CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2023-34039

    Last Modified: 13 Feb 2025

    Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI.

    Published: 29 Aug 2023
    5.3
    Medium

    CVE-2023-39522

    Last Modified: 21 Nov 2024

    goauthentik is an open-source Identity Provider. In affected versions using a recovery flow with an identification stage an attacker is able to determine if a username exists. Only setups configured with a recovery flow are impacted by this. Anyone with a user account on a system with the recovery flow described above is susceptible to having their username/email revealed as existing. An attacker can easily enumerate and check users' existence using the recovery flow, as a clear message is shown when a user doesn't exist. Depending on configuration this can either be done by username, email, or both. This issue has been addressed in versions 2023.5.6 and 2023.6.2. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 29 Aug 2023
    —
    Unknown

    CVE-2023-4609

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 29 Aug 2023
    4.3
    Medium

    CVE-2023-41037

    Last Modified: 21 Nov 2024

    OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. In affected versions OpenPGP Cleartext Signed Messages are cryptographically signed messages where the signed text is readable without special tools. These messages typically contain a "Hash: ..." header declaring the hash algorithm used to compute the signature digest. OpenPGP.js up to v5.9.0 ignored any data preceding the "Hash: ..." texts when verifying the signature. As a result, malicious parties could add arbitrary text to a third-party Cleartext Signed Message, to lead the victim to believe that the arbitrary text was signed. A user or application is vulnerable to said attack vector if it verifies the CleartextMessage by only checking the returned `verified` property, discarding the associated `data` information, and instead _visually trusting_ the contents of the original message. Since `verificationResult.data` would always contain the actual signed data, users and apps that check this information are not vulnerable. Similarly, given a CleartextMessage object, retrieving the data using `getText()` or the `text` field returns only the contents that are considered when verifying the signature. Finally, re-armoring a CleartextMessage object (using `armor()` will also result in a "sanitised" version, with the extraneous text being removed. This issue has been addressed in version 5.10.1 (current stable version) which will reject messages when calling `openpgp.readCleartextMessage()` and in version 4.10.11 (legacy version) which will will reject messages when calling `openpgp.cleartext.readArmored()`. Users are advised to upgrade. Users unable to upgrade should check the contents of `verificationResult.data` to see what data was actually signed, rather than visually trusting the contents of the armored message.

    Published: 29 Aug 2023
    5.9
    Medium

    CVE-2023-3646

    Last Modified: 21 Nov 2024

    On affected platforms running Arista EOS with mirroring to multiple destinations configured, an internal system error may trigger a kernel panic and cause system reload.

    Published: 29 Aug 2023
    5.3
    Medium

    CVE-2023-24548

    Last Modified: 21 Nov 2024

    On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware can cause egress ports to be unable to forward packets. The device will continue to be susceptible to the issue until remediation is in place.

    Published: 29 Aug 2023
    4.2
    Medium

    CVE-2021-32050

    Last Modified: 3 Nov 2025

    Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0).

    Published: 29 Aug 2023
    3.9
    Low

    CVE-2023-0654

    Last Modified: 21 Nov 2024

    Due to a misconfiguration, the WARP Mobile Client (< 6.29) for Android was susceptible to a tapjacking attack. In the event that an attacker built a malicious application and managed to install it on a victim's device, the attacker would be able to trick the user into believing that the app shown on the screen was the WARP client when in reality it was the attacker's app.

    Published: 29 Aug 2023
    3.9
    Low

    CVE-2023-0238

    Last Modified: 21 Nov 2024

    Due to lack of a security policy, the WARP Mobile Client (<=6.29) for Android was susceptible to this vulnerability which allowed a malicious app installed on a victim's device to exploit a peculiarity in an Android function, wherein under certain conditions, the malicious app could dictate the task behaviour of the WARP app.

    Published: 29 Aug 2023
    8.4
    High

    CVE-2023-23774

    Last Modified: 21 Nov 2024

    Motorola EBTS/MBTS Site Controller drops to debug prompt on unhandled exception. The Motorola MBTS Site Controller exposes a debug prompt on the device's serial port in case of an unhandled exception. This allows an attacker with physical access that is able to trigger such an exception to extract secret key material and/or gain arbitrary code execution on the device.

    Published: 29 Aug 2023
    7.2
    High

    CVE-2023-23773

    Last Modified: 21 Nov 2024

    Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device.

