CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2023-43235

    Last Modified: 21 Nov 2024

    D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter StartTime and EndTime in SetWifiDownSettings.

    Published: 21 Sept 2023
    9.8
    Critical

    CVE-2023-43236

    Last Modified: 21 Nov 2024

    D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter statuscheckpppoeuser in dir_setWanWifi.

    Published: 21 Sept 2023
    9.8
    Critical

    CVE-2023-43237

    Last Modified: 21 Nov 2024

    D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter macCloneMac in setMAC.

    Published: 21 Sept 2023
    9.8
    Critical

    CVE-2023-43238

    Last Modified: 21 Nov 2024

    D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter nvmacaddr in form2Dhcpip.cgi.

    Published: 21 Sept 2023
    9.8
    Critical

    CVE-2023-43240

    Last Modified: 21 Nov 2024

    D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter sip_address in ipportFilter.

    Published: 21 Sept 2023
    7.5
    High

    CVE-2023-37279

    Last Modified: 21 Nov 2024

    Faktory is a language-agnostic persistent background job server. Prior to version 1.8.0, the Faktory web dashboard can suffer from denial of service by a crafted malicious url query param `days`. The vulnerability is related to how the backend reads the `days` URL query parameter in the Faktory web dashboard. The value is used directly without any checks to create a string slice. If a very large value is provided, the backend server ends up using a significant amount of memory and causing it to crash. Version 1.8.0 fixes this issue.

    Published: 20 Sept 2023
    5.5
    Medium

    CVE-2023-22024

    Last Modified: 21 Nov 2024

    In the Unbreakable Enterprise Kernel (UEK), the RDS module in UEK has two setsockopt(2) options, RDS_CONN_RESET and RDS6_CONN_RESET, that are not re-entrant. A malicious local user with CAP_NET_ADMIN can use this to crash the kernel. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

    Published: 20 Sept 2023
    3.7
    Low

    CVE-2023-38718

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation 21.0.0 through 21.0.7.8 could disclose sensitive information from access to RPA scripts, workflows and related data. IBM X-Force ID: 261606.

    Published: 20 Sept 2023
    8.4
    High

    CVE-2023-37410

    Last Modified: 21 Nov 2024

    IBM Personal Communications 14.05, 14.06, and 15.0.0 could allow a local user to escalate their privileges to the SYSTEM user due to overly permissive access controls. IBM X-Force ID: 260138.

    Published: 20 Sept 2023
    4.4
    Medium

    CVE-2023-40368

    Last Modified: 21 Nov 2024

    IBM Storage Protect 8.1.0.0 through 8.1.19.0 could allow a privileged user to obtain sensitive information from the administrative command line client. IBM X-Force ID: 263456.

    Published: 20 Sept 2023
    5.5
    Medium

    CVE-2023-20597

    Last Modified: 27 Jun 2025

    Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.

    Published: 20 Sept 2023
    4.4
    Medium

    CVE-2023-20594

    Last Modified: 27 Jun 2025

    Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.

    Published: 20 Sept 2023
    —
    Unknown

    CVE-2023-5094

    Last Modified: 23 Dec 2025

    This CVE id was assigned to an issue which was later deemed not security relevant.

    Published: 20 Sept 2023
    —
    Unknown

    CVE-2023-5093

    Last Modified: 23 Dec 2025

    This CVE id was assigned to an issue which was later deemed not security relevant.

    Published: 20 Sept 2023
    6.1
    Medium

    CVE-2023-42656

    Last Modified: 21 Nov 2024

    In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a reflected cross-site scripting (XSS) vulnerability has been identified in MOVEit Transfer's web interface.  An attacker could craft a malicious payload targeting MOVEit Transfer users during the package composition procedure.  If a MOVEit user interacts with the crafted payload, the attacker would be able to execute malicious JavaScript within the context of the victims browser.

    Published: 20 Sept 2023
    4.3
    Medium

    CVE-2023-43502

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers to delete Failure Causes.

