CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2023-40163

    Last Modified: 4 Nov 2025

    An out-of-bounds write vulnerability exists in the allocate_buffer_for_jpeg_decoding functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 25 Sept 2023
    7.5
    High

    CVE-2023-41303

    Last Modified: 21 Nov 2024

    Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may cause variables in the sock structure to be modified.

    Published: 25 Sept 2023
    9.8
    Critical

    CVE-2022-48605

    Last Modified: 21 Nov 2024

    Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.

    Published: 25 Sept 2023
    7.5
    High

    CVE-2023-41293

    Last Modified: 21 Nov 2024

    Data security classification vulnerability in the DDMP module. Successful exploitation of this vulnerability may affect confidentiality.

    Published: 25 Sept 2023
    7.5
    High

    CVE-2023-41302

    Last Modified: 21 Nov 2024

    Redirection permission verification vulnerability in the home screen module. Successful exploitation of this vulnerability may cause features to perform abnormally.

    Published: 25 Sept 2023
    7.5
    High

    CVE-2023-41301

    Last Modified: 21 Nov 2024

    Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerability may cause features to perform abnormally.

    Published: 25 Sept 2023
    7.5
    High

    CVE-2023-41300

    Last Modified: 21 Nov 2024

    Vulnerability of parameters not being strictly verified in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.

    Published: 25 Sept 2023
    7.5
    High

    CVE-2023-41299

    Last Modified: 21 Nov 2024

    DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.

    Published: 25 Sept 2023
    7.5
    High

    CVE-2023-41298

    Last Modified: 21 Nov 2024

    Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.

    Published: 25 Sept 2023
    9.8
    Critical

    CVE-2023-41297

    Last Modified: 21 Nov 2024

    Vulnerability of defects introduced in the design process in the HiviewTunner module. Successful exploitation of this vulnerability may cause service hijacking.

    Published: 25 Sept 2023
    9.1
    Critical

    CVE-2023-41296

    Last Modified: 21 Nov 2024

    Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnerability may affect integrity and confidentiality.

    Published: 25 Sept 2023
    5.3
    Medium

    CVE-2023-41295

    Last Modified: 21 Nov 2024

    Vulnerability of improper permission management in the displayengine module. Successful exploitation of this vulnerability may cause the screen to turn dim.

    Published: 25 Sept 2023
    9.8
    Critical

    CVE-2023-41294

    Last Modified: 21 Nov 2024

    The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services.

    Published: 25 Sept 2023
    7.5
    High

    CVE-2023-39409

    Last Modified: 21 Nov 2024

    DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.

    Published: 25 Sept 2023
    7.5
    High

    CVE-2023-39408

    Last Modified: 21 Nov 2024

    DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.

    Published: 25 Sept 2023
    9.1
    Critical

    CVE-2023-39407

    Last Modified: 21 Nov 2024

    The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity.

    Published: 25 Sept 2023
    6.3
    Medium

    CVE-2023-5154

    Last Modified: 21 Nov 2024

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DAR-8000 up to 20151231 and classified as critical. This vulnerability affects unknown code of the file /sysmanage/changelogo.php. The manipulation of the argument file_upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-240250 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

    Published: 25 Sept 2023
    6.3
    Medium

    CVE-2023-5153

    Last Modified: 21 Nov 2024

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DAR-8000 up to 20151231. This affects an unknown part of the file /Tool/querysql.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240249 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

    Published: 25 Sept 2023
    6.3
    Medium

    CVE-2023-5152

    Last Modified: 21 Nov 2024

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-7000 and DAR-8000 up to 20151231. Affected by this issue is some unknown functionality of the file /importexport.php. The manipulation of the argument sql leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240248. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

    Published: 25 Sept 2023
    6.3
    Medium

    CVE-2023-5151

    Last Modified: 21 Nov 2024

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DAR-8000 up to 20151231. Affected by this vulnerability is an unknown functionality of the file /autheditpwd.php. The manipulation of the argument hid_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240247. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

    Published: 25 Sept 2023
    6.3
    Medium

    CVE-2023-5150

    Last Modified: 18 Jun 2025

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in D-Link DAR-7000 and DAR-8000 up to 20151231. Affected is an unknown function of the file /useratte/web.php. The manipulation of the argument file_upload leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-240246 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

    Published: 25 Sept 2023
    7.1
    High

    CVE-2023-41872

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Xtemos WoodMart plugin <= 7.2.4 versions.

    Published: 25 Sept 2023
    6.3
    Medium

    CVE-2023-5149

    Last Modified: 21 Nov 2024

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20151231. It has been rated as critical. This issue affects some unknown processing of the file /useratte/userattestation.php. The manipulation of the argument web_img leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240245 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

    Published: 25 Sept 2023
    6.3
    Medium

    CVE-2023-5148

    Last Modified: 21 Nov 2024

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 and DAR-8000 up to 20151231. It has been declared as critical. This vulnerability affects unknown code of the file /Tool/uploadfile.php. The manipulation of the argument file_upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240244. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

    Published: 25 Sept 2023
    7.1
    High

    CVE-2023-41874

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Order Delivery Date for WooCommerce plugin <= 3.20.0 versions.

    Published: 25 Sept 2023
    5.9
    Medium

    CVE-2023-41948

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Christoph Rado Cookie Notice & Consent plugin <= 1.6.0 versions.

    Published: 25 Sept 2023
    5.9
    Medium

    CVE-2023-41949

    Last Modified: 21 Nov 2024

    Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Avirtum iFolders plugin <= 1.5.0 versions.

