CVE Feed

    Dashboard / CVE

    8.4
    High

    CVE-2023-34999

    Last Modified: 21 Nov 2024

    A command injection vulnerability exists in RTS VLink Virtual Matrix Software Versions v5 (< 5.7.6) and v6 (< 6.5.0) that allows an attacker to perform arbitrary code execution via the admin web interface.

    Published: 18 Sept 2023
    8.8
    High

    CVE-2023-5036

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.

    Published: 18 Sept 2023
    6.3
    Medium

    CVE-2023-5034

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic was found in SourceCodester My Food Recipe 1.0. This vulnerability affects unknown code of the file index.php of the component Image Upload Handler. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-239878 is the identifier assigned to this vulnerability.

    Published: 18 Sept 2023
    6.3
    Medium

    CVE-2023-5033

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in OpenRapid RapidCMS 1.3.1. This affects an unknown part of the file /admin/category/cate-edit-run.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239877 was assigned to this vulnerability.

    Published: 18 Sept 2023
    6.3
    Medium

    CVE-2023-5032

    Last Modified: 21 Nov 2024

    A vulnerability was found in OpenRapid RapidCMS 1.3.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/article/article-edit-run.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239876.

    Published: 18 Sept 2023
    8.8
    High

    CVE-2023-41349

    Last Modified: 21 Nov 2024

    ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its Advanced Open VPN function. An authenticated remote attacker can exploit the exported OpenVPN configuration to execute an externally-controlled format string attack, resulting in sensitivity information leakage, or forcing the device to reset and permanent denial of service.

    Published: 18 Sept 2023
    7.5
    High

    CVE-2023-35851

    Last Modified: 21 Nov 2024

    SUNNET WMPro portal's FAQ function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to obtain sensitive information via a database.

    Published: 18 Sept 2023
    7.2
    High

    CVE-2023-35850

    Last Modified: 21 Nov 2024

    SUNNET WMPro portal's file management function has a vulnerability of insufficient filtering for user input. A remote attacker with administrator privilege or a privileged account can exploit this vulnerability to inject and execute arbitrary system commands to perform arbitrary system operations or disrupt service.

    Published: 18 Sept 2023
    6.3
    Medium

    CVE-2023-5031

    Last Modified: 21 Nov 2024

    A vulnerability was found in OpenRapid RapidCMS 1.3.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/article/article-add.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-239875.

    Published: 18 Sept 2023
    5.3
    Medium

    CVE-2023-26144

    Last Modified: 21 Nov 2024

    Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This vulnerability allows an attacker to degrade system performance. **Note:** It was not proven that this vulnerability can crash the process.

    Published: 18 Sept 2023
    7.8
    High

    CVE-2023-34195

    Last Modified: 21 Nov 2024

    An issue was discovered in SystemFirmwareManagementRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The implementation of the GetImage method retrieves the value of a runtime variable named GetImageProgress, and later uses this value as a function pointer. This variable is wiped out by the same module near the end of the function. By setting this UEFI variable from the OS to point into custom code, an attacker could achieve arbitrary code execution in the DXE phase, before several chipset locks are set.

    Published: 18 Sept 2023
    7.3
    High

    CVE-2023-41929

    Last Modified: 6 Mar 2025

    A DLL hijacking vulnerability in Samsung Memory Card & UFD Authentication Utility PC Software before 1.0.1 could allow a local attacker to escalate privileges. (An attacker must already have user privileges on Windows to exploit this vulnerability.)

    Published: 18 Sept 2023
    3.3
    Low

    CVE-2020-36766

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.8.6. drivers/media/cec/core/cec-api.c leaks one byte of kernel memory on specific hardware to unprivileged users, because of directly assigning log_addrs with a hole in the struct.

    Published: 18 Sept 2023
    9.8
    Critical

    CVE-2021-26837

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privileges, and gain sensitive information.

    Published: 18 Sept 2023
    9.8
    Critical

    CVE-2023-33831

    Last Modified: 21 Nov 2024

    A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.

