CVE Feed

    Dashboard / CVE

    8.6
    High

    CVE-2023-3037

    Last Modified: 21 Nov 2024

    Improper authorization vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a remote attacker to access the platform without authentication and retrieve personal data via the jsonGrid parameter.

    Published: 4 Oct 2023
    9.9
    Critical

    CVE-2023-4037

    Last Modified: 21 Nov 2024

    Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local attacker to obtain sensitive data stored in the database by sending a specially crafted SQL query to the xml parameter.

    Published: 4 Oct 2023
    5.4
    Medium

    CVE-2023-4090

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) reflected vulnerability on WideStand until 5.3.5 version, which generates one of the meta tags directly using the content of the queried URL, which would allow an attacker to inject HTML/Javascript code into the response.

    Published: 4 Oct 2023
    9.9
    Critical

    CVE-2023-3701

    Last Modified: 21 Nov 2024

    Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerability, an authenticated non privileged user could access/modify stored resources of other users. It could also be possible to access and modify the source and configuration files of the cloud disk platform, affecting the integrity and availability of the entire platform.

    Published: 4 Oct 2023
    8.8
    High

    CVE-2023-4997

    Last Modified: 3 Mar 2025

    Improper authorisation of regular users in ProIntegra Uptime DC software (versions below 2.0.0.33940) allows them to change passwords of all other users including administrators leading to a privilege escalation.

    Published: 4 Oct 2023
    7.5
    High

    CVE-2023-3512

    Last Modified: 21 Nov 2024

    Relative path traversal vulnerability in Setelsa Security's ConacWin CB, in its 3.8.2.2 version and earlier, the exploitation of which could allow an attacker to perform an arbitrary download of files from the system via the "Download file" parameter.

    Published: 4 Oct 2023
    7.8
    High

    CVE-2023-2809

    Last Modified: 21 Nov 2024

    Plaintext credential usage vulnerability in Sage 200 Spain 2023.38.001 version, the exploitation of which could allow a remote attacker to extract SQL database credentials from the DLL application. This vulnerability could be linked to known techniques to obtain remote execution of MS SQL commands and escalate privileges on Windows systems because the credentials are stored in plaintext.

    Published: 4 Oct 2023
    4.3
    Medium

    CVE-2023-25489

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Jeff Sherk Update Theme and Plugins from Zip File plugin <= 2.0.0 versions.

    Published: 4 Oct 2023
    6.3
    Medium

    CVE-2023-25788

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Saphali Saphali Woocommerce Lite plugin <= 1.8.13 versions.

    Published: 4 Oct 2023
    4.3
    Medium

    CVE-2023-25980

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in CAGE Web Design | Rolf van Gelder Optimize Database after Deleting Revisions plugin <= 5.1 versions.

    Published: 4 Oct 2023
    4.3
    Medium

    CVE-2023-37995

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole WP-CopyProtect [Protect your blog posts] plugin <= 3.1.0 versions.

    Published: 4 Oct 2023
    7.1
    High

    CVE-2023-5377

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in GitHub repository gpac/gpac prior to v2.2.2-DEV.

    Published: 4 Oct 2023
    6.1
    Medium

    CVE-2023-5375

    Last Modified: 21 Nov 2024

    Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2.

    Published: 4 Oct 2023
    5.4
    Medium

    CVE-2023-44272

    Last Modified: 21 Nov 2024

    A cross-site scripting vulnerability exists in Citadel versions prior to 994. When a malicious user sends an instant message with some JavaScript code, the script may be executed on the web browser of the victim user.

    Published: 4 Oct 2023
    5.5
    Medium

    CVE-2023-5370

    Last Modified: 13 Feb 2025

    On CPU 0 the check for the SMCCC workaround is called before SMCCC support has been initialized. This resulted in no speculative execution workarounds being installed on CPU 0.

    Published: 4 Oct 2023
    7.1
    High

    CVE-2023-5369

    Last Modified: 13 Feb 2025

    Before correction, the copy_file_range system call checked only for the CAP_READ and CAP_WRITE capabilities on the input and output file descriptors, respectively. Using an offset is logically equivalent to seeking, and the system call must additionally require the CAP_SEEK capability. This incorrect privilege check enabled sandboxed processes with only read or write but no seek capability on a file descriptor to read data from or write data to an arbitrary location within the file corresponding to that file descriptor.

