CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2020-24292

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in load function in PluginICO.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary code via opening of crafted ico file.

    Published: 22 Aug 2023
    8.8
    High

    CVE-2020-24293

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in psdThumbnail::Read in PSDParser.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary code via opening of crafted psd file.

    Published: 22 Aug 2023
    8.8
    High

    CVE-2020-24295

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in PSDParser.cpp::ReadImageLine() in FreeImage 3.19.0 [r1859] allows remote attackers to ru narbitrary code via use of crafted psd file.

    Published: 22 Aug 2023
    5.5
    Medium

    CVE-2020-26683

    Last Modified: 21 Nov 2024

    A memory leak issue discovered in /pdf/pdf-font-add.c in Artifex Software MuPDF 1.17.0 allows attackers to obtain sensitive information.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2021-30047

    Last Modified: 21 Nov 2024

    VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.

    Published: 22 Aug 2023
    6.1
    Medium

    CVE-2022-44215

    Last Modified: 21 Nov 2024

    There is an open redirect vulnerability in Titan FTP server 19.0 and below. Users are redirected to any target URL.

    Published: 22 Aug 2023
    9.8
    Critical

    CVE-2022-48522

    Last Modified: 21 Nov 2024

    In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.

    Published: 22 Aug 2023
    5.3
    Medium

    CVE-2022-48538

    Last Modified: 21 Nov 2024

    In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() allows a zero as the password.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2022-48560

    Last Modified: 21 Nov 2024

    A use-after-free exists in Python through 3.9 via heappushpop in heapq.

    Published: 22 Aug 2023
    6.5
    Medium

    CVE-2022-48564

    Last Modified: 21 Nov 2024

    read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.

    Published: 22 Aug 2023
    9.8
    Critical

    CVE-2022-48565

    Last Modified: 21 Nov 2024

    An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.

    Published: 22 Aug 2023
    5.9
    Medium

    CVE-2022-48566

    Last Modified: 21 Nov 2024

    An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2022-48571

    Last Modified: 21 Nov 2024

    memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.

    Published: 22 Aug 2023
    6.5
    Medium

    CVE-2023-38908

    Last Modified: 21 Nov 2024

    An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the TSKEP authentication function.

    Published: 22 Aug 2023
    6.5
    Medium

    CVE-2023-38909

    Last Modified: 21 Nov 2024

    An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the IV component in the AES128-CBC function.

    Published: 22 Aug 2023
    6.7
    Medium

    CVE-2023-38996

    Last Modified: 21 Nov 2024

    An issue in all versions of Douran DSGate allows a local authenticated privileged attacker to execute arbitrary code via the debug command.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2023-39026

    Last Modified: 21 Nov 2024

    Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2023-39141

    Last Modified: 21 Nov 2024

    webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.

    Published: 22 Aug 2023
    —
    Unknown

    CVE-2023-40790

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 22 Aug 2023
    —
    Unknown

    CVE-2023-40936

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 22 Aug 2023
    —
    Unknown

    CVE-2023-40937

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 22 Aug 2023
    —
    Unknown

    CVE-2023-40943

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 22 Aug 2023
    5.5
    Medium

    CVE-2020-21896

    Last Modified: 3 Nov 2025

    A Use After Free vulnerability in svg_dev_text_span_as_paths_defs function in source/fitz/svg-device.c in Artifex Software MuPDF 1.16.0 allows remote attackers to cause a denial of service via opening of a crafted PDF file.

    Published: 22 Aug 2023
    6.5
    Medium

    CVE-2022-38349

    Last Modified: 3 Nov 2025

    An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving an embedded file.

    Published: 22 Aug 2023
    7.5
    High

    CVE-2021-34193

    Last Modified: 3 Nov 2025

    Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs.

    Published: 22 Aug 2023
    6.1
    Medium

    CVE-2022-41444

    Last Modified: 4 Nov 2025

    Cross Site Scripting (XSS) vulnerability in Cacti 1.2.21 via crafted POST request to graphs_new.php.

    Published: 22 Aug 2023
    6.5
    Medium

    CVE-2021-46310

    Last Modified: 4 Nov 2025

    An issue was discovered IW44Image.cpp in djvulibre 3.5.28 in allows attackers to cause a denial of service via divide by zero.

