CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2023-45224

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 5 Oct 2023
    9.8
    Critical

    CVE-2023-32485

    Last Modified: 21 Nov 2024

    Dell SmartFabric Storage Software version 1.3 and lower contain an improper input validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability and escalate privileges up to the highest administration level. This is a critical severity vulnerability affecting user authentication. Dell recommends customers to upgrade at the earliest opportunity.

    Published: 5 Oct 2023
    4.3
    Medium

    CVE-2023-43073

    Last Modified: 21 Nov 2024

    Dell SmartFabric Storage Software v1.4 (and earlier) contains an Improper Input Validation vulnerability in RADIUS configuration. An authenticated remote attacker could potentially exploit this vulnerability, leading to gaining unauthorized access to data.

    Published: 5 Oct 2023
    4.4
    Medium

    CVE-2023-43072

    Last Modified: 21 Nov 2024

    Dell SmartFabric Storage Software v1.4 (and earlier) contains an improper access control vulnerability in the CLI. A local possibly unauthenticated attacker could potentially exploit this vulnerability, leading to ability to execute arbritrary shell commands.

    Published: 5 Oct 2023
    4.4
    Medium

    CVE-2023-43071

    Last Modified: 21 Nov 2024

    Dell SmartFabric Storage Software v1.4 (and earlier) contains possible vulnerabilities for HTML injection or CVS formula injection which might escalate to cross-site scripting attacks in HTML pages in the GUI. A remote authenticated attacker could potentially exploit these issues, leading to various injection type attacks.

    Published: 5 Oct 2023
    5.3
    Medium

    CVE-2023-44386

    Last Modified: 21 Nov 2024

    Vapor is an HTTP web framework for Swift. There is a denial of service vulnerability impacting all users of affected versions of Vapor. The HTTP1 error handler closed connections when HTTP parse errors occur instead of passing them on. The issue is fixed as of Vapor release 4.84.2.

    Published: 5 Oct 2023
    6.3
    Medium

    CVE-2023-43070

    Last Modified: 21 Nov 2024

    Dell SmartFabric Storage Software v1.4 (and earlier) contains a Path Traversal Vulnerability in the HTTP interface. A remote authenticated attacker could potentially exploit this vulnerability, leading to modify or write arbitrary files to arbitrary locations in the license container.

    Published: 5 Oct 2023
    7.8
    High

    CVE-2023-43069

    Last Modified: 21 Nov 2024

    Dell SmartFabric Storage Software v1.4 (and earlier) contain(s) an OS Command Injection Vulnerability in the CLI. An authenticated local attacker could potentially exploit this vulnerability, leading to possible injection of parameters to curl or docker.

    Published: 5 Oct 2023
    7.8
    High

    CVE-2023-43068

    Last Modified: 21 Nov 2024

    Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the restricted shell in SSH. An authenticated remote attacker could potentially exploit this vulnerability, leading to execute arbitrary commands.

    Published: 5 Oct 2023
    8.8
    High

    CVE-2023-5346

    Last Modified: 1 May 2025

    Type confusion in V8 in Google Chrome prior to 117.0.5938.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 5 Oct 2023
    7.8
    High

    CVE-2023-4401

    Last Modified: 21 Nov 2024

    Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the CLI use of the ‘more’ command. A local or remote authenticated attacker could potentially exploit this vulnerability, leading to the ability to gain root-level access.

    Published: 5 Oct 2023
    4.7
    Medium

    CVE-2023-5423

    Last Modified: 21 Nov 2024

    A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/ajax.php?action=confirm_order. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The identifier of this vulnerability is VDB-241384.

    Published: 5 Oct 2023
    10
    Critical

    CVE-2023-2306

    Last Modified: 16 Jan 2025

    Qognify NiceVision versions 3.1 and prior are vulnerable to exposing sensitive information using hard-coded credentials. With these credentials an attacker can retrieve information about the cameras, user information, and modify database records.

    Published: 5 Oct 2023
    8.8
    High

    CVE-2023-4570

    Last Modified: 21 Nov 2024

    An improper access restriction in NI MeasurementLink Python services could allow an attacker on an adjacent network to reach services exposed on localhost. These services were previously thought to be unreachable outside of the node. This affects measurement plug-ins written in Python using version 1.1.0 of the ni-measurementlink-service Python package and all previous versions.