    Published: 4 Oct 2023
    6.5
    Medium

    CVE-2023-5368

    Last Modified: 21 Nov 2024

    On an msdosfs filesystem, the 'truncate' or 'ftruncate' system calls under certain circumstances populate the additional space in the file with unallocated data from the underlying disk device, rather than zero bytes. This may permit a user with write access to files on a msdosfs filesystem to read unintended data (e.g. from a previously deleted file).

    Published: 4 Oct 2023
    5.5
    Medium

    CVE-2023-30738

    Last Modified: 21 Nov 2024

    An improper input validation in UEFI Firmware prior to Firmware update Oct-2023 Release in Galaxy Book, Galaxy Book Pro, Galaxy Book Pro 360 and Galaxy Book Odyssey allows local attacker to execute SMM memory corruption.

    Published: 4 Oct 2023
    4
    Medium

    CVE-2023-30737

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive information via implicit intent.

    Published: 4 Oct 2023
    4.4
    Medium

    CVE-2023-30736

    Last Modified: 21 Nov 2024

    Improper authorization in PushMsgReceiver of Samsung Assistant prior to version 8.7.00.1 allows attacker to execute javascript interface. To trigger this vulnerability, user interaction is required.

    Published: 4 Oct 2023
    5.1
    Medium

    CVE-2023-30735

    Last Modified: 21 Nov 2024

    Improper Preservation of Permissions vulnerability in SAssistant prior to version 8.7 allows local attackers to access backup data in SAssistant.

    Published: 4 Oct 2023
    4
    Medium

    CVE-2023-30734

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive information via implicit intent.

    Published: 4 Oct 2023
    7.8
    High

    CVE-2023-30733

    Last Modified: 21 Nov 2024

    Stack-based Buffer Overflow in vulnerability HDCP trustlet prior to SMR Oct-2023 Release 1 allows local privileged attackers to perform code execution.

    Published: 4 Oct 2023
    5.5
    Medium

    CVE-2023-30732

    Last Modified: 21 Nov 2024

    Improper access control in system property prior to SMR Oct-2023 Release 1 allows local attacker to get CPU serial number.

    Published: 4 Oct 2023
    5.7
    Medium

    CVE-2023-30731

    Last Modified: 21 Nov 2024

    Logic error in package installation via debugger command prior to SMR Oct-2023 Release 1 allows physical attacker to install an application that has different build type.

    Published: 4 Oct 2023
    6.7
    Medium

    CVE-2023-30727

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in SecSettings prior to SMR Oct-2023 Release 1 allows attackers to enable Wi-Fi and connect arbitrary Wi-Fi without User Interaction.

    Published: 4 Oct 2023
    8.5
    High

    CVE-2023-30692

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.

    Published: 4 Oct 2023
    8.5
    High

    CVE-2023-30690

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.

    Published: 4 Oct 2023
    6.4
    Medium

    CVE-2023-5291

    Last Modified: 8 Apr 2026

    The Blog Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'AWL-BlogFilter' shortcode in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 4 Oct 2023
    5.3
    Medium

    CVE-2023-3213

    Last Modified: 8 Apr 2026

    The WP Mail SMTP Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_print_page function in versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to disclose potentially sensitive email information.

    Published: 4 Oct 2023
    6.4
    Medium

    CVE-2023-5357

    Last Modified: 8 Apr 2026

    The Instagram for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 4 Oct 2023
    6.4
    Medium

    CVE-2023-37404

    Last Modified: 21 Nov 2024

    IBM Observability with Instana 1.0.243 through 1.0.254 could allow an attacker on the network to execute arbitrary code on the host after a successful DNS poisoning attack. IBM X-Force ID: 259789.

    Published: 4 Oct 2023
    4.6
    Medium

    CVE-2023-35905

    Last Modified: 21 Nov 2024

    IBM FileNet Content Manager 5.5.8, 5.5.10, and 5.5.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 259384.

