CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2023-4525

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 24 Aug 2023
    —
    Unknown

    CVE-2023-4524

    Last Modified: 7 Nov 2023

    CVE reject in favor of CVE-2023-40547

    Published: 24 Aug 2023
    7.5
    High

    CVE-2023-31412

    Last Modified: 9 Dec 2024

    The LMS5xx uses weak hash generation methods, resulting in the creation of insecure hashs. If an attacker manages to retrieve the hash, it could lead to collision attacks and the potential retrieval of the password.

    Published: 24 Aug 2023
    9.8
    Critical

    CVE-2023-4420

    Last Modified: 9 Dec 2024

    A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK LMS5xx. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive information. The attacker can exploit this weakness to eavesdrop on the communication between the LMS5xx and the Client, and potentially manipulate the data being transmitted.

    Published: 24 Aug 2023
    9.8
    Critical

    CVE-2023-4419

    Last Modified: 9 Dec 2024

    The LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure settings and /or disrupt the functionality of the device.

    Published: 24 Aug 2023
    7.5
    High

    CVE-2023-4418

    Last Modified: 9 Dec 2024

    A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. By exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests, overwhelming its resources and causing it to become unresponsive or unavailable for legitimate users.

    Published: 24 Aug 2023
    3.1
    Low

    CVE-2023-34973

    Last Modified: 21 Nov 2024

    An insufficient entropy vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to predict secret via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444 build 20230629 and later QuTS hero h5.1.0.2424 build 20230609 and later

    Published: 24 Aug 2023
    3.5
    Low

    CVE-2023-34972

    Last Modified: 21 Nov 2024

    A cleartext transmission of sensitive information vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows local network clients to read the contents of unexpected sensitive data via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444 build 20230629 and later QuTS hero h5.1.0.2424 build 20230609 and later

    Published: 24 Aug 2023
    7.1
    High

    CVE-2023-34971

    Last Modified: 21 Nov 2024

    An inadequate encryption strength vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows local network clients to decrypt the data using brute force attacks via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444 build 20230629 and later QTS 4.5.4.2467 build 20230718 and later QuTS hero h5.1.0.2424 build 20230609 and later QuTS hero h4.5.4.2476 build 20230728 and later

    Published: 24 Aug 2023
    6.8
    Medium

    CVE-2023-40710

    Last Modified: 21 Nov 2024

    An adversary could cause a continuous restart loop to the entire device by sending a large quantity of HTTP GET requests if the controller has the built-in web server enabled but does not have the built-in web server completely set up and configured for the SNAP PAC S1 Firmware version R10.3b

    Published: 24 Aug 2023
    6.8
    Medium

    CVE-2023-40709

    Last Modified: 21 Nov 2024

    An adversary could crash the entire device by sending a large quantity of ICMP requests if the controller has the built-in web server enabled but does not have the built-in web server completely set up and configured for the SNAP PAC S1 Firmware version R10.3b

    Published: 24 Aug 2023
    5.8
    Medium

    CVE-2023-40708

    Last Modified: 21 Nov 2024

    The File Transfer Protocol (FTP) port is open by default in the SNAP PAC S1 Firmware version R10.3b. This could allow an adversary to access some device files.

    Published: 24 Aug 2023
    8.6
    High

    CVE-2023-40707

    Last Modified: 21 Nov 2024

    There are no requirements for setting a complex password in the built-in web server of the SNAP PAC S1 Firmware version R10.3b, which could allow for a successful brute force attack if users don't set up complex credentials.

    Published: 24 Aug 2023
    8.6
    High

    CVE-2023-40706

    Last Modified: 21 Nov 2024

    There is no limit on the number of login attempts in the web server for the SNAP PAC S1 Firmware version R10.3b. This could allow for a brute-force attack on the built-in web server login.

    Published: 24 Aug 2023
    8.8
    High

    CVE-2022-46884

    Last Modified: 21 Nov 2024

    A potential use-after-free vulnerability existed in SVG Images if the Refresh Driver was destroyed at an inopportune time. This could have lead to memory corruption or a potentially exploitable crash. *Note*: This advisory was added on December 13th, 2022 after discovering it was inadvertently left out of the original advisory. The fix was included in the original release of Firefox 106. This vulnerability affects Firefox < 106.

