CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2023-43137

    Last Modified: 21 Nov 2024

    TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds ACL rules after authentication, and the rule name parameter has injection points.

    Published: 20 Sept 2023
    8.8
    High

    CVE-2023-43138

    Last Modified: 21 Nov 2024

    TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds NAPT rules after authentication, and the rule name has an injection point.

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2023-43196

    Last Modified: 21 Nov 2024

    D-Link DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the zn_jb parameter in the arp_sys.asp function.

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2023-43197

    Last Modified: 21 Nov 2024

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the fn parameter in the tgfile.asp function.

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2023-43198

    Last Modified: 21 Nov 2024

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the popupId parameter in the H5/hi_block.asp function.

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2023-43199

    Last Modified: 21 Nov 2024

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the prev parameter in the H5/login.cgi function.

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2023-43200

    Last Modified: 21 Nov 2024

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the id parameter in the yyxz.data function.

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2023-43201

    Last Modified: 21 Nov 2024

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the hi_up parameter in the qos_ext.asp function.

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2023-43202

    Last Modified: 21 Nov 2024

    D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function pcap_download_handler. This vulnerability allows attackers to execute arbitrary commands via the update.device.packet-capture.tftp-file-name parameter.

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2023-43203

    Last Modified: 21 Nov 2024

    D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a stack overflow vulnerability in the function update_users.

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2023-43206

    Last Modified: 21 Nov 2024

    D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function web_cert_download_handler. This vulnerability allows attackers to execute arbitrary commands via the certDownload parameter.

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2023-43371

    Last Modified: 21 Nov 2024

    Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the numcaselle parameter at /hoteldruid/creaprezzi.php.

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2023-43373

    Last Modified: 21 Nov 2024

    Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php.

    Published: 20 Sept 2023
    9.8
    Critical

    CVE-2023-43374

    Last Modified: 21 Nov 2024

    Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the id_utente_log parameter at /hoteldruid/personalizza.php.

    Published: 20 Sept 2023
    5.4
    Medium

    CVE-2023-43376

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the nometipotariffa1 parameter.

    Published: 20 Sept 2023
    5.4
    Medium

    CVE-2023-43377

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the destinatario_email1 parameter.

    Published: 20 Sept 2023
    4.3
    Medium

    CVE-2023-43494

    Last Modified: 21 Nov 2024

    Jenkins 2.50 through 2.423 (both inclusive), LTS 2.60.1 through 2.414.1 (both inclusive) does not exclude sensitive build variables (e.g., password parameter values) from the search in the build history widget, allowing attackers with Item/Read permission to obtain values of sensitive variables used in builds by iteratively testing different characters until the correct sequence is discovered.

    Published: 20 Sept 2023
    5.4
    Medium

    CVE-2023-43495

    Last Modified: 21 Nov 2024

    Jenkins 2.423 and earlier, LTS 2.414.1 and earlier does not escape the value of the 'caption' constructor parameter of 'ExpandableDetailsNote', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control this parameter.

    Published: 20 Sept 2023
    8.8
    High

    CVE-2023-43496

    Last Modified: 2 May 2025

    Jenkins 2.423 and earlier, LTS 2.414.1 and earlier creates a temporary file in the system temporary directory with the default permissions for newly created files when installing a plugin from a URL, potentially allowing attackers with access to the system temporary directory to replace the file before it is installed in Jenkins, potentially resulting in arbitrary code execution.

    Published: 20 Sept 2023
    8.1
    High

    CVE-2023-43497

    Last Modified: 21 Nov 2024

    In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using the Stapler web framework creates temporary files in the default system temporary directory with the default permissions for newly created files, potentially allowing attackers with access to the Jenkins controller file system to read and write the files before they are used.

    Published: 20 Sept 2023
    8.1
    High

    CVE-2023-43498

    Last Modified: 21 Nov 2024

    In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using MultipartFormDataParser creates temporary files in the default system temporary directory with the default permissions for newly created files, potentially allowing attackers with access to the Jenkins controller file system to read and write the files before they are used.

    Published: 20 Sept 2023
    7.8
    High

    CVE-2023-43619

    Last Modified: 21 Nov 2024

    An issue was discovered in Croc through 9.6.5. A sender may send dangerous new files to a receiver, such as executable content or a .ssh/authorized_keys file.

    Published: 20 Sept 2023
    5.5
    Medium

    CVE-2023-43616

    Last Modified: 21 Nov 2024

    An issue was discovered in Croc through 9.6.5. A sender can cause a receiver to overwrite files during ZIP extraction.

    Published: 20 Sept 2023
    5.3
    Medium

    CVE-2023-43617

    Last Modified: 21 Nov 2024

    An issue was discovered in Croc through 9.6.5. When a custom shared secret is used, the sender and receiver may divulge parts of this secret to an untrusted Relay, as part of composing a room name.

    Published: 20 Sept 2023
    5.3
    Medium

    CVE-2023-43618

    Last Modified: 21 Nov 2024

    An issue was discovered in Croc through 9.6.5. The protocol requires a sender to provide its local IP addresses in cleartext via an ips? message.

