CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2023-4092

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Arconte Áurea, in its 1.5.0.0 version. The exploitation of this vulnerability could allow an attacker to read sensitive data from the database, modify data (insert/update/delete), perform database administration operations and, in some cases, execute commands on the operating system.

    Published: 19 Sept 2023
    6.1
    Medium

    CVE-2022-47557

    Last Modified: 21 Nov 2024

    Vulnerability in ekorCCP and ekorRCI that could allow an attacker with access to the network where the device is located to decrypt the credentials of privileged users, and subsequently gain access to the system to perform malicious actions.

    Published: 19 Sept 2023
    6.5
    Medium

    CVE-2022-47556

    Last Modified: 21 Nov 2024

    Uncontrolled resource consumption in ekorRCI, allowing an attacker with low-privileged access to the web server to send continuous legitimate web requests to a functionality that is not properly validated, in order to cause a denial of service (DoS) on the device.

    Published: 19 Sept 2023
    9.3
    Critical

    CVE-2022-47555

    Last Modified: 21 Nov 2024

    Operating system command injection in ekorCCP and ekorRCI, which could allow an authenticated attacker to execute commands, create new users with elevated privileges or set up a backdoor.

    Published: 19 Sept 2023
    8.2
    High

    CVE-2022-47554

    Last Modified: 21 Nov 2024

    Exposure of sensitive information in ekorCCP and ekorRCI, potentially allowing a remote attacker to obtain critical information from various .xml files, including .xml files containing credentials, without being authenticated within the web server.

    Published: 19 Sept 2023
    6.1
    Medium

    CVE-2023-41834

    Last Modified: 13 Feb 2025

    Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted HTTP requests. Attackers could potentially inject malicious content into the HTTP response that is sent to the user's browser. Users should upgrade to Apache Flink Stateful Functions version 3.3.0.

    Published: 19 Sept 2023
    5.4
    Medium

    CVE-2023-23957

    Last Modified: 21 Nov 2024

    An authenticated user can see and modify the value for ‘next’ query parameter in Symantec Identity Portal 14.4

    Published: 19 Sept 2023
    8.6
    High

    CVE-2022-47553

    Last Modified: 21 Nov 2024

    Incorrect authorisation in ekorCCP and ekorRCI, which could allow a remote attacker to obtain resources with sensitive information for the organisation, without being authenticated within the web server.

    Published: 19 Sept 2023
    8.2
    High

    CVE-2023-32649

    Last Modified: 27 Feb 2025

    A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence functionality of our IDS, allows an unauthenticated attacker to crash the IDS module by sending specially crafted malformed network packets. During the (limited) time window before the IDS module is automatically restarted, network traffic may not be analyzed.

    Published: 19 Sept 2023
    9.2
    Critical

    CVE-2023-29245

    Last Modified: 27 Feb 2025

    A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence functionality of our IDS, may allow an unauthenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application by sending specially crafted malicious network packets. Malicious users with extensive knowledge on the underlying system may be able to extract arbitrary information from the DBMS in an uncontrolled way, alter its structure and data, and/or affect its availability.

    Published: 19 Sept 2023
    8.7
    High

    CVE-2023-2567

    Last Modified: 5 May 2025

    A SQL Injection vulnerability has been found in Nozomi Networks Guardian and CMC, due to improper input validation in certain parameters used in the Query functionality. Authenticated users may be able to execute arbitrary SQL statements on the DBMS used by the web application.

    Published: 19 Sept 2023
    7.8
    High

    CVE-2023-32184

    Last Modified: 21 Nov 2024

    A Insecure Storage of Sensitive Information vulnerability in openSUSE opensuse-welcome allows local attackers to execute code as the user that runs opensuse-welcome if a custom layout is chosen This issue affects opensuse-welcome: from 0.1 before 0.1.9+git.35.4b9444a.

    Published: 19 Sept 2023
    9.1
    Critical

    CVE-2023-0773

    Last Modified: 21 Nov 2024

    The vulnerability exists in Uniview IP Camera due to identification and authentication failure at its web-based management interface. A remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device. Successful exploitation of this vulnerability could allow the attacker to gain complete control of the targeted device.

