CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2023-37422

    Last Modified: 21 Nov 2024

    Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

    Published: 22 Aug 2023
    8.1
    High

    CVE-2023-37421

    Last Modified: 21 Nov 2024

    Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

    Published: 22 Aug 2023
    6.8
    Medium

    CVE-2023-4212

    Last Modified: 16 Jan 2025

    ​A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as root using a specially crafted filename. The vulnerability requires physical access to the device via a USB stick.

    Published: 22 Aug 2023
    7.8
    High

    CVE-2023-3899

    Last Modified: 20 Nov 2025

    A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the com.redhat.RHSM1.Config.SetAll() method, a low-privileged local user could tamper with the state of the registration, by unregistering the system or by changing the current entitlements. This flaw allows an attacker to set arbitrary configuration directives for /etc/rhsm/rhsm.conf, which can be abused to cause a local privilege escalation to an unconfined root.

    Published: 22 Aug 2023
    4.3
    Medium

    CVE-2023-38732

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation 21.0.0 through 21.0.7 server could allow an authenticated user to view sensitive information from application logs. IBM X-Force ID: 262289.

    Published: 22 Aug 2023
    6.4
    Medium

    CVE-2023-24517

    Last Modified: 21 Nov 2024

    Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attacker to make make use of this issue ( unrestricted file upload ) to execute arbitrary system commands. This issue affects Pandora FMS v767 version and prior versions on all platforms.

    Published: 22 Aug 2023
    5.9
    Medium

    CVE-2023-24516

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal the session cookie value of admin users easily with little user interaction. This issue affects Pandora FMS v767 version and prior versions on all platforms.

    Published: 22 Aug 2023
    6.3
    Medium

    CVE-2023-24514

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) vulnerability in Visual Console Module of Pandora FMS could be used to hijack admin users session cookie values, carry out phishing attacks, etc. This issue affects Pandora FMS v767 version and prior versions on all platforms.

    Published: 22 Aug 2023
    5.2
    Medium

    CVE-2023-24515

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS. Application does not have a check on the URL scheme used while retrieving API URL. Rather than validating the http/https scheme, the application allows other scheme such as file, which could allow a malicious user to fetch internal file content. This issue affects Pandora FMS v767 version and prior versions on all platforms.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2023-4475

    Last Modified: 21 Nov 2024

    An Arbitrary File Movement vulnerability was found in ASUSTOR Data Master (ADM) allows an attacker to exploit the file renaming feature to move files to unintended directories. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.

    Published: 22 Aug 2023
    8.7
    High

    CVE-2023-3699

    Last Modified: 21 Nov 2024

    An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users to modify the storage devices configuration. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.

    Published: 22 Aug 2023
    7.1
    High

    CVE-2022-44729

    Last Modified: 8 Oct 2026

    Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.

    Published: 22 Aug 2023
    7.8
    High

    CVE-2022-47069

    Last Modified: 20 Nov 2025

    p7zip 16.02 was discovered to contain a heap-buffer-overflow vulnerability via the function NArchive::NZip::CInArchive::FindCd(bool) at CPP/7zip/Archive/Zip/ZipIn.cpp. NOTE: the Supplier has found that this is not a buffer overflow; at most an out-of-bounds read can occur.

    Published: 22 Aug 2023
    5.4
    Medium

    CVE-2023-39599

    Last Modified: 12 Dec 2024

    Cross-Site Scripting (XSS) vulnerability in CSZ CMS v.1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Social Settings parameter.

    Published: 22 Aug 2023
    4.9
    Medium

    CVE-2023-23565

    Last Modified: 21 Nov 2024

    An issue was discovered in Geomatika IsiGeo Web 6.0. It allows remote authenticated users to retrieve PHP files from the server via Local File Inclusion.

    Published: 22 Aug 2023
    8.8
    High

    CVE-2023-23564

    Last Modified: 21 Nov 2024

    An issue was discovered in Geomatika IsiGeo Web 6.0. It allows remote authenticated users to execute commands.

