CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2023-5285

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in Tongda OA 2017. Affected by this vulnerability is an unknown functionality of the file general/hr/recruit/recruitment/delete.php. The manipulation of the argument RECRUITMENT_ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-240913 was assigned to this vulnerability.

    Published: 29 Sept 2023
    6.3
    Medium

    CVE-2023-5284

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in SourceCodester Engineers Online Portal 1.0. Affected is an unknown function of the file upload_save_student.php. The manipulation of the argument uploaded_file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240912.

    Published: 29 Sept 2023
    6.3
    Medium

    CVE-2023-5283

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been rated as critical. This issue affects some unknown processing of the file teacher_signup.php. The manipulation of the argument firstname/lastname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240911.

    Published: 29 Sept 2023
    6.3
    Medium

    CVE-2023-5282

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file seed_message_student.php. The manipulation of the argument teacher_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-240910 is the identifier assigned to this vulnerability.

    Published: 29 Sept 2023
    6.3
    Medium

    CVE-2023-5281

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been classified as critical. This affects an unknown part of the file remove_inbox_message.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240909 was assigned to this vulnerability.

    Published: 29 Sept 2023
    6.3
    Medium

    CVE-2023-5280

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Engineers Online Portal 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file my_students.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240908.

    Published: 29 Sept 2023
    6.3
    Medium

    CVE-2023-5279

    Last Modified: 21 Nov 2024

    A vulnerability has been found in SourceCodester Engineers Online Portal 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file my_classmates.php. The manipulation of the argument teacher_class_student_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240907.

    Published: 29 Sept 2023
    6.3
    Medium

    CVE-2023-5278

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in SourceCodester Engineers Online Portal 1.0. Affected is an unknown function of the file login.php. The manipulation of the argument username/password leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-240906 is the identifier assigned to this vulnerability.

    Published: 29 Sept 2023
    6.3
    Medium

    CVE-2023-5277

    Last Modified: 18 Jun 2025

    A vulnerability, which was classified as critical, has been found in SourceCodester Engineers Online Portal 1.0. This issue affects some unknown processing of the file student_avatar.php. The manipulation of the argument change leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240905 was assigned to this vulnerability.

    Published: 29 Sept 2023
    8
    High

    CVE-2023-26218

    Last Modified: 21 Nov 2024

    The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim's local system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Nimbus: versions 10.6.0 and below.

    Published: 29 Sept 2023
    6.3
    Medium

    CVE-2023-5276

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in SourceCodester Engineers Online Portal 1.0. This vulnerability affects unknown code of the file downloadable_student.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The identifier of this vulnerability is VDB-240904.

    Published: 29 Sept 2023
    5.9
    Medium

    CVE-2023-3024

    Last Modified: 21 Nov 2024

    Forcing the Bluetooth LE stack to segment 'prepare write response' packets can lead to an out-of-bounds memory access.

    Published: 29 Sept 2023
    3.5
    Low

    CVE-2023-5273

    Last Modified: 23 Dec 2024

    A vulnerability classified as problematic was found in SourceCodester Best Courier Management System 1.0. This vulnerability affects unknown code of the file manage_parcel_status.php. The manipulation of the argument id leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-240886 is the identifier assigned to this vulnerability.

    Published: 29 Sept 2023
    5.5
    Medium

    CVE-2023-5272

    Last Modified: 30 Sept 2025

    A vulnerability classified as critical has been found in SourceCodester Best Courier Management System 1.0. This affects an unknown part of the file edit_parcel.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-240885 was assigned to this vulnerability.

    Published: 29 Sept 2023
    5.5
    Medium

    CVE-2023-5271

    Last Modified: 30 Sept 2025

    A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file edit_parcel.php. The manipulation of the argument email leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240884.

    Published: 29 Sept 2023
    5.5
    Medium

    CVE-2023-5270

    Last Modified: 30 Sept 2025

    A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file view_parcel.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240883.

