CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2023-4546

    Last Modified: 21 Nov 2024

    A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230816. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /sysmanage/licence.php. The manipulation leads to improper access controls. The exploit has been disclosed to the public and may be used. The identifier VDB-238057 was assigned to this vulnerability.

    Published: 26 Aug 2023
    6.3
    Medium

    CVE-2023-4545

    Last Modified: 21 Nov 2024

    A vulnerability was found in IBOS OA 4.5.5. It has been classified as critical. Affected is an unknown function of the file ?r=recruit/bgchecks/export&checkids=x. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-238056. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 26 Aug 2023
    4.3
    Medium

    CVE-2023-4544

    Last Modified: 1 Jul 2025

    A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230809. It has been rated as problematic. This issue affects some unknown processing of the file /config/php.ini. The manipulation leads to direct request. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-238049 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 26 Aug 2023
    8.3
    High

    CVE-2023-36741

    Last Modified: 27 Feb 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 26 Aug 2023
    6.3
    Medium

    CVE-2023-4543

    Last Modified: 21 Nov 2024

    A vulnerability was found in IBOS OA 4.5.5. It has been declared as critical. This vulnerability affects unknown code of the file ?r=recruit/contact/export&contactids=x. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-238048. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 25 Aug 2023
    6.3
    Medium

    CVE-2023-4542

    Last Modified: 21 Nov 2024

    A vulnerability was found in D-Link DAR-8000-10 up to 20230809. It has been classified as critical. This affects an unknown part of the file /app/sys1.php. The manipulation of the argument cmd with the input id leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-238047. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 25 Aug 2023
    4.3
    Medium

    CVE-2023-40587

    Last Modified: 13 Feb 2025

    Pyramid is an open source Python web framework. A path traversal vulnerability in Pyramid versions 2.0.0 and 2.0.1 impacts users of Python 3.11 that are using a Pyramid static view with a full filesystem path and have a `index.html` file that is located exactly one directory above the location of the static view's file system path. No further path traversal exists, and the only file that could be disclosed accidentally is `index.html`. Pyramid version 2.0.2 rejects any path that contains a null-byte out of caution. While valid in directory/file names, we would strongly consider it a mistake to use null-bytes in naming files/directories. Secondly, Python 3.11, and 3.12 has fixed the underlying issue in `os.path.normpath` to no longer truncate on the first `0x00` found, returning the behavior to pre-3.11 Python, un an as of yet unreleased version. Fixes will be available in:Python 3.12.0rc2 and 3.11.5. Some workarounds are available. Use a version of Python 3 that is not affected, downgrade to Python 3.10 series temporarily, or wait until Python 3.11.5 is released and upgrade to the latest version of Python 3.11 series.

    Published: 25 Aug 2023
    6.1
    Medium

    CVE-2023-41080

    Last Modified: 29 Oct 2025

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, EOL versions may also be affected. The vulnerability is limited to the ROOT (default) web application.

    Published: 25 Aug 2023
    7.5
    High

    CVE-2023-40586

    Last Modified: 21 Nov 2024

    OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Due to the misuse of `log.Fatalf`, the application using coraza crashed after receiving crafted requests from attackers. The application will immediately crash after receiving a malicious request that triggers an error in `mime.ParseMediaType`. This issue was patched in version 3.0.1.

    Published: 25 Aug 2023
    7.3
    High

    CVE-2023-40585

    Last Modified: 21 Nov 2024

    ironic-image is a container image to run OpenStack Ironic as part of Metal³. Prior to version capm3-v1.4.3, if Ironic is not deployed with TLS and it does not have API and Conductor split into separate services, access to the API is not protected by any authentication. Ironic API is also listening in host network. In case the node is not behind a firewall, the API could be accessed by anyone via network without authentication. By default, Ironic API in Metal3 is protected by TLS and basic authentication, so this vulnerability requires operator to configure API without TLS for it to be vulnerable. TLS and authentication however should not be coupled as they are in versions prior to capm3-v1.4.3. A patch exists in versions capm3-v1.4.3 and newer. Some workarounds are available. Either configure TLS for Ironic API (`deploy.sh -t ...`, `IRONIC_TLS_SETUP=true`) or split Ironic API and Conductor via configuration change (old implementation, not recommended). With both workarounds, services are configured with httpd front-end, which has proper authentication configuration in place.

    Published: 25 Aug 2023
    9.8
    Critical

    CVE-2023-40571

    Last Modified: 21 Nov 2024

    weblogic-framework is a tool for detecting weblogic vulnerabilities. Versions 0.2.3 and prior do not verify the returned data packets, and there is a deserialization vulnerability which may lead to remote code execution. When weblogic-framework gets the command echo, it directly deserializes the data returned by the server without verifying it. At the same time, the classloader loads a lot of deserialization calls. In this case, the malicious serialized data returned by the server will cause remote code execution. Version 0.2.4 contains a patch for this issue.

