CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2023-5198

    Last Modified: 20 Nov 2025

    An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys.

    Published: 29 Sept 2023
    4.3
    Medium

    CVE-2023-0989

    Last Modified: 20 Nov 2025

    An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration.

    Published: 29 Sept 2023
    3.1
    Low

    CVE-2023-2233

    Last Modified: 20 Nov 2025

    An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5 and all versions starting from 16.4 before 16.4.1. It allows a project reporter to leak the owner's Sentry instance projects.

    Published: 29 Sept 2023
    5.4
    Medium

    CVE-2023-3115

    Last Modified: 20 Nov 2025

    An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only project repositories.

    Published: 29 Sept 2023
    4.3
    Medium

    CVE-2023-3920

    Last Modified: 25 Apr 2026

    An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation.

    Published: 29 Sept 2023
    4.3
    Medium

    CVE-2023-3917

    Last Modified: 20 Nov 2025

    Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail.

    Published: 29 Sept 2023
    5.4
    Medium

    CVE-2023-3914

    Last Modified: 20 Nov 2025

    A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.

    Published: 29 Sept 2023
    3.5
    Low

    CVE-2023-3906

    Last Modified: 20 Nov 2025

    An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.

    Published: 29 Sept 2023
    3.1
    Low

    CVE-2023-3979

    Last Modified: 20 Nov 2025

    An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that upstream members to collaborate with you on your branch get permission to write to the merge request’s source branch.

    Published: 29 Sept 2023
    4.3
    Medium

    CVE-2023-4532

    Last Modified: 26 Apr 2026

    An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. Users were capable of linking CI/CD jobs of private projects which they are not a member of.

    Published: 29 Sept 2023
    7.5
    High

    CVE-2023-30591

    Last Modified: 21 Nov 2024

    Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `eventName.toString()`, while processing Socket.IO messages via crafted Socket.IO messages containing array or object type for the event name respectively.

    Published: 29 Sept 2023
    5.3
    Medium

    CVE-2023-26147

    Last Modified: 21 Nov 2024

    All versions of the package ithewei/libhv are vulnerable to HTTP Response Splitting when untrusted user input is used to build headers values. An attacker can add the \r\n (carriage return line feeds) characters to end the HTTP response headers and inject malicious content, like for example additional headers or new response body, leading to a potential XSS vulnerability.

    Published: 29 Sept 2023
    5.4
    Medium

    CVE-2023-26148

    Last Modified: 21 Nov 2024

    All versions of the package ithewei/libhv are vulnerable to CRLF Injection when untrusted user input is used to set request headers. An attacker can add the \r\n (carriage return line feeds) characters and inject additional headers in the request sent.

    Published: 29 Sept 2023
    6.1
    Medium

    CVE-2023-26146

    Last Modified: 21 Nov 2024

    All versions of the package ithewei/libhv are vulnerable to Cross-site Scripting (XSS) such that when a file with a name containing a malicious payload is served by the application, the filename is displayed without proper sanitization when it is rendered.

    Published: 29 Sept 2023
    4.3
    Medium

    CVE-2023-44469

    Last Modified: 21 Nov 2024

    A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter. This is similar to CVE-2020-10770.

    Published: 29 Sept 2023
    8.8
    High

    CVE-2023-44466

    Last Modified: 23 May 2025

    An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, leading to a buffer overflow and remote code execution via HELLO or one of the AUTH frames. This occurs because of an untrusted length taken from a TCP packet in ceph_decode_32.

    Published: 29 Sept 2023
    7.5
    High

    CVE-2023-39410

    Last Modified: 13 Feb 2025

    When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue.

    Published: 29 Sept 2023
    8.8
    High

    CVE-2022-35908

    Last Modified: 21 Nov 2024

    Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent.

    Published: 29 Sept 2023
    6.1
    Medium

    CVE-2023-39193

    Last Modified: 6 Nov 2025

    A flaw was found in the Netfilter subsystem in the Linux kernel. The sctp_mt_check did not validate the flag_count field. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, leading to a crash or information disclosure.

