CVE Feed

    Dashboard / CVE

    7.4
    High

    CVE-2023-22382

    Last Modified: 27 Feb 2025

    Weak configuration in Automotive while VM is processing a listener request from TEE.

    Published: 3 Oct 2023
    8.7
    High

    CVE-2023-21673

    Last Modified: 11 Aug 2025

    Improper Access to the VM resource manager can lead to Memory Corruption.

    Published: 3 Oct 2023
    7.5
    High

    CVE-2023-26152

    Last Modified: 21 Nov 2024

    All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath function of server.js.

    Published: 3 Oct 2023
    6.5
    Medium

    CVE-2023-26150

    Last Modified: 21 Nov 2024

    Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space without encryption and authentication. **Note:** This issue is a result of missing checks for services that require an active session.

    Published: 3 Oct 2023
    5.3
    Medium

    CVE-2023-26151

    Last Modified: 21 Nov 2024

    Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a result, the server will enter into an infinite loop and consume excessive memory.

    Published: 3 Oct 2023
    6.4
    Medium

    CVE-2023-5334

    Last Modified: 8 Apr 2026

    The WP Responsive header image slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sp_responsiveslider' shortcode in versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 3 Oct 2023
    8.4
    High

    CVE-2023-3440

    Last Modified: 21 Nov 2024

    Incorrect Default Permissions vulnerability in Hitachi JP1/Performance Management on Windows allows File Manipulation.This issue affects JP1/Performance Management - Manager: from 09-00 before 12-50-07; JP1/Performance Management - Base: from 09-00 through 10-50-*; JP1/Performance Management - Agent Option for Application Server: from 11-00 before 11-50-16; JP1/Performance Management - Agent Option for Enterprise Applications: from 09-00 before 12-00-14; JP1/Performance Management - Agent Option for HiRDB: from 09-00 before 12-00-14; JP1/Performance Management - Agent Option for IBM Lotus Domino: from 10-00 before 11-50-16; JP1/Performance Management - Agent Option for Microsoft(R) Exchange Server: from 09-00 before  12-00-14; JP1/Performance Management - Agent Option for Microsoft(R) Internet Information Server: from 09-00 before 12-00-14; JP1/Performance Management - Agent Option for Microsoft(R) SQL Server: from 09-00 before 12-50-07; JP1/Performance Management - Agent Option for Oracle: from 09-00 before  12-10-08; JP1/Performance Management - Agent Option for Platform: from 09-00 before 12-50-07; JP1/Performance Management - Agent Option for Service Response: from 09-00 before 11-50-16; JP1/Performance Management - Agent Option for Transaction System: from 11-00 before 12-00-14; JP1/Performance Management - Remote Monitor for Microsoft(R) SQL Server: from 09-00 before 12-50-07; JP1/Performance Management - Remote Monitor for Oracle: from 09-00 before 12-10-08; JP1/Performance Management - Remote Monitor for Platform: from 09-00 before 12-10-08; JP1/Performance Management - Remote Monitor for Virtual Machine: from 10-00 before 12-50-07; JP1/Performance Management - Agent Option for Domino: from 09-00 through 09-00-*; JP1/Performance Management - Agent Option for IBM WebSphere Application Server: from 09-00 through 10-00-*; JP1/Performance Management - Agent Option for IBM WebSphere MQ: from 09-00 through 10-00-*; JP1/Performance Management - Agent Option for JP1/AJS3: from 09-00 through 10-00-*; JP1/Performance Management - Agent Option for OpenTP1: from 09-00 through 10-00-*; JP1/Performance Management - Agent Option for Oracle WebLogic Server: from 09-00 through 10-00-*; JP1/Performance Management - Agent Option for uCosminexus Application Server: from 09-00 through 10-00-*; JP1/Performance Management - Agent Option for Virtual Machine: from 09-00 through 09-01-*.

    Published: 3 Oct 2023
    5.3
    Medium

    CVE-2023-3967

    Last Modified: 21 Nov 2024

    Allocation of Resources Without Limits or Throttling vulnerability in Hitachi Ops Center Common Services on Linux allows DoS.This issue affects Hitachi Ops Center Common Services: before 10.9.3-00.