    Published: 29 Sept 2023
    5.1
    Medium

    CVE-2023-5269

    Last Modified: 6 Mar 2025

    A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as critical. Affected is an unknown function of the file parcel_list.php of the component GET Parameter Handler. The manipulation of the argument id/s leads to sql injection. The exploit has been disclosed to the public and may be used.

    Published: 29 Sept 2023
    6.3
    Medium

    CVE-2023-5268

    Last Modified: 21 Nov 2024

    A vulnerability was found in DedeBIZ 6.2 and classified as critical. This issue affects some unknown processing of the file /src/admin/makehtml_taglist_action.php. The manipulation of the argument mktime leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240881 was assigned to this vulnerability.

    Published: 29 Sept 2023
    5.5
    Medium

    CVE-2023-5267

    Last Modified: 21 Nov 2024

    A vulnerability has been found in Tongda OA 2017 and classified as critical. This vulnerability affects unknown code of the file general/hr/recruit/hr_pool/delete.php. The manipulation of the argument EXPERT_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-240880.

    Published: 29 Sept 2023
    6.3
    Medium

    CVE-2023-5266

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in DedeBIZ 6.2. This affects an unknown part of the file /src/admin/tags_main.php. The manipulation of the argument ids leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240879.

    Published: 29 Sept 2023
    5.5
    Medium

    CVE-2023-5265

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in Tongda OA 2017. Affected by this issue is some unknown functionality of the file general/hr/manage/staff_transfer/delete.php. The manipulation of the argument TRANSFER_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-240878 is the identifier assigned to this vulnerability.

    Published: 29 Sept 2023
    6.3
    Medium

    CVE-2023-5264

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in huakecms 3.0. Affected by this vulnerability is an unknown functionality of the file /admin/cms_content.php. The manipulation of the argument cid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240877 was assigned to this vulnerability.

    Published: 29 Sept 2023
    6.3
    Medium

    CVE-2023-5263

    Last Modified: 18 Jun 2025

    A vulnerability was found in ZZZCMS 2.1.7 and classified as critical. Affected by this issue is the function restore of the file /admin/save.php of the component Database Backup File Handler. The manipulation leads to permission issues. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240872.

    Published: 29 Sept 2023
    7.1
    High

    CVE-2023-39308

    Last Modified: 5 Feb 2025

    Unauth. Stored Cross-Site Scripting (XSS) vulnerability in UserFeedback Team User Feedback plugin <= 1.0.7 versions.

    Published: 29 Sept 2023
    —
    Unknown

    CVE-2023-5290

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 29 Sept 2023
    8.8
    High

    CVE-2023-5289

    Last Modified: 21 Nov 2024

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.4.

    Published: 29 Sept 2023
    7.1
    High

    CVE-2023-41691

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Pensopay WooCommerce PensoPay plugin <= 6.3.1 versions.

    Published: 29 Sept 2023
    6.5
    Medium

    CVE-2023-41687

    Last Modified: 21 Nov 2024

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Irina Sokolovskaya Goods Catalog plugin <= 2.4.1 versions.

    Published: 29 Sept 2023
    6.5
    Medium

    CVE-2023-41666

    Last Modified: 21 Nov 2024

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Stockdio Stock Quotes List plugin <= 2.9.9 versions.

    Published: 29 Sept 2023
    7.1
    High

    CVE-2023-41663

    Last Modified: 19 Feb 2025

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Giovambattista Fazioli WP Bannerize Pro plugin <= 1.6.9 versions.

    Published: 29 Sept 2023
    7.1
    High

    CVE-2023-41662

    Last Modified: 19 Feb 2025

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ulf Benjaminsson WP-dTree plugin <= 4.4.5 versions.

    Published: 29 Sept 2023
    5.9
    Medium

    CVE-2023-41661

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PressPage Entertainment Inc. Smarty for WordPress plugin <= 3.1.35 versions.

    Published: 29 Sept 2023
    7.1
    High

    CVE-2023-41658

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Photo Gallery Slideshow & Masonry Tiled Gallery plugin <= 1.0.13 versions.