    Published: 25 Aug 2023
    7.5
    High

    CVE-2023-40583

    Last Modified: 21 Nov 2024

    libp2p is a networking stack and library modularized out of The IPFS Project, and bundled separately for other tools to use. In go-libp2p, by using signed peer records a malicious actor can store an arbitrary amount of data in a remote node’s memory. This memory does not get garbage collected and so the victim can run out of memory and crash. If users of go-libp2p in production are not monitoring memory consumption over time, it could be a silent attack i.e. the attacker could bring down nodes over a period of time (how long depends on the node resources i.e. a go-libp2p node on a virtual server with 4 gb of memory takes about 90 sec to bring down; on a larger server, it might take a bit longer.) This issue was patched in version 0.27.4.

    Published: 25 Aug 2023
    5.5
    Medium

    CVE-2023-40166

    Last Modified: 21 Nov 2024

    Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer read overflow in `FileManager::detectLanguageFromTextBegining `. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information. As of time of publication, no known patches are available in existing versions of Notepad++.

    Published: 25 Aug 2023
    5.5
    Medium

    CVE-2023-40164

    Last Modified: 21 Nov 2024

    Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `nsCodingStateMachine::NextStater`. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information. As of time of publication, no known patches are available in existing versions of Notepad++.

    Published: 25 Aug 2023
    6.5
    Medium

    CVE-2023-32678

    Last Modified: 21 Nov 2024

    Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private stream and have been removed from it since retain the ability to edit messages/topics, move messages to other streams, and delete messages that they used to have access to, if other relevant organization permissions allow these actions. For example, a user may be able to edit or delete their old messages they posted in such a private stream. An administrator will be able to delete old messages (that they had access to) from the private stream. This issue was fixed in Zulip Server version 7.3.

    Published: 25 Aug 2023
    5.5
    Medium

    CVE-2023-40036

    Last Modified: 21 Nov 2024

    Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `CharDistributionAnalysis::HandleOneChar`. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information. As of time of publication, no known patches are available in existing versions of Notepad++.

    Published: 25 Aug 2023
    8.1
    High

    CVE-2023-40580

    Last Modified: 21 Nov 2024

    Freighter is a Stellar chrome extension. It may be possible for a malicious website to access the recovery mnemonic phrase when the Freighter wallet is unlocked. This vulnerability impacts access control to the mnemonic recovery phrase. This issue was patched in version 5.3.1.

    Published: 25 Aug 2023
    7.8
    High

    CVE-2023-40031

    Last Modified: 21 Nov 2024

    Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer write overflow in `Utf8_16_Read::convert`. This issue may lead to arbitrary code execution. As of time of publication, no known patches are available in existing versions of Notepad++.

    Published: 25 Aug 2023
    6.5
    Medium

    CVE-2023-40579

    Last Modified: 21 Nov 2024

    OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of OpenFGA v1.3.0 or earlier are vulnerable to authorization bypass when calling the ListObjects API. The vulnerability affects customers using `ListObjects` with specific models. The affected models contain expressions of type `rel1 from type1`. This issue has been patched in version 1.3.1.

    Published: 25 Aug 2023
    5.3
    Medium

    CVE-2023-25848

    Last Modified: 21 Nov 2024

    ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a crafted query that may result in a low severity information disclosure issue. The information disclosed is limited to a single attribute in a database connection string. No business data is disclosed.

    Published: 25 Aug 2023
    7.8
    High

    CVE-2019-13689

    Last Modified: 2 May 2025

    Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform arbitrary read/write via a malicious file. (Chromium security severity: Critical)

    Published: 25 Aug 2023
    9.6
    Critical

    CVE-2019-13690

    Last Modified: 2 May 2025

    Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)

    Published: 25 Aug 2023
    8.8
    High

    CVE-2022-4452

    Last Modified: 21 Nov 2024

    Insufficient data validation in crosvm in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 25 Aug 2023
    3.5
    Low

    CVE-2023-4534

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, was found in NeoMind Fusion Platform up to 20230731. Affected is an unknown function of the file /fusion/portal/action/Link. The manipulation of the argument link leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-238026 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 25 Aug 2023
    3.5
    Low

    CVE-2023-41250

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration

    Published: 25 Aug 2023
    4.6
    Medium

    CVE-2023-41249

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step

    Published: 25 Aug 2023
    4.6
    Medium

    CVE-2023-41248

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configuration

    Published: 25 Aug 2023
    7.1
    High

    CVE-2023-32797

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution video carousel slider with lightbox plugin <= 1.0.22 versions.

