CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2023-4357

    Last Modified: 13 Feb 2025

    Insufficient validation of untrusted input in XML in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 15 Aug 2023
    8.8
    High

    CVE-2023-4356

    Last Modified: 13 Feb 2025

    Use after free in Audio in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

    Published: 15 Aug 2023
    8.8
    High

    CVE-2023-4355

    Last Modified: 5 May 2025

    Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 15 Aug 2023
    8.8
    High

    CVE-2023-4354

    Last Modified: 5 May 2025

    Heap buffer overflow in Skia in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 15 Aug 2023
    8.8
    High

    CVE-2023-4353

    Last Modified: 13 Feb 2025

    Heap buffer overflow in ANGLE in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 15 Aug 2023
    8.8
    High

    CVE-2023-4352

    Last Modified: 5 May 2025

    Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 15 Aug 2023
    8.8
    High

    CVE-2023-4351

    Last Modified: 13 Feb 2025

    Use after free in Network in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has elicited a browser shutdown to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 15 Aug 2023
    6.5
    Medium

    CVE-2023-4350

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)

    Published: 15 Aug 2023
    8.8
    High

    CVE-2023-4349

    Last Modified: 13 Feb 2025

    Use after free in Device Trust Connectors in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 15 Aug 2023
    8.8
    High

    CVE-2023-2312

    Last Modified: 13 Feb 2025

    Use after free in Offline in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 15 Aug 2023
    8.1
    High

    CVE-2023-39438

    Last Modified: 21 Nov 2024

    A missing authorization check allows an arbitrary authenticated user to perform certain operations through the API of CLA-assistant by executing specific additional steps. This allows an arbitrary authenticated user to read CLA information including information of the persons who signed them as well as custom fields the CLA requester had configured. In addition, an arbitrary authenticated user can update or delete the CLA-configuration for repositories or organizations using CLA-assistant. The stored access tokens for GitHub are not affected, as these are redacted from the API-responses.

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-35082

    Last Modified: 31 Oct 2025

    An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

    Published: 15 Aug 2023
    3.5
    Low

    CVE-2023-4371

    Last Modified: 21 Nov 2024

    A vulnerability was found in phpRecDB 1.3.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument r/view leads to cross site scripting. The attack may be launched remotely. VDB-237194 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 15 Aug 2023
    7.1
    High

    CVE-2023-30498

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodeFlavors Vimeotheque: Vimeo WordPress Plugin <= 2.2.1 versions.

    Published: 15 Aug 2023
    5.5
    Medium

    CVE-2023-24478

    Last Modified: 21 Nov 2024

    Use of insufficiently random values for some Intel Agilex(R) software included as part of Intel(R) Quartus(R) Prime Pro Edition for linux before version 22.4 may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 15 Aug 2023
    5.5
    Medium

    CVE-2023-30778

    Last Modified: 21 Nov 2024

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Blubrry PowerPress Podcasting plugin by Blubrry plugin <= 10.0.1 versions.

    Published: 15 Aug 2023
    7.1
    High

    CVE-2023-30747

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPGem WooCommerce Easy Duplicate Product plugin <= 0.3.0.0 versions.

    Published: 15 Aug 2023
    7.5
    High

    CVE-2023-2916

    Last Modified: 8 Apr 2026

    The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including configuration. It can only be exploited if the plugin has not been configured yet. If combined with another arbitrary plugin installation and activation vulnerability, it may be possible to connect a site to InfiniteWP which would make remote management possible and allow for elevation of privileges.

    Published: 15 Aug 2023
    7.2
    High

    CVE-2023-4308

    Last Modified: 8 Apr 2026

    The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user-submitted-content’ parameter in versions up to, and including, 20230809 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 15 Aug 2023
    5.4
    Medium

    CVE-2023-4347

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0.

    Published: 15 Aug 2023
    —
    Unknown

    CVE-2023-4348

    Last Modified: 15 Nov 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 15 Aug 2023
    5.5
    Medium

    CVE-2023-4211

    Last Modified: 26 Feb 2026

    A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.

    Published: 15 Aug 2023
    8.8
    High

    CVE-2023-38916

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in eVotingSystem-PHP v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the user input fields.

    Published: 15 Aug 2023
    5.3
    Medium

    CVE-2023-38898

    Last Modified: 21 Nov 2024

    An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component. NOTE: this is disputed by the vendor because (1) neither 3.7 nor any other release is affected (it is a bug in some 3.12 pre-releases); (2) there are no common scenarios in which an adversary can call _asyncio._swap_current_task but does not already have the ability to call arbitrary functions; and (3) there are no common scenarios in which sensitive information, which is not already accessible to an adversary, becomes accessible through this bug.

