CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2023-4701

    Last Modified: 7 Nov 2023

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the vendor eventually states that this issue is identical to CVE-2023-3935

    Published: 13 Sept 2023
    9.8
    Critical

    CVE-2023-3935

    Last Modified: 27 Aug 2025

    A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.

    Published: 13 Sept 2023
    5.4
    Medium

    CVE-2023-38215

    Last Modified: 27 Feb 2025

    Adobe Experience Manager versions 6.5.17 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

    Published: 13 Sept 2023
    5.4
    Medium

    CVE-2023-38214

    Last Modified: 27 Feb 2025

    Adobe Experience Manager versions 6.5.17 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

    Published: 13 Sept 2023
    4.3
    Medium

    CVE-2021-44172

    Last Modified: 21 Nov 2024

    An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClientEMS versions 7.0.0 through 7.0.4, 7.0.6 through 7.0.7, in all 6.4 and 6.2 version management interface may allow an unauthenticated attacker to gain information on environment variables such as the EMS installation path.

    Published: 13 Sept 2023
    7.8
    High

    CVE-2022-35849

    Last Modified: 16 Dec 2025

    An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiADC 7.1.0 through 7.1.1, 7.0.0 through 7.0.3, 6.2.0 through 6.2.5 and 6.1.0 all versions may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.

    Published: 13 Sept 2023
    8
    High

    CVE-2023-29183

    Last Modified: 16 Dec 2025

    An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 and FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14 GUI may allow an authenticated attacker to trigger malicious JavaScript code execution via crafted guest management setting.

    Published: 13 Sept 2023
    5.5
    Medium

    CVE-2023-40715

    Last Modified: 21 Nov 2024

    A cleartext storage of sensitive information vulnerability [CWE-312] in FortiTester 2.3.0 through 7.2.3 may allow an attacker with access to the DB contents to retrieve the plaintext password of external servers configured in the device.

    Published: 13 Sept 2023
    5.3
    Medium

    CVE-2023-40717

    Last Modified: 21 Nov 2024

    A use of hard-coded credentials vulnerability [CWE-798] in FortiTester 2.3.0 through 7.2.3 may allow an attacker who managed to get a shell on the device to access the database via shell commands.

    Published: 13 Sept 2023
    4.3
    Medium

    CVE-2023-36638

    Last Modified: 21 Nov 2024

    An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions API may allow a remote and authenticated API admin user to access some system settings such as the mail server settings through the API via a stolen GUI session ID.

    Published: 13 Sept 2023
    7.1
    High

    CVE-2023-36634

    Last Modified: 21 Nov 2024

    An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to list and delete arbitrary files and directory via specially crafted command arguments.

    Published: 13 Sept 2023
    6.7
    Medium

    CVE-2023-36642

    Last Modified: 21 Nov 2024

    An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 3.0.0 through 7.2.3 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.

    Published: 13 Sept 2023
    7.5
    High

    CVE-2023-34984

    Last Modified: 16 Dec 2025

    A protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6 through 6.3.23 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.

    Published: 13 Sept 2023
    5.3
    Medium

    CVE-2023-27998

    Last Modified: 21 Nov 2024

    A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1.1 and 1.0 may allow an unauthenticated attacker with the ability to navigate to the login GUI to gain sensitive information via navigating to specific HTTP(s) paths.

    Published: 13 Sept 2023
    4.3
    Medium

    CVE-2023-36551

    Last Modified: 21 Nov 2024

    A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows attacker to information disclosure via a crafted http request.

    Published: 13 Sept 2023
    5.5
    Medium

    CVE-2023-25608

    Last Modified: 21 Nov 2024

    An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-W2 7.2.0 through 7.2.1, 7.0.3 through 7.0.5, 7.0.0 through 7.0.1, 6.4 all versions, 6.2 all versions, 6.0 all versions; FortiAP-C 5.4.0 through 5.4.4, 5.2 all versions; FortiAP 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4 all versions, 6.0 all versions; FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to read arbitrary files via specially crafted command arguments.