    Published: 29 Aug 2023
    7.2
    High

    CVE-2023-23772

    Last Modified: 21 Nov 2024

    Motorola MBTS Site Controller fails to check firmware update authenticity. The Motorola MBTS Site Controller lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device.

    Published: 29 Aug 2023
    8.4
    High

    CVE-2023-23771

    Last Modified: 21 Nov 2024

    Motorola MBTS Base Radio accepts hard-coded backdoor password. The Motorola MBTS Base Radio Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.

    Published: 29 Aug 2023
    9.4
    Critical

    CVE-2023-23770

    Last Modified: 21 Nov 2024

    Motorola MBTS Site Controller accepts hard-coded backdoor password. The Motorola MBTS Site Controller Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.

    Published: 29 Aug 2023
    7.5
    High

    CVE-2023-32457

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS, versions 8.2.2.x-9.5.0.x, contains an improper privilege management vulnerability. A remote attacker with low privileges could potentially exploit this vulnerability, leading to escalation of privileges.

    Published: 29 Aug 2023
    5.3
    Medium

    CVE-2023-1995

    Last Modified: 21 Nov 2024

    Insufficient Logging vulnerability in Hitachi HiRDB Server, HiRDB Server With Addtional Function, HiRDB Structured Data Access Facility.This issue affects HiRDB Server: before 09-60-39, before 09-65-23, before 09-66-17, before 10-01-10, before 10-03-12, before 10-04-06, before 10-05-06, before 10-06-02; HiRDB Server With Addtional Function: before 09-60-2M, before 09-65-/W , before 09-66-/Q ; HiRDB Structured Data Access Facility: before 09-60-39, before 10-03-12, before 10-04-06, before 10-06-02.

    Published: 29 Aug 2023
    8.8
    High

    CVE-2023-4584

    Last Modified: 18 Dec 2025

    Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.

    Published: 29 Aug 2023
    8.8
    High

    CVE-2023-4582

    Last Modified: 18 Dec 2025

    Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occurred when allocating too much private shader memory on mac OS. *This bug only affects Firefox on macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

    Published: 29 Aug 2023
    6.5
    Medium

    CVE-2023-4580

    Last Modified: 18 Dec 2025

    Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

    Published: 29 Aug 2023
    6.5
    Medium

    CVE-2023-4577

    Last Modified: 18 Dec 2025

    When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to entering the function, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

    Published: 29 Aug 2023
    8.8
    High

    CVE-2023-4585

    Last Modified: 18 Dec 2025

    Memory safety bugs present in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

    Published: 29 Aug 2023
    7.2
    High

    CVE-2023-41362

    Last Modified: 21 Nov 2024

    MyBB before 1.8.36 allows Code Injection by users with certain high privileges. Templates in Admin CP intentionally use eval, and there was some validation of the input to eval, but type juggling interfered with this when using PCRE within PHP.

    Published: 29 Aug 2023
    6.5
    Medium

    CVE-2023-4574

    Last Modified: 18 Dec 2025

    When creating a callback over IPC for showing the Color Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of the callbacks finished. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.

    Published: 29 Aug 2023
    8.6
    High

    CVE-2023-4576

    Last Modified: 18 Dec 2025

    On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a heap buffer overflow potentially leaking sensitive data that could have led to a sandbox escape. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.

    Published: 29 Aug 2023
    9.8
    Critical

    CVE-2020-18912

    Last Modified: 21 Nov 2024

    An issue found in Earcms Ear App v.20181124 allows a remote attacker to execute arbitrary code via the uload/index-uplog.php.

    Published: 29 Aug 2023
    9.8
    Critical

    CVE-2021-3262

    Last Modified: 21 Nov 2024

    TripSpark VEO Transportation-2.2.x-XP_BB-20201123-184084 NovusEDU-2.2.x-XP_BB-20201123-184084 allows unsafe data inputs in POST body parameters from end users without sanitizing using server-side logic. It was possible to inject custom SQL commands into the "Student Busing Information" search queries.

    Published: 29 Aug 2023
    5.3
    Medium

    CVE-2023-38283

    Last Modified: 21 Nov 2024

    In OpenBGPD before 8.1, incorrect handling of BGP update data (length of path attributes) set by a potentially distant remote actor may cause the system to incorrectly reset a session. This is fixed in OpenBSD 7.3 errata 006.

    Published: 29 Aug 2023
    7.5
    High

    CVE-2023-38802

    Last Modified: 21 Nov 2024

    FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).

    Published: 29 Aug 2023
    5.4
    Medium

    CVE-2023-38971

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the rack number parameter in the add new rack function.