    Published: 29 Sept 2023
    8.2
    High

    CVE-2023-39191

    Last Modified: 6 Nov 2025

    An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. This may allow an attacker with CAP_BPF privileges to escalate privileges and execute arbitrary code in the context of the kernel.

    Published: 29 Sept 2023
    9.1
    Critical

    CVE-2023-43909

    Last Modified: 21 Nov 2024

    Hospital Management System thru commit 4770d was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.

    Published: 29 Sept 2023
    7.8
    High

    CVE-2023-44464

    Last Modified: 21 Nov 2024

    pretix before 2023.7.2 allows Pillow to parse EPS files.

    Published: 29 Sept 2023
    5.4
    Medium

    CVE-2023-43944

    Last Modified: 27 Jan 2026

    A Stored Cross Site Scripting (XSS) vulnerability was found in SourceCodester Task Management System 1.0. It allows attackers to execute arbitrary code via parameter field in index.php?page=project_list.

    Published: 29 Sept 2023
    5.3
    Medium

    CVE-2023-44270

    Last Modified: 3 Nov 2025

    An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being included in a comment.

    Published: 29 Sept 2023
    3.2
    Low

    CVE-2023-39194

    Last Modified: 6 Nov 2025

    A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an information disclosure.

    Published: 29 Sept 2023
    6.7
    Medium

    CVE-2023-39192

    Last Modified: 8 Nov 2025

    A flaw was found in the Netfilter subsystem in the Linux kernel. The xt_u32 module did not validate the fields in the xt_u32 structure. This flaw allows a local privileged attacker to trigger an out-of-bounds read by setting the size fields with a value beyond the array boundaries, leading to a crash or information disclosure.

    Published: 29 Sept 2023
    7.6
    High

    CVE-2023-5077

    Last Modified: 21 Nov 2024

    The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets. Fixed in Vault 1.13.0.

    Published: 28 Sept 2023
    4.2
    Medium

    CVE-2023-3775

    Last Modified: 21 Nov 2024

    A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespace can be applied to requests outside in another non-descendant namespace, potentially resulting in denial of service. Fixed in Vault Enterprise 1.15.0, 1.14.4, 1.13.8.

    Published: 28 Sept 2023
    10
    Critical

    CVE-2023-43654

    Last Modified: 13 Feb 2025

    TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper input validation, enabling third parties to invoke remote HTTP download requests and write files to the disk. This issue could be taken advantage of to compromise the integrity of the system and sensitive data. This issue is present in versions 0.1.0 to 0.8.1. A user is able to load the model of their choice from any URL that they would like to use. The user of TorchServe is responsible for configuring both the allowed_urls and specifying the model URL to be used. A pull request to warn the user when the default value for allowed_urls is used has been merged in PR #2534. TorchServe release 0.8.2 includes this change. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 28 Sept 2023
    —
    Unknown

    CVE-2023-44168

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 28 Sept 2023
    8.6
    High

    CVE-2023-43662

    Last Modified: 21 Nov 2024

    ShokoServer is a media server which specializes in organizing anime. In affected versions the `/api/Image/WithPath` endpoint is accessible without authentication and is supposed to return default server images. The endpoint accepts the parameter `serverImagePath`, which is not sanitized in any way before being passed to `System.IO.File.OpenRead`, which results in an arbitrary file read. This issue may lead to an arbitrary file read which is exacerbated in the windows installer which installs the ShokoServer as administrator. Any unauthenticated attacker may be able to access sensitive information and read files stored on the server. The `/api/Image/WithPath` endpoint has been removed in commit `6c57ba0f0` which will be included in subsequent releases. Users should limit access to the `/api/Image/WithPath` endpoint or manually patch their installations until a patched release is made. This issue was discovered by the GitHub Security lab and is also indexed as GHSL-2023-191.

