CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2023-40336

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier allows attackers to copy folders.

    Published: 16 Aug 2023
    9.8
    Critical

    CVE-2023-39115

    Last Modified: 21 Nov 2024

    install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document.

    Published: 16 Aug 2023
    9.8
    Critical

    CVE-2023-33663

    Last Modified: 21 Nov 2024

    In the module “Customization fields fee for your store” (aicustomfee) from ai-dev module for PrestaShop, an attacker can perform SQL injection up to 0.2.0. Release 0.2.1 fixed this security issue.

    Published: 16 Aug 2023
    9.8
    Critical

    CVE-2023-39846

    Last Modified: 21 Nov 2024

    An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token.

    Published: 16 Aug 2023
    9.8
    Critical

    CVE-2023-38894

    Last Modified: 21 Nov 2024

    A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code via the extend function.

    Published: 16 Aug 2023
    5.4
    Medium

    CVE-2023-38904

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability in Netlify CMS v.2.10.192 allows a remote attacker to execute arbitrary code via a crafted payload to the body parameter of the new post function.

    Published: 16 Aug 2023
    4.3
    Medium

    CVE-2023-40337

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier allows attackers to copy a view inside a folder.

    Published: 16 Aug 2023
    4.3
    Medium

    CVE-2023-40338

    Last Modified: 21 Nov 2024

    Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier displays an error message that includes an absolute path of a log file when attempting to access the Scan Organization Folder Log if no logs are available, exposing information about the Jenkins controller file system.

    Published: 16 Aug 2023
    7.5
    High

    CVE-2023-40339

    Last Modified: 21 Nov 2024

    Jenkins Config File Provider Plugin 952.va_544a_6234b_46 and earlier does not mask (i.e., replace with asterisks) credentials specified in configuration files when they're written to the build log.

    Published: 16 Aug 2023
    8.8
    High

    CVE-2023-40341

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.27.5 and earlier allows attackers to connect to an attacker-specified URL, capturing GitHub credentials associated with an attacker-specified job.

    Published: 16 Aug 2023
    —
    Unknown

    CVE-2023-4377

    Last Modified: 29 Apr 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 15 Aug 2023
    7.1
    High

    CVE-2023-38402

    Last Modified: 21 Nov 2024

    A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM. A successful exploit could allow these malicious users to create a Denial-of-Service (DoS) condition affecting the Microsoft Windows operating System boot process.

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-4324

    Last Modified: 4 Nov 2025

    Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-4325

    Last Modified: 4 Nov 2025

    Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities

    Published: 15 Aug 2023
    7.5
    High

    CVE-2023-4326

    Last Modified: 4 Nov 2025

    Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites

    Published: 15 Aug 2023
    5.5
    Medium

    CVE-2023-4327

    Last Modified: 4 Nov 2025

    Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux

    Published: 15 Aug 2023
    5.5
    Medium

    CVE-2023-4328

    Last Modified: 4 Nov 2025

    Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Windows

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-4329

    Last Modified: 4 Nov 2025

    Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute

    Published: 15 Aug 2023
    —
    Unknown

    CVE-2023-4330

    Last Modified: 7 Nov 2023

    Broadcom were unable to duplicate the attack as described by Intel DCG Team.

    Published: 15 Aug 2023
    7.5
    High

    CVE-2023-4331

    Last Modified: 4 Nov 2025

    Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and vulnerable TLS protocols

    Published: 15 Aug 2023
    7.5
    High

    CVE-2023-4332

    Last Modified: 4 Nov 2025

    Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file

    Published: 15 Aug 2023
    5.5
    Medium

    CVE-2023-4333

    Last Modified: 4 Nov 2025

    Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server

    Published: 15 Aug 2023
    7.5
    High

    CVE-2023-4334

    Last Modified: 4 Nov 2025

    Broadcom RAID Controller Web server (nginx) is serving private files without any authentication

    Published: 15 Aug 2023
    7.5
    High

    CVE-2023-4335

    Last Modified: 21 Nov 2024

    Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-4336

    Last Modified: 4 Nov 2025

    Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-4337

    Last Modified: 4 Nov 2025

    Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-4338

    Last Modified: 4 Nov 2025

    Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers

    Published: 15 Aug 2023
    7.5
    High

    CVE-2023-4339

    Last Modified: 4 Nov 2025

    Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file permissions

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-4340

    Last Modified: 4 Nov 2025

    Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-4341

    Last Modified: 4 Nov 2025

    Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-4342

    Last Modified: 4 Nov 2025

    Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policy

    Published: 15 Aug 2023
    7.5
    High

    CVE-2023-4343

    Last Modified: 4 Nov 2025

    Broadcom RAID Controller web interface is vulnerable due to exposure of sensitive password information in the URL as a URL search parameter