    Published: 29 Aug 2023
    7.5
    High

    CVE-2023-38975

    Last Modified: 21 Nov 2024

    * Buffer Overflow vulnerability in qdrant v.1.3.2 allows a remote attacker cause a denial of service via the chucnked_vectors.rs component.

    Published: 29 Aug 2023
    6.1
    Medium

    CVE-2023-39558

    Last Modified: 21 Nov 2024

    AudimexEE v15.0 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the Show Kai Data component.

    Published: 29 Aug 2023
    5.3
    Medium

    CVE-2023-39559

    Last Modified: 21 Nov 2024

    AudimexEE 15.0 was discovered to contain a full path disclosure vulnerability.

    Published: 29 Aug 2023
    7.5
    High

    CVE-2023-39663

    Last Modified: 21 Nov 2024

    Mathjax up to v2.7.9 was discovered to contain two Regular expression Denial of Service (ReDoS) vulnerabilities in MathJax.js via the components pattern and markdownPattern. NOTE: the vendor disputes this because the regular expressions are not applied to user input; thus, there is no risk.

    Published: 29 Aug 2023
    6.1
    Medium

    CVE-2023-39678

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the device web interface (Log Query page) of BDCOM OLT P3310D-2AC 10.1.0F Build 69083 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter.

    Published: 29 Aug 2023
    5.4
    Medium

    CVE-2023-41153

    Last Modified: 21 Nov 2024

    A Stored Cross-Site Scripting (XSS) vulnerability in the SSH configuration tab in Usermin 2.001 allows remote attackers to inject arbitrary web script or HTML via options for the host value while editing the host options.

    Published: 29 Aug 2023
    9.6
    Critical

    CVE-2023-41265

    Last Modified: 31 Oct 2025

    An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their privilege by tunneling HTTP requests in the raw HTTP request. This allows them to send requests that get executed by the backend server hosting the repository application. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.

    Published: 29 Aug 2023
    8.2
    High

    CVE-2023-41266

    Last Modified: 31 Oct 2025

    A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unauthenticated remote attacker to generate an anonymous session. This allows them to transmit HTTP requests to unauthorized endpoints. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.

    Published: 29 Aug 2023
    9.8
    Critical

    CVE-2023-41361

    Last Modified: 21 Nov 2024

    An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.

    Published: 29 Aug 2023
    7.5
    High

    CVE-2023-41358

    Last Modified: 21 Nov 2024

    An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.

    Published: 29 Aug 2023
    9.1
    Critical

    CVE-2023-41359

    Last Modified: 21 Nov 2024

    An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.

    Published: 29 Aug 2023
    9.1
    Critical

    CVE-2023-41360

    Last Modified: 21 Nov 2024

    An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.

    Published: 29 Aug 2023
    4.3
    Medium

    CVE-2023-41363

    Last Modified: 21 Nov 2024

    In Cerebrate 1.14, a vulnerability in UserSettingsController allows authenticated users to change user settings of other users.

    Published: 29 Aug 2023
    —
    Unknown

    CVE-2023-41377

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2023. Notes: none.

    Published: 29 Aug 2023
    6.5
    Medium

    CVE-2023-4573

    Last Modified: 18 Dec 2025

    When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.

    Published: 29 Aug 2023
    4.3
    Medium

    CVE-2023-4581

    Last Modified: 18 Dec 2025

    Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their potential harm. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.

    Published: 29 Aug 2023
    7.5
    High

    CVE-2023-4583

    Last Modified: 18 Dec 2025

    When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been discarded which was not always the case for private channels after the private session had ended. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

    Published: 29 Aug 2023
    7.4
    High

    CVE-2023-4586

    Last Modified: 20 Nov 2025

    A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack.

    Published: 29 Aug 2023
    6.5
    Medium

    CVE-2023-39615

    Last Modified: 3 Nov 2025

    Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxml2/SAX2.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted XML file. NOTE: the vendor's position is that the product does not support the legacy SAX1 interface with custom callbacks; there is a crash even without crafted input.

    Published: 29 Aug 2023
    9.8
    Critical

    CVE-2023-40889

    Last Modified: 4 Nov 2025

    A heap-based buffer overflow exists in the qr_reader_match_centers function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner.

    Published: 29 Aug 2023
    9.8
    Critical

    CVE-2023-40890

    Last Modified: 4 Nov 2025

    A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner.

    Published: 29 Aug 2023