CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2023-39784

    Last Modified: 8 Dec 2025

    Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the list parameter in the save_virtualser_data function.

    Published: 21 Aug 2023
    7.5
    High

    CVE-2023-39785

    Last Modified: 8 Dec 2025

    Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the list parameter in the set_qosMib_list function.

    Published: 21 Aug 2023
    7.5
    High

    CVE-2023-39786

    Last Modified: 8 Dec 2025

    Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sscanf function.

    Published: 21 Aug 2023
    9.8
    Critical

    CVE-2023-39808

    Last Modified: 5 Jul 2026

    N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the SSH service. The cleartext password corresponding to the $1$4Tmm01jl$7HRvcW.bz7uGmX9hiQWvR hash was not determined by the vulnerability discoverer.

    Published: 21 Aug 2023
    9.8
    Critical

    CVE-2023-39809

    Last Modified: 5 Jul 2026

    N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain an OS command injection vulnerability via shell metacharacters in the system_hostname parameter at /manage/network-basic.php.

    Published: 21 Aug 2023
    6.3
    Medium

    CVE-2023-4441

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /patient/appointment.php. The manipulation of the argument sheduledate leads to sql injection. The attack can be initiated remotely. VDB-237562 is the identifier assigned to this vulnerability.

    Published: 20 Aug 2023
    6.3
    Medium

    CVE-2023-4440

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been classified as critical. This affects an unknown part of the file appointment.php. The manipulation of the argument sheduledate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-237561 was assigned to this vulnerability.

    Published: 20 Aug 2023
    4.3
    Medium

    CVE-2023-4439

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Card Holder Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Minus Value Handler. The manipulation leads to improper validation of specified quantity in input. The attack may be launched remotely. The identifier of this vulnerability is VDB-237560.

    Published: 20 Aug 2023
    6.3
    Medium

    CVE-2023-4438

    Last Modified: 21 Nov 2024

    A vulnerability has been found in SourceCodester Inventory Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file app/ajax/search_sales_report.php. The manipulation of the argument customer leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-237559.

    Published: 20 Aug 2023
    6.3
    Medium

    CVE-2023-4437

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file app/ajax/search_sell_paymen_report.php. The manipulation of the argument customer leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-237558 is the identifier assigned to this vulnerability.

    Published: 20 Aug 2023
    6.3
    Medium

    CVE-2023-4436

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in SourceCodester Inventory Management System 1.0. This issue affects some unknown processing of the file app/action/edit_update.php. The manipulation of the argument user_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-237557 was assigned to this vulnerability.

    Published: 20 Aug 2023
    6.1
    Medium

    CVE-2023-4451

    Last Modified: 13 Feb 2026

    Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

    Published: 20 Aug 2023
    5.5
    Medium

    CVE-2023-4435

    Last Modified: 21 Nov 2024

    Improper Input Validation in GitHub repository hamza417/inure prior to build88.

    Published: 20 Aug 2023
    6.1
    Medium

    CVE-2023-4434

    Last Modified: 21 Nov 2024

    Missing Authorization in GitHub repository hamza417/inure prior to build88.

    Published: 20 Aug 2023
    8.2
    High

    CVE-2022-46751

    Last Modified: 13 Feb 2025

    Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy prior to 2.5.2. When Apache Ivy prior to 2.5.2 parses XML files - either its own configuration, Ivy files or Apache Maven POMs - it will allow downloading external document type definitions and expand any entity references contained therein when used. This can be used to exfiltrate data, access resources only the machine running Ivy has access to or disturb the execution of Ivy in different ways. Starting with Ivy 2.5.2 DTD processing is disabled by default except when parsing Maven POMs where the default is to allow DTD processing but only to include a DTD snippet shipping with Ivy that is needed to deal with existing Maven POMs that are not valid XML files but are nevertheless accepted by Maven. Access can be be made more lenient via newly introduced system properties where needed. Users of Ivy prior to version 2.5.2 can use Java system properties to restrict processing of external DTDs, see the section about "JAXP Properties for External Access restrictions" inside Oracle's "Java API for XML Processing (JAXP) Security Guide".