    Published: 5 Oct 2023
    8.8
    High

    CVE-2023-45160

    Last Modified: 18 Jun 2025

    In the affected version of the 1E Client, an ordinary user could subvert downloaded instruction resource files, e.g., to substitute a harmful script. by replacing a resource script file created by an instruction at run time with a malicious script. The 1E Client's temporary directory is now locked down in the released patch. Resolution: This has been fixed in patch Q23094  This issue has also been fixed in the Mac Client in updated versions of Non-Windows release v8.1.2.62 - please re-download from the 1E Support site. Customers with Mac Client versions higher than v8.1 will need to upgrade to v23.11 to remediate this vulnerability.

    Published: 5 Oct 2023
    6.1
    Medium

    CVE-2023-44390

    Last Modified: 21 Nov 2024

    HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. The vulnerability occurs in configurations where foreign content is allowed, i.e. either `svg` or `math` are in the list of allowed elements. In the case an application sanitizes user input with a vulnerable configuration, an attacker could bypass the sanitization and inject arbitrary HTML, including JavaScript code. Note that in the default configuration the vulnerability is not present. The vulnerability has been fixed in versions 8.0.723 and 8.1.722-beta (preview version).

    Published: 5 Oct 2023
    8.4
    High

    CVE-2023-45159

    Last Modified: 18 Jun 2025

    1E Client installer can perform arbitrary file deletion on protected files.   A non-privileged user could provide a symbolic link or Windows junction to point to a protected directory in the installer that the 1E Client would then clear on service startup. A hotfix is available from the 1E support portal that forces the 1E Client to check for a symbolic link or junction and if it finds one refuses to use that path and instead creates a path involving a random GUID. for v8.1 use hotfix Q23097 for v8.4 use hotfix Q23105 for v9.0 use hotfix Q23115 for SaaS customers, use 1EClient v23.7 plus hotfix Q23121

    Published: 5 Oct 2023
    —
    Unknown

    CVE-2023-32640

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 5 Oct 2023
    —
    Unknown

    CVE-2023-40149

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 5 Oct 2023
    —
    Unknown

    CVE-2023-43759

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 5 Oct 2023
    —
    Unknown

    CVE-2023-40538

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 5 Oct 2023
    —
    Unknown

    CVE-2023-42779

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 5 Oct 2023
    —
    Unknown

    CVE-2023-40147

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 5 Oct 2023
    3.2
    Low

    CVE-2023-44387

    Last Modified: 8 Oct 2026

    Gradle is a build tool with a focus on build automation and support for multi-language development. When copying or archiving symlinked files, Gradle resolves them but applies the permissions of the symlink itself instead of the permissions of the linked file to the resulting file. This leads to files having too much permissions given that symlinks usually are world readable and writeable. While it is unlikely this results in a direct vulnerability for the impacted build, it may open up attack vectors depending on where build artifacts end up being copied to or un-archived. In versions 7.6.3, 8.4 and above, Gradle will now properly use the permissions of the file pointed at by the symlink to set permissions of the copied or archived file.

    Published: 5 Oct 2023
    7.5
    High

    CVE-2023-44838

    Last Modified: 21 Nov 2024

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the TXPower parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 5 Oct 2023
    7.5
    High

    CVE-2023-44836

    Last Modified: 21 Nov 2024

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the SSID parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 5 Oct 2023
    7.5
    High

    CVE-2023-44829

    Last Modified: 21 Nov 2024

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the AdminPassword parameter in the SetDeviceSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 5 Oct 2023
    6.1
    Medium

    CVE-2023-43260

    Last Modified: 21 Nov 2024

    Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the admin panel.

    Published: 5 Oct 2023
    9.8
    Critical

    CVE-2023-43269

    Last Modified: 21 Nov 2024

    pigcms up to 7.0 was discovered to contain an arbitrary file upload vulnerability.

    Published: 5 Oct 2023
    5.4
    Medium

    CVE-2023-43343

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Files - Description parameter in the Pages Menu component.

