CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2023-32823

    Last Modified: 21 Nov 2024

    In rpmb , there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07912966; Issue ID: ALPS07912966.

    Published: 2 Oct 2023
    6.7
    Medium

    CVE-2023-32822

    Last Modified: 21 Nov 2024

    In ftm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07994229; Issue ID: ALPS07994229.

    Published: 2 Oct 2023
    6.7
    Medium

    CVE-2023-32821

    Last Modified: 21 Nov 2024

    In video, there is a possible out of bounds write due to a permissions bypass. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08013430; Issue ID: ALPS08013433.

    Published: 2 Oct 2023
    7.5
    High

    CVE-2023-32820

    Last Modified: 21 Nov 2024

    In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637; Issue ID: ALPS07932637.

    Published: 2 Oct 2023
    4.4
    Medium

    CVE-2023-32819

    Last Modified: 21 Nov 2024

    In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07993705; Issue ID: ALPS08014138.

    Published: 2 Oct 2023
    9.8
    Critical

    CVE-2023-20819

    Last Modified: 21 Nov 2024

    In CDMA PPP protocol, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: MOLY01068234; Issue ID: ALPS08010003.

    Published: 2 Oct 2023
    4.3
    Medium

    CVE-2023-5329

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic was found in Field Logic DataCube4 up to 20231001. This vulnerability affects unknown code of the file /api/ of the component Web API. The manipulation leads to improper authentication. The exploit has been disclosed to the public and may be used. VDB-241030 is the identifier assigned to this vulnerability.

    Published: 2 Oct 2023
    9.8
    Critical

    CVE-2023-44011

    Last Modified: 21 Nov 2024

    An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin management component.

    Published: 2 Oct 2023
    9.8
    Critical

    CVE-2023-43891

    Last Modified: 21 Nov 2024

    Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function. This vulnerability is exploited via a crafted payload.

    Published: 2 Oct 2023
    5.5
    Medium

    CVE-2023-37605

    Last Modified: 21 Nov 2024

    Weak Exception Handling vulnerability in baramundi software GmbH EMM Agent 23.1.50 and before allows an attacker to cause a denial of service via a crafted request to the password parameter.

    Published: 2 Oct 2023
    6.2
    Medium

    CVE-2023-5341

    Last Modified: 20 Nov 2025

    A heap use-after-free flaw was found in coders/bmp.c in ImageMagick.

    Published: 2 Oct 2023
    7.8
    High

    CVE-2023-43361

    Last Modified: 4 Nov 2025

    Buffer Overflow vulnerability in Vorbis-tools v.1.4.2 allows a local attacker to execute arbitrary code and cause a denial of service during the conversion of wav files to ogg files.

    Published: 2 Oct 2023
    9.8
    Critical

    CVE-2023-43893

    Last Modified: 21 Nov 2024

    Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the Wake-On-LAN (WoL) function. This vulnerability is exploited via a crafted payload.

    Published: 2 Oct 2023
    7.5
    High

    CVE-2023-41580

    Last Modified: 21 Nov 2024

    Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerability allows attackers to enumerate arbitrary fields in the LDAP server and access sensitive data via a crafted POST request.

    Published: 2 Oct 2023
    5.4
    Medium

    CVE-2023-43267

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the publish article function of emlog pro v2.1.14 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title field.

    Published: 2 Oct 2023
    8.8
    High

    CVE-2023-43268

    Last Modified: 21 Nov 2024

    Deyue Remote Vehicle Management System v1.1 was discovered to contain a deserialization vulnerability.

    Published: 2 Oct 2023
    5.4
    Medium

    CVE-2023-43297

    Last Modified: 21 Nov 2024

    An issue in animal-art-lab v13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.

    Published: 2 Oct 2023
    8.8
    High

    CVE-2023-43835

    Last Modified: 21 Nov 2024

    Super Store Finder 3.7 and below is vulnerable to authenticated Arbitrary PHP Code Injection that could lead to Remote Code Execution when settings overwrite config.inc.php content.

    Published: 2 Oct 2023
    6.5
    Medium

    CVE-2023-43836

    Last Modified: 21 Nov 2024

    There is a SQL injection vulnerability in the Jizhicms 2.4.9 backend, which users can use to obtain database information

    Published: 2 Oct 2023
    8.8
    High

    CVE-2023-43890

    Last Modified: 21 Nov 2024

    Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the diagnostic tools page. This vulnerability is exploited via a crafted HTTP request.

