023
    7.5
    High

    CVE-2023-45349

    Last Modified: 21 Nov 2024

    Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.34.7, 4000 Assistant V10 R1.42.0, 4000 Assistant V10 R0, 4000 Manager V10 R1 before V10 R1.34.7, 4000 Manager V10 R1.42.0, and 4000 Manager V10 R0 expose sensitive information that may allow lateral movement to the backup system via AShbr. This is also known as OSFOURK-23722.

    Published: 9 Oct 2023
    8.8
    High

    CVE-2023-45350

    Last Modified: 21 Nov 2024

    Atos Unify OpenScape 4000 Manager V10 R1 before V10 R1.42.1 and 4000 Manager V10 R0 allow Privilege escalation that may lead to the ability of an authenticated attacker to run arbitrary code via AScm. This is also known as OSFOURK-24034.

    Published: 9 Oct 2023
    8.8
    High

    CVE-2023-45351

    Last Modified: 21 Nov 2024

    Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.1, 4000 Assistant V10 R0, 4000 Manager V10 R1 before V10 R1.42.1, and 4000 Manager V10 R0 allow Authenticated Command Injection via AShbr. This is also known as OSFOURK-24039.

    Published: 9 Oct 2023
    8.8
    High

    CVE-2023-45352

    Last Modified: 21 Nov 2024

    Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the operating system via a Common Management Portal web interface Path traversal vulnerability allowing write access outside the intended folders. This is also known as OCMP-6592.

    Published: 9 Oct 2023
    8.8
    High

    CVE-2023-45353

    Last Modified: 21 Nov 2024

    Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the operating system by leveraging the Common Management Portal web interface for Authenticated remote upload and creation of arbitrary files affecting the underlying operating system. This is also known as OCMP-6591.

    Published: 9 Oct 2023
    8.8
    High

    CVE-2023-45354

    Last Modified: 21 Nov 2024

    Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated remote attacker to execute arbitrary code on the operating system by using the Common Management Portal web interface. This is also known as OCMP-6589.

    Published: 9 Oct 2023
    8.8
    High

    CVE-2023-45356

    Last Modified: 21 Nov 2024

    Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access, via dtb pages of the platform portal. This is also known as OSFOURK-23719.

    Published: 9 Oct 2023
    7.5
    High

    CVE-2023-45363

    Last Modified: 21 Nov 2024

    An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It allows attackers to cause a denial of service (unbounded loop and RequestTimeoutException) when querying pages redirected to other variants with redirects and converttitles set.

    Published: 9 Oct 2023
    5.3
    Medium

    CVE-2023-45364

    Last Modified: 21 Nov 2024

    An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision existence is leaked due to incorrect permissions being checked. This reveals that a given revision ID belonged to the given page title, and its timestamp, both of which are not supposed to be public information.

    Published: 9 Oct 2023
    6.5
    Medium

    CVE-2023-45367

    Last Modified: 21 Nov 2024

    An issue was discovered in the CheckUser extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. A user can use a rest.php/checkuser/v0/useragent-clienthints/revision/ URL to store an arbitrary number of rows in cu_useragent_clienthints, leading to a denial of service.

    Published: 9 Oct 2023
    4.3
    Medium

    CVE-2023-45369

    Last Modified: 21 Nov 2024

    An issue was discovered in the PageTriage extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. Usernames of hidden users are exposed.

    Published: 9 Oct 2023
    5.3
    Medium

    CVE-2023-45370

    Last Modified: 21 Nov 2024

    An issue was discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. SportsTeams: Special:SportsManagerLogo and Special:SportsTeamsManagerLogo do not check for the sportsteamsmanager user right, and thus an attacker may be able to affect pages that are concerned with sports teams.

    Published: 9 Oct 2023
    6.1
    Medium

    CVE-2023-45373

    Last Modified: 21 Nov 2024

    An issue was discovered in the ProofreadPage extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. XSS can occur via formatNumNoSeparators.

    Published: 9 Oct 2023