CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2023-25477

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Yotuwp Video Gallery plugin <= 1.3.12 versions.

    Published: 1 Sept 2023
    6.5
    Medium

    CVE-2023-3210

    Last Modified: 20 Nov 2025

    An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content.

    Published: 1 Sept 2023
    5.5
    Medium

    CVE-2023-3950

    Last Modified: 20 Nov 2025

    An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it.

    Published: 1 Sept 2023
    4.3
    Medium

    CVE-2023-4018

    Last Modified: 27 Apr 2026

    An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to create model experiments in public projects.

    Published: 1 Sept 2023
    5.5
    Medium

    CVE-2023-4378

    Last Modified: 24 Apr 2026

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A malicious Maintainer can, under specific circumstances, leak the sentry token by changing the configured URL in the Sentry error tracking settings page. This was as a result of an incomplete fix for CVE-2022-4365.

    Published: 1 Sept 2023
    5.3
    Medium

    CVE-2023-4647

    Last Modified: 21 Apr 2026

    An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which the projects API pagination can be skipped, potentially leading to DoS on certain instances.

    Published: 1 Sept 2023
    —
    Unknown

    CVE-2023-4705

    Last Modified: 7 Nov 2023

    CVE-2023-4705 was wrongly assigned to a bug that was deemed to be a non-security issue by the Linux kernel security team.

    Published: 1 Sept 2023
    5
    Medium

    CVE-2022-4343

    Last Modified: 20 Nov 2025

    An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which a project member can leak credentials stored in site profile.

    Published: 1 Sept 2023
    3.5
    Low

    CVE-2023-0120

    Last Modified: 20 Nov 2025

    An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to edit labels description by an unauthorised user.

    Published: 1 Sept 2023
    2.6
    Low

    CVE-2023-1279

    Last Modified: 20 Nov 2025

    An issue has been discovered in GitLab affecting all versions starting from 4.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 where it was possible to create a URL that would redirect to a different project.

    Published: 1 Sept 2023
    2.7
    Low

    CVE-2023-1555

    Last Modified: 20 Nov 2025

    An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A namespace-level banned user can access the API.

    Published: 1 Sept 2023
    6.5
    Medium

    CVE-2023-3205

    Last Modified: 20 Nov 2025

    An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content.

    Published: 1 Sept 2023
    6.5
    Medium

    CVE-2023-3915

    Last Modified: 20 Nov 2025

    An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may escalate their privileges on the instance by creating a service account in that group. This service account is not classified as external and may be used to access internal projects.

    Published: 1 Sept 2023
    4.9
    Medium

    CVE-2023-4704

    Last Modified: 21 Nov 2024

    External Control of System or Configuration Setting in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

    Published: 1 Sept 2023
    8.8
    High

    CVE-2023-4697

    Last Modified: 21 Nov 2024

    Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.

    Published: 1 Sept 2023
    7.5
    High

    CVE-2023-4698

    Last Modified: 21 Nov 2024

    Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.

    Published: 1 Sept 2023
    9.8
    Critical

    CVE-2023-4696

    Last Modified: 21 Nov 2024

    Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.

    Published: 1 Sept 2023
    8.1
    High

    CVE-2023-4695

    Last Modified: 21 Nov 2024

    Use of Predictable Algorithm in Random Number Generator in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

    Published: 1 Sept 2023
    5.5
    Medium

    CVE-2023-41633

    Last Modified: 18 Feb 2026

    Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/fileutil.c.

    Published: 1 Sept 2023
    7.5
    High

    CVE-2023-40239

    Last Modified: 21 Nov 2024

    Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability.

    Published: 1 Sept 2023
    9.8
    Critical

    CVE-2023-36326

    Last Modified: 21 Nov 2024

    Integer Overflow vulnerability in RELIC before commit 34580d840469361ba9b5f001361cad659687b9ab, allows attackers to execute arbitrary code, cause a denial of service, and escalate privileges when calling realloc function in bn_grow function.

    Published: 1 Sept 2023
    9.8
    Critical

    CVE-2023-36327

    Last Modified: 21 Nov 2024

    Integer Overflow vulnerability in RELIC before commit 421f2e91cf2ba42473d4d54daf24e295679e290e, allows attackers to execute arbitrary code and cause a denial of service in pos argument in bn_get_prime function.

    Published: 1 Sept 2023
    9.8
    Critical

    CVE-2023-36328

    Last Modified: 26 Jun 2025

    Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denial of service (DoS).

    Published: 1 Sept 2023
    5.4
    Medium

    CVE-2022-44349

    Last Modified: 15 Jan 2026

    NAVBLUE S.A.S N-Ops & Crew 22.5-rc.50 is vulnerable to Cross Site Scripting (XSS).

    Published: 1 Sept 2023
    7.5
    High

    CVE-2023-28366

    Last Modified: 26 Jun 2025

    The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.

    Published: 1 Sept 2023
    7.5
    High

    CVE-2023-36088

    Last Modified: 21 Nov 2024

    Server Side Request Forgery (SSRF) vulnerability in NebulaGraph Studio version 3.7.0, allows remote attackers to gain sensitive information.

