CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2023-39709

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Member section.

    Published: 28 Aug 2023
    7.8
    High

    CVE-2023-39810

    Last Modified: 24 Apr 2025

    An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-40748

    Last Modified: 21 Nov 2024

    PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-40749

    Last Modified: 21 Nov 2024

    PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.

    Published: 28 Aug 2023
    6.1
    Medium

    CVE-2023-40750

    Last Modified: 21 Nov 2024

    There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Yacht Listing Script v1.0.

    Published: 28 Aug 2023
    6.1
    Medium

    CVE-2023-40751

    Last Modified: 21 Nov 2024

    PHPJabbers Fundraising Script v1.0 is vulnerable to Cross Site Scripting (XSS) via the "action" parameter of index.php.

    Published: 28 Aug 2023
    6.1
    Medium

    CVE-2023-40752

    Last Modified: 21 Nov 2024

    There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.

    Published: 28 Aug 2023
    5.4
    Medium

    CVE-2023-40753

    Last Modified: 21 Nov 2024

    There is a Cross Site Scripting (XSS) vulnerability in the message parameter of index.php in PHPJabbers Ticket Support Script v3.2.

    Published: 28 Aug 2023
    6.1
    Medium

    CVE-2023-40755

    Last Modified: 21 Nov 2024

    There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Callback Widget v1.0.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-40756

    Last Modified: 21 Nov 2024

    User enumeration is found in PHPJabbers Callback Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-40757

    Last Modified: 21 Nov 2024

    User enumeration is found in PHPJabbers Food Delivery Script v3.1. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-40758

    Last Modified: 21 Nov 2024

    User enumeration is found in PHPJabbers Document Creator v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-40759

    Last Modified: 21 Nov 2024

    User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-40761

    Last Modified: 21 Nov 2024

    User enumeration is found in PHPJabbers Yacht Listing Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-40762

    Last Modified: 21 Nov 2024

    User enumeration is found in PHPJabbers Fundraising Script v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-40763

    Last Modified: 21 Nov 2024

    User enumeration is found in PHPJabbers Taxi Booking Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-40764

    Last Modified: 21 Nov 2024

    User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-40765

    Last Modified: 21 Nov 2024

    User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-40766

    Last Modified: 21 Nov 2024

    User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

    Published: 28 Aug 2023
    6.5
    Medium

    CVE-2023-40781

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in Libming Libming v.0.4.8 allows a remote attacker to cause a denial of service via a crafted .swf file to the makeswf function.

    Published: 28 Aug 2023
    7.2
    High

    CVE-2023-40825

    Last Modified: 21 Nov 2024

    An issue in Perfree PerfreeBlog v.3.1.2 allows a remote attacker to execute arbitrary code via crafted plugin listed in admin/plugin/access/list.

    Published: 28 Aug 2023
    7.5
    High

    CVE-2023-40826

    Last Modified: 21 Nov 2024

    An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the zippluginPath parameter.

    Published: 28 Aug 2023
    7.5
    High

    CVE-2023-40827

    Last Modified: 21 Nov 2024

    An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the loadpluginPath parameter.

    Published: 28 Aug 2023
    7.5
    High

    CVE-2023-40828

    Last Modified: 21 Nov 2024

    An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the expandIfZip method in the extract function.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-40846

    Last Modified: 21 Nov 2024

    Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function sub_90998.

    Published: 28 Aug 2023
    7.5
    High

    CVE-2023-40997

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via a crafted packet.

    Published: 28 Aug 2023
    7.5
    High

    CVE-2023-40998

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via the packet size component.

    Published: 28 Aug 2023
    7.8
    High

    CVE-2023-41005

    Last Modified: 21 Nov 2024

    An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction functions in UpdateController.php

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-41109

    Last Modified: 21 Nov 2024

    SmartNode SN200 (aka SN200) 3.21.2-23021 allows unauthenticated OS Command Injection.

    Published: 28 Aug 2023
    8.1
    High

    CVE-2023-35785

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and below, Exchange Reporter Plus 5709 and below, Log360 5315 and below, Log360 UEBA 4045 and below, M365 Manager Plus 4529 and below, M365 Security Plus 4529 and below, Recovery Manager Plus 6061 and below, ServiceDesk Plus 14204 and below and 143xx 14302 and below, ServiceDesk Plus MSP 14300 and below, SharePoint Manager Plus 4402 and below, and Support Center Plus 14300 and below are vulnerable to 2FA bypass via a few TOTP authenticators. Note: A valid pair of username and password is required to leverage this vulnerability.

    Published: 28 Aug 2023
    7.5
    High

    CVE-2023-36481

    Last Modified: 21 Nov 2024

    An issue was discovered in Samsung Exynos Mobile Processor and Wearable Processor 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, and W920. Improper handling of PPP length parameter inconsistency can cause an infinite loop.