    Published: 25 Sept 2023
    6.3
    Medium

    CVE-2023-5147

    Last Modified: 21 Nov 2024

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20151231. It has been classified as critical. This affects an unknown part of the file /sysmanage/updateos.php. The manipulation of the argument 1_file_upload leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240243. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

    Published: 25 Sept 2023
    6.3
    Medium

    CVE-2023-5146

    Last Modified: 21 Nov 2024

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 and DAR-8000 up to 20151231 and classified as critical. Affected by this issue is some unknown functionality of the file /sysmanage/updatelib.php. The manipulation of the argument file_upload leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-240242 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

    Published: 25 Sept 2023
    7.5
    High

    CVE-2023-5156

    Last Modified: 18 Dec 2025

    A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash.

    Published: 25 Sept 2023
    4.5
    Medium

    CVE-2023-4535

    Last Modified: 21 Nov 2025

    An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized access to sensitive data, compromising the system's security.

    Published: 25 Sept 2023
    6.5
    Medium

    CVE-2023-43132

    Last Modified: 21 Nov 2024

    szvone vmqphp <=1.13 is vulnerable to SQL Injection. Unauthorized remote users can use sql injection attacks to obtain the hash of the administrator password.

    Published: 25 Sept 2023
    7.5
    High

    CVE-2023-38907

    Last Modified: 21 Nov 2024

    An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to replay old messages encrypted with a still valid session key.

    Published: 25 Sept 2023
    5.4
    Medium

    CVE-2023-40661

    Last Modified: 6 Nov 2025

    Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an attacker must have physical access to the computer system and employ a custom-crafted USB device or smart card to manipulate responses to APDUs. This manipulation can potentially allow compromise key generation, certificate loading, and other card management operations during enrollment.

    Published: 25 Sept 2023
    6.6
    Medium

    CVE-2023-40660

    Last Modified: 6 Nov 2025

    A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed. This issue poses a security risk, particularly for OS logon/screen unlock and for small, permanently connected tokens to computers. Additionally, the token can internally track login status. This flaw allows an attacker to gain unauthorized access, carry out malicious actions, or compromise the system without the user's awareness.

    Published: 25 Sept 2023
    6.5
    Medium

    CVE-2023-6240

    Last Modified: 8 Nov 2025

    A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key.

    Published: 25 Sept 2023
    5.3
    Medium

    CVE-2015-6964

    Last Modified: 21 Nov 2024

    MultiBit HD before 0.1.2 allows attackers to conduct bit-flipping attacks that insert unspendable Bitcoin addresses into the list that MultiBit uses to send fees to the developers. (Attackers cannot realistically steal these fees for themselves.) This occurs because there is no message authentication code (MAC).

    Published: 25 Sept 2023
    6.5
    Medium

    CVE-2023-43256

    Last Modified: 21 Nov 2024

    A path traversal in Gladys Assistant v4.26.1 and below allows authenticated attackers to extract sensitive files in the host machine by exploiting a non-sanitized user input.

    Published: 25 Sept 2023
    5.4
    Medium

    CVE-2023-43458

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Resort Reservation System v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the room, name, and description parameters in the manage_room function.

    Published: 25 Sept 2023
    7.3
    High

    CVE-2023-3550

    Last Modified: 13 Feb 2025

    Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attacker with a low-privileged user account can use this exploit to become an administrator by sending a malicious link to the instance administrator.

    Published: 25 Sept 2023
    9.8
    Critical

    CVE-2023-39640

    Last Modified: 21 Nov 2024

    UpLight cookiebanner before 1.5.1 was discovered to contain a SQL injection vulnerability via the component Hook::getHookModuleExecList().

    Published: 25 Sept 2023
    6.1
    Medium

    CVE-2023-42426

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary code via the 'Insert link' parameter in the 'Insert Image' component.

    Published: 25 Sept 2023
    6.5
    Medium

    CVE-2023-42755

    Last Modified: 8 Nov 2025

    A flaw was found in the IPv4 Resource Reservation Protocol (RSVP) classifier in the Linux kernel. The xprt pointer may go beyond the linear part of the skb, leading to an out-of-bounds read in the `rsvp_classify` function. This issue may allow a local user to crash the system and cause a denial of service.

    Published: 25 Sept 2023
    9.8
    Critical

    CVE-2023-43131

    Last Modified: 21 Nov 2024

    General Device Manager 2.5.2.2 is vulnerable to Buffer Overflow.

    Published: 25 Sept 2023
    9.8
    Critical

    CVE-2023-43141

    Last Modified: 21 Nov 2024

    TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control.

    Published: 25 Sept 2023
    8.8
    High

    CVE-2023-43278

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an admin account.

    Published: 25 Sept 2023
    6.1
    Medium

    CVE-2023-43319

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in the Sign-In page of IceWarp WebClient 10.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter.

    Published: 25 Sept 2023
    6.1
    Medium

    CVE-2023-43325

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in the data[redirect_url] parameter of mooSocial v3.1.8 allows attackers to steal user's session cookies and impersonate their account via a crafted URL.

    Published: 25 Sept 2023
    6.1
    Medium

    CVE-2023-43326

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability exisits in multiple url of mooSocial v3.1.8 allows attackers to steal user's session cookies and impersonate their account via a crafted URL.

    Published: 25 Sept 2023
    6.1
    Medium

    CVE-2023-43339

    Last Modified: 21 Nov 2024

    Cross-Site Scripting (XSS) vulnerability in cmsmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload injected into the Database Name, DataBase User or Database Port components.

    Published: 25 Sept 2023