CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2023-4527

    Last Modified: 12 May 2026

    A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.

    Published: 12 Sept 2023
    5.5
    Medium

    CVE-2023-4910

    Last Modified: 20 Nov 2025

    A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens page is rendered from the browser cache.

    Published: 12 Sept 2023
    8.8
    High

    CVE-2023-4759

    Last Modified: 21 Nov 2024

    Arbitrary File Overwrite in Eclipse JGit <= 6.6.0 In Eclipse JGit, all versions <= 6.6.0.202305301015-r, a symbolic link present in a specially crafted git repository can be used to write a file to locations outside the working tree when this repository is cloned with JGit to a case-insensitive filesystem, or when a checkout from a clone of such a repository is performed on a case-insensitive filesystem. This can happen on checkout (DirCacheCheckout), merge (ResolveMerger via its WorkingTreeUpdater), pull (PullCommand using merge), and when applying a patch (PatchApplier). This can be exploited for remote code execution (RCE), for instance if the file written outside the working tree is a git filter that gets executed on a subsequent git command. The issue occurs only on case-insensitive filesystems, like the default filesystems on Windows and macOS. The user performing the clone or checkout must have the rights to create symbolic links for the problem to occur, and symbolic links must be enabled in the git configuration. Setting git configuration option core.symlinks = false before checking out avoids the problem. The issue was fixed in Eclipse JGit version 6.6.1.202309021850-r and 6.7.0.202309050840-r, available via Maven Central https://repo1.maven.org/maven2/org/eclipse/jgit/  and repo.eclipse.org https://repo.eclipse.org/content/repositories/jgit-releases/ . A backport is available in 5.13.3 starting from 5.13.3.202401111512-r. The JGit maintainers would like to thank RyotaK for finding and reporting this issue.

    Published: 12 Sept 2023
    9.8
    Critical

    CVE-2023-39637

    Last Modified: 21 Nov 2024

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis.

    Published: 12 Sept 2023
    9.8
    Critical

    CVE-2023-40834

    Last Modified: 21 Nov 2024

    OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated attackers to gain access to the application via a brute force attack to the password parameter.

    Published: 12 Sept 2023
    6.7
    Medium

    CVE-2022-47637

    Last Modified: 21 Nov 2024

    The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory. Common use cases execute files under C:\xampp with administrative privileges.

    Published: 12 Sept 2023
    4.7
    Medium

    CVE-2023-6176

    Last Modified: 6 Nov 2025

    A null pointer dereference flaw was found in the Linux kernel API for the cryptographic algorithm scatterwalk functionality. This issue occurs when a user constructs a malicious packet with specific socket configuration, which could allow a local user to crash the system or escalate their privileges on the system.

    Published: 12 Sept 2023
    9.8
    Critical

    CVE-2023-39073

    Last Modified: 21 Nov 2024

    An issue in SNMP Web Pro v.1.1 allows a remote attacker to execute arbitrary code and obtain senstive information via a crafted request.

    Published: 12 Sept 2023
    9.8
    Critical

    CVE-2023-39150

    Last Modified: 21 Nov 2024

    ConEmu before commit 230724 does not sanitize title responses correctly for control characters, potentially leading to arbitrary code execution. This is related to an incomplete fix for CVE-2022-46387.

    Published: 12 Sept 2023
    9.8
    Critical

    CVE-2023-40784

    Last Modified: 21 Nov 2024

    DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.

    Published: 12 Sept 2023
    5.4
    Medium

    CVE-2023-41423

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in WP Githuber MD plugin v.1.16.2 allows a remote attacker to execute arbitrary code via a crafted payload to the new article function.

    Published: 12 Sept 2023
    8.8
    High

    CVE-2023-4918

    Last Modified: 21 Nov 2024

    A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself through registration flow, the "password" and "password-confirm" field from the form will occur as regular user attributes. All users and clients with proper rights and roles are able to read users attributes, allowing a malicious user with minimal access to retrieve the users passwords in clear text, jeopardizing their environment.

    Published: 12 Sept 2023
    2
    Low

    CVE-2023-40218

    Last Modified: 21 Nov 2024

    An issue was discovered in the NPU kernel driver in Samsung Exynos Mobile Processor 9820, 980, 2100, 2200, 1280, and 1380. An integer overflow can bypass detection of error cases via a crafted application.

    Published: 12 Sept 2023
    3.3
    Low

    CVE-2023-40442

    Last Modified: 13 Feb 2025

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Monterey 12.6.8. An app may be able to read sensitive location information.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2023-41990

    Last Modified: 23 Oct 2025

    The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Ventura 13.2, watchOS 9.3. Processing a font file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1.

    Published: 11 Sept 2023
    7.5
    High

    CVE-2023-40440

    Last Modified: 25 Jun 2025

    This issue was addressed with improved state management of S/MIME encrypted emails. This issue is fixed in macOS Monterey 12.6.8. A S/MIME encrypted email may be inadvertently sent unencrypted.

    Published: 11 Sept 2023
    8.8
    High

    CVE-2023-4899

    Last Modified: 21 Nov 2024

    SQL Injection in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.

    Published: 11 Sept 2023
    7.5
    High

    CVE-2023-4898

    Last Modified: 21 Nov 2024

    Authentication Bypass by Primary Weakness in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.

