CVE Feed

    Dashboard / CVE

    7.4
    High

    CVE-2023-40165

    Last Modified: 21 Nov 2024

    rubygems.org is the Ruby community's primary gem (library) hosting service. Insufficient input validation allowed malicious actors to replace any uploaded gem version that had a platform, version number, or gem name matching `/-\d/`, permanently replacing the legitimate upload in the canonical gem storage bucket, and triggering an immediate CDN purge so that the malicious gem would be served immediately. The maintainers have checked all gems matching the `/-\d/` pattern and can confirm that no unexpected `.gem`s were found. As a result, we believe this vulnerability was _not_ exploited. The easiest way to ensure that a user's applications were not exploited by this vulnerability is to check that all of your downloaded .gems have a checksum that matches the checksum recorded in the RubyGems.org database. RubyGems contributor Maciej Mensfeld wrote a tool to automatically check that all downloaded .gem files match the checksums recorded in the RubyGems.org database. You can use it by running: `bundle add bundler-integrity` followed by `bundle exec bundler-integrity`. Neither this tool nor anything else can prove you were not exploited, but the can assist your investigation by quickly comparing RubyGems API-provided checksums with the checksums of files on your disk. The issue has been patched with improved input validation and the changes are live. No action is required on the part of the user. Users are advised to validate their local gems.

    Published: 17 Aug 2023
    6.7
    Medium

    CVE-2023-34419

    Last Modified: 21 Nov 2024

    A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

    Published: 17 Aug 2023
    8.4
    High

    CVE-2023-4030

    Last Modified: 21 Nov 2024

    A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover to insecure settings if the BIOS becomes corrupt.

    Published: 17 Aug 2023
    6.7
    Medium

    CVE-2023-4029

    Last Modified: 21 Nov 2024

    A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

    Published: 17 Aug 2023
    6.7
    Medium

    CVE-2023-4028

    Last Modified: 21 Nov 2024

    A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

    Published: 17 Aug 2023
    7.8
    High

    CVE-2023-3078

    Last Modified: 21 Nov 2024

    An uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with elevated privileges.

    Published: 17 Aug 2023
    9.8
    Critical

    CVE-2023-2917

    Last Modified: 21 Nov 2024

    The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability.  Due to an improper input validation, a path traversal vulnerability exists, via the filename field, when the ThinManager processes a certain function. If exploited, an unauthenticated remote attacker can upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed.  A malicious user could exploit this vulnerability by sending a crafted synchronization protocol message and potentially gain remote code execution abilities.

    Published: 17 Aug 2023
    7.5
    High

    CVE-2023-2915

    Last Modified: 21 Nov 2024

    The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to improper input validation, a path traversal vulnerability exists when the ThinManager software processes a certain function. If exploited, an unauthenticated remote threat actor can delete arbitrary files with system privileges. A malicious user could exploit this vulnerability by sending a specifically crafted synchronization protocol message resulting in a denial-of-service condition.

    Published: 17 Aug 2023
    7.5
    High

    CVE-2023-2914

    Last Modified: 21 Nov 2024

    The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer overflow condition exists in the affected products. When the ThinManager processes incoming messages, a read access violation occurs and terminates the process. A malicious user could exploit this vulnerability by sending a crafted synchronization protocol message and causing a denial of service condition in the software.

    Published: 17 Aug 2023
    5.9
    Medium

    CVE-2023-28783

    Last Modified: 21 Nov 2024

    Auth. (shop manager+) Stored Cross-Site Scripting (XSS) vulnerability in PHPRADAR Woocommerce Tip/Donation plugin <= 1.2 versions.

    Published: 17 Aug 2023
    7.1
    High

    CVE-2023-28693

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Balasaheb Bhise Advanced Youtube Channel Pagination plugin <= 1.0 version.

    Published: 17 Aug 2023
    7.1
    High

    CVE-2023-31072

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Praveen Goswami Advanced Category Template plugin <= 0.1 versions.

    Published: 17 Aug 2023
    6.5
    Medium

    CVE-2023-31079

    Last Modified: 21 Nov 2024

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Chris Roberts Tippy plugin <= 6.2.1 versions.

    Published: 17 Aug 2023
    7.5
    High

    CVE-2023-40272

    Last Modified: 13 Feb 2025

    Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection giving an opportunity to read files on the Airflow server. It is recommended to upgrade to a version that is not affected.