    Published: 20 Aug 2023
    7
    High

    CVE-2023-37250

    Last Modified: 21 Nov 2024

    Unity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per User" mode. The application intentionally launches DLLs from a user-owned directory but intended to always perform integrity verification of those DLLs. This affects Parsec Loader versions through 8. Parsec Loader 9 is a fixed version.

    Published: 20 Aug 2023
    9.8
    Critical

    CVE-2022-24989

    Last Modified: 21 Nov 2024

    TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI. (Shell metacharacters can be placed in raidtype because popen is used without any sanitization.) The credentials from CVE-2022-24990 exploitation can be used.

    Published: 20 Aug 2023
    7.5
    High

    CVE-2023-40711

    Last Modified: 21 Nov 2024

    Veilid before 0.1.9 does not check the size of uncompressed data during decompression upon an envelope receipt, which allows remote attackers to cause a denial of service (out-of-memory abort) via crafted packet data, as exploited in the wild in August 2023.

    Published: 20 Aug 2023
    6.3
    Medium

    CVE-2023-2971

    Last Modified: 21 Nov 2024

    Improper path handling in Typora before 1.7.0-dev on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/typemark/". This vulnerability can be exploited if a user opens a malicious markdown file in Typora, or copies text from a malicious webpage and paste it into Typora.

    Published: 19 Aug 2023
    8.6
    High

    CVE-2023-2318

    Last Modified: 21 Nov 2024

    DOM-based XSS in src/muya/lib/contentState/pasteCtrl.js in MarkText 0.17.1 and before on Windows, Linux and macOS allows arbitrary JavaScript code to run in the context of MarkText main window. This vulnerability can be exploited if a user copies text from a malicious webpage and paste it into MarkText.

    Published: 19 Aug 2023
    8.6
    High

    CVE-2023-2317

    Last Modified: 21 Nov 2024

    DOM-based XSS in updater/update.html in Typora before 1.6.7 on Windows and Linux allows a crafted markdown file to run arbitrary JavaScript code in the context of Typora main window via loading typora://app/typemark/updater/update.html in <embed> tag. This vulnerability can be exploited if a user opens a malicious markdown file in Typora, or copies text from a malicious webpage and paste it into Typora.

    Published: 19 Aug 2023
    7.4
    High

    CVE-2023-2316

    Last Modified: 21 Nov 2024

    Improper path handling in Typora before 1.6.7 on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/<absolute-path>". This vulnerability can be exploited if a user opens a malicious markdown file in Typora, or copies text from a malicious webpage and paste it into Typora.

    Published: 19 Aug 2023
    8.2
    High

    CVE-2023-2110

    Last Modified: 21 Nov 2024

    Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/<absolute-path>". This vulnerability can be exploited if a user opens a malicious markdown file in Obsidian, or copies text from a malicious webpage and paste it into Obsidian.

    Published: 19 Aug 2023
    5.4
    Medium

    CVE-2023-4433

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

    Published: 19 Aug 2023
    6.1
    Medium

    CVE-2023-4432

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

    Published: 19 Aug 2023
    6.5
    Medium

    CVE-2023-40037

    Last Modified: 13 Feb 2025

    Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and authorized user can bypass connection URL validation using custom input formatting. The resolution enhances connection URL validation and introduces validation for additional related properties. Upgrading to Apache NiFi 1.23.1 is the recommended mitigation.

    Published: 18 Aug 2023
    6.5
    Medium

    CVE-2023-40172

    Last Modified: 21 Nov 2024

    Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. A Cross-site request forgery (CSRF) attack is a type of malicious attack whereby an attacker tricks a victim into performing an action on a website that they do not intend to do. This can be done by sending the victim a malicious link or by exploiting a vulnerability in the website. Prior to version 1.0.5 Social media skeleton did not properly restrict CSRF attacks. This has been addressed in version 1.0.5 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 18 Aug 2023
    7.5
    High

    CVE-2023-40173

    Last Modified: 21 Nov 2024

    Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. Prior to version 1.0.5 Social media skeleton did not properly salt passwords leaving user passwords susceptible to cracking should an attacker gain access to hashed passwords. This issue has been addressed in version 1.0.5 and users are advised to upgrade. There are no known workarounds for this issue.