    Published: 24 Aug 2023
    6.2
    Medium

    CVE-2023-40371

    Last Modified: 21 Nov 2024

    IBM AIX 7.2, 7.3, VIOS 3.1's OpenSSH implementation could allow a non-privileged local user to access files outside of those allowed due to improper access controls. IBM X-Force ID: 263476.

    Published: 24 Aug 2023
    5.3
    Medium

    CVE-2023-34040

    Last Modified: 21 Nov 2024

    In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Specifically, an application is vulnerable when all of the following are true: * The user does not configure an ErrorHandlingDeserializer for the key and/or value of the record * The user explicitly sets container properties checkDeserExWhenKeyNull and/or checkDeserExWhenValueNull container properties to true. * The user allows untrusted sources to publish to a Kafka topic By default, these properties are false, and the container only attempts to deserialize the headers if an ErrorHandlingDeserializer is configured. The ErrorHandlingDeserializer prevents the vulnerability by removing any such malicious headers before processing the record.

    Published: 24 Aug 2023
    7.1
    High

    CVE-2023-32516

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GloriaFood Restaurant Menu – Food Ordering System – Table Reservation plugin <= 2.3.6 versions.

    Published: 24 Aug 2023
    7.1
    High

    CVE-2023-32511

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking Calendar Plugin plugin <= 1.1.8 versions.

    Published: 24 Aug 2023
    7.1
    High

    CVE-2023-32510

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rolf van Gelder Order Your Posts Manually plugin <= 2.2.5 versions.

    Published: 24 Aug 2023
    7.5
    High

    CVE-2023-3705

    Last Modified: 21 Nov 2024

    The vulnerability exists in CP-Plus NVR due to an improper input handling at the web-based management interface of the affected product. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device. Successful exploitation of this vulnerability could allow the remote attacker to obtain sensitive information on the targeted device.

    Published: 24 Aug 2023
    5.3
    Medium

    CVE-2023-4230

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which has the potential to facilitate the collection of information on ioLogik 4000 Series devices. This vulnerability may enable attackers to gather information for the purpose of assessing vulnerabilities and potential attack vectors.

    Published: 24 Aug 2023
    5.3
    Medium

    CVE-2023-3704

    Last Modified: 21 Nov 2024

    The vulnerability exists in CP-Plus DVR due to an improper input validation within the web-based management interface of the affected products. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device. Successful exploitation of this vulnerability could allow the remote attacker to change system time of the targeted device.

    Published: 24 Aug 2023
    4.3
    Medium

    CVE-2023-4229

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, potentially exposing users to security risks. This vulnerability may allow attackers to trick users into interacting with malicious content, leading to unintended actions or unauthorized data disclosures.

    Published: 24 Aug 2023
    3.1
    Low

    CVE-2023-4228

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and manipulation.

    Published: 24 Aug 2023
    5.3
    Medium

    CVE-2023-4227

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in the ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which can be exploited by malicious actors to potentially gain unauthorized access to the product. This could lead to security breaches, data theft, and unauthorized manipulation of sensitive information. The vulnerability is attributed to the presence of an unauthorized service, which could potentially enable unauthorized access to the. device.

    Published: 24 Aug 2023
    9
    Critical

    CVE-2023-40573

    Last Modified: 21 Nov 2024

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki supports scheduled jobs that contain Groovy scripts. Currently, the job checks the content author of the job for programming right. However, modifying or adding a job script to a document doesn't modify the content author. Together with a CSRF vulnerability in the job scheduler, this can be exploited for remote code execution by an attacker with edit right on the wiki. If the attack is successful, an error log entry with "Job content executed" will be produced. This vulnerability has been patched in XWiki 14.10.9 and 15.4RC1.

    Published: 24 Aug 2023
    9
    Critical

    CVE-2023-40572

    Last Modified: 21 Nov 2024

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The create action is vulnerable to a CSRF attack, allowing script and thus remote code execution when targeting a user with script/programming right, thus compromising the confidentiality, integrity and availability of the whole XWiki installation. When a user with script right views this image and a log message `ERROR foo - Script executed!` appears in the log, the XWiki installation is vulnerable. This has been patched in XWiki 14.10.9 and 15.4RC1 by requiring a CSRF token for the actual page creation.