    Published: 3 Oct 2023
    6.5
    Medium

    CVE-2023-3335

    Last Modified: 21 Nov 2024

    Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator on Linux allows local users  to gain sensitive information.This issue affects Hitachi Ops Center Administrator: before 10.9.3-00.

    Published: 3 Oct 2023
    5.7
    Medium

    CVE-2023-43627

    Last Modified: 21 Nov 2024

    Path traversal vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adjacent authenticated attacker to alter critical information such as system files by sending a specially crafted request. They are affected when running in ST(Standalone) mode.

    Published: 3 Oct 2023
    8.8
    High

    CVE-2023-42771

    Last Modified: 21 Nov 2024

    Authentication bypass vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adjacent unauthenticated attacker who can access the affected product to download configuration files and/or log files, and upload configuration files and/or firmware. They are affected when running in ST(Standalone) mode.

    Published: 3 Oct 2023
    8.8
    High

    CVE-2023-41086

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability exists in FURUNO SYSTEMS wireless LAN access point devices. If a user views a malicious page while logged in, unintended operations may be performed. Affected products and versions are as follows: ACERA 1210 firmware ver.02.36 and earlier, ACERA 1150i firmware ver.01.35 and earlier, ACERA 1150w firmware ver.01.35 and earlier, ACERA 1110 firmware ver.01.76 and earlier, ACERA 1020 firmware ver.01.86 and earlier, ACERA 1010 firmware ver.01.86 and earlier, ACERA 950 firmware ver.01.60 and earlier, ACERA 850F firmware ver.01.60 and earlier, ACERA 900 firmware ver.02.54 and earlier, ACERA 850M firmware ver.02.06 and earlier, ACERA 810 firmware ver.03.74 and earlier, and ACERA 800ST firmware ver.07.35 and earlier. They are affected when running in ST(Standalone) mode.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-39429

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to inject an arbitrary script via a crafted configuration. Affected products and versions are as follows: ACERA 1210 firmware ver.02.36 and earlier, ACERA 1150i firmware ver.01.35 and earlier, ACERA 1150w firmware ver.01.35 and earlier, ACERA 1110 firmware ver.01.76 and earlier, ACERA 1020 firmware ver.01.86 and earlier, ACERA 1010 firmware ver.01.86 and earlier, ACERA 950 firmware ver.01.60 and earlier, ACERA 850F firmware ver.01.60 and earlier, ACERA 900 firmware ver.02.54 and earlier, ACERA 850M firmware ver.02.06 and earlier, ACERA 810 firmware ver.03.74 and earlier, and ACERA 800ST firmware ver.07.35 and earlier. They are affected when running in ST(Standalone) mode.

    Published: 3 Oct 2023
    8.8
    High

    CVE-2023-39222

    Last Modified: 21 Nov 2024

    OS command injection vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to execute an arbitrary OS command that is not intended to be executed from the web interface by sending a specially crafted request. Affected products and versions are as follows: ACERA 1320 firmware ver.01.26 and earlier, ACERA 1310 firmware ver.01.26 and earlier, ACERA 1210 firmware ver.02.36 and earlier, ACERA 1150i firmware ver.01.35 and earlier, ACERA 1150w firmware ver.01.35 and earlier, ACERA 1110 firmware ver.01.76 and earlier, ACERA 1020 firmware ver.01.86 and earlier, ACERA 1010 firmware ver.01.86 and earlier, ACERA 950 firmware ver.01.60 and earlier, ACERA 850F firmware ver.01.60 and earlier, ACERA 900 firmware ver.02.54 and earlier, ACERA 850M firmware ver.02.06 and earlier, ACERA 810 firmware ver.03.74 and earlier, and ACERA 800ST firmware ver.07.35 and earlier. They are affected when running in ST(Standalone) mode.

    Published: 3 Oct 2023
    4.4
    Medium

    CVE-2023-5255

    Last Modified: 20 Nov 2025

    For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.

    Published: 3 Oct 2023
    2.6
    Low

    CVE-2023-46159

    Last Modified: 21 Nov 2024

    IBM Storage Ceph 5.3z1, 5.3z5, and 6.1z1 could allow an authenticated user on the network to cause a denial of service from RGW. IBM X-Force ID: 268906.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-43952

    Last Modified: 21 Nov 2024

    SSCMS 7.2.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Material Management component.