    Published: 2 Oct 2023
    9.8
    Critical

    CVE-2023-43892

    Last Modified: 4 Apr 2025

    Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the Hostname parameter within the WAN settings. This vulnerability is exploited via a crafted payload.

    Published: 2 Oct 2023
    9.8
    Critical

    CVE-2023-43980

    Last Modified: 21 Nov 2024

    Presto Changeo testsitecreator up to v1.1.1 was discovered to contain a SQL injection vulnerability via the component disable_json.php.

    Published: 2 Oct 2023
    9.8
    Critical

    CVE-2023-44008

    Last Modified: 21 Nov 2024

    File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.

    Published: 2 Oct 2023
    9.8
    Critical

    CVE-2023-44009

    Last Modified: 21 Nov 2024

    File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function.

    Published: 2 Oct 2023
    6.1
    Medium

    CVE-2023-44012

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the helpkey parameter in the Help.aspx component.

    Published: 2 Oct 2023
    5.3
    Medium

    CVE-2023-44463

    Last Modified: 21 Nov 2024

    An issue was discovered in pretix before 2023.7.1. Incorrect parsing of configuration files causes the application to trust unchecked X-Forwarded-For headers even though it has not been configured to do so. This can lead to IP address spoofing by users of the application.

    Published: 2 Oct 2023
    —
    Unknown

    CVE-2023-44793

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 2 Oct 2023
    7.8
    High

    CVE-2023-5345

    Last Modified: 20 Mar 2025

    A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege escalation. In case of an error in smb3_fs_context_parse_param, ctx->password was freed but the field was not set to NULL which could lead to double free. We recommend upgrading past commit e6e43b8aa7cd3c3af686caf0c2e11819a886d705.

    Published: 2 Oct 2023
    7.5
    High

    CVE-2023-5344

    Last Modified: 3 Nov 2025

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.

    Published: 2 Oct 2023
    6.3
    Medium

    CVE-2023-5328

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in SATO CL4NX-J Plus 1.13.2-u455_r2. This affects an unknown part of the component Cookie Handler. The manipulation with the input auth=user,level1,settings; web=true leads to improper authentication. Access to the local network is required for this attack. The exploit has been disclosed to the public and may be used. The identifier VDB-241029 was assigned to this vulnerability.

    Published: 1 Oct 2023
    3.5
    Low

    CVE-2023-5327

    Last Modified: 21 Nov 2024

    A vulnerability was found in SATO CL4NX-J Plus 1.13.2-u455_r2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /rest/dir/. The manipulation of the argument full leads to path traversal. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-241028.

    Published: 1 Oct 2023
    6.3
    Medium

    CVE-2023-5326

    Last Modified: 21 Nov 2024

    A vulnerability was found in SATO CL4NX-J Plus 1.13.2-u455_r2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component WebConfig. The manipulation leads to improper authentication. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-241027.

    Published: 1 Oct 2023
    4.3
    Medium

    CVE-2023-5324

    Last Modified: 18 Jun 2025

    A vulnerability has been found in eeroOS up to 6.16.4-11 and classified as critical. This vulnerability affects unknown code of the component Ethernet Interface. The manipulation leads to denial of service. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-241024.

    Published: 1 Oct 2023
    4.7
    Medium

    CVE-2023-5322

    Last Modified: 21 Nov 2024

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20151231. It has been rated as critical. Affected by this issue is some unknown functionality of the file /sysmanage/edit_manageadmin.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240992. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

    Published: 1 Oct 2023
    6.1
    Medium

    CVE-2023-5323

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr prior to 18.0.

    Published: 1 Oct 2023
    7.8
    High

    CVE-2023-43907

    Last Modified: 21 Nov 2024

    OptiPNG v0.7.7 was discovered to contain a global buffer overflow via the 'buffer' variable at gifread.c.

    Published: 1 Oct 2023
    5.5
    Medium

    CVE-2023-5441

    Last Modified: 13 Feb 2025

    NULL Pointer Dereference in GitHub repository vim/vim prior to 20d161ace307e28690229b68584f2d84556f8960.

    Published: 1 Oct 2023
    5.4
    Medium

    CVE-2023-5112

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "specials_type_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-5111

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "featured_type_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43735

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "formats_titles[7]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43734

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "name" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43733

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "company_address" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43732

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "tax_class_title" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43731

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "zone_name" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43730

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "countries_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43729

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "xsell_type_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43728

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "stock_delivery_terms_text[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43727

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "stock_indication_text[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43726

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "orders_products_status_manual_name_long[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43725

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "orders_products_status_name_long[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023