CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2023-4270

    Last Modified: 2 May 2025

    The Min Max Control WordPress plugin before 4.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 11 Sept 2023
    4.3
    Medium

    CVE-2023-4307

    Last Modified: 23 Apr 2025

    The Lock User Account WordPress plugin through 1.0.3 does not have CSRF check when bulk locking and unlocking accounts, which could allow attackers to make logged in admins lock and unlock arbitrary users via a CSRF attack

    Published: 11 Sept 2023
    8.8
    High

    CVE-2023-36497

    Last Modified: 16 Jan 2025

    Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 could allow a guest user to elevate to admin privileges.

    Published: 11 Sept 2023
    6.8
    Medium

    CVE-2023-38256

    Last Modified: 16 Jan 2025

    Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 vulnerable to a path traversal attack, which could allow an attacker to access files stored on the system.

    Published: 11 Sept 2023
    6.5
    Medium

    CVE-2023-41336

    Last Modified: 21 Nov 2024

    ux-autocomplete is a JavaScript Autocomplete functionality for Symfony. Under certain circumstances, an attacker could successfully submit an entity id for an `EntityType` that is *not* part of the valid choices. The problem has been fixed in `symfony/ux-autocomplete` version 2.11.2.

    Published: 11 Sept 2023
    6.1
    Medium

    CVE-2023-39227

    Last Modified: 21 Nov 2024

    ​Softneta MedDream PACS stores usernames and passwords in plaintext. The plaintext storage could be abused by attackers to leak legitimate user’s credentials.

    Published: 11 Sept 2023
    9.8
    Critical

    CVE-2023-40150

    Last Modified: 21 Nov 2024

    Softneta MedDream PACS does not perform an authentication check and performs some dangerous functionality, which could result in unauthenticated remote code execution.0

    Published: 11 Sept 2023
    9.1
    Critical

    CVE-2023-41256

    Last Modified: 16 Jan 2025

    Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 are vulnerable to authentication bypass that could allow an unauthorized attacker to obtain user access.

    Published: 11 Sept 2023
    5.5
    Medium

    CVE-2023-40032

    Last Modified: 21 Apr 2025

    libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade to libvips version 8.14.4 (or later) when processing untrusted input.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2019-16471

    Last Modified: 21 Nov 2024

    Adobe Acrobat Reader versions 2019.021.20056 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2019-16470

    Last Modified: 21 Nov 2024

    Adobe Acrobat Reader versions 2019.021.20056 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Sept 2023
    5.5
    Medium

    CVE-2019-7819

    Last Modified: 21 Nov 2024

    Adobe Acrobat Reader versions 2019.010.20098 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Sept 2023
    5.5
    Medium

    CVE-2022-34238

    Last Modified: 27 Feb 2025

    Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 20.005.30334 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2022-34227

    Last Modified: 27 May 2026

    Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2022-34224

    Last Modified: 27 May 2026

    Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2022-28835

    Last Modified: 27 Feb 2025

    Adobe InCopy versions 17.1 (and earlier) and 16.4.1 (and earlier) are affected by an Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2022-28834

    Last Modified: 27 Feb 2025

    Adobe InCopy versions 17.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2022-28836

    Last Modified: 27 Feb 2025

    Adobe InCopy versions 17.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2022-28831

    Last Modified: 27 Feb 2025

    Adobe InDesign versions 17.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2022-28833

    Last Modified: 27 Feb 2025

    Adobe InDesign versions 17.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2022-28832

    Last Modified: 27 Feb 2025

    Adobe InDesign versions 17.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Sept 2023
    5
    Medium

    CVE-2023-4630

    Last Modified: 21 Apr 2026

    An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which any user can read limited information about any project's imports.

    Published: 11 Sept 2023
    8.2
    High

    CVE-2023-3612

    Last Modified: 21 Nov 2024

    Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content.

    Published: 11 Sept 2023
    5.5
    Medium

    CVE-2023-4104

    Last Modified: 3 Jul 2025

    An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups. *This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected.* This vulnerability affects Mozilla VPN 2.16.1 < (Linux).

    Published: 11 Sept 2023
    3.1
    Low

    CVE-2023-4579

    Last Modified: 18 Dec 2025

    Search queries in the default search engine could appear to have been the currently navigated URL if the search query itself was a well formed URL. This could have led to a site spoofing another if it had been maliciously set as the default search engine. This vulnerability affects Firefox < 117.

    Published: 11 Sept 2023
    6.9
    Medium

    CVE-2023-4816

    Last Modified: 21 Nov 2024

    A vulnerability exists in the Equipment Tag Out authentication, when configured with Single Sign-On (SSO) with password validation in T214. This vulnerability can be exploited by an authenticated user per-forming an Equipment Tag Out holder action (Accept, Release, and Clear) for another user and entering an arbitrary password in the holder action confirmation dialog box. Despite entering an arbitrary password in the confirmation box, the system will execute the selected holder action.

    Published: 11 Sept 2023
    9.8
    Critical

    CVE-2023-31068

    Last Modified: 3 Mar 2026

    An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\UserDesktop\themes.

    Published: 11 Sept 2023
    9.8
    Critical

    CVE-2023-40039

    Last Modified: 21 Nov 2024

    An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame.