    Published: 13 Sept 2023
    6.1
    Medium

    CVE-2023-29305

    Last Modified: 27 Feb 2025

    Adobe Connect versions 12.3 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

    Published: 13 Sept 2023
    6.1
    Medium

    CVE-2023-29306

    Last Modified: 27 Feb 2025

    Adobe Connect versions 12.3 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

    Published: 13 Sept 2023
    7.8
    High

    CVE-2023-26369

    Last Modified: 23 Oct 2025

    Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Sept 2023
    6.2
    Medium

    CVE-2023-4400

    Last Modified: 21 Nov 2024

    A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x prior to 10.2.25 and controlled release 12.x prior to 12.2.1, allows some authentication information stored in configuration files to be extracted through SWG REST API. This was possible due to SWG storing the password in plain text in some configuration files.

    Published: 13 Sept 2023
    5.3
    Medium

    CVE-2023-4915

    Last Modified: 8 Apr 2026

    The WP User Control plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 1.5.3. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (in the WP User Control Widget). The function changes the user's password after providing the email. The new password is only sent to the user's email, so the attacker does not have access to the new password.

    Published: 13 Sept 2023
    5.3
    Medium

    CVE-2023-4917

    Last Modified: 8 Apr 2026

    The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.7 via the 'leyka_ajax_get_env_and_options' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including Sberbank API key and password, PayPal Client Secret, and more keys and passwords.

    Published: 13 Sept 2023
    8.8
    High

    CVE-2023-4153

    Last Modified: 8 Apr 2026

    The BAN Users plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.5.3 due to a missing capability check on the 'w3dev_save_ban_user_settings_callback' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify the plugin settings to access the ban and unban functionality and set the role of the unbanned user.

    Published: 13 Sept 2023
    8.8
    High

    CVE-2023-4916

    Last Modified: 8 Apr 2026

    The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.6. This is due to missing nonce validation on the 'lwp_update_password_action' function. This makes it possible for unauthenticated attackers to change user password via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 13 Sept 2023
    8.8
    High

    CVE-2023-4213

    Last Modified: 8 Apr 2026

    The Simplr Registration Form Plus+ plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.4.5. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with subscriber-level permissions or above to change user passwords and potentially take over administrator accounts.

    Published: 13 Sept 2023
    7.2
    High

    CVE-2023-4928

    Last Modified: 21 Nov 2024

    SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1.

    Published: 13 Sept 2023
    6.1
    Medium

    CVE-2023-41162

    Last Modified: 21 Nov 2024

    A Reflected Cross-site scripting (XSS) vulnerability in the file manager tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the file mask field while searching under the tools drop down.

    Published: 13 Sept 2023
    6.1
    Medium

    CVE-2023-40617

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start 7 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'file' parameter in 'displayPDF.php'.

    Published: 13 Sept 2023
    7.5
    High

    CVE-2023-40850

    Last Modified: 21 Nov 2024

    netentsec NS-ASG 6.3 is vulnerable to Incorrect Access Control. There is a file leak in the website source code of the application security gateway.

    Published: 13 Sept 2023
    5.4
    Medium

    CVE-2023-41152

    Last Modified: 21 Nov 2024

    A Stored Cross-Site Scripting (XSS) vulnerability in the MIME type programs tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the handle program field while creating a new MIME type program.

    Published: 13 Sept 2023
    5.4
    Medium

    CVE-2023-41154

    Last Modified: 21 Nov 2024

    A Stored Cross-Site Scripting (XSS) vulnerability in the scheduled cron jobs tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the value field parameter while creating a new environment variable.

    Published: 13 Sept 2023
    5.4
    Medium

    CVE-2023-41155

    Last Modified: 21 Nov 2024

    A Stored Cross-Site Scripting (XSS) vulnerability in the mail forwarding and replies tab in Webmin and Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the forward to field while creating a mail forwarding rule.

    Published: 13 Sept 2023
    5.4
    Medium

    CVE-2023-41158

    Last Modified: 21 Nov 2024

    A Stored Cross-Site Scripting (XSS) vulnerability in the MIME type programs tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the description field while creating a new MIME type program.

    Published: 13 Sept 2023
    5.3
    Medium

    CVE-2023-42468

    Last Modified: 21 Nov 2024

    The com.cutestudio.colordialer application through 2.1.8-2 for Android allows a remote attacker to initiate phone calls without user consent, because of improper export of the com.cutestudio.dialer.activities.DialerActivity component. A third-party application (without any permissions) can craft an intent targeting com.cutestudio.dialer.activities.DialerActivity via the android.intent.action.CALL action in conjunction with a tel: URI, thereby placing a phone call.

