CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2023-39512

    Last Modified: 13 Feb 2025

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-time. The script under `data_sources.php` displays the data source management information (e.g. data source path, polling configuration, device name related to the datasource etc.) for different data visualizations of the _cacti_ app. _CENSUS_ found that an adversary that is able to configure a malicious device name, can deploy a stored XSS attack against any user of the same (or broader) privileges. A user that possesses the _General Administration>Sites/Devices/Data_ permissions can configure the device names in _cacti_. This configuration occurs through `http://<HOST>/cacti/host.php`, while the rendered malicious payload is exhibited at `http://<HOST>/cacti/data_sources.php`. This vulnerability has been addressed in version 1.2.25. Users are advised to upgrade. Users unable to update should manually filter HTML output.

    Published: 5 Sept 2023
    9.8
    Critical

    CVE-2023-4310

    Last Modified: 21 Nov 2024

    BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of this vulnerability can allow an unauthenticated remote attacker to execute underlying operating system commands within the context of the site user. This issue is fixed in version 23.2.3.

    Published: 5 Sept 2023
    6.1
    Medium

    CVE-2023-39513

    Last Modified: 25 Feb 2026

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-time. The script under `host.php` is used to monitor and manage hosts in the _cacti_ app, hence displays useful information such as data queries and verbose logs. _CENSUS_ found that an adversary that is able to configure a data-query template with malicious code appended in the template path, in order to deploy a stored XSS attack against any user with the _General Administration>Sites/Devices/Data_ privileges. A user that possesses the _Template Editor>Data Queries_ permissions can configure the data query template path in _cacti_. Please note that such a user may be a low privileged user. This configuration occurs through `http://<HOST>/cacti/data_queries.php` by editing an existing or adding a new data query template. If a template is linked to a device then the formatted template path will be rendered in the device's management page, when a _verbose data query_ is requested. This vulnerability has been addressed in version 1.2.25. Users are advised to upgrade. Users unable to update should manually filter HTML output.

    Published: 5 Sept 2023
    6.1
    Medium

    CVE-2023-39515

    Last Modified: 25 Jun 2025

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the cacti's database. These data will be viewed by administrative cacti accounts and execute JavaScript code in the victim's browser at view-time. The script under `data_debug.php` displays data source related debugging information such as _data source paths, polling settings, meta-data on the data source_. _CENSUS_ found that an adversary that is able to configure a malicious data-source path, can deploy a stored XSS attack against any user that has privileges related to viewing the `data_debug.php` information. A user that possesses the _General Administration>Sites/Devices/Data_ permissions can configure the data source path in _cacti_. This configuration occurs through `http://<HOST>/cacti/data_sources.php`. This vulnerability has been addressed in version 1.2.25. Users are advised to upgrade. Users unable to update should manually filter HTML output.

    Published: 5 Sept 2023
    6.1
    Medium

    CVE-2023-39514

    Last Modified: 10 Apr 2025

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-time. The script under `graphs.php` displays graph details such as data-source paths, data template information and graph related fields. _CENSUS_ found that an adversary that is able to configure either a data-source template with malicious code appended in the data-source name or a device with a malicious payload injected in the device name, may deploy a stored XSS attack against any user with _General Administration>Graphs_ privileges. A user that possesses the _Template Editor>Data Templates_ permissions can configure the data-source name in _cacti_. Please note that this may be a _low privileged_ user. This configuration occurs through `http://<HOST>/cacti/data_templates.php` by editing an existing or adding a new data template. If a template is linked to a graph then the formatted template name will be rendered in the graph's management page. A user that possesses the _General Administration>Sites/Devices/Data_ permissions can configure the device name in _cacti_. This vulnerability has been addressed in version 1.2.25. Users are advised to upgrade. Users unable to upgrade should add manual HTML escaping.