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-38866

    Last Modified: 21 Nov 2024

    COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter interface and display_name.

    Published: 15 Aug 2023
    6.5
    Medium

    CVE-2023-38853

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the xls_parseWorkBook function in xls.c:1015.

    Published: 15 Aug 2023
    6.5
    Medium

    CVE-2023-38851

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the xls_parseWorkBook function in xls.c:1018.

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-39662

    Last Modified: 21 Nov 2024

    An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine function.

    Published: 15 Aug 2023
    8.8
    High

    CVE-2023-28479

    Last Modified: 21 Nov 2024

    An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform installs a full development toolchain within every TigerGraph deployment. An attacker is able to compile new executables on each Tigergraph system and modify system and Tigergraph binaries.

    Published: 15 Aug 2023
    5.5
    Medium

    CVE-2023-38850

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in Michaelrsweet codedoc v.3.7 allows an attacker to cause a denial of service via the codedoc.c:1742 comppnent.

    Published: 15 Aug 2023
    6.5
    Medium

    CVE-2023-38858

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability infaad2 v.2.10.1 allows a remote attacker to execute arbitrary code and cause a denial of service via the mp4info function in mp4read.c:1039.

    Published: 15 Aug 2023
    5.5
    Medium

    CVE-2023-38840

    Last Modified: 21 Nov 2024

    Bitwarden Desktop 2023.7.0 and below allows an attacker with local access to obtain sensitive information via the Bitwarden.exe process.

    Published: 15 Aug 2023
    6.5
    Medium

    CVE-2023-38854

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the transcode_latin1_to_utf8 function in xlstool.c:296.

    Published: 15 Aug 2023
    6.5
    Medium

    CVE-2023-38855

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the get_string function in xlstool.c:395.

    Published: 15 Aug 2023
    6.5
    Medium

    CVE-2023-38856

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the get_string function in xlstool.c:411.

    Published: 15 Aug 2023
    5.5
    Medium

    CVE-2023-38857

    Last Modified: 26 Nov 2024

    Buffer Overflow vulnerability infaad2 v.2.10.1 allows a remote attacker to execute arbitrary code and cause a denial of service via the stcoin function in mp4read.c.

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-38860

    Last Modified: 21 Nov 2024

    An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter.

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-38861

    Last Modified: 21 Nov 2024

    An issue in Wavlink WL_WNJ575A3 v.R75A3_V1410_220513 allows a remote attacker to execute arbitrary code via username parameter of the set_sys_adm function in adm.cgi.

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-38862

    Last Modified: 21 Nov 2024

    An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the destination parameter of sub_431F64 function in bin/webmgnt.

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-38863

    Last Modified: 21 Nov 2024

    An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the ifname and mac parameters in the sub_410074 function at bin/webmgnt.

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-38864

    Last Modified: 21 Nov 2024

    An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter in the sub_41171C function at bin/webmgnt.

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-38865

    Last Modified: 21 Nov 2024

    COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter timestr.

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-38915

    Last Modified: 21 Nov 2024

    File Upload vulnerability in Wolf-leo EasyAdmin8 v.1.0 allows a remote attacker to execute arbtirary code via the upload type function.

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-38889

    Last Modified: 21 Nov 2024

    An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lang.String).

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-38896

    Last Modified: 21 Nov 2024

    An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and from_colored_object_prompt functions.

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-39661

    Last Modified: 21 Nov 2024

    An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function.

    Published: 15 Aug 2023
    9.8
    Critical

    CVE-2023-39659

    Last Modified: 21 Nov 2024

    An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLTool._run component.

    Published: 15 Aug 2023
    4.6
    Medium

    CVE-2023-39841

    Last Modified: 21 Nov 2024

    Missing encryption in the RFID tag of Etekcity 3-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device.

    Published: 15 Aug 2023
    2.4
    Low

    CVE-2023-39842

    Last Modified: 21 Nov 2024

    Missing encryption in the RFID tag of Digoo DG-HAMB Smart Home Security System v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device.

    Published: 15 Aug 2023
    2.4
    Low

    CVE-2023-39843

    Last Modified: 21 Nov 2024

    Missing encryption in the RFID tag of Suleve 5-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device.

    Published: 15 Aug 2023