    Published: 13 Sept 2023
    3.3
    Low

    CVE-2023-42469

    Last Modified: 21 Nov 2024

    The com.full.dialer.top.secure.encrypted application through 1.0.1 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.full.dialer.top.secure.encrypted.activities.DialerActivity component.

    Published: 13 Sept 2023
    7.5
    High

    CVE-2023-38039

    Last Modified: 2 Dec 2025

    When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.

    Published: 13 Sept 2023
    6.5
    Medium

    CVE-2023-4421

    Last Modified: 4 Nov 2025

    The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mounting Bleichenbacher-like attacks. Both the overall correctness of the padding as well as the length of the encrypted message was leaking through timing side-channel. By sending large number of attacker-selected ciphertexts, the attacker would be able to decrypt a previously intercepted PKCS#1 v1.5 ciphertext (for example, to decrypt a TLS session that used RSA key exchange), or forge a signature using the victim's key. The issue was fixed by implementing the implicit rejection algorithm, in which the NSS returns a deterministic random message in case invalid padding is detected, as proposed in the Marvin Attack paper. This vulnerability affects NSS < 3.61.

    Published: 13 Sept 2023
    7.5
    High

    CVE-2023-41081

    Last Modified: 21 Nov 2024

    Important: Authentication Bypass CVE-2023-41081 The mod_jk component of Apache Tomcat Connectors in some circumstances, such as when a configuration included "JkOptions +ForwardDirectories" but the configuration did not provide explicit mounts for all possible proxied requests, mod_jk would use an implicit mapping and map the request to the first defined worker. Such an implicit mapping could result in the unintended exposure of the status worker and/or bypass security constraints configured in httpd. As of JK 1.2.49, the implicit mapping functionality has been removed and all mappings must now be via explicit configuration. Only mod_jk is affected by this issue. The ISAPI redirector is not affected. This issue affects Apache Tomcat Connectors (mod_jk only): from 1.2.0 through 1.2.48. Users are recommended to upgrade to version 1.2.49, which fixes the issue. History 2023-09-13 Original advisory 2023-09-28 Updated summary

    Published: 13 Sept 2023
    —
    Unknown

    CVE-2023-4927

    Last Modified: 8 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 12 Sept 2023
    4.3
    Medium

    CVE-2023-4909

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)

    Published: 12 Sept 2023
    4.3
    Medium

    CVE-2023-4908

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)

    Published: 12 Sept 2023
    4.3
    Medium

    CVE-2023-4907

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)

    Published: 12 Sept 2023
    4.3
    Medium

    CVE-2023-4906

    Last Modified: 13 Feb 2025

    Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 12 Sept 2023
    4.3
    Medium

    CVE-2023-4905

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

    Published: 12 Sept 2023
    4.3
    Medium

    CVE-2023-4904

    Last Modified: 13 Feb 2025

    Insufficient policy enforcement in Downloads in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Enterprise policy restrictions via a crafted download. (Chromium security severity: Medium)

    Published: 12 Sept 2023
    4.3
    Medium

    CVE-2023-4903

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

    Published: 12 Sept 2023
    4.3
    Medium

    CVE-2023-4902

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

    Published: 12 Sept 2023
    4.3
    Medium

    CVE-2023-4901

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

    Published: 12 Sept 2023
    4.3
    Medium

    CVE-2023-4900

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate a permission prompt via a crafted HTML page. (Chromium security severity: Medium)

    Published: 12 Sept 2023
    5.3
    Medium

    CVE-2023-41885

    Last Modified: 21 Nov 2024

    Piccolo is an ORM and query builder which supports asyncio. In versions 0.120.0 and prior, the implementation of `BaseUser.login` leaks enough information to a malicious user such that they would be able to successfully generate a list of valid users on the platform. As Piccolo on its own does not also enforce strong passwords, these lists of valid accounts are likely to be used in a password spray attack with the outcome being attempted takeover of user accounts on the platform. The impact of this vulnerability is minor as it requires chaining with other attack vectors in order to gain more then simply a list of valid users on the underlying platform. The likelihood of this vulnerability is possible as it requires minimal skills to pull off, especially given the underlying login functionality for Piccolo based sites is open source. This issue has been patched in version 0.121.0.

    Published: 12 Sept 2023