    Published: 19 Sept 2023
    7.5
    High

    CVE-2023-32186

    Last Modified: 21 Nov 2024

    A Allocation of Resources Without Limits or Throttling vulnerability in SUSE RKE2 allows attackers with access to K3s servers apiserver/supervisor port (TCP 6443) cause denial of service. This issue affects RKE2: from 1.24.0 before 1.24.17+rke2r1, from v1.25.0 before v1.25.13+rke2r1, from v1.26.0 before v1.26.8+rke2r1, from v1.27.0 before v1.27.5+rke2r1, from v1.28.0 before v1.28.1+rke2r1.

    Published: 19 Sept 2023
    8.2
    High

    CVE-2023-5009

    Last Modified: 20 Nov 2025

    An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions starting from 16.3 before 16.3.4. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies. This was a bypass of [CVE-2023-3932](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3932) showing additional impact.

    Published: 19 Sept 2023
    5.8
    Medium

    CVE-2023-5054

    Last Modified: 8 Apr 2026

    The Super Store Finder plugin for WordPress is vulnerable to unauthenticated arbitrary email creation and relay in versions up to, and including, 6.9.3. This is due to insufficient restrictions on the sendMail.php file that allows direct access. This makes it possible for unauthenticated attackers to send emails utilizing the vulnerable site's server, with arbitrary content. Please note that this vulnerability has already been publicly disclosed with an exploit which is why we are publishing the details without a patch available, we are attempting to initiate contact with the developer.

    Published: 19 Sept 2023
    6.5
    Medium

    CVE-2023-26143

    Last Modified: 21 Nov 2024

    Versions of the package blamer before 1.0.4 are vulnerable to Arbitrary Argument Injection via the blameByFile() API. The library does not sanitize for user input or validate the given file path conforms to a specific schema, nor does it properly pass command-line flags to the git binary using the double-dash POSIX characters (--) to communicate the end of options.

    Published: 19 Sept 2023
    6.1
    Medium

    CVE-2023-5060

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1.

    Published: 19 Sept 2023
    8.8
    High

    CVE-2023-36319

    Last Modified: 21 Nov 2024

    File Upload vulnerability in Openupload Stable v.0.4.3 allows a remote attacker to execute arbitrary code via the action parameter of the compress-inc.php file.

    Published: 19 Sept 2023
    5.4
    Medium

    CVE-2023-40932

    Last Modified: 21 Nov 2024

    A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login page which means the attacker is able to to steal plaintext credentials.

    Published: 19 Sept 2023
    8.8
    High

    CVE-2023-40933

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function.

    Published: 19 Sept 2023
    5.5
    Medium

    CVE-2020-24089

    Last Modified: 21 Nov 2024

    An issue was discovered in ImfHpRegFilter.sys in IOBit Malware Fighter version 8.0.2, allows local attackers to cause a denial of service (DoS).

    Published: 19 Sept 2023
    7.2
    High

    CVE-2023-31808

    Last Modified: 21 Nov 2024

    Technicolor TG670 10.5.N.9 devices contain multiple accounts with hard-coded passwords. One account has administrative privileges, allowing for unrestricted access over the WAN interface if Remote Administration is enabled.

    Published: 19 Sept 2023
    8.1
    High

    CVE-2023-38352

    Last Modified: 21 Nov 2024

    MiniTool Partition Wizard 12.8 contains an insecure update mechanism that allows attackers to achieve remote code execution through a man in the middle attack.

    Published: 19 Sept 2023
    8.1
    High

    CVE-2023-38351

    Last Modified: 21 Nov 2024

    MiniTool Partition Wizard 12.8 contains an insecure installation mechanism that allows attackers to achieve remote code execution through a man in the middle attack.

    Published: 19 Sept 2023
    8.1
    High

    CVE-2023-38354

    Last Modified: 21 Nov 2024

    MiniTool Shadow Maker version 4.1 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

    Published: 19 Sept 2023
    8.1
    High

    CVE-2023-38355

    Last Modified: 21 Nov 2024

    MiniTool Movie Maker 7.0 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

    Published: 19 Sept 2023
    8.1
    High

    CVE-2023-38356

    Last Modified: 21 Nov 2024

    MiniTool Power Data Recovery 11.6 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

    Published: 19 Sept 2023
    5.4
    Medium

    CVE-2023-39575

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in the url_str URL parameter of ISL ARP Guard v4.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 19 Sept 2023
    6.5
    Medium

    CVE-2023-40931

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php

    Published: 19 Sept 2023
    7.2
    High

    CVE-2023-40934

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings.