    Published: 5 Sept 2023
    5.4
    Medium

    CVE-2020-10128

    Last Modified: 21 Nov 2024

    SearchBlox product with version before 9.2.1 is vulnerable to stored cross-site scripting at multiple user input parameters. In SearchBlox products multiple parameters are not sanitized/validate properly which allows an attacker to inject malicious JavaScript.

    Published: 5 Sept 2023
    9.8
    Critical

    CVE-2023-4178

    Last Modified: 21 May 2026

    Authentication Bypass by Spoofing vulnerability in Neutron Neutron Smart VMS allows Authentication Bypass. This issue affects Neutron Smart VMS: before b1130.1.0.1.

    Published: 5 Sept 2023
    9.8
    Critical

    CVE-2023-4531

    Last Modified: 21 May 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestav Software E-commerce Software allows SQL Injection. This issue affects E-commerce Software: before 20230901 .

    Published: 5 Sept 2023
    7.5
    High

    CVE-2023-41317

    Last Modified: 21 Nov 2024

    The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when GraphQL Subscriptions are enabled. It can be triggered when **all of the following conditions are met**: 1. Running Apollo Router v1.28.0, v1.28.1 or v1.29.0 ("impacted versions"); **and** 2. The Supergraph schema provided to the Router (either via Apollo Uplink or explicitly via other configuration) **has a `subscription` type** with root-fields defined; **and** 3. The YAML configuration provided to the Router **has subscriptions enabled** (they are _disabled_ by default), either by setting `enabled: true` _or_ by setting a valid `mode` within the `subscriptions` object (as seen in [subscriptions' documentation](https://www.apollographql.com/docs/router/executing-operations/subscription-support/#router-setup)); **and** 4. An [anonymous](https://spec.graphql.org/draft/#sec-Anonymous-Operation-Definitions) (i.e., un-named) `subscription` operation (e.g., `subscription { ... }`) is received by the Router If **all four** of these criteria are met, the impacted versions will panic and terminate. There is no data-privacy risk or sensitive-information exposure aspect to this vulnerability. This is fixed in Apollo Router v1.29.1. Users are advised to upgrade. Updating to v1.29.1 should be a clear and simple upgrade path for those running impacted versions. However, if Subscriptions are **not** necessary for your Graph – but are enabled via configuration — then disabling subscriptions is another option to mitigate the risk.

    Published: 5 Sept 2023
    9.8
    Critical

    CVE-2023-4034

    Last Modified: 21 May 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digita Information Technology Smartrise Document Management System allows SQL Injection. This issue affects Smartrise Document Management System: before Hvl-2.0.

    Published: 5 Sept 2023
    —
    Unknown

    CVE-2023-4780

    Last Modified: 12 Mar 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-0590. Reason: This candidate is a duplicate of CVE-2024-0590. Notes: All CVE users should reference CVE-2024-0590 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 5 Sept 2023
    9.8
    Critical

    CVE-2023-3616

    Last Modified: 22 May 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mava Software Hotel Management System allows SQL Injection. This issue affects Hotel Management System: before 2.0.

    Published: 5 Sept 2023
    9.8
    Critical

    CVE-2023-35072

    Last Modified: 22 May 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Coyav Travel Proagent allows SQL Injection. This issue affects Proagent: before 20230904 .

    Published: 5 Sept 2023
    9.8
    Critical

    CVE-2023-35068

    Last Modified: 22 May 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BMA Personnel Tracking System allows SQL Injection. This issue affects Personnel Tracking System: before 20230904.

    Published: 5 Sept 2023
    9.8
    Critical

    CVE-2023-35065

    Last Modified: 22 May 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Osoft Paint Production Management allows SQL Injection. This issue affects Paint Production Management: before 2.1.

    Published: 5 Sept 2023
    7.2
    High

    CVE-2023-3375

    Last Modified: 22 May 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Unisign Bookreen allows OS Command Injection. This issue affects Bookreen: before 3.0.0.

