CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2023-39616

    Last Modified: 21 Nov 2024

    AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p in av1/common/av1_common_int.h.

    Published: 29 Aug 2023
    9.8
    Critical

    CVE-2023-40787

    Last Modified: 21 Nov 2024

    In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection.

    Published: 29 Aug 2023
    7.5
    High

    CVE-2023-41376

    Last Modified: 21 Nov 2024

    Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-handling update-fault-tolerance is not enabled, mishandle BGP path attributes.

    Published: 29 Aug 2023
    6.5
    Medium

    CVE-2023-4575

    Last Modified: 18 Dec 2025

    When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of the callbacks finished. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.

    Published: 29 Aug 2023
    6.5
    Medium

    CVE-2023-4578

    Last Modified: 18 Dec 2025

    When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErrorAndClear`. A path in the function could attempt to allocate memory when none is available which would have caused a newly created Out of Memory exception to be mishandled as a Syntax Error. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

    Published: 29 Aug 2023
    4.3
    Medium

    CVE-2023-39968

    Last Modified: 13 Feb 2025

    jupyter-server is the backend for Jupyter web applications. Open Redirect Vulnerability. Maliciously crafted login links to known Jupyter Servers can cause successful login or an already logged-in session to be redirected to arbitrary sites, which should be restricted to Jupyter Server-served URLs. This issue has been addressed in commit `29036259` which is included in release 2.7.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 28 Aug 2023
    4.6
    Medium

    CVE-2023-40170

    Last Modified: 13 Feb 2025

    jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on `/files/` URLs could allow exposure of certain file contents, or accessing files when opening untrusted files via "Open image in new tab". This issue has been addressed in commit `87a49272728` which has been included in release `2.7.2`. Users are advised to upgrade. Users unable to upgrade may use the lower performance `--ContentsManager.files_handler_class=jupyter_server.files.handlers.FilesHandler`, which implements the correct checks.

    Published: 28 Aug 2023
    4
    Medium

    CVE-2023-39348

    Last Modified: 21 Nov 2024

    Spinnaker is an open source, multi-cloud continuous delivery platform. Log output when updating GitHub status is improperly set to FULL always. It's recommended to apply the patch and rotate the GitHub token used for github status notifications. Given that this would output github tokens to a log system, the risk is slightly higher than a "low" since token exposure could grant elevated access to repositories outside of control. If using READ restricted tokens, the exposure is such that the token itself could be used to access resources otherwise restricted from reads. This only affects users of GitHub Status Notifications. This issue has been addressed in pull request 1316. Users are advised to upgrade. Users unable to upgrade should disable GH Status Notifications, Filter their logs for Echo log data and use read-only tokens that are limited in scope.

    Published: 28 Aug 2023
    8.8
    High

    CVE-2023-1997

    Last Modified: 21 Nov 2024

    An OS Command Injection vulnerability exists in SIMULIA 3DOrchestrate from Release 3DEXPERIENCE R2021x through Release 3DEXPERIENCE R2023x. A specially crafted HTTP request can lead to arbitrary command execution.

    Published: 28 Aug 2023
    —
    Unknown

    CVE-2023-4567

    Last Modified: 7 Nov 2023

    Issue has been found to be non-reproducible, therefore not a viable flaw.

    Published: 28 Aug 2023
    3.5
    Low

    CVE-2018-25089

    Last Modified: 21 Nov 2024

    A vulnerability was found in glb Meetup Tag Extension 0.1 on MediaWiki. It has been rated as problematic. This issue affects some unknown processing of the component Link Attribute Handler. The manipulation leads to use of web link to untrusted target with window.opener access. Upgrading to version 0.2 is able to address this issue. The identifier of the patch is 850c726d6bbfe0bf270801fbb92a30babea4155c. It is recommended to upgrade the affected component. The identifier VDB-238157 was assigned to this vulnerability.

    Published: 28 Aug 2023
    3.5
    Low

    CVE-2017-20186

    Last Modified: 1 Jul 2025

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in nikooo777 ckSurf up to 1.19.2. It has been declared as problematic. This vulnerability affects the function SpecListMenuDead of the file csgo/addons/sourcemod/scripting/ckSurf/misc.sp of the component Spectator List Name Handler. The manipulation of the argument cleanName leads to denial of service. Upgrading to version 1.21.0 is able to address this issue. The name of the patch is fd6318d99083a06363091441a0614bd2f21068e6. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-238156. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 28 Aug 2023
    —
    Unknown

    CVE-2023-4563

    Last Modified: 7 Nov 2023

    This was assigned as a duplicate of CVE-2023-4244.