    Published: 25 Aug 2023
    7.1
    High

    CVE-2023-32603

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RedNao Donations Made Easy – Smart Donations plugin <= 4.0.12 versions.

    Published: 25 Aug 2023
    7.1
    High

    CVE-2023-32598

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in A. R. Jones Featured Image Pro Post Grid plugin <= 5.14 versions.

    Published: 25 Aug 2023
    5.9
    Medium

    CVE-2023-32575

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Product page shipping calculator for WooCommerce plugin <= 1.3.25 versions.

    Published: 25 Aug 2023
    5.9
    Medium

    CVE-2023-24394

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy iframe popup plugin <= 3.3 versions.

    Published: 25 Aug 2023
    5.9
    Medium

    CVE-2023-32596

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wolfgang Ertl weebotLite plugin <= 1.0.0 versions.

    Published: 25 Aug 2023
    5.9
    Medium

    CVE-2023-32595

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Palasthotel by Edward Bock, Katharina Rompf Sunny Search plugin <= 1.0.2 versions.

    Published: 25 Aug 2023
    6.5
    Medium

    CVE-2023-25981

    Last Modified: 21 Nov 2024

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form plugin <= 2.8.1 versions.

    Published: 25 Aug 2023
    6.8
    Medium

    CVE-2023-25649

    Last Modified: 21 Nov 2024

    There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

    Published: 25 Aug 2023
    4.3
    Medium

    CVE-2023-4478

    Last Modified: 21 Nov 2024

    Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thus blocking them from later accessing Mattermost without the system admin activating their accounts.

    Published: 25 Aug 2023
    5.9
    Medium

    CVE-2023-32591

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Cloud Primero B.V DBargain plugin <= 3.0.0 versions.

    Published: 25 Aug 2023
    5.9
    Medium

    CVE-2023-32584

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in John Newcombe eBecas plugin <= 3.1.3 versions.

    Published: 25 Aug 2023
    5.9
    Medium

    CVE-2023-32577

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eji Osigwe DevBuddy Twitter Feed plugin <= 4.0.0 versions.

    Published: 25 Aug 2023
    6.5
    Medium

    CVE-2023-32576

    Last Modified: 21 Nov 2024

    Auth. (subscriber+) Stored Cross-Site Scripting') vulnerability in Plainware Locatoraid Store Locator plugin <= 3.9.18 versions.

    Published: 25 Aug 2023
    7.1
    High

    CVE-2023-32518

    Last Modified: 19 Feb 2025

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ono Oogami WP Chinese Conversion plugin <= 1.1.16 versions.

    Published: 25 Aug 2023
    7.7
    High

    CVE-2023-3406

    Last Modified: 23 Feb 2026

    Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files on the web server

    Published: 25 Aug 2023
    6.5
    Medium

    CVE-2023-3425

    Last Modified: 23 Feb 2026

    Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated user to read restricted amount of bytes from memory.

    Published: 25 Aug 2023
    9.8
    Critical

    CVE-2023-32757

    Last Modified: 21 Nov 2024

    e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker without logging the service can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.

    Published: 25 Aug 2023
    —
    Unknown

    CVE-2023-4533

    Last Modified: 30 Apr 2025

    Red Hat Product Security has come to the conclusion that this CVE is not needed. It was assigned as a duplicate of CVE-2023-52440

    Published: 25 Aug 2023
    7.5
    High

    CVE-2023-32756

    Last Modified: 21 Nov 2024

    e-Excellence U-Office Force has a path traversal vulnerability within its file uploading and downloading functions. An unauthenticated remote attacker can exploit this vulnerability to read arbitrary system files, but can’t control system or disrupt service.

    Published: 25 Aug 2023
    5.3
    Medium

    CVE-2023-32755

    Last Modified: 21 Nov 2024

    e-Excellence U-Office Force generates an error message in webiste service. An unauthenticated remote attacker can obtain partial sensitive system information from error message by sending a crafted command.

    Published: 25 Aug 2023
    4.7
    Medium

    CVE-2023-40530

    Last Modified: 21 Nov 2024

    Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.13 and earlier allows an attacker to lead a user to access an arbitrary website via another application installed on the user's device.

    Published: 25 Aug 2023
    5.4
    Medium

    CVE-2023-4520

    Last Modified: 8 Apr 2026

    The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_fv_player_user_video’ parameter saved via the 'save' function hooked via init, and the plugin is also vulnerable to Arbitrary Usermeta Update via the 'save' function in versions up to, and including, 7.5.37.7212 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, and makes it possible to update the user metas arbitrarily, but the meta value can only be a string.

    Published: 25 Aug 2023