    Published: 29 Sept 2023
    6.3
    Medium

    CVE-2023-5262

    Last Modified: 21 Nov 2024

    A vulnerability has been found in OpenRapid RapidCMS 1.3.1 and classified as critical. Affected by this vulnerability is the function isImg of the file /admin/config/uploadicon.php. The manipulation of the argument fileName leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240871.

    Published: 29 Sept 2023
    5.9
    Medium

    CVE-2023-41657

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Groundhogg Inc. HollerBox plugin <= 2.3.2 versions.

    Published: 29 Sept 2023
    5.9
    Medium

    CVE-2023-41655

    Last Modified: 6 Mar 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Andreas Heigl authLdap plugin <= 2.5.9 versions.

    Published: 29 Sept 2023
    5.5
    Medium

    CVE-2023-5261

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in Tongda OA 2017. Affected is an unknown function of the file general/hr/manage/staff_title_evaluation/delete.php. The manipulation of the argument EVALUATION_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-240870 is the identifier assigned to this vulnerability.

    Published: 29 Sept 2023
    6.3
    Medium

    CVE-2023-5260

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in SourceCodester Simple Membership System 1.0. This issue affects some unknown processing of the file group_validator.php. The manipulation of the argument club_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240869 was assigned to this vulnerability.

    Published: 29 Sept 2023
    9.8
    Critical

    CVE-2023-5288

    Last Modified: 9 Dec 2024

    A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings. The adversary may also reset the SIM and in the worst case upload a new firmware version to the device.

    Published: 29 Sept 2023
    2.7
    Low

    CVE-2023-5259

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic was found in ForU CMS. This vulnerability affects unknown code of the file /admin/cms_admin.php. The manipulation of the argument del leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of this vulnerability is VDB-240868.

    Published: 29 Sept 2023
    6.3
    Medium

    CVE-2023-5258

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in OpenRapid RapidCMS 1.3.1. This affects an unknown part of the file /resource/addgood.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240867.

    Published: 29 Sept 2023
    3.5
    Low

    CVE-2023-5257

    Last Modified: 21 Nov 2024

    A vulnerability was found in WhiteHSBG JNDIExploit 1.4 on Windows. It has been rated as problematic. Affected by this issue is the function handleFileRequest of the file src/main/java/com/feihong/ldap/HTTPServer.java. The manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. VDB-240866 is the identifier assigned to this vulnerability.

    Published: 29 Sept 2023
    2.7
    Low

    CVE-2023-5194

    Last Modified: 21 Nov 2024

    Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manager to demote / deactivate another manager

    Published: 29 Sept 2023
    6.5
    Medium

    CVE-2023-5195

    Last Modified: 21 Nov 2024

    Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of

    Published: 29 Sept 2023
    4.9
    Medium

    CVE-2023-5193

    Last Modified: 21 Nov 2024

    Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to manage channels to read the posts of a DM conversation.

    Published: 29 Sept 2023
    6.5
    Medium

    CVE-2023-5196

    Last Modified: 21 Nov 2024

    Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_prop resulting in the server consuming an abnormal quantity of computing resources and possibly becoming temporarily unavailable for its users.

    Published: 29 Sept 2023
    3.8
    Low

    CVE-2023-5159

    Last Modified: 21 Nov 2024

    Mattermost fails to properly verify the permissions when managing/updating a bot allowing a User Manager role with user edit permissions to manage/update bots.

    Published: 29 Sept 2023
    6.5
    Medium

    CVE-2023-3413

    Last Modified: 20 Nov 2025

    An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to read the source code of a project through a fork created before changing visibility to only project members.

    Published: 29 Sept 2023
    3
    Low

    CVE-2023-3922

    Last Modified: 25 Apr 2026

    An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to hijack some links and buttons on the GitLab UI to a malicious page.

    Published: 29 Sept 2023
    7.8
    High

    CVE-2023-32477

    Last Modified: 21 Nov 2024

    Dell Common Event Enabler 8.9.8.2 for Windows and prior, contain an improper access control vulnerability. A local low-privileged malicious user may potentially exploit this vulnerability to gain elevated privileges.

    Published: 29 Sept 2023