    Published: 22 Aug 2023
    4.2
    Medium

    CVE-2023-4301

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 21 Aug 2023
    4.2
    Medium

    CVE-2023-4302

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 21 Aug 2023
    4.3
    Medium

    CVE-2023-4303

    Last Modified: 21 Nov 2024

    Jenkins Fortify Plugin 22.1.38 and earlier does not escape the error message for a form validation method, resulting in an HTML injection vulnerability.

    Published: 21 Aug 2023
    7.5
    High

    CVE-2023-25913

    Last Modified: 9 Jan 2025

    Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP addresses, usernames, store names and other sensitive information.

    Published: 21 Aug 2023
    8.8
    High

    CVE-2023-25914

    Last Modified: 19 Jul 2025

    Due to improper restriction, authenticated attackers could retrieve and read system files of the underlying server through the XML interface. The information that can be read can lead to a full system compromise.

    Published: 21 Aug 2023
    9.9
    Critical

    CVE-2023-25915

    Last Modified: 17 Jan 2025

    Due to improper input validation, an authenticated remote attacker could execute arbitrary commands on the target system.

    Published: 21 Aug 2023
    8.8
    High

    CVE-2023-36787

    Last Modified: 1 Jan 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 21 Aug 2023
    3.1
    Low

    CVE-2023-38158

    Last Modified: 28 Feb 2025

    Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

    Published: 21 Aug 2023
    6.5
    Medium

    CVE-2023-4417

    Last Modified: 21 Nov 2024

    Improper access controls in the entry duplication component in Devolutions Remote Desktop Manager 2023.2.19 and earlier versions on Windows allows an authenticated user, under specific circumstances, to inadvertently share their personal vault entry with shared vaults via an incorrect vault in the duplication write process.

    Published: 21 Aug 2023
    9.8
    Critical

    CVE-2023-4373

    Last Modified: 21 Nov 2024

    Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature.

    Published: 21 Aug 2023
    9.8
    Critical

    CVE-2023-38035

    Last Modified: 31 Oct 2025

    A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

    Published: 21 Aug 2023
    7.5
    High

    CVE-2023-3604

    Last Modified: 16 Jan 2026

    The Change WP Admin Login WordPress plugin before 1.1.4 discloses the URL of the hidden login page when accessing a crafted URL, bypassing the protection offered.

    Published: 21 Aug 2023
    4.3
    Medium

    CVE-2023-3366

    Last Modified: 21 Nov 2024

    The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.2 does not have CRSF check when deleting a shipment, allowing attackers to make any logged in user, delete arbitrary shipment via a CSRF attack

    Published: 21 Aug 2023
    6.1
    Medium

    CVE-2023-3936

    Last Modified: 23 Apr 2025

    The Blog2Social WordPress plugin before 7.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 21 Aug 2023
    6.1
    Medium

    CVE-2023-3954

    Last Modified: 5 May 2025

    The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 21 Aug 2023
    4.8
    Medium

    CVE-2023-3667

    Last Modified: 5 May 2025

    The Bit Assist WordPress plugin before 1.1.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 21 Aug 2023
    7.5
    High

    CVE-2023-40735

    Last Modified: 2 Jul 2025

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cavo – Connecting for a Safer World BUTTERFLY BUTTON (Architecture flaw) allows loss of plausible deniability and confidentiality.This issue affects BUTTERFLY BUTTON: As of 2023-08-21.

    Published: 21 Aug 2023
    5.7
    Medium

    CVE-2023-3481

    Last Modified: 21 Nov 2024

    Critters versions 0.0.17-0.0.19 have an issue when parsing the HTML, which leads to a potential cross-site scripting (XSS) bug. We recommend upgrading to version 0.0.20 of the extension. 

    Published: 21 Aug 2023
    6.5
    Medium

    CVE-2023-4455

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3.

    Published: 21 Aug 2023
    5.7
    Medium

    CVE-2023-4454

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3.

    Published: 21 Aug 2023
    5.4
    Medium

    CVE-2023-4453

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.8.

    Published: 21 Aug 2023
    9.1
    Critical

    CVE-2023-39939

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute arbitrary queries against the database and obtain or alter the information in it.

    Published: 21 Aug 2023
    6.1
    Medium

    CVE-2023-39543

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the product.

    Published: 21 Aug 2023