    Published: 17 Aug 2023
    4.8
    Medium

    CVE-2023-34412

    Last Modified: 21 Nov 2024

    A vulnerability in Red Lion Europe mbNET/mbNET.rokey and Helmholz REX 200 and REX 250 devices with firmware lower 7.3.2 allows an authenticated remote attacker with high privileges to inject malicious HTML or JavaScript code (XSS).

    Published: 17 Aug 2023
    5.9
    Medium

    CVE-2023-31091

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pradeep Singh Dynamically Register Sidebars plugin <= 1.0.1 versions.

    Published: 17 Aug 2023
    7.1
    High

    CVE-2023-26530

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Paul Kehrer Updraft plugin <= 0.6.1 versions.

    Published: 17 Aug 2023
    7.1
    High

    CVE-2023-31074

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in hupe13 Extensions for Leaflet Map plugin <= 3.4.1 versions.

    Published: 17 Aug 2023
    6.4
    Medium

    CVE-2023-29182

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiOS before 7.0.3 allows a privileged attacker to execute arbitrary code via specially crafted CLI commands, provided the attacker were able to evade FortiOS stack protections.

    Published: 17 Aug 2023
    8.5
    High

    CVE-2023-3698

    Last Modified: 21 Nov 2024

    Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.

    Published: 17 Aug 2023
    8.5
    High

    CVE-2023-3697

    Last Modified: 21 Nov 2024

    Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and create files. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.

    Published: 17 Aug 2023
    8.8
    High

    CVE-2023-2910

    Last Modified: 21 Nov 2024

    Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Master (ADM) allows remote unauthorized users to execute arbitrary commands via unspecified vectors. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.

    Published: 17 Aug 2023
    7.1
    High

    CVE-2023-31076

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.6 versions.

    Published: 17 Aug 2023
    7.1
    High

    CVE-2023-31071

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yannick Lefebvre Modal Dialog plugin <= 3.5.14 versions.

    Published: 17 Aug 2023
    7.1
    High

    CVE-2023-30877

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maxim Glazunov XML for Google Merchant Center plugin <= 3.0.1 versions.

    Published: 17 Aug 2023
    5.9
    Medium

    CVE-2023-30874

    Last Modified: 28 Apr 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Steve Curtis, St. Pete Design Gps Plotter plugin <= 5.1.4 versions.

    Published: 17 Aug 2023
    5.9
    Medium

    CVE-2023-30876

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Dave Ross Dave's WordPress Live Search plugin <= 4.8.1 versions.

    Published: 17 Aug 2023
    5.9
    Medium

    CVE-2023-28533

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in M Williams Cab Grid plugin <= 1.5.15 versions.

    Published: 17 Aug 2023
    5.9
    Medium

    CVE-2023-28622

    Last Modified: 21 Nov 2024

    Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in Trident Technolabs Easy Slider Revolution plugin <= 1.0.0 versions.

    Published: 17 Aug 2023
    5.2
    Medium

    CVE-2023-40251

    Last Modified: 21 Nov 2024

    Missing Encryption of Sensitive Data vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Man in the Middle Attack.This issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Genian NAC V5.0: from V5.0.0 through V5.0.42 (Revision 117460); Genian NAC Suite V5.0: from V5.0.0 through V5.0.54; Genian ZTNA: from V6.0.0 through V6.0.15.

    Published: 17 Aug 2023
    8.1
    High

    CVE-2023-34217

    Last Modified: 21 Nov 2024

    TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability stems from insufficient input validation in the certificate-delete function, which could potentially allow malicious users to delete arbitrary files.

    Published: 17 Aug 2023
    4.3
    Medium

    CVE-2023-3244

    Last Modified: 8 Apr 2026

    The Comments Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the restore_settings function called via an AJAX action in versions up to, and including, 1.2.0. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to reset the plugin's settings. NOTE: this issue is was only partially patched in version 1.2.0, as the nonce is still present to subscriber-level users.

    Published: 17 Aug 2023
    6
    Medium

    CVE-2023-40252

    Last Modified: 21 Nov 2024

    Improper Control of Generation of Code ('Code Injection') vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Replace Trusted Executable.This issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Genian NAC V5.0: from V5.0.0 through V5.0.42 (Revision 117460); Genian NAC Suite V5.0: from V5.0.0 through V5.0.54; Genian ZTNA: from V6.0.0 through V6.0.15.

    Published: 17 Aug 2023
    8.1
    High

    CVE-2023-34216

    Last Modified: 21 Nov 2024

    TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability derives from insufficient input validation in the key-delete function, which could potentially allow malicious users to delete arbitrary files.