    Published: 20 Sept 2023
    7.8
    High

    CVE-2023-43620

    Last Modified: 21 Nov 2024

    An issue was discovered in Croc through 9.6.5. A sender may place ANSI or CSI escape sequences in a filename to attack the terminal device of a receiver.

    Published: 20 Sept 2023
    4.7
    Medium

    CVE-2023-43621

    Last Modified: 21 Nov 2024

    An issue was discovered in Croc through 9.6.5. The shared secret, located on a command line, can be read by local users who list all processes and their arguments.

    Published: 20 Sept 2023
    8.8
    High

    CVE-2023-40476

    Last Modified: 17 Mar 2026

    GStreamer H265 Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of H265 encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-21768.

    Published: 20 Sept 2023
    4.8
    Medium

    CVE-2023-2995

    Last Modified: 23 Apr 2025

    The Leyka WordPress plugin before 3.30.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 19 Sept 2023
    4.8
    Medium

    CVE-2023-4376

    Last Modified: 23 Apr 2025

    The Serial Codes Generator and Validator with WooCommerce Support WordPress plugin before 2.4.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 19 Sept 2023
    —
    Unknown

    CVE-2023-5069

    Last Modified: 6 Jan 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 19 Sept 2023
    8.8
    High

    CVE-2023-22513

    Last Modified: 6 Mar 2025

    This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Bitbucket Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Bitbucket Data Center and Server 8.9: Upgrade to a release greater than or equal to 8.9.5 Bitbucket Data Center and Server 8.10: Upgrade to a release greater than or equal to 8.10.5 Bitbucket Data Center and Server 8.11: Upgrade to a release greater than or equal to 8.11.4 Bitbucket Data Center and Server 8.12: Upgrade to a release greater than or equal to 8.12.2 Bitbucket Data Center and Server 8.13: Upgrade to a release greater than or equal to 8.13.1 Bitbucket Data Center and Server 8.14: Upgrade to a release greater than or equal to 8.14.0 Bitbucket Data Center and Server version >= 8.0 and < 8.9: Upgrade to any of the listed fix versions. See the release notes (https://confluence.atlassian.com/bitbucketserver/release-notes). You can download the latest version of Bitbucket Data Center and Server from the download center (https://www.atlassian.com/software/bitbucket/download-archives). This vulnerability was discovered by a private user and reported via our Bug Bounty program

    Published: 19 Sept 2023
    3.5
    Low

    CVE-2023-43566

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration

    Published: 19 Sept 2023
    9.8
    Critical

    CVE-2023-42793

    Last Modified: 24 Oct 2025

    In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible

    Published: 19 Sept 2023
    6.1
    Medium

    CVE-2023-42452

    Last Modified: 21 Nov 2024

    Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.x branch prior to versions 4.0.10, 4.2.8, and 4.2.0-rc2, under certain conditions, attackers can abuse the translation feature to bypass the server-side HTML sanitization, allowing unescaped HTML to execute in the browser. The impact is limited thanks to Mastodon's strict Content Security Policy, blocking inline scripts, etc. However a CSP bypass or loophole could be exploited to execute malicious XSS. Furthermore, it requires user interaction, as this can only occur upon clicking the “Translate” button on a malicious post. Versions 4.0.10, 4.2.8, and 4.2.0-rc2 contain a patch for this issue.

    Published: 19 Sept 2023
    7.4
    High

    CVE-2023-42451

    Last Modified: 21 Nov 2024

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2, under certain circumstances, attackers can exploit a flaw in domain name normalization to spoof domains they do not own. Versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2 contain a patch for this issue.

    Published: 19 Sept 2023
    5.4
    Medium

    CVE-2023-42450

    Last Modified: 18 Jun 2025

    Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 4.2.0-beta1 and prior to version 4.2.0-rc2, by crafting specific input, attackers can inject arbitrary data into HTTP requests issued by Mastodon. This can be used to perform confused deputy attacks if the server configuration includes `ALLOWED_PRIVATE_ADDRESSES` to allow access to local exploitable services. Version 4.2.0-rc2 has a patch for the issue.

    Published: 19 Sept 2023
    —
    Unknown

    CVE-2023-40744

    Last Modified: 7 Nov 2023

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2023. Notes: none.

    Published: 19 Sept 2023
    5.9
    Medium

    CVE-2023-32182

    Last Modified: 21 Nov 2024

    A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux Enterprise High Performance Computing 15 SP5 postfix, SUSE openSUSE Leap 15.5 postfix.This issue affects SUSE Linux Enterprise Desktop 15 SP5: before 3.7.3-150500.3.5.1; SUSE Linux Enterprise High Performance Computing 15 SP5: before 3.7.3-150500.3.5.1; openSUSE Leap 15.5 : before 3.7.3-150500.3.5.1.

    Published: 19 Sept 2023
    8.6
    High

    CVE-2023-42447

    Last Modified: 21 Nov 2024

    blurhash-rs is a pure Rust implementation of Blurhash, software for encoding images into ASCII strings that can be turned into a gradient of colors representing the original image. In version 0.1.1, the blurhash parsing code may panic due to multiple panic-guarded out-of-bounds accesses on untrusted input. In a typical deployment, this may get triggered by feeding a maliciously crafted blurhashes over the network. These may include UTF-8 compliant strings containing multi-byte UTF-8 characters. A patch is available in version 0.2.0, which requires user intervention because of slight API churn. No known workarounds are available.

