CVE Feed

    Dashboard / CVE

    2.2
    Low

    CVE-2023-4505

    Last Modified: 8 Apr 2026

    The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 1.2.3. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the LDAP server and retrieve the credentials for the original LDAP server.

    Published: 26 Sept 2023
    2.2
    Low

    CVE-2023-4506

    Last Modified: 8 Apr 2026

    The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the LDAP server and retrieve the credentials for the original LDAP server.

    Published: 26 Sept 2023
    7.5
    High

    CVE-2022-48606

    Last Modified: 21 Nov 2024

    Stability-related vulnerability in the binder background management and control module. Successful exploitation of this vulnerability may affect availability.

    Published: 26 Sept 2023
    5.3
    Medium

    CVE-2023-4565

    Last Modified: 21 Nov 2024

    Broadcast permission control vulnerability in the framework module. Successful exploitation of this vulnerability may cause the hotspot feature to be unavailable.

    Published: 26 Sept 2023
    5.3
    Medium

    CVE-2023-41312

    Last Modified: 21 Nov 2024

    Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several apps to be activated automatically.

    Published: 26 Sept 2023
    5.3
    Medium

    CVE-2023-41311

    Last Modified: 21 Nov 2024

    Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause an app to be activated automatically.

    Published: 26 Sept 2023
    3.3
    Low

    CVE-2023-41310

    Last Modified: 21 Nov 2024

    Keep-alive vulnerability in the sticky broadcast mechanism. Successful exploitation of this vulnerability may cause malicious apps to run continuously in the background.

    Published: 26 Sept 2023
    7.5
    High

    CVE-2023-41309

    Last Modified: 21 Nov 2024

    Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of this vulnerability may affect availability.

    Published: 26 Sept 2023
    7.5
    High

    CVE-2023-41308

    Last Modified: 21 Nov 2024

    Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality.

    Published: 26 Sept 2023
    7.5
    High

    CVE-2023-41307

    Last Modified: 21 Nov 2024

    Memory overwriting vulnerability in the security module. Successful exploitation of this vulnerability may affect availability.

    Published: 26 Sept 2023
    3.7
    Low

    CVE-2023-41306

    Last Modified: 21 Nov 2024

    Vulnerability of mutex management in the bone voice ID trusted application (TA) module. Successful exploitation of this vulnerability may cause the bone voice ID feature to be unavailable.

    Published: 26 Sept 2023
    7.5
    High

    CVE-2023-41305

    Last Modified: 21 Nov 2024

    Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS message module. Successful exploitation of this vulnerability may affect confidentiality.

    Published: 26 Sept 2023
    9.8
    Critical

    CVE-2023-5176

    Last Modified: 1 May 2025

    Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

    Published: 26 Sept 2023
    5.3
    Medium

    CVE-2023-44216

    Last Modified: 21 Nov 2024

    PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one origin if they control a resource from a different origin.

    Published: 26 Sept 2023
    3.7
    Low

    CVE-2023-22025

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u381-perf, 17.0.8, 21; Oracle GraalVM for JDK: 17.0.8, 21; Oracle GraalVM Enterprise Edition: 21.3.7 and 22.3.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition,. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).

    Published: 26 Sept 2023
    7.5
    High

    CVE-2023-5557

    Last Modified: 20 Nov 2025

    A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.

    Published: 26 Sept 2023
    9.8
    Critical

    CVE-2023-43154

    Last Modified: 21 Nov 2024

    In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in "isValidLogin()" function during login attempt results in PHP type confusion vulnerability that leads to authentication bypass and takeover of the administrator account.

    Published: 26 Sept 2023
    9.8
    Critical

    CVE-2021-38243

    Last Modified: 18 Jun 2025

    xunruicms up to v4.5.1 was discovered to contain a remote code execution (RCE) vulnerability in /index.php. This vulnerability allows attackers to execute arbitrary code via a crafted GET request.

    Published: 26 Sept 2023
    9.8
    Critical

    CVE-2023-5168

    Last Modified: 1 May 2025

    A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

    Published: 26 Sept 2023
    8.8
    High

    CVE-2023-35793

    Last Modified: 21 Nov 2024

    An issue was discovered in Cassia Access Controller 2.1.1.2303271039. Establishing a web SSH session to gateways is vulnerable to Cross Site Request Forgery (CSRF) attacks.

    Published: 26 Sept 2023
    5.4
    Medium

    CVE-2023-41904

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs.

    Published: 26 Sept 2023
    9.8
    Critical

    CVE-2023-43187

    Last Modified: 21 Nov 2024

    A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests.

    Published: 26 Sept 2023
    9.8
    Critical

    CVE-2023-43216

    Last Modified: 21 Nov 2024

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.

    Published: 26 Sept 2023
    9.8
    Critical

    CVE-2023-43222

    Last Modified: 21 Nov 2024

    SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.

    Published: 26 Sept 2023
    5.4
    Medium

    CVE-2023-43232

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the Website column management function of DedeBIZ v6.2.11 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter.

    Published: 26 Sept 2023
    9.8
    Critical

    CVE-2023-43234

    Last Modified: 21 Nov 2024

    DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at /admin/file_manage_control.php via the $activepath and $filename parameters.

    Published: 26 Sept 2023
    6.1
    Medium

    CVE-2023-43263

    Last Modified: 21 Nov 2024

    A Cross-site scripting (XSS) vulnerability in Froala Editor v.4.1.1 allows attackers to execute arbitrary code via the Markdown component.

