CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2023-40068

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product with the administrative privilege.

    Published: 21 Aug 2023
    6.3
    Medium

    CVE-2023-4450

    Last Modified: 2 Jul 2025

    A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-237571.

    Published: 21 Aug 2023
    6.3
    Medium

    CVE-2023-4449

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /index.php?page=member. The manipulation of the argument columns[0][data] leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-237570 is the identifier assigned to this vulnerability.

    Published: 21 Aug 2023
    6.3
    Medium

    CVE-2023-4448

    Last Modified: 21 Nov 2024

    A vulnerability was found in OpenRapid RapidCMS 1.3.1 and classified as critical. This issue affects some unknown processing of the file admin/run-movepass.php. The manipulation of the argument password/password2 leads to weak password recovery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 4dff387283060961c362d50105ff8da8ea40bcbe. It is recommended to apply a patch to fix this issue. The identifier VDB-237569 was assigned to this vulnerability.

    Published: 21 Aug 2023
    6.3
    Medium

    CVE-2023-4447

    Last Modified: 21 Nov 2024

    A vulnerability has been found in OpenRapid RapidCMS 1.3.1 and classified as critical. This vulnerability affects unknown code of the file admin/article-chat.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-237568.

    Published: 21 Aug 2023
    5.5
    Medium

    CVE-2023-4446

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in OpenRapid RapidCMS 1.3.1. This affects an unknown part of the file template/default/category.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-237567.

    Published: 21 Aug 2023
    6.3
    Medium

    CVE-2023-4445

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in Mini-Tmall up to 20230811. Affected by this issue is some unknown functionality of the file product/1/1?test=1&test2=2&. The manipulation of the argument orderBy leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-237566 is the identifier assigned to this vulnerability.

    Published: 21 Aug 2023
    6.3
    Medium

    CVE-2023-4444

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected by this vulnerability is an unknown functionality of the file vm\patient\edit-user.php. The manipulation of the argument id00/nic/oldemail/email/spec/Tele leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-237565 was assigned to this vulnerability.

    Published: 21 Aug 2023
    6.3
    Medium

    CVE-2023-4443

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in SourceCodester Free Hospital Management System for Small Practices 1.0/5.0.12. Affected is an unknown function of the file vm\doctor\edit-doc.php. The manipulation of the argument id00/nic/oldemail/email/spec/Tele leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-237564.

    Published: 21 Aug 2023
    6.3
    Medium

    CVE-2023-4442

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been rated as critical. This issue affects some unknown processing of the file \vm\patient\booking-complete.php. The manipulation of the argument userid/apponum/scheduleid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-237563.

    Published: 21 Aug 2023
    9.8
    Critical

    CVE-2023-39807

    Last Modified: 5 Jul 2026

    N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a SQL injection vulnerability via the a_passwd parameter at /portal/user-register.php.

    Published: 21 Aug 2023
    7.5
    High

    CVE-2023-39748

    Last Modified: 21 Nov 2024

    An issue in the component /userRpm/NetworkCfgRpm of TP-Link TL-WR1041N V2 allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

    Published: 21 Aug 2023
    5.7
    Medium

    CVE-2023-4456

    Last Modified: 20 Nov 2025

    A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a token valid for one action to execute other actions as long as the authorization allowing the original action is still cached.

    Published: 21 Aug 2023
    7.2
    High

    CVE-2023-40352

    Last Modified: 21 Nov 2024

    McAfee Safe Connect before 2.16.1.126 may allow an adversary with system privileges to achieve privilege escalation by loading arbitrary DLLs.

    Published: 21 Aug 2023
    9.8
    Critical

    CVE-2023-38961

    Last Modified: 21 Nov 2024

    Buffer Overflwo vulnerability in JerryScript Project jerryscript v.3.0.0 allows a remote attacker to execute arbitrary code via the scanner_is_context_needed component in js-scanner-until.c.

    Published: 21 Aug 2023
    9.8
    Critical

    CVE-2020-28715

    Last Modified: 21 Nov 2024

    An issue was discovered in kdmserver service in LeEco LeTV X43 version V2401RCN02C080080B04121S, allows attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS).

    Published: 21 Aug 2023
    3.5
    Low

    CVE-2023-39061

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) vulnerability in Chamilo v.1.11 thru v.1.11.20 allows a remote authenticated privileged attacker to execute arbitrary code.