    Published: 4 Oct 2023
    7.5
    High

    CVE-2023-43261

    Last Modified: 4 Jul 2026

    An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.

    Published: 4 Oct 2023
    4.8
    Medium

    CVE-2023-43877

    Last Modified: 21 Nov 2024

    Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a payload crafted in the Home Page fields in the Administration menu.

    Published: 4 Oct 2023
    7.8
    High

    CVE-2023-40299

    Last Modified: 21 Nov 2024

    Kong Insomnia 2023.4.0 on macOS allows attackers to execute code and access restricted files, or make requests for TCC permissions, by using the DYLD_INSERT_LIBRARIES environment variable.

    Published: 4 Oct 2023
    9.8
    Critical

    CVE-2023-36619

    Last Modified: 21 Nov 2024

    Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users.

    Published: 4 Oct 2023
    8.8
    High

    CVE-2023-36618

    Last Modified: 21 Nov 2024

    Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-privileged authenticated users.

    Published: 4 Oct 2023
    9.8
    Critical

    CVE-2023-35803

    Last Modified: 21 Nov 2024

    IQ Engine before 10.6r2 on Extreme Network AP devices has a Buffer Overflow.

    Published: 4 Oct 2023
    8.1
    High

    CVE-2023-22618

    Last Modified: 21 Nov 2024

    If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users with administrative privileges by manipulating a web request. This affects (for example) WaveLite Metro 200 and Fan, WaveLite Metro 200 OPS and Fans, WaveLite Metro 200 and F2B fans, WaveLite Metro 200 OPS and F2B fans, WaveLite Metro 200 NE and F2B fans, and WaveLite Metro 200 NE OPS and F2B fans.

    Published: 4 Oct 2023
    7.2
    High

    CVE-2023-5408

    Last Modified: 7 Nov 2025

    A privilege escalation flaw was found in the node restriction admission plugin of the kubernetes api server of OpenShift. A remote attacker who modifies the node role label could steer workloads from the control plane and etcd nodes onto different worker nodes and gain broader access to the cluster.

    Published: 4 Oct 2023
    5.5
    Medium

    CVE-2023-43789

    Last Modified: 6 Nov 2025

    A vulnerability was found in libXpm where a vulnerability exists due to a boundary condition, a local user can trigger an out-of-bounds read error and read contents of memory on the system.

    Published: 4 Oct 2023
    5.5
    Medium

    CVE-2023-43786

    Last Modified: 6 Nov 2025

    A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available system resources and cause a denial of service condition.

    Published: 4 Oct 2023
    6.5
    Medium

    CVE-2023-43785

    Last Modified: 6 Nov 2025

    A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() function. This flaw allows a local user to trigger an out-of-bounds read error and read the contents of memory on the system.

    Published: 4 Oct 2023
    5.5
    Medium

    CVE-2023-43788

    Last Modified: 6 Nov 2025

    A vulnerability was found in libXpm due to a boundary condition within the XpmCreateXpmImageFromBuffer() function. This flaw allows a local attacker to trigger an out-of-bounds read error and read the contents of memory on the system.

    Published: 4 Oct 2023
    6.1
    Medium

    CVE-2023-27121

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the component /framework/cron/action/humanize of Pleasant Solutions Pleasant Password Server v7.11.41.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cronString parameter.

    Published: 4 Oct 2023
    8.8
    High

    CVE-2023-43321

    Last Modified: 21 Nov 2024

    File Upload vulnerability in Digital China Networks DCFW-1800-SDC v.3.0 allows an authenticated attacker to execute arbitrary code via the wget function in the /sbin/cloudadmin.sh component.

    Published: 4 Oct 2023
    7.8
    High

    CVE-2023-43787

    Last Modified: 6 Nov 2025

    A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges.

    Published: 4 Oct 2023
    7.8
    High

    CVE-2023-43838

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar.

    Published: 4 Oct 2023
    5.4
    Medium

    CVE-2023-44075

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in Small CRM in PHP v.3.0 allows a remote attacker to execute arbitrary code via a crafted payload to the Address parameter.

    Published: 4 Oct 2023