    Published: 18 Sept 2023
    5.4
    Medium

    CVE-2023-37611

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Neos CMS 8.3.3 allows a remote authenticated attacker to execute arbitrary code via a crafted SVG file to the neos/management/media component.

    Published: 18 Sept 2023
    6.5
    Medium

    CVE-2023-39049

    Last Modified: 21 Nov 2024

    An information leak in youmart-tokunaga v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

    Published: 18 Sept 2023
    6.5
    Medium

    CVE-2023-39039

    Last Modified: 21 Nov 2024

    An information leak in Camp Style Project Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

    Published: 18 Sept 2023
    6.5
    Medium

    CVE-2023-39040

    Last Modified: 21 Nov 2024

    An information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

    Published: 18 Sept 2023
    6.5
    Medium

    CVE-2023-39043

    Last Modified: 21 Nov 2024

    An information leak in YKC Tokushima_awayokocho Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

    Published: 18 Sept 2023
    6.5
    Medium

    CVE-2023-39046

    Last Modified: 21 Nov 2024

    An information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

    Published: 18 Sept 2023
    6.5
    Medium

    CVE-2023-39056

    Last Modified: 21 Nov 2024

    An information leak in Coffee-jumbo v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

    Published: 18 Sept 2023
    6.5
    Medium

    CVE-2023-39058

    Last Modified: 21 Nov 2024

    An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

    Published: 18 Sept 2023
    5.3
    Medium

    CVE-2023-40788

    Last Modified: 21 Nov 2024

    SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error logs

    Published: 18 Sept 2023
    7.2
    High

    CVE-2023-41443

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list.

    Published: 18 Sept 2023
    7.5
    High

    CVE-2023-41595

    Last Modified: 21 Nov 2024

    An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password.

    Published: 18 Sept 2023
    9.8
    Critical

    CVE-2023-42320

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in Tenda AC10V4 v.US_AC10V4.0si_V16.03.10.13_cn_TDC01 allows a remote attacker to cause a denial of service via the mac parameter in the GetParentControlInfo function.

    Published: 18 Sept 2023
    9.8
    Critical

    CVE-2023-42359

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Exam Form Submission in PHP with Source Code v.1.0 allows a remote attacker to escalate privileges via the val-username parameter in /index.php.

    Published: 18 Sept 2023
    5.4
    Medium

    CVE-2023-42371

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in Summernote Rich Text Editor v.0.8.18 and before allows a remote attacker to execute arbitrary code via a crafted script to the insert link function in the editor component.

    Published: 18 Sept 2023
    7.5
    High

    CVE-2023-42387

    Last Modified: 21 Nov 2024

    An issue in TDSQL Chitu management platform v.10.3.19.5.0 allows a remote attacker to obtain sensitive information via get_db_info function in install.php.

    Published: 18 Sept 2023
    7.5
    High

    CVE-2023-42521

    Last Modified: 21 Nov 2024

    Certain WithSecure products allow a remote crash of a scanning engine via processing of a compressed file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1.

    Published: 18 Sept 2023
    7.5
    High

    CVE-2023-42523

    Last Modified: 21 Nov 2024

    Certain WithSecure products allow a remote crash of a scanning engine via unpacking of a PE file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1.

    Published: 18 Sept 2023
    7.5
    High

    CVE-2023-42525

    Last Modified: 21 Nov 2024

    Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1.

    Published: 18 Sept 2023
    7.5
    High

    CVE-2023-42526

    Last Modified: 21 Nov 2024

    Certain WithSecure products allow a remote crash of a scanning engine via decompression of crafted data files. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1.

    Published: 18 Sept 2023
    8.8
    High

    CVE-2023-43115

    Last Modified: 21 Nov 2024

    In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the IJS server can be specified on a gs command line (the IJS device inherently must execute a command to start the IJS server).

    Published: 18 Sept 2023
    8.8
    High

    CVE-2023-42328

    Last Modified: 21 Nov 2024

    An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the hardcoded session cookie.

