CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2023-45374

    Last Modified: 21 Nov 2024

    An issue was discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It does not check for the anti-CSRF edit token in Special:SportsTeamsManager and Special:UpdateFavoriteTeams.

    Published: 9 Oct 2023
    —
    Unknown

    CVE-2023-45485

    Last Modified: 19 Jan 2024

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 9 Oct 2023
    5.5
    Medium

    CVE-2023-44821

    Last Modified: 4 Nov 2025

    Gifsicle through 1.94, if deployed in a way that allows untrusted input to affect Gif_Realloc calls, might allow a denial of service (memory consumption). NOTE: this has been disputed by multiple parties because the Gifsicle code is not commonly used for unattended operation in which new input arrives for a long-running process, does not ship with functionality to link it into another application as a library, and does not have realistic use cases in which an adversary controls the entire command line.

    Published: 9 Oct 2023
    6.5
    Medium

    CVE-2022-36228

    Last Modified: 21 Nov 2024

    Nokelock Smart padlock O1 Version 5.3.0 is vulnerable to Insecure Permissions. By sending a request, you can add any device and set the device password in the Nokelock app.

    Published: 9 Oct 2023
    6.1
    Medium

    CVE-2023-44813

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a crafted payload to the mode parameter of the invite friend login function.

    Published: 9 Oct 2023
    8.8
    High

    CVE-2023-45355

    Last Modified: 21 Nov 2024

    Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 and 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access via the webservice. This is also known as OSFOURK-24120.

    Published: 9 Oct 2023
    6.7
    Medium

    CVE-2023-40654

    Last Modified: 21 Nov 2024

    In FW-PackageManager, there is a possible missing permission check. This could lead to local escalation of privilege with System execution privileges needed

    Published: 8 Oct 2023
    6.7
    Medium

    CVE-2023-40653

    Last Modified: 21 Nov 2024

    In FW-PackageManager, there is a possible missing permission check. This could lead to local escalation of privilege with System execution privileges needed

    Published: 8 Oct 2023
    4.4
    Medium

    CVE-2023-40652

    Last Modified: 21 Nov 2024

    In jpg driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with System execution privileges needed

    Published: 8 Oct 2023
    4.4
    Medium

    CVE-2023-40651

    Last Modified: 21 Nov 2024

    In urild service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

    Published: 8 Oct 2023
    5.5
    Medium

    CVE-2023-40650

    Last Modified: 21 Nov 2024

    In Telecom service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 8 Oct 2023
    5.5
    Medium

    CVE-2023-40649

    Last Modified: 21 Nov 2024

    In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 8 Oct 2023
    5.5
    Medium

    CVE-2023-40648

    Last Modified: 21 Nov 2024

    In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 8 Oct 2023
    5.5
    Medium

    CVE-2023-40647

    Last Modified: 21 Nov 2024

    In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 8 Oct 2023
    5.5
    Medium

    CVE-2023-40646

    Last Modified: 21 Nov 2024

    In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 8 Oct 2023
    5.5
    Medium

    CVE-2023-40645

    Last Modified: 21 Nov 2024

    In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 8 Oct 2023
    5.5
    Medium

    CVE-2023-40644

    Last Modified: 21 Nov 2024

    In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 8 Oct 2023
    5.5
    Medium

    CVE-2023-40643

    Last Modified: 21 Nov 2024

    In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 8 Oct 2023
    5.5
    Medium

    CVE-2023-40642

    Last Modified: 21 Nov 2024

    In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 8 Oct 2023
    5.5
    Medium

    CVE-2023-40641

    Last Modified: 21 Nov 2024

    In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 8 Oct 2023
    5.5
    Medium

    CVE-2023-40640

    Last Modified: 21 Nov 2024

    In SoundRecorder service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

    Published: 8 Oct 2023
    5.5
    Medium

    CVE-2023-40639

    Last Modified: 21 Nov 2024

    In SoundRecorder service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

    Published: 8 Oct 2023
    4.4
    Medium

    CVE-2023-40638

    Last Modified: 21 Nov 2024

    In Telecom service, there is a possible missing permission check. This could lead to local denial of service with System execution privileges needed

    Published: 8 Oct 2023
    5.5
    Medium

    CVE-2023-40637

    Last Modified: 21 Nov 2024

    In telecom service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

    Published: 8 Oct 2023
    4.4
    Medium

    CVE-2023-40636

    Last Modified: 21 Nov 2024

    In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with System execution privileges needed

    Published: 8 Oct 2023
    7.8
    High

    CVE-2023-40635

    Last Modified: 21 Nov 2024

    In linkturbo, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

    Published: 8 Oct 2023
    7.8
    High

    CVE-2023-40634

    Last Modified: 21 Nov 2024

    In phasechecksercer, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

    Published: 8 Oct 2023
    5.5
    Medium

    CVE-2023-40633

    Last Modified: 21 Nov 2024

    In phasecheckserver, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

    Published: 8 Oct 2023
    7.5
    High

    CVE-2023-40632

    Last Modified: 21 Nov 2024

    In jpg driver, there is a possible use after free due to a logic error. This could lead to remote information disclosure no additional execution privileges needed

    Published: 8 Oct 2023
    4.4
    Medium

    CVE-2023-40631

    Last Modified: 21 Nov 2024

    In Dialer, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed

    Published: 8 Oct 2023
    7.5
    High

    CVE-2023-43615

    Last Modified: 5 Jun 2026

    Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.