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-4344

    Last Modified: 4 Nov 2025

    Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-4323

    Last Modified: 4 Nov 2025

    Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup

    Published: 15 Aug 2023
    7.8
    High

    CVE-2023-38401

    Last Modified: 22 Nov 2024

    A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow local users to elevate privileges. Successful exploitation could allow execution of arbitrary code with NT AUTHORITY\SYSTEM privileges on the operating system.

    Published: 15 Aug 2023
    6.5
    Medium

    CVE-2023-4345

    Last Modified: 4 Nov 2025

    Broadcom RAID Controller web interface is vulnerable client-side control bypass leads to unauthorized data access for low privileged user

    Published: 15 Aug 2023
    3.7
    Low

    CVE-2023-40027

    Last Modified: 21 Nov 2024

    Keystone is an open source headless CMS for Node.js — built with GraphQL and React. When `ui.isAccessAllowed` is set as `undefined`, the `adminMeta` GraphQL query is publicly accessible (no session required). This is different to the behaviour of the default AdminUI middleware, which by default will only be publicly accessible (no session required) if a `session` strategy is not defined. This vulnerability does not affect developers using the `@keystone-6/auth` package, or any users that have written their own `ui.isAccessAllowed` (that is to say, `isAccessAllowed` is not `undefined`). This vulnerability does affect users who believed that their `session` strategy will, by default, enforce that `adminMeta` is inaccessible by the public in accordance with that strategy; akin to the behaviour of the AdminUI middleware. This vulnerability has been patched in `@keystone-6/core` version `5.5.1`. Users are advised to upgrade. Users unable to upgrade may opt to write their own `isAccessAllowed` functionality to work-around this vulnerability.

    Published: 15 Aug 2023
    4.9
    Medium

    CVE-2023-40028

    Last Modified: 21 Nov 2024

    Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload files that are symlinks. This can be exploited to perform an arbitrary file read of any file on the host operating system. Site administrators can check for exploitation of this issue by looking for unknown symlinks within Ghost's `content/` folder. Version 5.59.1 contains a fix for this issue. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 15 Aug 2023
    8.8
    High

    CVE-2023-4369

    Last Modified: 5 May 2025

    Insufficient data validation in Systems Extensions in Google Chrome on ChromeOS prior to 116.0.5845.120 allowed an attacker who convinced a user to install a malicious extension to bypass file restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 15 Aug 2023
    8.8
    High

    CVE-2023-4368

    Last Modified: 13 Feb 2025

    Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 15 Aug 2023
    6.5
    Medium

    CVE-2023-4367

    Last Modified: 13 Feb 2025

    Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 15 Aug 2023
    8.8
    High

    CVE-2023-4366

    Last Modified: 13 Feb 2025

    Use after free in Extensions in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

    Published: 15 Aug 2023
    4.3
    Medium

    CVE-2023-4365

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Fullscreen in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

    Published: 15 Aug 2023
    4.3
    Medium

    CVE-2023-4364

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Permission Prompts in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

    Published: 15 Aug 2023
    4.3
    Medium

    CVE-2023-4363

    Last Modified: 13 Feb 2025

    Inappropriate implementation in WebShare in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to spoof the contents of a dialog URL via a crafted HTML page. (Chromium security severity: Medium)

    Published: 15 Aug 2023
    8.8
    High

    CVE-2023-4362

    Last Modified: 13 Feb 2025

    Heap buffer overflow in Mojom IDL in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process and gained control of a WebUI process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

    Published: 15 Aug 2023
    5.3
    Medium

    CVE-2023-4361

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Autofill in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 15 Aug 2023
    4.3
    Medium

    CVE-2023-4360

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Color in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

    Published: 15 Aug 2023
    5.3
    Medium

    CVE-2023-4359

    Last Modified: 13 Feb 2025

    Inappropriate implementation in App Launcher in Google Chrome on iOS prior to 116.0.5845.96 allowed a remote attacker to potentially spoof elements of the security UI via a crafted HTML page. (Chromium security severity: Medium)

    Published: 15 Aug 2023
    8.8
    High

    CVE-2023-4358

    Last Modified: 3 Jul 2025

    Use after free in DNS in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

    Published: 15 Aug 2023