    Published: 5 Sept 2023
    9.8
    Critical

    CVE-2023-3374

    Last Modified: 22 May 2026

    Incomplete List of Disallowed Inputs vulnerability in Unisign Bookreen allows Privilege Escalation. This issue affects Bookreen: before 3.0.0.

    Published: 5 Sept 2023
    8.1
    High

    CVE-2023-31242

    Last Modified: 13 Feb 2025

    An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially-crafted series of network requests can lead to arbitrary authentication. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 5 Sept 2023
    8.1
    High

    CVE-2023-34998

    Last Modified: 13 Feb 2025

    An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary authentication. An attacker can sniff network traffic to trigger this vulnerability.

    Published: 5 Sept 2023
    6.5
    Medium

    CVE-2023-32615

    Last Modified: 13 Feb 2025

    A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 5 Sept 2023
    6.5
    Medium

    CVE-2023-34317

    Last Modified: 13 Feb 2025

    An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to unexpected data in the configuration. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 5 Sept 2023
    3.1
    Low

    CVE-2023-34994

    Last Modified: 13 Feb 2025

    An improper resource allocation vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to creation of an arbitrary directory. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 5 Sept 2023
    6.5
    Medium

    CVE-2023-32271

    Last Modified: 13 Feb 2025

    An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to a disclosure of sensitive information. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 5 Sept 2023
    3.1
    Low

    CVE-2023-35124

    Last Modified: 13 Feb 2025

    An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to a disclosure of sensitive information. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 5 Sept 2023
    7.5
    High

    CVE-2023-34353

    Last Modified: 13 Feb 2025

    An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted network sniffing can lead to decryption of sensitive information. An attacker can sniff network traffic to trigger this vulnerability.

    Published: 5 Sept 2023
    5.5
    Medium

    CVE-2023-4778

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

    Published: 5 Sept 2023
    5.5
    Medium

    CVE-2023-4480

    Last Modified: 21 Nov 2024

    Due to an out-of-date dependency in the “Fusion File Manager” component accessible through the admin panel, an attacker can send a crafted request that allows them to read the contents of files on the system accessible within the privileges of the running process. Additionally, they may write files to arbitrary locations, provided the files pass the application’s mime-type and file extension validation. 

    Published: 5 Sept 2023
    9.8
    Critical

    CVE-2023-40743

    Last Modified: 13 Feb 2025

    ** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanisms such as LDAP. When passing untrusted input to this API method, this could expose the application to DoS, SSRF and even attacks leading to RCE. As Axis 1 has been EOL we recommend you migrate to a different SOAP engine, such as Apache Axis 2/Java. As a workaround, you may review your code to verify no untrusted or unsanitized input is passed to "ServiceFactory.getService", or by applying the patch from https://github.com/apache/axis-axis1-java/commit/7e66753427466590d6def0125e448d2791723210 . The Apache Axis project does not expect to create an Axis 1.x release fixing this problem, though contributors that would like to work towards this are welcome.

    Published: 5 Sept 2023
    8.8
    High

    CVE-2023-2453

    Last Modified: 21 Nov 2024

    There is insufficient sanitization of tainted file names that are directly concatenated with a path that is subsequently passed to a ‘require_once’ statement. This allows arbitrary files with the ‘.php’ extension for which the absolute path is known to be included and executed. There are no known means in PHPFusion through which an attacker can upload and target a ‘.php’ file payload.

    Published: 5 Sept 2023
    —
    Unknown

    CVE-2023-32086

    Last Modified: 7 Nov 2023

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 5 Sept 2023
    4.2
    Medium

    CVE-2023-20898

    Last Modified: 13 Feb 2025

    Git Providers can read from the wrong environment because they get the same cache directory base name in Salt masters prior to 3005.2 or 3006.2. Anything that uses Git Providers with different environments can get garbage data or the wrong data, which can lead to wrongful data disclosure, wrongful executions, data corruption and/or crash.