    Published: 1 Sept 2023
    9.8
    Critical

    CVE-2023-36100

    Last Modified: 21 Nov 2024

    An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain sensitive information via UserID parameter in api/User/ChangeUser.

    Published: 1 Sept 2023
    7.8
    High

    CVE-2023-24674

    Last Modified: 21 Nov 2024

    Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter.

    Published: 1 Sept 2023
    6.1
    Medium

    CVE-2023-40969

    Last Modified: 21 Nov 2024

    Senayan Library Management Systems SLIMS 9 Bulian v9.6.1 is vulnerable to Server Side Request Forgery (SSRF) via admin/modules/bibliography/pop_p2p.php.

    Published: 1 Sept 2023
    7.5
    High

    CVE-2023-41628

    Last Modified: 21 Nov 2024

    An issue in O-RAN Software Community E2 G-Release allows attackers to cause a Denial of Service (DoS) by incorrectly initiating the messaging procedure between the E2Node and E2Term components.

    Published: 1 Sept 2023
    5.8
    Medium

    CVE-2023-0809

    Last Modified: 13 Feb 2025

    In Mosquitto before 2.0.16, excessive memory is allocated based on malicious initial packets that are not CONNECT packets.

    Published: 1 Sept 2023
    9.8
    Critical

    CVE-2020-22612

    Last Modified: 21 Nov 2024

    Installer RCE on settings file write in MyBB before 1.8.22.

    Published: 1 Sept 2023
    7.5
    High

    CVE-2022-46527

    Last Modified: 21 Nov 2024

    ELSYS ERS 1.5 Sound v2.3.8 was discovered to contain a buffer overflow via the NFC data parser.

    Published: 1 Sept 2023
    4.8
    Medium

    CVE-2023-24675

    Last Modified: 21 Nov 2024

    Cross Site Scripting Vulnerability in BluditCMS v.3.14.1 allows attackers to execute arbitrary code via the Categories Friendly URL.

    Published: 1 Sept 2023
    5.8
    Medium

    CVE-2023-3592

    Last Modified: 13 Feb 2025

    In Mosquitto before 2.0.16, a memory leak occurs when clients send v5 CONNECT packets with a will message that contains invalid property types.

    Published: 1 Sept 2023
    6.1
    Medium

    CVE-2023-37826

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in General Solutions Steiner GmbH CASE 3 Taskmanagement V 3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fieldname parameter.

    Published: 1 Sept 2023
    6.1
    Medium

    CVE-2023-37827

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in General Solutions Steiner GmbH CASE 3 Taskmanagement V 3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the executionBlockName parameter.

    Published: 1 Sept 2023
    6.1
    Medium

    CVE-2023-37829

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in General Solutions Steiner GmbH CASE 3 Taskmanagement V 3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the notification.message parameter.

    Published: 1 Sept 2023
    6.1
    Medium

    CVE-2023-37830

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in General Solutions Steiner GmbH CASE 3 Taskmanagement V 3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.

    Published: 1 Sept 2023
    4.9
    Medium

    CVE-2023-39582

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in Chamilo LMS v.1.11 thru v.1.11.20 allows a remote privileged attacker to obtain sensitive information via the import sessions functions.

    Published: 1 Sept 2023
    7.5
    High

    CVE-2023-39685

    Last Modified: 21 Nov 2024

    An issue in hjson-java up to v3.0.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted JSON string.

    Published: 1 Sept 2023
    6.1
    Medium

    CVE-2023-39703

    Last Modified: 21 Nov 2024

    A cross site scripting (XSS) vulnerability in the Markdown Editor component of Typora v1.6.7 allows attackers to execute arbitrary code via uploading a crafted Markdown file.

    Published: 1 Sept 2023
    6.1
    Medium

    CVE-2023-39710

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Customer section.

    Published: 1 Sept 2023
    6.1
    Medium

    CVE-2023-39714

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Member section.

    Published: 1 Sept 2023
    7.5
    High

    CVE-2023-40771

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in DataEase v.1.18.9 allows a remote attacker to obtain sensitive information via a crafted string outside of the blacklist function.

    Published: 1 Sept 2023
    7.5
    High

    CVE-2023-40968

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in hzeller timg v.1.5.1 and before allows a remote attacker to cause a denial of service via the 0x61200000045c address.

    Published: 1 Sept 2023
    8.8
    High

    CVE-2023-40970

    Last Modified: 21 Nov 2024

    Senayan Library Management Systems SLIMS 9 Bulian v 9.6.1 is vulnerable to SQL Injection via admin/modules/circulation/loan_rules.php.

    Published: 1 Sept 2023
    9.8
    Critical

    CVE-2023-40980

    Last Modified: 21 Nov 2024

    File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file.

    Published: 1 Sept 2023
    9.8
    Critical

    CVE-2023-41364

    Last Modified: 21 Nov 2024

    In tine through 2023.01.14.325, the sort parameter of the /index.php endpoint allows SQL Injection.

    Published: 1 Sept 2023
    7.5
    High

    CVE-2023-41627

    Last Modified: 21 Nov 2024

    O-RAN Software Community ric-plt-lib-rmr v4.9.0 does not validate the source of the routing tables it receives, potentially allowing attackers to send forged routing tables to the device.

    Published: 1 Sept 2023