    Published: 19 Sept 2023
    5.6
    Medium

    CVE-2023-3892

    Last Modified: 21 Nov 2024

    Improper Restriction of XML External Entity Reference vulnerability in MIM Assistant and Client DICOM RTst Loading modules allows XML Entity Linking / XML External Entities Blowup. In order to take advantage of this vulnerability, an attacker must craft a malicious XML document, embed this document into specific 3rd party private RTst metadata tags, transfer the now compromised DICOM object to MIM, and force MIM to archive and load the data. Users on either version are strongly encouraged to update to an unaffected version (7.2.11+, 7.3.4+). This issue was found and analyzed by MIM Software's internal security team.  We are unaware of any proof of concept or actual exploit available in the wild. For more information, visit https://www.mimsoftware.com/cve-2023-3892 https://www.mimsoftware.com/cve-2023-3892 This issue affects MIM Assistant: 7.2.10, 7.3.3; MIM Client: 7.2.10, 7.3.3.

    Published: 19 Sept 2023
    8.6
    High

    CVE-2023-42444

    Last Modified: 21 Nov 2024

    phonenumber is a library for parsing, formatting and validating international phone numbers. Prior to versions `0.3.3+8.13.9` and `0.2.5+8.11.3`, the phonenumber parsing code may panic due to a panic-guarded out-of-bounds access on the phonenumber string. In a typical deployment of `rust-phonenumber`, this may get triggered by feeding a maliciously crafted phonenumber over the network, specifically the string `.;phone-context=`. Versions `0.3.3+8.13.9` and `0.2.5+8.11.3` contain a patch for this issue. There are no known workarounds.

    Published: 19 Sept 2023
    7.5
    High

    CVE-2023-41890

    Last Modified: 21 Nov 2024

    Sustainsys.Saml2 library adds SAML2P support to ASP.NET web sites, allowing the web site to act as a SAML2 Service Provider. Prior to versions 1.0.3 and 2.9.2, when a response is processed, the issuer of the Identity Provider is not sufficiently validated. This could allow a malicious identity provider to craft a Saml2 response that is processed as if issued by another identity provider. It is also possible for a malicious end user to cause stored state intended for one identity provider to be used when processing the response from another provider. An application is impacted if they rely on any of these features in their authentication/authorization logic: the issuer of the generated identity and claims; or items in the stored request state (AuthenticationProperties). This issue is patched in versions 2.9.2 and 1.0.3. The `AcsCommandResultCreated` notification can be used to add the validation required if an upgrade to patched packages is not possible.

    Published: 19 Sept 2023
    7.2
    High

    CVE-2023-41179

    Last Modified: 31 Oct 2025

    A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation. Note that an attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.

    Published: 19 Sept 2023
    8.6
    High

    CVE-2023-4096

    Last Modified: 21 Nov 2024

    Weak password recovery mechanism vulnerability in Fujitsu Arconte Áurea version 1.5.0.0, which exploitation could allow an attacker to perform a brute force attack on the emailed PIN number in order to change the password of a legitimate user.

    Published: 19 Sept 2023
    5.3
    Medium

    CVE-2023-4095

    Last Modified: 21 Nov 2024

    User enumeration vulnerability in Arconte Áurea 1.5.0.0 version. The exploitation of this vulnerability could allow an attacker to obtain a list of registered users in the application, obtaining the necessary information to perform more complex attacks on the platform.

    Published: 19 Sept 2023
    6.5
    Medium

    CVE-2023-4094

    Last Modified: 21 Nov 2024

    ARCONTE Aurea's authentication system, in its 1.5.0.0 version, could allow an attacker to make incorrect access requests in order to block each legitimate account and cause a denial of service. In addition, a resource has been identified that could allow circumventing the attempt limit set in the login form.

    Published: 19 Sept 2023
    8.6
    High

    CVE-2022-47559

    Last Modified: 21 Nov 2024

    Lack of device control over web requests in ekorCCP and ekorRCI, allowing an attacker to create customised requests to execute malicious actions when a user is logged in, affecting availability, privacy and integrity.

    Published: 19 Sept 2023
    5.5
    Medium

    CVE-2023-4093

    Last Modified: 21 Nov 2024

    Reflected and persistent XSS vulnerability in Arconte Áurea, in its 1.5.0.0 version. The exploitation of this vulnerability could allow an attacker to inject malicious JavaScript code, compromise the victim's browser and take control of it, redirect the user to malicious domains or access information being viewed by the legitimate user.

    Published: 19 Sept 2023
    9.4
    Critical

    CVE-2022-47558

    Last Modified: 21 Nov 2024

    Devices ekorCCP and ekorRCI are vulnerable due to access to the FTP service using default credentials. Exploitation of this vulnerability can allow an attacker to modify critical files that could allow the creation of new users, delete or modify existing users, modify configuration files, install rootkits or backdoors.

    Published: 19 Sept 2023