    Published: 3 Oct 2023
    6.1
    Medium

    CVE-2023-40519

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the bpk-common/auth/login/index.html login portal in Broadpeak Centralized Accounts Management Auth Agent 01.01.00.19219575_ee9195b0, 01.01.01.30097902_fd999e76, and 00.12.01.9565588_1254b459 allows remote attackers to inject arbitrary web script or HTML via the disconnectMessage parameter.

    Published: 3 Oct 2023
    9.8
    Critical

    CVE-2023-33269

    Last Modified: 21 Nov 2024

    An issue was discovered in DTS Monitoring 3.57.0. The parameter options within the WGET check function is vulnerable to OS command injection (blind).

    Published: 3 Oct 2023
    9.8
    Critical

    CVE-2023-33268

    Last Modified: 21 Nov 2024

    An issue was discovered in DTS Monitoring 3.57.0. The parameter port within the SSL Certificate check function is vulnerable to OS command injection (blind).

    Published: 3 Oct 2023
    9.8
    Critical

    CVE-2023-39645

    Last Modified: 21 Nov 2024

    Improper neutralization of SQL parameter in Theme Volty CMS Payment Icon module for PrestaShop. In the module “Theme Volty CMS Payment Icon” (tvcmspaymenticon) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

    Published: 3 Oct 2023
    9.8
    Critical

    CVE-2023-39651

    Last Modified: 21 Nov 2024

    Improper neutralization of SQL parameter in Theme Volty CMS BrandList module for PrestaShop In the module “Theme Volty CMS BrandList” (tvcmsbrandlist) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

    Published: 3 Oct 2023
    9.8
    Critical

    CVE-2023-33270

    Last Modified: 21 Nov 2024

    An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the Curl check function is vulnerable to OS command injection (blind).

    Published: 3 Oct 2023
    9.8
    Critical

    CVE-2023-33271

    Last Modified: 21 Nov 2024

    An issue was discovered in DTS Monitoring 3.57.0. The parameter common_name within the SSL Certificate check function is vulnerable to OS command injection (blind).

    Published: 3 Oct 2023
    9.8
    Critical

    CVE-2023-33272

    Last Modified: 21 Nov 2024

    An issue was discovered in DTS Monitoring 3.57.0. The parameter ip within the Ping check function is vulnerable to OS command injection (blind).

    Published: 3 Oct 2023
    9.8
    Critical

    CVE-2023-39646

    Last Modified: 21 Nov 2024

    Improper neutralization of SQL parameter in Theme Volty CMS Category Chain Slider module for PrestaShop. In the module “Theme Volty CMS Category Chain Slide"(tvcmscategorychainslider) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

    Published: 3 Oct 2023
    9.8
    Critical

    CVE-2023-39647

    Last Modified: 21 Nov 2024

    Improper neutralization of SQL parameter in Theme Volty CMS Category Product module for PrestaShop. In the module “Theme Volty CMS Category Product” (tvcmscategoryproduct) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

    Published: 3 Oct 2023
    9.8
    Critical

    CVE-2023-39648

    Last Modified: 21 Nov 2024

    Improper neutralization of SQL parameter in Theme Volty CMS Testimonial module for PrestaShop. In the module “Theme Volty CMS Testimonial” (tvcmstestimonial) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

    Published: 3 Oct 2023
    9.8
    Critical

    CVE-2023-39649

    Last Modified: 21 Nov 2024

    Improper neutralization of SQL parameter in Theme Volty CMS Category Slider module for PrestaShop. In the module “Theme Volty CMS Category Slider” (tvcmscategoryslider) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

    Published: 3 Oct 2023
    9.8
    Critical

    CVE-2023-40830

    Last Modified: 17 Jun 2025

    Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length.

    Published: 3 Oct 2023
    8.8
    High

    CVE-2023-43176

    Last Modified: 21 Nov 2024

    A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplying a crafted .sabredav file.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-43953

    Last Modified: 29 May 2025

    SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.

    Published: 3 Oct 2023
    5.5
    Medium

    CVE-2023-43898

    Last Modified: 17 Jun 2025

    Nothings stb 2.28 was discovered to contain a Null Pointer Dereference via the function stbi__convert_format. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted pic file.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-43951

    Last Modified: 21 Nov 2024

    SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Column Management component.