    Published: 19 Sept 2023
    9.1
    Critical

    CVE-2023-41387

    Last Modified: 21 Nov 2024

    A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session tokens and overwrite arbitrary files inside the app's container. The internal database of the framework is exposed to the local user if an app uses UIFileSharingEnabled and LSSupportsOpeningDocumentsInPlace properties. As a result, local users can obtain the same attack primitives as remote attackers by tampering with the internal database of the framework on the device.

    Published: 19 Sept 2023
    5.3
    Medium

    CVE-2023-41599

    Last Modified: 21 Nov 2024

    An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal.

    Published: 19 Sept 2023
    6.1
    Medium

    CVE-2023-42399

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in xdsoft.net Jodit Editor v.4.0.0-beta.86 allows a remote attacker to obtain sensitive information via the rich text editor component.

    Published: 19 Sept 2023
    5.5
    Medium

    CVE-2023-42752

    Last Modified: 21 Nov 2024

    An integer overflow flaw was found in the Linux kernel. This issue leads to the kernel allocating `skb_shared_info` in the userspace, which is exploitable in systems without SMAP protection since `skb_shared_info` contains references to function pointers.

    Published: 19 Sept 2023
    9.8
    Critical

    CVE-2022-28357

    Last Modified: 21 Nov 2024

    NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.

    Published: 19 Sept 2023
    5.9
    Medium

    CVE-2023-38353

    Last Modified: 21 Nov 2024

    MiniTool Power Data Recovery version 11.6 and before contains an insecure in-app payment system that allows attackers to steal highly sensitive information through a man in the middle attack.

    Published: 19 Sept 2023
    10
    Critical

    CVE-2023-42454

    Last Modified: 21 Nov 2024

    SQLpage is a SQL-only webapp builder. Someone using SQLpage versions prior to 0.11.1, whose SQLpage instance is exposed publicly, with a database connection string specified in the `sqlpage/sqlpage.json` configuration file (not in an environment variable), with the web_root is the current working directory (the default), and with their database exposed publicly, is vulnerable to an attacker retrieving database connection information from SQLPage and using it to connect to their database directly. Version 0.11.0 fixes this issue. Some workarounds are available. Using an environment variable instead of the configuration file to specify the database connection string prevents exposing it on vulnerable versions. Using a different web root (that is not a parent of the SQLPage configuration directory) fixes the issue. One should also avoid exposing one's database publicly.

    Published: 18 Sept 2023
    6.5
    Medium

    CVE-2023-42446

    Last Modified: 21 Nov 2024

    Pow is a authentication and user management solution for Phoenix and Plug-based apps. Starting in version 1.0.14 and prior to version 1.0.34, use of `Pow.Store.Backend.MnesiaCache` is susceptible to session hijacking as expired keys are not being invalidated correctly on startup. A session may expire when all `Pow.Store.Backend.MnesiaCache` instances have been shut down for a period that is longer than a session's remaining TTL. Version 1.0.34 contains a patch for this issue. As a workaround, expired keys, including all expired sessions, can be manually invalidated.