    Published: 18 Sept 2023
    6.1
    Medium

    CVE-2023-42253

    Last Modified: 21 Nov 2024

    Code-Projects Vehicle Management 1.0 is vulnerable to Cross Site Scripting (XSS) in Add Accounts via Invoice No, To, and Mammul.

    Published: 18 Sept 2023
    7.5
    High

    CVE-2023-42520

    Last Modified: 21 Nov 2024

    Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1.

    Published: 18 Sept 2023
    7.5
    High

    CVE-2023-42522

    Last Modified: 21 Nov 2024

    Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1.

    Published: 18 Sept 2023
    7.5
    High

    CVE-2023-42524

    Last Modified: 21 Nov 2024

    Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1.

    Published: 18 Sept 2023
    5.5
    Medium

    CVE-2023-5030

    Last Modified: 18 Jun 2025

    A vulnerability has been found in Tongda OA up to 11.10 and classified as critical. This vulnerability affects unknown code of the file general/hr/recruit/plan/delete.php. The manipulation of the argument PLAN_ID leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239872.

    Published: 17 Sept 2023
    5.5
    Medium

    CVE-2023-5029

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /category/order/hits/copyright/46/finish/1/list/1. The manipulation with the input '"1 leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-239871.

    Published: 17 Sept 2023
    6.3
    Medium

    CVE-2023-5027

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in SourceCodester Simple Membership System 1.0. Affected by this vulnerability is an unknown functionality of the file club_validator.php. The manipulation of the argument club leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239869 was assigned to this vulnerability.

    Published: 17 Sept 2023
    2
    Low

    CVE-2023-5028

    Last Modified: 18 Jun 2025

    A vulnerability, which was classified as problematic, has been found in China Unicom TEWA-800G 4.16L.04_CT2015_Yueme. Affected by this issue is some unknown functionality. The manipulation leads to information exposure through debug log file. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. VDB-239870 is the identifier assigned to this vulnerability.

    Published: 17 Sept 2023
    3.5
    Low

    CVE-2023-5026

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in Tongda OA 11.10. Affected is an unknown function of the file /general/ipanel/menu_code.php?MENU_TYPE=FAV. The manipulation of the argument OA_SUB_WINDOW leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239868.

    Published: 17 Sept 2023
    3.5
    Low

    CVE-2023-5025

    Last Modified: 21 Nov 2024

    A vulnerability was found in KOHA up to 23.05.03. It has been declared as problematic. This vulnerability affects unknown code of the file /cgi-bin/koha/catalogue/search.pl of the component MARC. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-239866 is the identifier assigned to this vulnerability.

    Published: 17 Sept 2023
    3.5
    Low

    CVE-2023-5024

    Last Modified: 21 Nov 2024

    A vulnerability was found in Planno 23.04.04. It has been classified as problematic. This affects an unknown part of the component Comment Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239865 was assigned to this vulnerability.

    Published: 17 Sept 2023
    5.5
    Medium

    CVE-2023-5023

    Last Modified: 21 Nov 2024

    A vulnerability was found in Tongda OA 2017 and classified as critical. Affected by this issue is some unknown functionality of the file general/hr/manage/staff_relatives/delete.php. The manipulation of the argument RELATIVES_ID leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239864.

    Published: 17 Sept 2023
    5.5
    Medium

    CVE-2023-5022

    Last Modified: 18 Jun 2025

    A vulnerability has been found in DedeCMS up to 5.7.100 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_templets_post.php. The manipulation of the argument activepath leads to absolute path traversal. The associated identifier of this vulnerability is VDB-239863.

    Published: 17 Sept 2023
    3.5
    Low

    CVE-2023-5021

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, was found in SourceCodester AC Repair and Services System 1.0. Affected is an unknown function of the file admin/?page=system_info/contact_information. The manipulation of the argument telephone/mobile/address leads to cross site scripting. It is possible to launch the attack remotely. VDB-239862 is the identifier assigned to this vulnerability.

    Published: 17 Sept 2023