    Published: 28 Aug 2023
    7.8
    High

    CVE-2023-40590

    Last Modified: 21 Nov 2024

    GitPython is a python library used to interact with Git repositories. When resolving a program, Python/Windows look for the current working directory, and after that the PATH environment. GitPython defaults to use the `git` command, if a user runs GitPython from a repo has a `git.exe` or `git` executable, that program will be run instead of the one in the user's `PATH`. This is more of a problem on how Python interacts with Windows systems, Linux and any other OS aren't affected by this. But probably people using GitPython usually run it from the CWD of a repo. An attacker can trick a user to download a repository with a malicious `git` executable, if the user runs/imports GitPython from that directory, it allows the attacker to run any arbitrary commands. There is no fix currently available for windows users, however there are a few mitigations. 1: Default to an absolute path for the git program on Windows, like `C:\\Program Files\\Git\\cmd\\git.EXE` (default git path installation). 2: Require users to set the `GIT_PYTHON_GIT_EXECUTABLE` environment variable on Windows systems. 3: Make this problem prominent in the documentation and advise users to never run GitPython from an untrusted repo, or set the `GIT_PYTHON_GIT_EXECUTABLE` env var to an absolute path. 4: Resolve the executable manually by only looking into the `PATH` environment variable.

    Published: 28 Aug 2023
    8.8
    High

    CVE-2023-40754

    Last Modified: 21 Nov 2024

    In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-40760

    Last Modified: 21 Nov 2024

    User enumeration is found in PHP Jabbers Hotel Booking System v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

    Published: 28 Aug 2023
    9.8
    Critical

    CVE-2023-40767

    Last Modified: 21 Nov 2024

    User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

    Published: 28 Aug 2023
    7.5
    High

    CVE-2022-43904

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of excessive authentication attempts. IBM X-Force ID: 240895.

    Published: 27 Aug 2023
    7.6
    High

    CVE-2023-33852

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.4 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 257614.

    Published: 27 Aug 2023
    4.6
    Medium

    CVE-2022-43909

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 240905.

    Published: 27 Aug 2023
    7.2
    High

    CVE-2022-43907

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.4 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 240901.

    Published: 27 Aug 2023
    6.3
    Medium

    CVE-2023-4559

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in Bettershop LaikeTui. Affected by this issue is some unknown functionality of the file index.php?module=api&action=user&m=upload of the component POST Request Handler. The manipulation leads to unrestricted upload. The attack may be launched remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of this vulnerability is VDB-238160.

    Published: 27 Aug 2023
    6.3
    Medium

    CVE-2023-4558

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file staff_data.php. The manipulation of the argument columns[0][data] leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-238159.

    Published: 27 Aug 2023
    5.3
    Medium

    CVE-2023-30437

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request. IBM X-Force ID: 252293.

    Published: 27 Aug 2023
    5.5
    Medium

    CVE-2023-30436

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 252292.

    Published: 27 Aug 2023
    8.9
    High

    CVE-2023-30435

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 252291.

    Published: 27 Aug 2023
    5.9
    Medium

    CVE-2023-38730

    Last Modified: 21 Nov 2024

    IBM Storage Copy Data Management 2.2.0.0 through 2.2.19.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 262268.

    Published: 27 Aug 2023
    6.3
    Medium

    CVE-2023-4557

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file app/ajax/search_purchase_paymen_report.php. The manipulation of the argument customer leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-238158 is the identifier assigned to this vulnerability.

    Published: 27 Aug 2023
    6.3
    Medium

    CVE-2023-4556

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. Affected by this issue is the function mysqli_query of the file sexit.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-238154 is the identifier assigned to this vulnerability.

    Published: 27 Aug 2023
    3.5
    Low

    CVE-2023-4555

    Last Modified: 21 Nov 2024

    A vulnerability has been found in SourceCodester Inventory Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file suppliar_data.php. The manipulation of the argument name/company leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-238153 was assigned to this vulnerability.

    Published: 27 Aug 2023
    2.1
    Low

    CVE-2023-4548

    Last Modified: 22 Sept 2026

    A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3. The impacted element is an unknown function of the file /search of the component GET Parameter Handler. Such manipulation of the argument filter[brandid] leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. Upgrading to version 1.9.1.4 is sufficient to resolve this issue. You should upgrade the affected component.

    Published: 26 Aug 2023
    2
    Low

    CVE-2023-4547

    Last Modified: 22 Sept 2026

    A flaw has been found in SPA-Cart eCommerce CMS 1.9.0.3. The affected element is an unknown function of the file /search. This manipulation of the argument filter[brandid]/filter[price] causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. Upgrading to version 1.9.1.4 is sufficient to fix this issue. It is advisable to upgrade the affected component.

    Published: 26 Aug 2023