    Published: 28 Aug 2023
    —
    Unknown

    CVE-2023-41269

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 28 Aug 2023
    8.8
    High

    CVE-2023-40195

    Last Modified: 23 Apr 2025

    Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflow Spark Provider. When the Apache Spark provider is installed on an Airflow deployment, an Airflow user that is authorized to configure Spark hooks can effectively run arbitrary code on the Airflow node by pointing it at a malicious Spark server. Prior to version 4.1.3, this was not called out in the documentation explicitly, so it is possible that administrators provided authorizations to configure Spark hooks without taking this into account. We recommend administrators to review their configurations to make sure the authorization to configure Spark hooks is only provided to fully trusted users. To view the warning in the docs please visit  https://airflow.apache.org/docs/apache-airflow-providers-apache-spark/4.1.3/connections/spark.html

    Published: 28 Aug 2023
    8.8
    High

    CVE-2023-27604

    Last Modified: 21 Nov 2024

    Apache Airflow Sqoop Provider, versions before 4.0.0, is affected by a vulnerability that allows an attacker pass parameters with the connections, which makes it possible to implement RCE attacks via ‘sqoop import --connect’, obtain airflow server permissions, etc. The attacker needs to be logged in and have authorization (permissions) to create/edit connections. It is recommended to upgrade to a version that is not affected. This issue was reported independently by happyhacking-k, And Xie Jianming and LiuHui of Caiji Sec Team also reported it.

    Published: 28 Aug 2023
    7.5
    High

    CVE-2023-38030

    Last Modified: 21 Nov 2024

    Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. An unauthenticated remote attacker can execute system commands in partial website URLs to read sensitive device information without permissions.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-38029

    Last Modified: 21 Nov 2024

    Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within their file uploading function. A unauthenticate remote attacker authenticated can upload and execute arbitrary files to perform arbitrary system commands or disrupt service.

    Published: 28 Aug 2023
    9.1
    Critical

    CVE-2023-38028

    Last Modified: 21 Nov 2024

    Saho’s attendance devices ADM100 and ADM-100FP have insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication to read system information and operate user's data, but can’t control system or disrupt service.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-38027

    Last Modified: 21 Nov 2024

    SpotCam Co., Ltd. SpotCam Sense’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthenticated attacker can exploit this vulnerability to execute command injection attack to perform arbitrary system commands or disrupt service.

    Published: 28 Aug 2023
    3.5
    Low

    CVE-2016-15035

    Last Modified: 21 Nov 2024

    A vulnerability was found in Doc2k RE-Chat 1.0. It has been classified as problematic. This affects an unknown part of the file js_on_radio-emergency.de_/re_chat.js. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The patch is named bd17d497ddd3bab4ef9c6831c747c37cc016c570. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-238155.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-38026

    Last Modified: 21 Nov 2024

    SpotCam Co., Ltd. SpotCam FHD 2 has a vulnerability of using hard-coded uBoot credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-38025

    Last Modified: 21 Nov 2024

    SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthenticated attacker can exploit this vulnerability to execute command injection attack to arbitrary system commands or disrupt service.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-38024

    Last Modified: 21 Nov 2024

    SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of using hard-coded Telnet credentials. An remote unauthenticated attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.

    Published: 28 Aug 2023
    5.3
    Medium

    CVE-2023-24959

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Systems 11.7 could expose information about the host system and environment configuration. IBM X-Force ID: 246332.

    Published: 28 Aug 2023
    5.3
    Medium

    CVE-2023-23473

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 245400.

    Published: 28 Aug 2023
    7
    High

    CVE-2023-22877

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 244368.

    Published: 28 Aug 2023
    6.5
    Medium

    CVE-2023-26270

    Last Modified: 21 Nov 2024

    IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to execute arbitrary code on the system, caused by an angular template injection flaw. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 248119.

    Published: 28 Aug 2023
    5.3
    Medium

    CVE-2023-26271

    Last Modified: 21 Nov 2024

    IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 248126.

    Published: 28 Aug 2023
    5.3
    Medium

    CVE-2023-26272

    Last Modified: 21 Nov 2024

    IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 248133.