    Published: 21 Aug 2023
    9.8
    Critical

    CVE-2023-31447

    Last Modified: 21 Nov 2024

    user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers to send a crafted payload to modify the content of the code segment, insert shellcode, and execute arbitrary code.

    Published: 21 Aug 2023
    8.8
    High

    CVE-2023-38836

    Last Modified: 21 Nov 2024

    File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks.

    Published: 21 Aug 2023
    7.8
    High

    CVE-2023-38899

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in berkaygediz O_Blog v.1.0 allows a local attacker to escalate privileges via the secure_file_priv component.

    Published: 21 Aug 2023
    6.5
    Medium

    CVE-2023-38906

    Last Modified: 21 Nov 2024

    An issue in TPLink Smart Bulb Tapo series L530 1.1.9, L510E 1.0.8, L630 1.0.3, P100 1.4.9, Smart Camera Tapo series C200 1.1.18, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the authentication code for the UDP message.

    Published: 21 Aug 2023
    7.5
    High

    CVE-2023-38976

    Last Modified: 21 Nov 2024

    An issue in weaviate v.1.20.0 allows a remote attacker to cause a denial of service via the handleUnbatchedGraphQLRequest function.

    Published: 21 Aug 2023
    5.4
    Medium

    CVE-2023-39094

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in ZeroWdd studentmanager v.1.0 allows a remote attacker to execute arbitrary code via the username parameter in the student list function.

    Published: 21 Aug 2023
    8.8
    High

    CVE-2023-39106

    Last Modified: 21 Nov 2024

    An issue in Nacos Group Nacos Spring Project v.1.1.1 and before allows a remote attacker to execute arbitrary code via the SnakeYamls Constructor() component.

    Published: 21 Aug 2023
    9.8
    Critical

    CVE-2023-39617

    Last Modified: 21 Nov 2024

    TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.

    Published: 21 Aug 2023
    9.8
    Critical

    CVE-2023-39618

    Last Modified: 21 Nov 2024

    TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg interface.

    Published: 21 Aug 2023
    9.8
    Critical

    CVE-2023-39660

    Last Modified: 21 Nov 2024

    An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function.

    Published: 21 Aug 2023
    7.5
    High

    CVE-2023-39745

    Last Modified: 21 Nov 2024

    TP-Link TL-WR940N V2, TP-Link TL-WR941ND V5 and TP-Link TL-WR841N V8 were discovered to contain a buffer overflow via the component /userRpm/AccessCtrlAccessRulesRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

    Published: 21 Aug 2023
    9.8
    Critical

    CVE-2023-39747

    Last Modified: 21 Nov 2024

    TP-Link WR841N V8, TP-Link TL-WR940N V2, and TL-WR941ND V5 were discovered to contain a buffer overflow via the radiusSecret parameter at /userRpm/WlanSecurityRpm.

    Published: 21 Aug 2023
    9.8
    Critical

    CVE-2023-39749

    Last Modified: 21 Nov 2024

    D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the component /adv_resource. This vulnerability is exploited via a crafted GET request.

    Published: 21 Aug 2023
    9.8
    Critical

    CVE-2023-39750

    Last Modified: 21 Nov 2024

    D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the f_ipv6_enable parameter at /bsc_ipv6. This vulnerability is exploited via a crafted POST request.

    Published: 21 Aug 2023
    9.8
    Critical

    CVE-2023-39751

    Last Modified: 21 Nov 2024

    TP-Link TL-WR941ND V6 were discovered to contain a buffer overflow via the pSize parameter at /userRpm/PingIframeRpm.

    Published: 21 Aug 2023
    7.5
    High

    CVE-2023-39784

    Last Modified: 8 Dec 2025

    Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the list parameter in the save_virtualser_data function.

    Published: 21 Aug 2023
    7.5
    High

    CVE-2023-39785

    Last Modified: 8 Dec 2025

    Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the list parameter in the set_qosMib_list function.

    Published: 21 Aug 2023
    7.5
    High

    CVE-2023-39786

    Last Modified: 8 Dec 2025

    Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sscanf function.

    Published: 21 Aug 2023
    9.8
    Critical

    CVE-2023-39808

    Last Modified: 5 Jul 2026

    N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the SSH service. The cleartext password corresponding to the $1$4Tmm01jl$7HRvcW.bz7uGmX9hiQWvR hash was not determined by the vulnerability discoverer.