    Published: 17 Aug 2023
    4.8
    Medium

    CVE-2023-40281

    Last Modified: 21 Nov 2024

    EC-CUBE 2.11.0 to 2.17.2-p1 contain a cross-site scripting vulnerability in "mail/template" and "products/product" of Management page. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the other administrator or the user who accessed the website using the product.

    Published: 17 Aug 2023
    7.2
    High

    CVE-2023-34215

    Last Modified: 21 Nov 2024

    TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability stems from insufficient input validation and improper authentication in the certification-generation function, which could potentially allow malicious users to execute remote code on affected devices.

    Published: 17 Aug 2023
    5.4
    Medium

    CVE-2023-4395

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

    Published: 17 Aug 2023
    3.7
    Low

    CVE-2023-4392

    Last Modified: 21 Nov 2024

    A vulnerability was found in Control iD Gerencia Web 1.30 and classified as problematic. Affected by this issue is some unknown functionality of the component Cookie Handler. The manipulation leads to cleartext storage of sensitive information. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-237380. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 17 Aug 2023
    7.2
    High

    CVE-2023-34214

    Last Modified: 21 Nov 2024

    TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability stems from insufficient input validation in the certificate-generation function, which could potentially allow malicious users to execute remote code on affected devices.

    Published: 17 Aug 2023
    8.8
    High

    CVE-2023-34213

    Last Modified: 21 Nov 2024

    TN-5900 Series firmware versions v3.3 and prior are vulnerable to command-injection vulnerability. This vulnerability stems from insufficient input validation and improper authentication in the key-generation function, which could potentially allow malicious users to execute remote code on affected devices.

    Published: 17 Aug 2023
    8.8
    High

    CVE-2023-33239

    Last Modified: 21 Nov 2024

    TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnerability. This vulnerability stems from insufficient input validation in the key-generation function, which could potentially allow malicious users to execute remote code on affected devices.

    Published: 17 Aug 2023
    4.7
    Medium

    CVE-2023-25647

    Last Modified: 21 Nov 2024

    There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, applications in mobile phone could monitor the touch event.

    Published: 17 Aug 2023
    7.2
    High

    CVE-2023-33238

    Last Modified: 21 Nov 2024

    TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnerability. This vulnerability stems from inadequate input validation in the certificate management function, which could potentially allow malicious users to execute remote code on affected devices.

    Published: 17 Aug 2023
    8.8
    High

    CVE-2023-33237

    Last Modified: 21 Nov 2024

    TN-5900 Series firmware version v3.3 and prior is vulnerable to improper-authentication vulnerability. This vulnerability arises from inadequate authentication measures implemented in the web API handler, allowing low-privileged APIs to execute restricted actions that only high-privileged APIs are allowed This presents a potential risk of unauthorized exploitation by malicious actors.

    Published: 17 Aug 2023
    7.5
    High

    CVE-2023-39198

    Last Modified: 24 Mar 2026

    A race condition was found in the QXL driver in the Linux kernel. The qxl_mode_dumb_create() function dereferences the qobj returned by the qxl_gem_object_create_with_handle(), but the handle is the only one holding a reference to it. This flaw allows an attacker to guess the returned handle value and trigger a use-after-free issue, potentially leading to a denial of service or privilege escalation.

    Published: 17 Aug 2023
    7.5
    High

    CVE-2023-39125

    Last Modified: 21 Nov 2024

    NTSC-CRT 2.2.1 has an integer overflow and out-of-bounds write in loadBMP in bmp_rw.c because a file's width, height, and BPP are not validated. NOTE: the vendor's perspective is "this main application was not intended to be a well tested program, it's just something to demonstrate it works and for the user to see how to integrate it into their own programs."

    Published: 17 Aug 2023
    7.5
    High

    CVE-2023-36106

    Last Modified: 21 Nov 2024

    An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive information via the interface for querying via appId parameter to /container/list.

    Published: 17 Aug 2023
    7.2
    High

    CVE-2023-31939

    Last Modified: 21 Nov 2024

    SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the costomer_id parameter at customer_edit.php.

    Published: 17 Aug 2023
    7.2
    High

    CVE-2023-31946

    Last Modified: 21 Nov 2024

    File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the artical.php.

    Published: 17 Aug 2023
    9.8
    Critical

    CVE-2023-26469

    Last Modified: 21 Nov 2024

    In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.

    Published: 17 Aug 2023