CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2023-41374

    Last Modified: 21 Nov 2024

    Double free issue exists in Kostac PLC Programming Software Version 1.6.11.0 and earlier. Arbitrary code may be executed by having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier because the issue exists in parsing of KPP project files. The vendor states that Kostac PLC Programming Software Version 1.6.10.0 or later implements the function which prevents a project file alteration. Therefore, to mitigate the impact of these vulnerabilities, a project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier needs to be saved again using Kostac PLC Programming Software Version 1.6.10.0 or later.

    Published: 20 Sept 2023
    7.8
    High

    CVE-2023-41375

    Last Modified: 21 Nov 2024

    Use after free vulnerability exists in Kostac PLC Programming Software Version 1.6.11.0. Arbitrary code may be executed by having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier because the issue exists in parsing of KPP project files. The vendor states that Kostac PLC Programming Software Version 1.6.10.0 or later implements the function which prevents a project file alteration. Therefore, to mitigate the impact of these vulnerabilities, a project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier needs to be saved again using Kostac PLC Programming Software Version 1.6.10.0 or later.

    Published: 20 Sept 2023
    9.4
    Critical

    CVE-2023-22644

    Last Modified: 7 Apr 2025

    A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.

    Published: 20 Sept 2023
    7.5
    High

    CVE-2022-47562

    Last Modified: 21 Nov 2024

    Vulnerability in the RCPbind service running on UDP port (111), allowing a remote attacker to create a denial of service (DoS) condition.

    Published: 20 Sept 2023
    7.3
    High

    CVE-2022-47561

    Last Modified: 21 Nov 2024

    The web application stores credentials in clear text in the "admin.xml" file, which can be accessed without logging into the website, which could allow an attacker to obtain credentials related to all users, including admin users, in clear text, and use them to subsequently execute malicious actions.

    Published: 20 Sept 2023
    5.7
    Medium

    CVE-2022-47560

    Last Modified: 18 Jun 2025

    The lack of web request control on ekorCCP and ekorRCI devices allows a potential attacker to create custom requests to execute malicious actions when a user is logged in.

    Published: 20 Sept 2023
    6.4
    Medium

    CVE-2023-5063

    Last Modified: 8 Apr 2026

    The Widget Responsive for Youtube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube' shortcode in versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 20 Sept 2023
    6.4
    Medium

    CVE-2023-5062

    Last Modified: 8 Apr 2026

    The WordPress Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wp_charts' shortcode in versions up to, and including, 0.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 20 Sept 2023
    9.3
    Critical

    CVE-2023-4088

    Last Modified: 21 Nov 2024

    Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products allows a malicious local attacker to execute a malicious code, resulting in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition, if the product is installed in a folder other than the default installation folder.

    Published: 20 Sept 2023
    4.2
    Medium

    CVE-2023-31014

    Last Modified: 21 Nov 2024

    NVIDIA GeForce Now for Android contains a vulnerability in the game launcher component, where a malicious application on the same device can process the implicit intent meant for the streamer component. A successful exploit of this vulnerability may lead to limited information disclosure, denial of service, and code execution.

    Published: 20 Sept 2023
    6.6
    Medium

    CVE-2023-31015

    Last Modified: 21 Nov 2024

    NVIDIA DGX H100 BMC contains a vulnerability in the REST service where a host user may cause as improper authentication issue. A successful exploit of this vulnerability may lead to escalation of privileges, information disclosure, code execution, and denial of service.

    Published: 20 Sept 2023
    6.1
    Medium

    CVE-2023-31013

    Last Modified: 21 Nov 2024

    NVIDIA DGX H100 BMC contains a vulnerability in the REST service, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to escalation of privileges and information disclosure.

    Published: 20 Sept 2023
    6.1
    Medium

    CVE-2023-31012

    Last Modified: 21 Nov 2024

    NVIDIA DGX H100 BMC contains a vulnerability in the REST service where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to escalation of privileges and information disclosure.

    Published: 20 Sept 2023
    5.2
    Medium

    CVE-2023-31011

    Last Modified: 21 Nov 2024

    NVIDIA DGX H100 BMC contains a vulnerability in the REST service where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to escalation of privileges and information disclosure.