    Published: 21 Aug 2023
    9.8
    Critical

    CVE-2023-39809

    Last Modified: 5 Jul 2026

    N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain an OS command injection vulnerability via shell metacharacters in the system_hostname parameter at /manage/network-basic.php.

    Published: 21 Aug 2023
    6.3
    Medium

    CVE-2023-4441

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /patient/appointment.php. The manipulation of the argument sheduledate leads to sql injection. The attack can be initiated remotely. VDB-237562 is the identifier assigned to this vulnerability.

    Published: 20 Aug 2023
    6.3
    Medium

    CVE-2023-4440

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been classified as critical. This affects an unknown part of the file appointment.php. The manipulation of the argument sheduledate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-237561 was assigned to this vulnerability.

    Published: 20 Aug 2023
    4.3
    Medium

    CVE-2023-4439

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Card Holder Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Minus Value Handler. The manipulation leads to improper validation of specified quantity in input. The attack may be launched remotely. The identifier of this vulnerability is VDB-237560.

    Published: 20 Aug 2023
    6.3
    Medium

    CVE-2023-4438

    Last Modified: 21 Nov 2024

    A vulnerability has been found in SourceCodester Inventory Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file app/ajax/search_sales_report.php. The manipulation of the argument customer leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-237559.

    Published: 20 Aug 2023
    6.3
    Medium

    CVE-2023-4437

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file app/ajax/search_sell_paymen_report.php. The manipulation of the argument customer leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-237558 is the identifier assigned to this vulnerability.

    Published: 20 Aug 2023
    6.3
    Medium

    CVE-2023-4436

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in SourceCodester Inventory Management System 1.0. This issue affects some unknown processing of the file app/action/edit_update.php. The manipulation of the argument user_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-237557 was assigned to this vulnerability.

    Published: 20 Aug 2023
    6.1
    Medium

    CVE-2023-4451

    Last Modified: 13 Feb 2026

    Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

    Published: 20 Aug 2023
    5.5
    Medium

    CVE-2023-4435

    Last Modified: 21 Nov 2024

    Improper Input Validation in GitHub repository hamza417/inure prior to build88.

    Published: 20 Aug 2023
    6.1
    Medium

    CVE-2023-4434

    Last Modified: 21 Nov 2024

    Missing Authorization in GitHub repository hamza417/inure prior to build88.

    Published: 20 Aug 2023
    8.2
    High

    CVE-2022-46751

    Last Modified: 13 Feb 2025

    Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy prior to 2.5.2. When Apache Ivy prior to 2.5.2 parses XML files - either its own configuration, Ivy files or Apache Maven POMs - it will allow downloading external document type definitions and expand any entity references contained therein when used. This can be used to exfiltrate data, access resources only the machine running Ivy has access to or disturb the execution of Ivy in different ways. Starting with Ivy 2.5.2 DTD processing is disabled by default except when parsing Maven POMs where the default is to allow DTD processing but only to include a DTD snippet shipping with Ivy that is needed to deal with existing Maven POMs that are not valid XML files but are nevertheless accepted by Maven. Access can be be made more lenient via newly introduced system properties where needed. Users of Ivy prior to version 2.5.2 can use Java system properties to restrict processing of external DTDs, see the section about "JAXP Properties for External Access restrictions" inside Oracle's "Java API for XML Processing (JAXP) Security Guide".

    Published: 20 Aug 2023
    7
    High

    CVE-2023-37250

    Last Modified: 21 Nov 2024

    Unity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per User" mode. The application intentionally launches DLLs from a user-owned directory but intended to always perform integrity verification of those DLLs. This affects Parsec Loader versions through 8. Parsec Loader 9 is a fixed version.

    Published: 20 Aug 2023
    9.8
    Critical

    CVE-2022-24989

    Last Modified: 21 Nov 2024

    TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI. (Shell metacharacters can be placed in raidtype because popen is used without any sanitization.) The credentials from CVE-2022-24990 exploitation can be used.

    Published: 20 Aug 2023
    7.5
    High

    CVE-2023-40711

    Last Modified: 21 Nov 2024

    Veilid before 0.1.9 does not check the size of uncompressed data during decompression upon an envelope receipt, which allows remote attackers to cause a denial of service (out-of-memory abort) via crafted packet data, as exploited in the wild in August 2023.

    Published: 20 Aug 2023