    Published: 11 Sept 2023
    7.5
    High

    CVE-2023-41879

    Last Modified: 21 Nov 2024

    Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. This issue has been patched in versions 19.5.1 and 20.1.1.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2023-35687

    Last Modified: 21 Nov 2024

    In MtpPropertyValue of MtpProperty.h, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Sept 2023
    8.8
    High

    CVE-2023-35684

    Last Modified: 21 Nov 2024

    In avdt_msg_asmbl of avdt_msg.cc, there is a possible out of bounds write due to an integer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Sept 2023
    5.5
    Medium

    CVE-2023-35683

    Last Modified: 21 Nov 2024

    In bindSelection of DatabaseUtils.java, there is a possible way to access files from other applications due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2023-35682

    Last Modified: 5 May 2025

    In hasPermissionForActivity of PackageManagerHelper.java, there is a possible way to start arbitrary components due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 11 Sept 2023
    9.8
    Critical

    CVE-2023-35681

    Last Modified: 21 Nov 2024

    In eatt_l2cap_reconfig_completed of eatt_impl.h, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Sept 2023
    5.5
    Medium

    CVE-2023-35680

    Last Modified: 21 Nov 2024

    In multiple locations, there is a possible way to import contacts belonging to other users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Sept 2023
    5.5
    Medium

    CVE-2023-35679

    Last Modified: 21 Nov 2024

    In MtpPropertyValue of MtpProperty.h, there is a possible out of bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 11 Sept 2023
    5.5
    Medium

    CVE-2023-35677

    Last Modified: 21 Nov 2024

    In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission check. This could lead to local denial of service (factory reset or continuous locking) with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2023-35676

    Last Modified: 21 Nov 2024

    In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a background activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Sept 2023
    5.5
    Medium

    CVE-2023-35675

    Last Modified: 21 Nov 2024

    In loadMediaResumptionControls of MediaResumeListener.kt, there is a possible way to play and listen to media files played by another user on the same device due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2023-35674

    Last Modified: 23 Oct 2025

    In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Sept 2023
    8.8
    High

    CVE-2023-35673

    Last Modified: 21 Nov 2024

    In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Sept 2023
    5.5
    Medium

    CVE-2023-35671

    Last Modified: 21 Nov 2024

    In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number and expiry details when the device is in locked screen mode due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2023-35670

    Last Modified: 2 May 2025

    In computeValuesFromData of FileUtils.java, there is a possible way to insert files to other apps' external private directories due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2023-35669

    Last Modified: 21 Nov 2024

    In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activities due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2023-35667

    Last Modified: 21 Nov 2024

    In updateList of NotificationAccessSettings.java, there is a possible way to hide approved notification listeners in the settings due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2023-35666

    Last Modified: 21 Nov 2024

    In bta_av_rc_msg of bta_av_act.cc, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2023-35665

    Last Modified: 21 Nov 2024

    In multiple files, there is a possible way to import a contact from another user due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Sept 2023
    5.5
    Medium

    CVE-2023-35664

    Last Modified: 21 Nov 2024

    In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Sept 2023
    8.8
    High

    CVE-2023-35658

    Last Modified: 21 Nov 2024

    In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible privilege escalation due to a use after free. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Sept 2023
    9.8
    Critical

    CVE-2023-4897

    Last Modified: 21 Nov 2024

    Relative Path Traversal in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.

    Published: 11 Sept 2023
    6.1
    Medium

    CVE-2023-4294

    Last Modified: 2 May 2025

    The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing an unauthenticated attacker to inject malicious javascript that will trigger in the plugins admin panel with statistics of the created short link.

    Published: 11 Sept 2023
    4.8
    Medium

    CVE-2023-3170

    Last Modified: 21 Nov 2024

    The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not validate and escape some settings, which could allow users with Admin privileges to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 11 Sept 2023
    7.5
    High

    CVE-2023-4278

    Last Modified: 23 Apr 2025

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instructor. They can then add courses and/or posts.

    Published: 11 Sept 2023
    4.8
    Medium

    CVE-2023-4060

    Last Modified: 23 Apr 2025

    The WP Adminify WordPress plugin before 3.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 11 Sept 2023
    5.4
    Medium

    CVE-2023-3510

    Last Modified: 21 Nov 2024

    The FTP Access WordPress plugin through 1.0 does not have authorisation and CSRF checks when updating its settings and is missing sanitisation as well as escaping in them, allowing any authenticated users, such as subscriber to update them with XSS payloads, which will be triggered when an admin will view the settings of the plugin. The attack could also be perform via CSRF against any authenticated user.

    Published: 11 Sept 2023
    6.1
    Medium

    CVE-2023-3169

    Last Modified: 21 Nov 2024

    The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not have authorisation in a REST route and does not validate as well as escape some parameters when outputting them back, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.

    Published: 11 Sept 2023
    7.2
    High

    CVE-2023-4314

    Last Modified: 23 Apr 2025

    The wpDataTables WordPress plugin before 2.1.66 does not validate the "Serialized PHP array" input data before deserializing the data. This allows admins to deserialize arbitrary data which may lead to remote code execution if a suitable gadget chain is present on the server. This is impactful in environments where admin users should not be allowed to execute arbitrary code, such as multisite.

    Published: 11 Sept 2023
    6.1
    Medium

    CVE-2023-2705

    Last Modified: 21 Nov 2024

    The gAppointments WordPress plugin before 1.10.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin

    Published: 11 Sept 2023
    4.8
    Medium

    CVE-2023-4022

    Last Modified: 23 Apr 2025

    The Herd Effects WordPress plugin before 5.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 11 Sept 2023
    4.3
    Medium

    CVE-2023-4318

    Last Modified: 23 Apr 2025

    The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items, which could allow attackers to make logged in admins delete arbitrary effects via a CSRF attack

    Published: 11 Sept 2023