    Published: 28 Aug 2023
    6.5
    Medium

    CVE-2023-4560

    Last Modified: 21 Nov 2024

    Improper Authorization of Index Containing Sensitive Information in GitHub repository omeka/omeka-s prior to 4.0.4.

    Published: 28 Aug 2023
    4.8
    Medium

    CVE-2023-4561

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.4.

    Published: 28 Aug 2023
    7.8
    High

    CVE-2023-4244

    Last Modified: 28 Jul 2026

    A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Due to a race condition between nf_tables netlink control plane transaction and nft_set element garbage collection, it is possible to underflow the reference counter causing a use-after-free vulnerability. We recommend upgrading past commit 3e91b0ebd994635df2346353322ac51ce84ce6d8.

    Published: 28 Aug 2023
    5.5
    Medium

    CVE-2023-39562

    Last Modified: 21 Nov 2024

    GPAC v2.3-DEV-rev449-g5948e4f70-master was discovered to contain a heap-use-after-free via the gf_bs_align function at bitstream.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.

    Published: 28 Aug 2023
    8.8
    High

    CVE-2023-40857

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in VirusTotal yara v.4.3.2 allows a remote attacker to execute arbtirary code via the yr_execute_cod function in the exe.c component.

    Published: 28 Aug 2023
    6.1
    Medium

    CVE-2020-27366

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in wlscanresults.html in Humax HGB10R-02 BRGCAB version 1.0.03, allows local attackers to execute arbitrary code.

    Published: 28 Aug 2023
    7.5
    High

    CVE-2023-26095

    Last Modified: 21 Nov 2024

    ASQ in Stormshield Network Security (SNS) 4.3.15 before 4.3.16 and 4.6.x before 4.6.3 allows a crash when analysing a crafted SIP packet.

    Published: 28 Aug 2023
    8.1
    High

    CVE-2023-34758

    Last Modified: 21 Nov 2024

    Sliver from v1.5.x to v1.5.39 has an improper cryptographic implementation, which allows attackers to execute a man-in-the-middle attack via intercepted and crafted responses.

    Published: 28 Aug 2023
    6.1
    Medium

    CVE-2023-39062

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in Spipu HTML2PDF before v.5.2.8 allows a remote attacker to execute arbitrary code via a crafted script to the forms.php.

    Published: 28 Aug 2023
    6.8
    Medium

    CVE-2023-34724

    Last Modified: 21 Nov 2024

    An issue was discovered in TECHView LA5570 Wireless Gateway 1.0.19_T53, allows physical attackers to gain escalated privileges via the UART interface.

    Published: 28 Aug 2023
    6.8
    Medium

    CVE-2023-34725

    Last Modified: 21 Nov 2024

    An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows physical attackers to gain escalated privileges via a telnet connection.

    Published: 28 Aug 2023
    8.8
    High

    CVE-2020-24165

    Last Modified: 21 Nov 2024

    An issue was discovered in TCG Accelerator in QEMU 4.2.0, allows local attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS). Note: This is disputed as a bug and not a valid security issue by multiple third parties.

    Published: 28 Aug 2023
    5.3
    Medium

    CVE-2022-46783

    Last Modified: 21 Nov 2024

    An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may be able to access the other encrypted address book.

    Published: 28 Aug 2023
    5.4
    Medium

    CVE-2023-38969

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerabiltiy in Badaso v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the title parameter in the new book and edit book function.

    Published: 28 Aug 2023
    8.8
    High

    CVE-2023-39059

    Last Modified: 21 Nov 2024

    An issue in ansible semaphore v.2.8.90 allows a remote attacker to execute arbitrary code via a crafted payload to the extra variables parameter.

    Published: 28 Aug 2023
    4.8
    Medium

    CVE-2023-39578

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the Create function of Zenario CMS v9.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Menu navigation text field.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-39560

    Last Modified: 21 Nov 2024

    ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-39650

    Last Modified: 21 Nov 2024

    Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-39652

    Last Modified: 21 Nov 2024

    theme volty tvcmsvideotab up to v4.0.0 was discovered to contain a SQL injection vulnerability via the component TvcmsVideoTabConfirmDeleteModuleFrontController::run().

    Published: 28 Aug 2023
    6.1
    Medium

    CVE-2023-39708

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Add New parameter under the New Buy section.

    Published: 28 Aug 2023