    Published: 22 Aug 2023
    6.5
    Medium

    CVE-2023-23563

    Last Modified: 21 Nov 2024

    An issue was discovered in Geomatika IsiGeo Web 6.0. It allows remote authenticated users to obtain sensitive database content via SQL Injection.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2021-32420

    Last Modified: 21 Nov 2024

    dpic 2021.01.01 has a Heap-based Buffer Overflow in thestorestring function in dpic.y.

    Published: 22 Aug 2023
    9.8
    Critical

    CVE-2022-45611

    Last Modified: 27 Nov 2024

    An issue was discovered in Fresenius Kabi PharmaHelp 5.1.759.0 allows attackers to gain escalated privileges via via capture of user login information.

    Published: 22 Aug 2023
    6.1
    Medium

    CVE-2022-45582

    Last Modified: 21 Nov 2024

    Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2022-43358

    Last Modified: 21 Nov 2024

    Stack overflow vulnerability in ast_selectors.cpp: in function Sass::ComplexSelector::has_placeholder in libsass:3.6.5-8-g210218, which can be exploited by attackers to cause a denial of service (DoS).

    Published: 22 Aug 2023
    7.5
    High

    CVE-2022-43357

    Last Modified: 21 Nov 2024

    Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by attackers to causea denial of service (DoS). Also affects the command line driver for libsass, sassc 3.6.2.

    Published: 22 Aug 2023
    4.9
    Medium

    CVE-2022-40433

    Last Modified: 17 Feb 2024

    ** REJECT ** This CVE ID has been rejected by its CNA as it was not a security issue.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2022-34038

    Last Modified: 21 Nov 2024

    Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go. NOTE: the vendor's position is that this is not a vulnerability.

    Published: 22 Aug 2023
    7.1
    High

    CVE-2022-48541

    Last Modified: 4 Nov 2025

    A memory leak in ImageMagick 7.0.10-45 and 6.9.11-22 allows remote attackers to perform a denial of service via the "identify -help" command.

    Published: 22 Aug 2023
    6.5
    Medium

    CVE-2021-46312

    Last Modified: 4 Nov 2025

    An issue was discovered IW44EncodeCodec.cpp in djvulibre 3.5.28 in allows attackers to cause a denial of service via divide by zero.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2022-28068

    Last Modified: 21 Nov 2024

    A heap buffer overflow in r_sleb128 function in radare2 5.4.2 and 5.4.0.

    Published: 22 Aug 2023
    9.8
    Critical

    CVE-2023-36281

    Last Modified: 21 Nov 2024

    An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This is related to __subclasses__ or a template.

    Published: 22 Aug 2023
    6.5
    Medium

    CVE-2020-18378

    Last Modified: 21 Nov 2024

    A NULL pointer dereference was discovered in SExpressionWasmBuilder::makeBlock in wasm/wasm-s-parser.c in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-as.

    Published: 22 Aug 2023
    5.5
    Medium

    CVE-2020-18770

    Last Modified: 10 Jul 2025

    An issue was discovered in function zzip_disk_entry_to_file_header in mmapped.c in zziplib 0.13.69, which will lead to a denial-of-service.

    Published: 22 Aug 2023
    5.5
    Medium

    CVE-2020-18781

    Last Modified: 21 Nov 2024

    Heap buffer overflow vulnerability in FilePOSIX::read in File.cpp in audiofile 0.3.6 may cause denial-of-service via a crafted wav file, this bug can be triggered by the executable sfconvert.

    Published: 22 Aug 2023
    5.5
    Medium

    CVE-2020-21679

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in WritePCXImage function in pcx.c in GraphicsMagick 1.4 allows remote attackers to cause a denial of service via converting of crafted image file to pcx format.

    Published: 22 Aug 2023
    5.5
    Medium

    CVE-2020-21710

    Last Modified: 21 Nov 2024

    A divide by zero issue discovered in eps_print_page in gdevepsn.c in Artifex Software GhostScript 9.50 allows remote attackers to cause a denial of service via opening of crafted PDF file.