    Published: 7 Oct 2023
    9.8
    Critical

    CVE-2023-45199

    Last Modified: 5 Jun 2026

    Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.

    Published: 7 Oct 2023
    5.5
    Medium

    CVE-2023-5182

    Last Modified: 21 Nov 2024

    Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use this information to find hashed passwords and possibly escalate their privilege.

    Published: 6 Oct 2023
    3.7
    Low

    CVE-2022-33160

    Last Modified: 21 Nov 2024

    IBM Security Directory Suite 8.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 228568.

    Published: 6 Oct 2023
    4
    Medium

    CVE-2022-34355

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation (IBM Engineering Lifecycle Management 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) could disclose sensitive version information to a user that could be used in further attacks against the system. IBM X-Force ID: 230498.

    Published: 6 Oct 2023
    7.6
    High

    CVE-2023-3725

    Last Modified: 13 Feb 2025

    Potential buffer overflow vulnerability in the Zephyr CAN bus subsystem

    Published: 6 Oct 2023
    5.4
    Medium

    CVE-2023-5452

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.2.2.

    Published: 6 Oct 2023
    5.5
    Medium

    CVE-2023-21291

    Last Modified: 21 Nov 2024

    In visitUris of Notification.java, there is a possible way to reveal image contents from another user due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.

    Published: 6 Oct 2023
    7.8
    High

    CVE-2023-21266

    Last Modified: 5 May 2025

    In multiple functions of ActivityManagerService.java, there is a possible way to escape Google Play protection due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 6 Oct 2023
    5.5
    Medium

    CVE-2023-21253

    Last Modified: 21 Nov 2024

    In multiple locations, there is a possible way to crash multiple system services due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 6 Oct 2023
    5.5
    Medium

    CVE-2023-21252

    Last Modified: 21 Nov 2024

    In validatePassword of WifiConfigurationUtil.java, there is a possible way to get the device into a boot loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 6 Oct 2023
    6.7
    Medium

    CVE-2023-21244

    Last Modified: 1 May 2025

    In visitUris of Notification.java, there is a possible bypass of user profile boundaries due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

    Published: 6 Oct 2023
    6.5
    Medium

    CVE-2023-5214

    Last Modified: 21 Nov 2024

    In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.

    Published: 6 Oct 2023
    9.8
    Critical

    CVE-2023-45239

    Last Modified: 13 Feb 2025

    A lack of input validation exists in tac_plus prior to commit 4fdf178 which, when pre or post auth commands are enabled, allows an attacker who can control the username, rem-addr, or NAC address sent to tac_plus to inject shell commands and gain remote code execution on the tac_plus server.

    Published: 6 Oct 2023
    4.1
    Medium

    CVE-2023-44384

    Last Modified: 21 Nov 2024

    Discourse-jira is a Discourse plugin allows Jira projects, issue types, fields and field options will be synced automatically. An administrator user can make an SSRF attack by setting the Jira URL to an arbitrary location and enabling the `discourse_jira_verbose_log` site setting. A moderator user could manipulate the request path to the Jira API, allowing them to perform arbitrary GET requests using the Jira API credentials, potentially with elevated permissions, used by the application.

    Published: 6 Oct 2023
    —
    Unknown

    CVE-2023-45291

    Last Modified: 13 Feb 2026

    reserved but not needed

    Published: 6 Oct 2023
    3.8
    Low

    CVE-2023-32972

    Last Modified: 21 Nov 2024

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444 build 20230629 and later QTS 4.5.4.2467 build 20230718 and later QuTS hero h5.0.1.2515 build 20230907 and later QuTS hero h5.1.0.2424 build 20230609 and later QuTS hero h4.5.4.2476 build 20230728 and later QuTScloud c5.1.0.2498 and later

    Published: 6 Oct 2023
    3.8
    Low

    CVE-2023-32971

    Last Modified: 21 Nov 2024

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444 build 20230629 and later QTS 4.5.4.2467 build 20230718 and later QuTS hero h5.0.1.2515 build 20230907 and later QuTS hero h5.1.0.2424 build 20230609 and later QuTS hero h4.5.4.2476 build 20230728 and later QuTScloud c5.1.0.2498 and later

    Published: 6 Oct 2023
    5.2
    Medium

    CVE-2023-23371

    Last Modified: 21 Nov 2024

    A cleartext transmission of sensitive information vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated administrators to read sensitive data via unspecified vectors. We have already fixed the vulnerability in the following version: QVPN Windows 2.2.0.0823 and later

    Published: 6 Oct 2023
    6.7
    Medium

    CVE-2023-23370

    Last Modified: 21 Nov 2024

    An insufficiently protected credentials vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated administrators to gain access to user accounts and access sensitive data used by the user account via unspecified vectors. We have already fixed the vulnerability in the following version: QVPN Windows 2.1.0.0518 and later

    Published: 6 Oct 2023