    Published: 5 Oct 2023
    6.7
    Medium

    CVE-2023-26237

    Last Modified: 21 Nov 2024

    An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to bypass the defensive capabilities by adding a registry key as SYSTEM.

    Published: 5 Oct 2023
    5.5
    Medium

    CVE-2023-26238

    Last Modified: 21 Nov 2024

    An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to enable or disable defensive capabilities by sending a crafted message to a named pipe.

    Published: 5 Oct 2023
    5.5
    Medium

    CVE-2023-26239

    Last Modified: 21 Nov 2024

    An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of a password check, it is possible to obtain credentials to access the management console as a non-privileged user.

    Published: 5 Oct 2023
    7.5
    High

    CVE-2023-3171

    Last Modified: 21 Nov 2024

    A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed. This issue could allow an attacker to submit malicious requests using these classes, which could eventually exhaust the heap and result in a Denial of Service.

    Published: 5 Oct 2023
    8.1
    High

    CVE-2023-39323

    Last Modified: 12 Jun 2025

    Line directives ("//line") can be used to bypass the restrictions on "//go:cgo_" directives, allowing blocked linker and compiler flags to be passed during compilation. This can result in unexpected execution of arbitrary code when running "go build". The line directive requires the absolute path of the file in which the directive lives, which makes exploiting this issue significantly more complex.

    Published: 5 Oct 2023
    9.8
    Critical

    CVE-2023-40920

    Last Modified: 21 Nov 2024

    Prixan prixanconnect up to v1.62 was discovered to contain a SQL injection vulnerability via the component CartsGuruCatalogModuleFrontController::importProducts().

    Published: 5 Oct 2023
    8.8
    High

    CVE-2023-43284

    Last Modified: 21 Nov 2024

    D-Link Wireless MU-MIMO Gigabit AC1200 Router DIR-846 100A53DBR-Retail devices allow an authenticated remote attacker to execute arbitrary code via an unspecified manipulation of the QoS POST parameter.

    Published: 5 Oct 2023
    9.8
    Critical

    CVE-2023-43981

    Last Modified: 21 Nov 2024

    Presto Changeo testsitecreator up to 1.1.1 was discovered to contain a deserialization vulnerability via the component delete_excluded_folder.php.

    Published: 5 Oct 2023
    7.5
    High

    CVE-2023-44828

    Last Modified: 21 Nov 2024

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the CurrentPassword parameter in the CheckPasswdSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 5 Oct 2023
    7.5
    High

    CVE-2023-44830

    Last Modified: 21 Nov 2024

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the EndTime parameter in the SetParentsControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 5 Oct 2023
    7.5
    High

    CVE-2023-44831

    Last Modified: 21 Nov 2024

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Type parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 5 Oct 2023
    7.5
    High

    CVE-2023-44832

    Last Modified: 21 Nov 2024

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the MacAddress parameter in the SetWanSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 5 Oct 2023
    7.5
    High

    CVE-2023-44833

    Last Modified: 21 Nov 2024

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the GuardInt parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 5 Oct 2023
    7.5
    High

    CVE-2023-44834

    Last Modified: 21 Nov 2024

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the StartTime parameter in the SetParentsControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 5 Oct 2023
    7.5
    High

    CVE-2023-44835

    Last Modified: 21 Nov 2024

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Mac parameter in the SetParentsControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 5 Oct 2023
    7.5
    High

    CVE-2023-44837

    Last Modified: 21 Nov 2024

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Password parameter in the SetWanSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 5 Oct 2023
    7.5
    High

    CVE-2023-44839

    Last Modified: 21 Nov 2024

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Encryption parameter in the SetWLanRadioSecurity function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 5 Oct 2023
    7.5
    High

    CVE-2023-45198

    Last Modified: 21 Nov 2024

    ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the portable version of NetBSD ftpd) before 20231001 is also vulnerable.

    Published: 5 Oct 2023
    —
    Unknown

    CVE-2023-45251

    Last Modified: 26 Dec 2023

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 5 Oct 2023
    6.5
    Medium

    CVE-2023-4061

    Last Modified: 7 Nov 2025

    A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system.

    Published: 5 Oct 2023