    Published: 18 Sept 2023
    8.1
    High

    CVE-2023-42443

    Last Modified: 21 Nov 2024

    Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). In version 0.3.9 and prior, under certain conditions, the memory used by the builtins `raw_call`, `create_from_blueprint` and `create_copy_of` can be corrupted. For `raw_call`, the argument buffer of the call can be corrupted, leading to incorrect `calldata` in the sub-context. For `create_from_blueprint` and `create_copy_of`, the buffer for the to-be-deployed bytecode can be corrupted, leading to deploying incorrect bytecode. Each builtin has conditions that must be fulfilled for the corruption to happen. For `raw_call`, the `data` argument of the builtin must be `msg.data` and the `value` or `gas` passed to the builtin must be some complex expression that results in writing to the memory. For `create_copy_of`, the `value` or `salt` passed to the builtin must be some complex expression that results in writing to the memory. For `create_from_blueprint`, either no constructor parameters should be passed to the builtin or `raw_args` should be set to True, and the `value` or `salt` passed to the builtin must be some complex expression that results in writing to the memory. As of time of publication, no patched version exists. The issue is still being investigated, and there might be other cases where the corruption might happen. When the builtin is being called from an `internal` function `F`, the issue is not present provided that the function calling `F` wrote to memory before calling `F`. As a workaround, the complex expressions that are being passed as kwargs to the builtin should be cached in memory prior to the call to the builtin.

    Published: 18 Sept 2023
    5.3
    Medium

    CVE-2023-42441

    Last Modified: 21 Nov 2024

    Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). Starting in version 0.2.9 and prior to version 0.3.10, locks of the type `@nonreentrant("")` or `@nonreentrant('')` do not produce reentrancy checks at runtime. This issue is fixed in version 0.3.10. As a workaround, ensure the lock name is a non-empty string.

    Published: 18 Sept 2023
    6.5
    Medium

    CVE-2023-38255

    Last Modified: 21 Nov 2024

    A potential attacker with or without (cookie theft) access to the device would be able to include malicious code (XSS) when uploading new device configuration that could affect the intended function of the device.

    Published: 18 Sept 2023
    6.3
    Medium

    CVE-2023-38582

    Last Modified: 18 Jun 2025

    Persistent cross-site scripting (XSS) in the web application of MOD3GP-SY-120K allows an authenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into the field MAIL_RCV. When a legitimate user attempts to access to the vulnerable page of the web application, the XSS payload will be executed.

    Published: 18 Sept 2023
    8.9
    High

    CVE-2023-39446

    Last Modified: 21 Nov 2024

    Thanks to the weaknesses that the web application has at the user management level, an attacker could obtain the information from the headers that is necessary to create specially designed URLs and originate malicious actions when a legitimate user is logged into the web application.

    Published: 18 Sept 2023
    7.5
    High

    CVE-2023-39452

    Last Modified: 21 Nov 2024

    The web application that owns the device clearly stores the credentials within the user management section. Obtaining this information can be done remotely due to the incorrect management of the sessions in the web application.

    Published: 18 Sept 2023
    8.8
    High

    CVE-2023-40221

    Last Modified: 21 Nov 2024

    The absence of filters when loading some sections in the web application of the vulnerable device allows potential attackers to inject malicious code that will be interpreted when a legitimate user accesses the web section (MAIL SERVER) where the information is displayed. Injection can be done on parameter MAIL_RCV. When a legitimate user attempts to review NOTIFICATION/MAIL SERVER, the injected code will be executed.

    Published: 18 Sept 2023
    10
    Critical

    CVE-2023-41084

    Last Modified: 21 Nov 2024

    Session management within the web application is incorrect and allows attackers to steal session cookies to perform a multitude of actions that the web app allows on the device.

    Published: 18 Sept 2023
    7.5
    High

    CVE-2023-41965

    Last Modified: 15 Apr 2025

    Sending some requests in the web application of the vulnerable device allows information to be obtained due to the lack of security in the authentication process.

    Published: 18 Sept 2023
    6.3
    Medium

    CVE-2023-41030

    Last Modified: 21 Nov 2024

    Hard-coded credentials in Juplink RX4-1500 versions V1.0.2 through V1.0.5 allow unauthenticated attackers to log in to the web interface or telnet service as the 'user' user.

    Published: 18 Sept 2023
    7.5
    High

    CVE-2023-32187

    Last Modified: 21 Nov 2024

    An Allocation of Resources Without Limits or Throttling vulnerability in SUSE k3s allows attackers with access to K3s servers' apiserver/supervisor port (TCP 6443) cause denial of service. This issue affects k3s: from v1.24.0 before v1.24.17+k3s1, from v1.25.0 before v1.25.13+k3s1, from v1.26.0 before v1.26.8+k3s1, from sev1.27.0 before v1.27.5+k3s1, from v1.28.0 before v1.28.1+k3s1.

    Published: 18 Sept 2023