    Published: 3 Oct 2023
    8.1
    High

    CVE-2023-43976

    Last Modified: 21 Nov 2024

    An issue in CatoNetworks CatoClient before v.5.4.0 allows attackers to escalate privileges and winning the race condition (TOCTOU) via the PrivilegedHelperTool component.

    Published: 3 Oct 2023
    9.8
    Critical

    CVE-2023-44973

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

    Published: 3 Oct 2023
    9.8
    Critical

    CVE-2023-44974

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

    Published: 3 Oct 2023
    7.5
    High

    CVE-2023-4692

    Last Modified: 7 Nov 2025

    An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection bypass may be achieved.

    Published: 3 Oct 2023
    5.3
    Medium

    CVE-2023-4693

    Last Modified: 7 Nov 2025

    An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attacker to present a specially crafted NTFS file system image to read arbitrary memory locations. A successful attack allows sensitive data cached in memory or EFI variable values to be leaked, presenting a high Confidentiality risk.

    Published: 3 Oct 2023
    7.4
    High

    CVE-2023-40548

    Last Modified: 20 Nov 2025

    A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed from the PE binary being used by Shim. This value is further used for memory allocation operations, leading to a heap-based buffer overflow. This flaw causes memory corruption and can lead to a crash or data integrity issues during the boot phase.

    Published: 3 Oct 2023
    9.8
    Critical

    CVE-2023-33273

    Last Modified: 21 Nov 2024

    An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the WGET check function is vulnerable to OS command injection (blind).

    Published: 3 Oct 2023
    8.8
    High

    CVE-2023-36628

    Last Modified: 21 Nov 2024

    A flaw exists in VASA which allows users with access to a vSphere/ESXi VMware admin on a FlashArray to gain root access through privilege escalation.

    Published: 2 Oct 2023
    6.5
    Medium

    CVE-2023-32572

    Last Modified: 21 Nov 2024

    A flaw exists in FlashArray Purity wherein under limited circumstances, an array administrator can alter the retention lock of a pgroup and disable pgroup SafeMode protection.

    Published: 2 Oct 2023
    4.4
    Medium

    CVE-2023-28373

    Last Modified: 21 Nov 2024

    A flaw exists in FlashArray Purity whereby an array administrator by configuring an external key manager can affect the availability of data on the system including snapshots protected by SafeMode.

    Published: 2 Oct 2023
    7.7
    High

    CVE-2023-36627

    Last Modified: 21 Nov 2024

    A flaw exists in FlashBlade Purity whereby a user with access to an administrative account on a FlashBlade that is configured with timezone-dependent snapshot schedules can configure a timezone to prevent the schedule from functioning properly.

    Published: 2 Oct 2023
    7.7
    High

    CVE-2023-31042

    Last Modified: 21 Nov 2024

    A flaw exists in FlashBlade Purity whereby an authenticated user with access to FlashBlade’s object store protocol can impact the availability of the system’s data access and replication protocols.

    Published: 2 Oct 2023
    6.5
    Medium

    CVE-2023-28372

    Last Modified: 21 Nov 2024

    A flaw exists in FlashBlade Purity (OE) Version 4.1.0 whereby a user with privileges to extend an object’s retention period can affect the availability of the object lock.

    Published: 2 Oct 2023
    9.8
    Critical

    CVE-2023-4659

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the platform as an administrator, simply by changing the token value to "admin". It is also possible to perform POST, GET and DELETE requests without any token value. Therefore, an unprivileged remote user is able to create, delete and modify users within theapplication.

    Published: 2 Oct 2023
    6.3
    Medium

    CVE-2015-10124

    Last Modified: 21 Nov 2024

    A vulnerability was found in Most Popular Posts Widget Plugin up to 0.8 on WordPress. It has been classified as critical. Affected is the function add_views/show_views of the file functions.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. Upgrading to version 0.9 is able to address this issue. The patch is identified as a99667d11ac8d320006909387b100e9a8b5c12e1. It is recommended to upgrade the affected component. VDB-241026 is the identifier assigned to this vulnerability.

    Published: 2 Oct 2023
    9.9
    Critical

    CVE-2023-3744

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to internal services or upload the contents of relevant files via the "scrape_image.php" file in the imageURL parameter.

    Published: 2 Oct 2023