    Published: 20 Sept 2023
    6.8
    Medium

    CVE-2023-31010

    Last Modified: 21 Nov 2024

    NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to escalation of privileges, information disclosure, and denial of service.

    Published: 20 Sept 2023
    8.3
    High

    CVE-2023-31009

    Last Modified: 21 Nov 2024

    NVIDIA DGX H100 BMC contains a vulnerability in the REST service, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, and information disclosure.

    Published: 20 Sept 2023
    7.3
    High

    CVE-2023-31008

    Last Modified: 21 Nov 2024

    NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to code execution, denial of services, escalation of privileges, and information disclosure.

    Published: 20 Sept 2023
    5.7
    Medium

    CVE-2023-25534

    Last Modified: 21 Nov 2024

    NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

    Published: 20 Sept 2023
    8.3
    High

    CVE-2023-25533

    Last Modified: 21 Nov 2024

    NVIDIA DGX H100 BMC contains a vulnerability in the web UI, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to information disclosure, code execution, and escalation of privileges.

    Published: 20 Sept 2023
    6.5
    Medium

    CVE-2023-25532

    Last Modified: 21 Nov 2024

    NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploit of this vulnerability may lead to information disclosure.

    Published: 20 Sept 2023
    7.6
    High

    CVE-2023-25531

    Last Modified: 21 Nov 2024

    NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and escalation of privileges.

    Published: 20 Sept 2023
    8
    High

    CVE-2023-25530

    Last Modified: 21 Nov 2024

    NVIDIA DGX H100 BMC contains a vulnerability in the KVM service, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, and information disclosure.

    Published: 20 Sept 2023
    8
    High

    CVE-2023-25529

    Last Modified: 21 Nov 2024

    NVIDIA DGX H100 BMC and DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a leak of another user’s session token by observing timing discrepancies between server responses. A successful exploit of this vulnerability may lead to information disclosure, escalation of privileges, and data tampering.

    Published: 20 Sept 2023
    8.8
    High

    CVE-2023-25528

    Last Modified: 21 Nov 2024

    NVIDIA DGX H100 baseboard management controller (BMC) contains a vulnerability in a web server plugin, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.

    Published: 20 Sept 2023
    7.8
    High

    CVE-2023-25527

    Last Modified: 21 Nov 2024

    NVIDIA DGX H100 BMC contains a vulnerability in the host KVM daemon, where an authenticated local attacker may cause corruption of kernel memory. A successful exploit of this vulnerability may lead to arbitrary kernel code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

    Published: 20 Sept 2023
    6.5
    Medium

    CVE-2023-25526

    Last Modified: 21 Nov 2024

    NVIDIA Cumulus Linux contains a vulnerability in neighmgrd and nlmanager where an attacker on an adjacent network may cause an uncaught exception by injecting a crafted packet. A successful exploit may lead to denial of service.

    Published: 20 Sept 2023
    7.5
    High

    CVE-2023-25525

    Last Modified: 21 Nov 2024

    NVIDIA Cumulus Linux contains a vulnerability in forwarding where a VxLAN-encapsulated IPv6 packet received on an SVI interface with DMAC/DIPv6 set to the link-local address of the SVI interface may be incorrectly forwarded. A successful exploit may lead to information disclosure.

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2023-34575

    Last Modified: 12 Jun 2026

    SQL injection vulnerability in PrestaShop opartsavecart through 2.0.7 allows remote attackers to run arbitrary SQL commands via OpartSaveCartDefaultModuleFrontController::initContent() and OpartSaveCartDefaultModuleFrontController::displayAjaxSendCartByEmail() methods.

    Published: 20 Sept 2023
    8.8
    High

    CVE-2023-40475

    Last Modified: 17 Mar 2026

    GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of MXF video files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-21661.

    Published: 20 Sept 2023
    7.5
    High

    CVE-2023-39677

    Last Modified: 18 Feb 2026

    MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php.

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2023-39675

    Last Modified: 18 Feb 2026

    SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php.