    Published: 20 Sept 2023
    6.5
    Medium

    CVE-2023-43501

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified hostname and port using attacker-specified username and password.

    Published: 20 Sept 2023
    8.8
    High

    CVE-2023-43500

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and password.

    Published: 20 Sept 2023
    5.4
    Medium

    CVE-2023-43499

    Last Modified: 21 Nov 2024

    Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier does not escape Failure Cause names in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or update Failure Causes.

    Published: 20 Sept 2023
    7.2
    High

    CVE-2023-40043

    Last Modified: 27 Feb 2025

    In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer web interface that could allow a MOVEit system administrator account to gain unauthorized access to the MOVEit Transfer database. A MOVEit system administrator could submit a crafted payload to the MOVEit Transfer web interface which could result in modification and disclosure of MOVEit database content.

    Published: 20 Sept 2023
    8.8
    High

    CVE-2023-42660

    Last Modified: 27 Feb 2025

    In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer machine interface that could allow an authenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to the MOVEit Transfer machine interface which could result in modification and disclosure of MOVEit database content.

    Published: 20 Sept 2023
    —
    Unknown

    CVE-2023-5092

    Last Modified: 23 Dec 2025

    This CVE id was assigned to an issue which was later deemed not security relevant.

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2023-5074

    Last Modified: 21 Nov 2024

    Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2023-2262

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability exists in the Rockwell Automation select 1756-EN* communication devices. If exploited, a threat actor could potentially leverage this vulnerability to perform a remote code execution. To exploit this vulnerability, a threat actor would have to send a maliciously crafted CIP request to device.

    Published: 20 Sept 2023
    5.3
    Medium

    CVE-2023-2508

    Last Modified: 21 Nov 2024

    The `PaperCutNG Mobility Print` version 1.0.3512 application allows an unauthenticated attacker to perform a CSRF attack on an instance administrator to configure the clients host (in the "configure printer discovery" section). This is possible because the application has no protections against CSRF attacks, like Anti-CSRF tokens, header origin validation, samesite cookies, etc.

    Published: 20 Sept 2023
    8.8
    High

    CVE-2023-43635

    Last Modified: 21 Nov 2024

    Vault Key Sealed With SHA1 PCRs The measured boot solution implemented in EVE OS leans on a PCR locking mechanism. Different parts of the system update different PCR values in the TPM, resulting in a unique value for each PCR entry. These PCRs are then used in order to seal/unseal a key from the TPM which is used to encrypt/decrypt the “vault” directory. This “vault” directory is the most sensitive point in the system and as such, its content should be protected. This mechanism is noted in Zededa’s documentation as the “measured boot” mechanism, designed to protect said “vault”. The code that’s responsible for generating and fetching the key from the TPM assumes that SHA256 PCRs are used in order to seal/unseal the key, and as such their presence is being checked. The issue here is that the key is not sealed using SHA256 PCRs, but using SHA1 PCRs. This leads to several issues: • Machines that have their SHA256 PCRs enabled but SHA1 PCRs disabled, as well as not sealing their keys at all, meaning the “vault” is not protected from an attacker. • SHA1 is considered insecure and reduces the complexity level required to unseal the key in machines which have their SHA1 PCRs enabled. An attacker can very easily retrieve the contents of the “vault”, which will effectively render the “measured boot” mechanism meaningless.

    Published: 20 Sept 2023
    8.8
    High

    CVE-2023-43636

    Last Modified: 21 Nov 2024

    In EVE OS, the “measured boot” mechanism prevents a compromised device from accessing the encrypted data located in the vault. As per the “measured boot” design, the PCR values calculated at different stages of the boot process will change if any of their respective parts are changed. This includes, among other things, the configuration of the bios, grub, the kernel cmdline, initrd, and more. However, this mechanism does not validate the entire rootfs, so an attacker can edit the filesystem and gain control over the system. As the default filesystem used by EVE OS is squashfs, this is somewhat harder than an ext4, which is easily changeable. This will not stop an attacker, as an attacker can repackage the squashfs with their changes in it and replace the partition altogether. This can also be done directly on the device, as the “003-storage-init” container contains the “mksquashfs” and “unsquashfs” binaries (with the corresponding libs). An attacker can gain full control over the device without changing the PCR values, thus not triggering the “measured boot” mechanism, and having full access to the vault. Note: This issue was partially fixed in these commits (after disclosure to Zededa), where the config partition measurement was added to PCR13: • aa3501d6c57206ced222c33aea15a9169d629141 • 5fef4d92e75838cc78010edaed5247dfbdae1889. This issue was made viable in version 9.0.0 when the calculation was moved to PCR14 but it was not included in the measured boot.