    Published: 5 Sept 2023
    5.3
    Medium

    CVE-2023-20897

    Last Modified: 13 Feb 2025

    Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the request server equal to the number of worker threads, the master will become unresponsive to return requests until restarted.

    Published: 5 Sept 2023
    5.4
    Medium

    CVE-2023-38569

    Last Modified: 21 Nov 2024

    Stored cross-site scripting vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.

    Published: 5 Sept 2023
    6.1
    Medium

    CVE-2023-36492

    Last Modified: 21 Nov 2024

    Reflected cross-site scripting vulnerability in SHIRASAGI prior to v1.18.0 allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.

    Published: 5 Sept 2023
    5.4
    Medium

    CVE-2023-40705

    Last Modified: 21 Nov 2024

    Stored cross-site scripting vulnerability in Map setting page of VI Web Client prior to 7.9.6 allows a remote authenticated attacker to inject an arbitrary script.

    Published: 5 Sept 2023
    5.4
    Medium

    CVE-2023-40535

    Last Modified: 21 Nov 2024

    Stored cross-site scripting vulnerability in View setting page of VI Web Client prior to 7.9.6 allows a remote authenticated attacker to inject an arbitrary script.

    Published: 5 Sept 2023
    6.1
    Medium

    CVE-2023-39938

    Last Modified: 21 Nov 2024

    Reflected cross-site scripting vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to inject an arbitrary script.

    Published: 5 Sept 2023
    6.1
    Medium

    CVE-2023-38574

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.

    Published: 5 Sept 2023
    8.8
    High

    CVE-2023-39448

    Last Modified: 21 Nov 2024

    Path traversal vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to alter or create arbitrary files on the server, resulting in arbitrary code execution.

    Published: 5 Sept 2023
    7.5
    High

    CVE-2023-4540

    Last Modified: 4 Apr 2025

    Improper Handling of Exceptional Conditions vulnerability in Daurnimator lua-http library allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending a properly crafted request to the server. Such a request causes the program to enter an infinite loop. This issue affects lua-http: all versions before commit ddab283.

    Published: 5 Sept 2023
    8.1
    High

    CVE-2023-28543

    Last Modified: 27 Feb 2025

    A malformed DLC can trigger Memory Corruption in SNPE library due to out of bounds read, such as by loading an untrusted model (e.g. from a remote source).

    Published: 5 Sept 2023
    8.4
    High

    CVE-2023-33021

    Last Modified: 21 Nov 2024

    Memory corruption in Graphics while processing user packets for command submission.

    Published: 5 Sept 2023
    7.5
    High

    CVE-2023-33020

    Last Modified: 21 Nov 2024

    Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE.

    Published: 5 Sept 2023
    7.5
    High

    CVE-2023-33019

    Last Modified: 21 Nov 2024

    Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE.

    Published: 5 Sept 2023
    7.5
    High

    CVE-2023-33016

    Last Modified: 21 Nov 2024

    Transient DOS in WLAN firmware while parsing MLO (multi-link operation).

    Published: 5 Sept 2023
    7.5
    High

    CVE-2023-33015

    Last Modified: 21 Nov 2024

    Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame.

    Published: 5 Sept 2023
    7.5
    High

    CVE-2023-28584

    Last Modified: 21 Nov 2024

    Transient DOS in WLAN Host when a mobile station receives invalid channel in CSA IE while doing channel switch announcement (CSA).

    Published: 5 Sept 2023
    9.8
    Critical

    CVE-2023-28581

    Last Modified: 27 Feb 2025

    Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE.

    Published: 5 Sept 2023
    7.8
    High

    CVE-2023-28573

    Last Modified: 21 Nov 2024

    Memory corruption in WLAN HAL while parsing WMI command parameters.

    Published: 5 Sept 2023
    7.8
    High

    CVE-2023-28567

    Last Modified: 27 Feb 2025

    Memory corruption in WLAN HAL while handling command through WMI interfaces.

    Published: 5 Sept 2023