    Published: 26 Sept 2023
    9.8
    Critical

    CVE-2023-43291

    Last Modified: 21 Nov 2024

    Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php component.

    Published: 26 Sept 2023
    5.4
    Medium

    CVE-2023-43331

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the Add User function of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

    Published: 26 Sept 2023
    7.5
    High

    CVE-2023-43381

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in Tianchoy Blog v.1.8.8 allows a remote attacker to obtain sensitive information via the id parameter in the login.php

    Published: 26 Sept 2023
    7.5
    High

    CVE-2023-43856

    Last Modified: 4 Apr 2025

    Dreamer CMS v4.1.3 was discovered to contain an arbitrary file read vulnerability via the component /admin/TemplateController.java.

    Published: 26 Sept 2023
    5.4
    Medium

    CVE-2023-43857

    Last Modified: 4 Apr 2025

    Dreamer CMS v4.1.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component /admin/u/toIndex.

    Published: 26 Sept 2023
    5.4
    Medium

    CVE-2023-44042

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in /settings/index.php of Black Cat CMS 1.4.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website header parameter.

    Published: 26 Sept 2023
    6.1
    Medium

    CVE-2023-44043

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in /install/index.php of Black Cat CMS 1.4.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website title parameter.

    Published: 26 Sept 2023
    7.2
    High

    CVE-2023-44044

    Last Modified: 21 Nov 2024

    Super Store Finder v3.6 and below was discovered to contain a SQL injection vulnerability via the Search parameter at /admin/stores.php.

    Published: 26 Sept 2023
    9.8
    Critical

    CVE-2023-44169

    Last Modified: 21 Nov 2024

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.

    Published: 26 Sept 2023
    9.8
    Critical

    CVE-2023-44170

    Last Modified: 21 Nov 2024

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.

    Published: 26 Sept 2023
    9.8
    Critical

    CVE-2023-44171

    Last Modified: 21 Nov 2024

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.

    Published: 26 Sept 2023
    9.8
    Critical

    CVE-2023-44172

    Last Modified: 21 Nov 2024

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.

    Published: 26 Sept 2023
    6.5
    Medium

    CVE-2023-5169

    Last Modified: 13 Feb 2025

    A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

    Published: 26 Sept 2023
    6.5
    Medium

    CVE-2023-5171

    Last Modified: 13 Feb 2025

    During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

    Published: 26 Sept 2023
    9.8
    Critical

    CVE-2023-5174

    Last Modified: 5 May 2025

    If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash. *This bug only affects Firefox on Windows when run in non-standard configurations (such as using `runas`). Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

    Published: 26 Sept 2023
    7.1
    High

    CVE-2023-5366

    Last Modified: 13 Feb 2025

    A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.

    Published: 26 Sept 2023
    7.5
    High

    CVE-2023-46728

    Last Modified: 3 Nov 2025

    Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1. Responses triggering this bug are possible to be received from any gopher server, even those without malicious intent. Gopher support has been removed in Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should reject all gopher URL requests.

    Published: 26 Sept 2023
    6.5
    Medium

    CVE-2023-43040

    Last Modified: 4 Nov 2025

    IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM X-Force ID: 266807.

    Published: 26 Sept 2023
    7.1
    High

    CVE-2023-4259

    Last Modified: 13 Feb 2025

    Two potential buffer overflow vulnerabilities at the following locations in the Zephyr eS-WiFi driver source code.

    Published: 25 Sept 2023
    8.6
    High

    CVE-2023-4258

    Last Modified: 21 Nov 2024

    In Bluetooth mesh implementation If provisionee has a public key that is sent OOB then during provisioning it can be sent back and will be accepted by provisionee.

    Published: 25 Sept 2023
    9.1
    Critical

    CVE-2023-43644

    Last Modified: 21 Nov 2024

    Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafted requests are sent to sing-box. This affects all SOCKS5 inbounds with user authentication and an attacker may be able to bypass authentication. Users are advised to update to sing-box 1.4.4 or to 1.5.0-rc.4. Users unable to update should not expose the SOCKS5 inbound to insecure environments.

    Published: 25 Sept 2023
    7.5
    High

    CVE-2023-43642

    Last Modified: 21 Nov 2024

    snappy-java is a Java port of the snappy, a fast C++ compresser/decompresser developed by Google. The SnappyInputStream was found to be vulnerable to Denial of Service (DoS) attacks when decompressing data with a too large chunk size. Due to missing upper bound check on chunk length, an unrecoverable fatal error can occur. All versions of snappy-java including the latest released version 1.1.10.3 are vulnerable to this issue. A fix has been introduced in commit `9f8c3cf74` which will be included in the 1.1.10.4 release. Users are advised to upgrade. Users unable to upgrade should only accept compressed data from trusted sources.

    Published: 25 Sept 2023
    5.4
    Medium

    CVE-2023-42817

    Last Modified: 21 Nov 2024

    Pimcore admin-ui-classic-bundle provides a Backend UI for Pimcore. The translation value with text including “%s” (from “%suggest%) is parsed by sprintf() even though it’s supposed to be output literally to the user. The translations may be accessible by a user with comparatively lower overall access (as the translation permission cannot be scoped to certain “modules”) and a skilled attacker might be able to exploit the parsing of the translation string in the dialog box. This issue has been patched in commit `abd77392` which is included in release 1.1.2. Users are advised to update to version 1.1.2 or apply the patch manually.

    Published: 25 Sept 2023