    Published: 20 Sept 2023
    8.8
    High

    CVE-2023-43630

    Last Modified: 21 Nov 2024

    PCR14 is not in the list of PCRs that seal/unseal the “vault” key, but due to the change that was implemented in commit “7638364bc0acf8b5c481b5ce5fea11ad44ad7fd4”, fixing this issue alone would not solve the problem of the config partition not being measured correctly. Also, the “vault” key is sealed/unsealed with SHA1 PCRs instead of SHA256. This issue was somewhat mitigated due to all of the PCR extend functions updating both the values of SHA256 and SHA1 for a given PCR ID. However, due to the change that was implemented in commit “7638364bc0acf8b5c481b5ce5fea11ad44ad7fd4”, this is no longer the case for PCR14, as the code in “measurefs.go” explicitly updates only the SHA256 instance of PCR14, which means that even if PCR14 were to be added to the list of PCRs sealing/unsealing the “vault” key, changes to the config partition would still not be measured. An attacker could modify the config partition without triggering the measured boot, this could result in the attacker gaining full control over the device with full access to the contents of the encrypted “vault”

    Published: 20 Sept 2023
    8.8
    High

    CVE-2023-43478

    Last Modified: 21 Nov 2024

    fake_upload.cgi on the Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, allows unauthenticated attackers to upload firmware images and configuration backups, which could allow them to alter the firmware or the configuration on the device, ultimately leading to code execution as root. 

    Published: 20 Sept 2023
    6.8
    Medium

    CVE-2023-43477

    Last Modified: 21 Nov 2024

    The ping_from parameter of ping_tracerte.cgi in the web UI of Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, was not properly sanitized before being used in a system call, which could allow an authenticated attacker to achieve command injection as root on the device. 

    Published: 20 Sept 2023
    8.8
    High

    CVE-2023-0829

    Last Modified: 21 Nov 2024

    Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.

    Published: 20 Sept 2023
    3.5
    Low

    CVE-2022-45448

    Last Modified: 21 Nov 2024

    M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to an arbitrary HTML Document crafting vulnerability. The resource /m4pdf/pdf.php uses templates to dynamically create documents. In the case that the template does not exist, the application will return a fixed document with a message in mpdf format. An attacker could exploit this vulnerability by inputting a valid HTML/CSS document as the value of the parameter.

    Published: 20 Sept 2023
    7
    High

    CVE-2023-4504

    Last Modified: 4 Nov 2025

    Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.

    Published: 20 Sept 2023
    7.5
    High

    CVE-2023-5042

    Last Modified: 10 Apr 2026

    Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40713, Acronis True Image OEM (Windows) before build 42575.

    Published: 20 Sept 2023
    3.9
    Low

    CVE-2023-5084

    Last Modified: 3 Dec 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8.

    Published: 20 Sept 2023
    6.5
    Medium

    CVE-2022-45447

    Last Modified: 21 Nov 2024

    M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to a directory traversal vulnerability. The “f” parameter is not properly checked in the resource /m4pdf/pdf.php, returning any file given its relative path. An attacker that exploits this vulnerability could download /etc/passwd from the server if the file exists.

    Published: 20 Sept 2023
    3.1
    Low

    CVE-2023-34047

    Last Modified: 21 Nov 2024

    A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context with values, including security context values, from a different session. An application is vulnerable if it provides a DataLoaderOptions instance when registering batch loader functions through DefaultBatchLoaderRegistry.