    Published: 22 Aug 2023
    7.8
    High

    CVE-2020-21724

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in ExtractorInformation function in streamExtractor.cpp in oggvideotools 0.9.1 allows remaote attackers to run arbitrary code via opening of crafted ogg file.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2020-22218

    Last Modified: 21 Nov 2024

    An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory.

    Published: 22 Aug 2023
    5.5
    Medium

    CVE-2020-22916

    Last Modified: 21 Nov 2024

    An issue discovered in XZ 5.2.5 allows attackers to cause a denial of service via decompression of a crafted file. NOTE: the vendor disputes the claims of "endless output" and "denial of service" because decompression of the 17,486 bytes always results in 114,881,179 bytes, which is often a reasonable size increase.

    Published: 22 Aug 2023
    6.5
    Medium

    CVE-2020-24294

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in psdParser::UnpackRLE function in PSDParser.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to cuase a denial of service via opening of crafted psd file.

    Published: 22 Aug 2023
    8.8
    High

    CVE-2020-25887

    Last Modified: 21 Nov 2024

    Buffer overflow in mg_resolve_from_hosts_file in Mongoose 6.18, when reading from a crafted hosts file.

    Published: 22 Aug 2023
    4.4
    Medium

    CVE-2020-27418

    Last Modified: 21 Nov 2024

    A Use After Free vulnerability in Fedora Linux kernel 5.9.0-rc9 allows attackers to obatin sensitive information via vgacon_invert_region() function.

    Published: 22 Aug 2023
    4.4
    Medium

    CVE-2022-44730

    Last Modified: 13 Feb 2025

    Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. A malicious SVG can probe user profile / data and send it directly as parameter to a URL.

    Published: 22 Aug 2023
    6.5
    Medium

    CVE-2020-35357

    Last Modified: 7 Dec 2024

    A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6. Processing a maliciously crafted input data for gsl_stats_quantile_from_sorted_data of the library may lead to unexpected application termination or arbitrary code execution.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2021-40211

    Last Modified: 21 Nov 2024

    An issue was discovered with ImageMagick 7.1.0-4 via Division by zero in function ReadEnhMetaFile of coders/emf.c.

    Published: 22 Aug 2023
    8.8
    High

    CVE-2021-40265

    Last Modified: 21 Nov 2024

    A heap overflow bug exists FreeImage before 1.18.0 via ofLoad function in PluginJPEG.cpp.

    Published: 22 Aug 2023
    7.1
    High

    CVE-2021-29390

    Last Modified: 21 Nov 2024

    libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.

    Published: 22 Aug 2023
    5.5
    Medium

    CVE-2022-48545

    Last Modified: 21 Nov 2024

    An infinite recursion in Catalog::findDestInTree can cause denial of service for xpdf 4.02.

    Published: 22 Aug 2023
    6.1
    Medium

    CVE-2022-48547

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in Cacti 0.8.7g and earlier allows unauthenticated remote attackers to inject arbitrary web script or HTML in the "ref" parameter at auth_changepassword.php.

    Published: 22 Aug 2023
    9.8
    Critical

    CVE-2021-32292

    Last Modified: 25 Jun 2025

    An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit.

    Published: 22 Aug 2023
    9.8
    Critical

    CVE-2021-33388

    Last Modified: 21 Nov 2024

    dpic 2021.04.10 has a Heap Buffer Overflow in themakevar() function in dpic.y

    Published: 22 Aug 2023
    9.8
    Critical

    CVE-2021-33390

    Last Modified: 21 Nov 2024

    dpic 2021.04.10 has a use-after-free in thedeletestringbox() function in dpic.y. A different vulnerablility than CVE-2021-32421.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2021-35309

    Last Modified: 21 Nov 2024

    An issue discovered in Samsung SyncThru Web Service SPL 5.93 06-09-2014 allows attackers to gain escalated privileges via MITM attacks.

    Published: 22 Aug 2023