    Published: 11 Sept 2023
    4.7
    Medium

    CVE-2023-35845

    Last Modified: 21 Nov 2024

    Anaconda 3 2023.03-1-Linux allows local users to disrupt TLS certificate validation by modifying the cacert.pem file used by the installed pip program. This occurs because many files are installed as world-writable on Linux, ignoring umask, even when these files are installed as root. Miniconda is also affected.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2023-39063

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in RaidenFTPD 2.4.4005 allows a local attacker to execute arbitrary code via the Server name field of the Step by step setup wizard.

    Published: 11 Sept 2023
    9.8
    Critical

    CVE-2023-36140

    Last Modified: 21 Nov 2024

    In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts.

    Published: 11 Sept 2023
    7.5
    High

    CVE-2023-36161

    Last Modified: 21 Nov 2024

    An issue was discovered in Qubo Smart Plug 10A version HSP02_01_01_14_SYSTEM-10A, allows attackers to cause a denial of service (DoS) via Wi-Fi deauthentication.

    Published: 11 Sept 2023
    9.8
    Critical

    CVE-2023-40945

    Last Modified: 21 Nov 2024

    Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php.

    Published: 11 Sept 2023
    7.5
    High

    CVE-2020-19323

    Last Modified: 21 Nov 2024

    An issue was discovered in /bin/mini_upnpd on D-Link DIR-619L 2.06beta devices. There is a heap buffer overflow allowing remote attackers to restart router via the M-search request ST parameter. No authentication required

    Published: 11 Sept 2023
    5.4
    Medium

    CVE-2023-41593

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Dairy Farm Shop Management System Using PHP and MySQL v1.1 allow attackers to execute arbitrary web scripts and HTML via a crafted payload injected into the Category and Category Field parameters.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2020-24088

    Last Modified: 21 Nov 2024

    An issue was discovered in MmMapIoSpace routine in Foxconn Live Update Utility 2.1.6.26, allows local attackers to escalate privileges.

    Published: 11 Sept 2023
    9.8
    Critical

    CVE-2023-42471

    Last Modified: 21 Nov 2024

    The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It contains a manifest entry that exports the wave.ai.browser.ui.splash.SplashScreen activity. This activity uses a WebView component to display web content and doesn't adequately validate or sanitize the URI or any extra data passed in the intent by a third party application (with no permissions).

    Published: 11 Sept 2023
    8.1
    High

    CVE-2022-23382

    Last Modified: 21 Nov 2024

    Shenzhen Hichip Vision Technology IP Camera Firmware V11.4.8.1.1-20170926 has a denial of service vulnerability through sending a crafted multicast message in a local network.

    Published: 11 Sept 2023
    8.8
    High

    CVE-2020-19318

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in D-Link DIR-605L, hardware version AX, firmware version 1.17beta and below, allows authorized attackers execute arbitrary code via sending crafted data to the webserver service program.

    Published: 11 Sept 2023
    9.8
    Critical

    CVE-2020-19319

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the FILECODE parameter on login.

    Published: 11 Sept 2023
    9.8
    Critical

    CVE-2020-19559

    Last Modified: 21 Nov 2024

    An issue in Diebold Aglis XFS for Opteva v.4.1.61.1 allows a remote attacker to execute arbitrary code via a crafted payload to the ResolveMethod() parameter.

    Published: 11 Sept 2023
    8.8
    High

    CVE-2023-4863

    Last Modified: 24 Oct 2025

    Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

    Published: 11 Sept 2023
    9.8
    Critical

    CVE-2020-19320

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the curTime parameter on login.

    Published: 11 Sept 2023
    7
    High

    CVE-2023-27470

    Last Modified: 21 Nov 2024

    BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PROGRAMDATA%\GetSupportService_N-Central\PushUpdates, leading to arbitrary file deletion.

    Published: 11 Sept 2023
    9.8
    Critical

    CVE-2023-30058

    Last Modified: 21 Nov 2024

    novel-plus 3.6.2 is vulnerable to SQL Injection.

    Published: 11 Sept 2023
    9.8
    Critical

    CVE-2023-31069

    Last Modified: 3 Mar 2026

    An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML source code of the login page.

    Published: 11 Sept 2023
    9.8
    Critical

    CVE-2023-31067

    Last Modified: 21 Nov 2024

    An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\Clients\www.

    Published: 11 Sept 2023
    7.8
    High

    CVE-2023-31468

    Last Modified: 21 Nov 2024

    An issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\INOSOFT GmbH" folder has weak permissions for Everyone, allowing an attacker to insert a Trojan horse file that runs as SYSTEM. 2024-1 is a fixed version.

    Published: 11 Sept 2023
    5.3
    Medium

    CVE-2023-36980

    Last Modified: 21 Nov 2024

    An issue in Ethereum Blockchain v0.1.1+commit.6ff4cd6 cause the balance to be zeroed out when the value of betsize+casino.balance exceeds the threshold.

    Published: 11 Sept 2023
    7.2
    High

    CVE-2023-38743

    Last Modified: 5 May 2025

    Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine.

    Published: 11 Sept 2023