    Published: 20 Sept 2023
    7.8
    High

    CVE-2023-41374

    Last Modified: 21 Nov 2024

    Double free issue exists in Kostac PLC Programming Software Version 1.6.11.0 and earlier. Arbitrary code may be executed by having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier because the issue exists in parsing of KPP project files. The vendor states that Kostac PLC Programming Software Version 1.6.10.0 or later implements the function which prevents a project file alteration. Therefore, to mitigate the impact of these vulnerabilities, a project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier needs to be saved again using Kostac PLC Programming Software Version 1.6.10.0 or later.

    Published: 20 Sept 2023
    7.8
    High

    CVE-2023-41375

    Last Modified: 21 Nov 2024

    Use after free vulnerability exists in Kostac PLC Programming Software Version 1.6.11.0. Arbitrary code may be executed by having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier because the issue exists in parsing of KPP project files. The vendor states that Kostac PLC Programming Software Version 1.6.10.0 or later implements the function which prevents a project file alteration. Therefore, to mitigate the impact of these vulnerabilities, a project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier needs to be saved again using Kostac PLC Programming Software Version 1.6.10.0 or later.

    Published: 20 Sept 2023
    9.4
    Critical

    CVE-2023-22644

    Last Modified: 7 Apr 2025

    A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.

    Published: 20 Sept 2023
    7.5
    High

    CVE-2022-47562

    Last Modified: 21 Nov 2024

    Vulnerability in the RCPbind service running on UDP port (111), allowing a remote attacker to create a denial of service (DoS) condition.

    Published: 20 Sept 2023
    7.3
    High

    CVE-2022-47561

    Last Modified: 21 Nov 2024

    The web application stores credentials in clear text in the "admin.xml" file, which can be accessed without logging into the website, which could allow an attacker to obtain credentials related to all users, including admin users, in clear text, and use them to subsequently execute malicious actions.

    Published: 20 Sept 2023
    5.7
    Medium

    CVE-2022-47560

    Last Modified: 18 Jun 2025

    The lack of web request control on ekorCCP and ekorRCI devices allows a potential attacker to create custom requests to execute malicious actions when a user is logged in.

    Published: 20 Sept 2023
    6.4
    Medium

    CVE-2023-5063

    Last Modified: 8 Apr 2026

    The Widget Responsive for Youtube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube' shortcode in versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 20 Sept 2023
    6.4
    Medium

    CVE-2023-5062

    Last Modified: 8 Apr 2026

    The WordPress Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wp_charts' shortcode in versions up to, and including, 0.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 20 Sept 2023
    9.3
    Critical

    CVE-2023-4088

    Last Modified: 21 Nov 2024

    Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products allows a malicious local attacker to execute a malicious code, resulting in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition, if the product is installed in a folder other than the default installation folder.

    Published: 20 Sept 2023
    4.2
    Medium

    CVE-2023-31014

    Last Modified: 21 Nov 2024

    NVIDIA GeForce Now for Android contains a vulnerability in the game launcher component, where a malicious application on the same device can process the implicit intent meant for the streamer component. A successful exploit of this vulnerability may lead to limited information disclosure, denial of service, and code execution.

    Published: 20 Sept 2023
    6.6
    Medium

    CVE-2023-31015

    Last Modified: 21 Nov 2024

    NVIDIA DGX H100 BMC contains a vulnerability in the REST service where a host user may cause as improper authentication issue. A successful exploit of this vulnerability may lead to escalation of privileges, information disclosure, code execution, and denial of service.

    Published: 20 Sept 2023
    6.1
    Medium

    CVE-2023-31013

    Last Modified: 21 Nov 2024

    NVIDIA DGX H100 BMC contains a vulnerability in the REST service, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to escalation of privileges and information disclosure.

    Published: 20 Sept 2023
    6.1
    Medium

    CVE-2023-31012

    Last Modified: 21 Nov 2024

    NVIDIA DGX H100 BMC contains a vulnerability in the REST service where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to escalation of privileges and information disclosure.

    Published: 20 Sept 2023