    Published: 18 Aug 2023
    6.8
    Medium

    CVE-2023-40174

    Last Modified: 21 Nov 2024

    Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. Insufficient session expiration is a web application security vulnerability that occurs when a web application does not properly manage the lifecycle of a user's session. Social media skeleton releases prior to 1.0.5 did not properly limit manage user session lifecycles. This issue has been addressed in version 1.0.5 and users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 18 Aug 2023
    —
    Unknown

    CVE-2023-4426

    Last Modified: 19 Mar 2024

    **REJECT** Not a valid security issue - vendor unable to replicate.

    Published: 18 Aug 2023
    7.5
    High

    CVE-2023-20212

    Last Modified: 21 Nov 2024

    A vulnerability in the AutoIt module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a logic error in the memory management of an affected device. An attacker could exploit this vulnerability by submitting a crafted AutoIt file to be scanned by ClamAV on the affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to restart unexpectedly, resulting in a DoS condition.

    Published: 18 Aug 2023
    4.8
    Medium

    CVE-2023-4422

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

    Published: 18 Aug 2023
    7.3
    High

    CVE-2023-4415

    Last Modified: 21 Nov 2024

    A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/sys/login. The manipulation leads to improper authentication. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-237518 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 18 Aug 2023
    6.3
    Medium

    CVE-2023-4414

    Last Modified: 21 Nov 2024

    A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230807. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /log/decodmail.php. The manipulation of the argument file leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-237517 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 18 Aug 2023
    5.8
    Medium

    CVE-2023-32122

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Spiffy Plugins Spiffy Calendar plugin <= 4.9.3 versions.

    Published: 18 Aug 2023
    5.9
    Medium

    CVE-2023-32130

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Daniel Powney Multi Rating plugin <= 5.0.6 versions.

    Published: 18 Aug 2023
    —
    Unknown

    CVE-2023-4413

    Last Modified: 7 Nov 2023

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: Permission to access the file is limited to administrative users only by default.

    Published: 18 Aug 2023
    6.5
    Medium

    CVE-2023-29387

    Last Modified: 21 Nov 2024

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Julien Crego Manager for Icomoon plugin <= 2.0 versions.

    Published: 18 Aug 2023
    7.1
    High

    CVE-2023-32109

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ignazio Scimone Albo Pretorio On line plugin <= 4.6.3 versions.

    Published: 18 Aug 2023
    7.1
    High

    CVE-2023-30499

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.32.7212 versions.

    Published: 18 Aug 2023
    6.3
    Medium

    CVE-2023-4412

    Last Modified: 21 Nov 2024

    A vulnerability was found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This issue affects the function setWanCfg. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-237515. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 18 Aug 2023
    7.1
    High

    CVE-2023-32108

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ignazio Scimone Albo Pretorio On line plugin <= 4.6.3 versions.

    Published: 18 Aug 2023
    6.3
    Medium

    CVE-2023-4411

    Last Modified: 21 Nov 2024

    A vulnerability has been found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-237514 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 18 Aug 2023
    6.3
    Medium

    CVE-2023-4410

    Last Modified: 3 Jul 2025

    A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023. This affects the function setDiagnosisCfg. The manipulation leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-237513 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 18 Aug 2023
    7.1
    High

    CVE-2023-32107

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Photo Gallery Team Photo Gallery by Ays – Responsive Image Gallery plugin <= 5.1.3 versions.

    Published: 18 Aug 2023
    7.1
    High

    CVE-2023-32106

    Last Modified: 19 Feb 2025

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Fahad Mahmood WP Docs plugin <= 1.9.9 versions.

    Published: 18 Aug 2023
    7.1
    High

    CVE-2023-32105

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ollybach WPPizza – A Restaurant Plugin plugin <= 3.17.1 versions.

    Published: 18 Aug 2023
    6.5
    Medium

    CVE-2023-32103

    Last Modified: 21 Nov 2024

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Theme Palace TP Education plugin <= 4.4 versions.

    Published: 18 Aug 2023
    7.1
    High

    CVE-2023-31218

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.6 versions.

    Published: 18 Aug 2023
    5.9
    Medium

    CVE-2023-31232

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in David Artiss Plugins List plugin <= 2.5 versions.

    Published: 18 Aug 2023