    Published: 24 Aug 2023
    9.8
    Critical

    CVE-2023-40900

    Last Modified: 8 Dec 2025

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetNetControlList.

    Published: 24 Aug 2023
    9.8
    Critical

    CVE-2023-40898

    Last Modified: 8 Dec 2025

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter timeZone at /goform/SetSysTimeCfg.

    Published: 24 Aug 2023
    9.8
    Critical

    CVE-2023-40896

    Last Modified: 8 Dec 2025

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list and bindnum at /goform/SetIpMacBind.

    Published: 24 Aug 2023
    9.8
    Critical

    CVE-2023-39699

    Last Modified: 21 Nov 2024

    IceWarp Mail Server v10.4.5 was discovered to contain a local file inclusion (LFI) vulnerability via the component /calendar/minimizer/index.php. This vulnerability allows attackers to include or execute files from the local file system of the targeted server.

    Published: 24 Aug 2023
    5.3
    Medium

    CVE-2023-4511

    Last Modified: 27 Mar 2026

    BT SDP dissector infinite loop in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file

    Published: 24 Aug 2023
    5.3
    Medium

    CVE-2023-4512

    Last Modified: 27 Mar 2026

    CBOR dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file

    Published: 24 Aug 2023
    5.3
    Medium

    CVE-2023-4513

    Last Modified: 27 Mar 2026

    BT SDP dissector memory leak in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file

    Published: 24 Aug 2023
    6.1
    Medium

    CVE-2023-39700

    Last Modified: 21 Nov 2024

    IceWarp Mail Server v10.4.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the color parameter.

    Published: 24 Aug 2023
    4.6
    Medium

    CVE-2023-39801

    Last Modified: 21 Nov 2024

    A lack of exception handling in the Renault Easy Link Multimedia System Software Version 283C35519R allows attackers to cause a Denial of Service (DoS) via supplying crafted WMA files when connecting a device to the vehicle's USB plug and play feature.

    Published: 24 Aug 2023
    9.8
    Critical

    CVE-2023-39834

    Last Modified: 21 Nov 2024

    PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function.

    Published: 24 Aug 2023
    7.5
    High

    CVE-2023-40577

    Last Modified: 13 Feb 2025

    Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.

    Published: 24 Aug 2023
    5.4
    Medium

    CVE-2023-40874

    Last Modified: 21 Nov 2024

    DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_add.php via the votename and voteitem1 parameters.

    Published: 24 Aug 2023
    5.4
    Medium

    CVE-2023-40875

    Last Modified: 21 Nov 2024

    DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_edit.php via the votename and votenote parameters.

    Published: 24 Aug 2023
    5.4
    Medium

    CVE-2023-40876

    Last Modified: 21 Nov 2024

    DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_add.php via the title parameter.

    Published: 24 Aug 2023
    5.4
    Medium

    CVE-2023-40877

    Last Modified: 21 Nov 2024

    DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_edit.php via the title parameter.

    Published: 24 Aug 2023
    9.8
    Critical

    CVE-2023-40891

    Last Modified: 8 Dec 2025

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter firewallEn at /goform/SetFirewallCfg.

    Published: 24 Aug 2023
    9.8
    Critical

    CVE-2023-40893

    Last Modified: 8 Dec 2025

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet.

    Published: 24 Aug 2023
    9.8
    Critical

    CVE-2023-40897

    Last Modified: 8 Dec 2025

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter mac at /goform/GetParentControlInfo.

    Published: 24 Aug 2023
    9.8
    Critical

    CVE-2023-40899

    Last Modified: 8 Dec 2025

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at /goform/setMacFilterCfg.

    Published: 24 Aug 2023
    9.8
    Critical

    CVE-2023-40901

    Last Modified: 21 Nov 2024

    Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at url /goform/setMacFilterCfg.

    Published: 24 Aug 2023
    9.8
    Critical

    CVE-2023-40904

    Last Modified: 21 Nov 2024

    Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at /goform/setMacFilterCfg.

    Published: 24 Aug 2023
    7.5
    High

    CVE-2023-45871

    Last Modified: 5 May 2025

    An issue was discovered in drivers/net/ethernet/intel/igb/igb_main.c in the IGB driver in the Linux kernel before 6.5.3. A buffer size may not be adequate for frames larger than the MTU.

    Published: 24 Aug 2023