    Published: 20 Sept 2023
    7.5
    High

    CVE-2023-3341

    Last Modified: 2 Dec 2025

    The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size; depending on the environment, this may cause the packet-parsing code to run out of available stack memory, causing `named` to terminate unexpectedly. Since each incoming control channel message is fully parsed before its contents are authenticated, exploiting this flaw does not require the attacker to hold a valid RNDC key; only network access to the control channel's configured TCP port is necessary. This issue affects BIND 9 versions 9.2.0 through 9.16.43, 9.18.0 through 9.18.18, 9.19.0 through 9.19.16, 9.9.3-S1 through 9.16.43-S1, and 9.18.0-S1 through 9.18.18-S1.

    Published: 20 Sept 2023
    6.1
    Medium

    CVE-2023-40618

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start versions 4, 5, 6, 7 as well as Visual Project Explorer 1.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'service' parameter in 'headstart_snapshot.php'.

    Published: 20 Sept 2023
    5.4
    Medium

    CVE-2023-36234

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Netbox 3.5.1, allows attackers to execute arbitrary code via Name field in device-roles/add function.

    Published: 20 Sept 2023
    7.5
    High

    CVE-2023-5157

    Last Modified: 18 Mar 2026

    A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.

    Published: 20 Sept 2023
    6.5
    Medium

    CVE-2023-39052

    Last Modified: 21 Nov 2024

    An information leak in Earthgarden_waiting 13.6.1 allows attackers to obtain the channel access token and send crafted messages.

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2023-36109

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in JerryScript version 3.0, allows remote attackers to execute arbitrary code via ecma_stringbuilder_append_raw component at /jerry-core/ecma/base/ecma-helpers-string.c.

    Published: 20 Sept 2023
    9.6
    Critical

    CVE-2023-38888

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2023-43204

    Last Modified: 21 Nov 2024

    D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function sub_2EF50. This vulnerability allows attackers to execute arbitrary commands via the manual-time-string parameter.

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2023-43207

    Last Modified: 21 Nov 2024

    D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function config_upload_handler. This vulnerability allows attackers to execute arbitrary commands via the configRestore parameter.

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2019-19450

    Last Modified: 21 Nov 2024

    paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar element in a crafted XML document with '<unichar code="' followed by arbitrary Python code, a similar issue to CVE-2019-17626.

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2023-43375

    Last Modified: 21 Nov 2024

    Hoteldruid v3.0.5 was discovered to contain multiple SQL injection vulnerabilities at /hoteldruid/clienti.php via the annonascita, annoscaddoc, giornonascita, giornoscaddoc, lingua_cli, mesenascita, and mesescaddoc parameters.

    Published: 20 Sept 2023
    6.1
    Medium

    CVE-2023-38875

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'validator' parameter in '/reset-password'.

    Published: 20 Sept 2023
    6.1
    Medium

    CVE-2023-38876

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selector' parameter in '/reset-password'.

    Published: 20 Sept 2023
    7.2
    High

    CVE-2023-38886

    Last Modified: 21 Nov 2024

    An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.

    Published: 20 Sept 2023
    8.8
    High

    CVE-2023-38887

    Last Modified: 21 Nov 2024

    File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions.

    Published: 20 Sept 2023
    6.5
    Medium

    CVE-2023-39041

    Last Modified: 21 Nov 2024

    An information leak in KUKURUDELI Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

    Published: 20 Sept 2023
    6.5
    Medium

    CVE-2023-39044

    Last Modified: 21 Nov 2024

    An information leak in ajino-Shiretoko Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

    Published: 20 Sept 2023
    6.5
    Medium

    CVE-2023-39045

    Last Modified: 21 Nov 2024

    An information leak in kokoroe_members card Line 13.6.1 allows attackers to obtain the channel access token and send crafted messages.

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2023-40619

    Last Modified: 21 Nov 2024

    phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP 'unserialize()' function in multiple places. An example is the functionality to manage tables in 'tables.php' where the 'ma[]' POST parameter is deserialized.

    Published: 20 Sept 2023