    Published: 28 Sept 2023
    —
    Unknown

    CVE-2023-44167

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 28 Sept 2023
    9.8
    Critical

    CVE-2023-44166

    Last Modified: 21 Nov 2024

    The 'age' parameter of the process_registration.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 28 Sept 2023
    —
    Unknown

    CVE-2023-44165

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 28 Sept 2023
    9.8
    Critical

    CVE-2023-44164

    Last Modified: 21 Nov 2024

    The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 28 Sept 2023
    9.8
    Critical

    CVE-2023-44163

    Last Modified: 21 Nov 2024

    The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 28 Sept 2023
    9.8
    Critical

    CVE-2023-43739

    Last Modified: 21 Nov 2024

    The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 28 Sept 2023
    6.4
    Medium

    CVE-2023-44174

    Last Modified: 21 Nov 2024

    Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Stored Cross-Site Scripting vulnerability.

    Published: 28 Sept 2023
    8.8
    High

    CVE-2023-43014

    Last Modified: 21 Nov 2024

    Asset Management System v1.0 is vulnerable to an Authenticated SQL Injection vulnerability on the 'first_name' and 'last_name' parameters of user.php page, allowing an authenticated attacker to dump all the contents of the database contents.

    Published: 28 Sept 2023
    9.8
    Critical

    CVE-2023-43013

    Last Modified: 21 Nov 2024

    Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.

    Published: 28 Sept 2023
    5.4
    Medium

    CVE-2023-44173

    Last Modified: 21 Nov 2024

    Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Reflected Cross-Site Scripting vulnerability.

    Published: 28 Sept 2023
    9.1
    Critical

    CVE-2023-5185

    Last Modified: 21 Nov 2024

    Gym Management System Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'file' parameter of profile/i.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

    Published: 28 Sept 2023
    8.8
    High

    CVE-2023-43740

    Last Modified: 21 Nov 2024

    Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_edit.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

    Published: 28 Sept 2023
    9.8
    Critical

    CVE-2023-5053

    Last Modified: 21 Nov 2024

    Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.

    Published: 28 Sept 2023
    9.8
    Critical

    CVE-2023-5004

    Last Modified: 21 Nov 2024

    Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.

    Published: 28 Sept 2023
    7.5
    High

    CVE-2023-4316

    Last Modified: 3 Dec 2025

    Zod in versions 3.21.0 up to and including 3.22.3 allows an attacker to perform a denial of service while validating emails.

    Published: 28 Sept 2023
    7.5
    High

    CVE-2023-5256

    Last Modified: 21 Nov 2024

    In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause sensitive information to be cached and made available to anonymous users, leading to privilege escalation. This vulnerability only affects sites with the JSON:API module enabled, and can be mitigated by uninstalling JSON:API. The core REST and contributed GraphQL modules are not affected.

    Published: 28 Sept 2023
    4.3
    Medium

    CVE-2023-43664

    Last Modified: 21 Nov 2024

    PrestaShop is an Open Source e-commerce web application. In the Prestashop Back office interface, an employee can list all modules without any access rights: method `ajaxProcessGetPossibleHookingListForModule` doesn't check access rights. This issue has been addressed in commit `15bd281c` which is included in version 8.1.2. Users are advised to upgrade. There are no known workaround for this issue.

    Published: 28 Sept 2023
    6.3
    Medium

    CVE-2023-43663

    Last Modified: 21 Nov 2024

    PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled from back office, even with low user right. This allows low privileged users to disable portions of a shops functionality. Commit `ce1f6708` addresses this issue and is included in version 8.1.2. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 28 Sept 2023
    7.2
    High

    CVE-2023-43657

    Last Modified: 21 Nov 2024

    discourse-encrypt is a plugin that provides a secure communication channel through Discourse. Improper escaping of encrypted topic titles could lead to a cross site scripting (XSS) issue when a site has content security policy (CSP) headers disabled. Having CSP disabled is a non-default configuration, and having it disabled with discourse-encrypt installed will result in a warning in the Discourse admin dashboard. This has been fixed in commit `9c75810af9` which is included in the latest version of the discourse-encrypt plugin. Users are advised to upgrade. Users unable to upgrade should ensure that CSP headers are enabled and properly configured.

    Published: 28 Sept 2023