CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2023-3160

    Last Modified: 21 Nov 2024

    The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or move files without having proper permissions.

    Published: 14 Aug 2023
    6.8
    Medium

    CVE-2023-1832

    Last Modified: 21 Nov 2024

    An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant.

    Published: 14 Aug 2023
    7.6
    High

    CVE-2023-4320

    Last Modified: 20 Nov 2025

    An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attacker who uses this arithmetic overflow to create personal access tokens that are valid indefinitely, resulting in damage to the system's integrity.

    Published: 14 Aug 2023
    —
    Unknown

    CVE-2023-4319

    Last Modified: 16 Jan 2025

    This CVE ID is a reservation duplicate of CVE-2023-4677. Notes: All CVE users should reference CVE-2023-4677 instead of this CVE ID.

    Published: 14 Aug 2023
    9.1
    Critical

    CVE-2023-3267

    Last Modified: 21 Nov 2024

    When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without sanitization into CMD running as NT/Authority System. An authenticated attacker can leverage this vulnerability to execute arbitrary code with system-level access to the CyberPower PowerPanel Enterprise server.

    Published: 14 Aug 2023
    9.8
    Critical

    CVE-2023-3266

    Last Modified: 21 Nov 2024

    A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication checks if LDAP authentication is selected.An unauthenticated attacker can leverage this vulnerability to log in to the CypberPower PowerPanel Enterprise as an administrator by selecting LDAP authentication from a hidden HTML combo box. Successful exploitation of this vulnerability also requires the attacker to know at least one username on the device, but any password will authenticate successfully.

    Published: 14 Aug 2023
    9.8
    Critical

    CVE-2023-3265

    Last Modified: 21 Nov 2024

    An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an attacker to login into the application with the default user "cyberpower" by appending a non-printable character.An unauthenticated attacker can leverage this vulnerability to log in to the CypberPower PowerPanel Enterprise as an administrator with hardcoded default credentials.

    Published: 14 Aug 2023
    6.7
    Medium

    CVE-2023-3264

    Last Modified: 21 Nov 2024

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database. A malicious agent with the ability to execute operating system commands on the device can leverage this vulnerability to read, modify, or delete arbitrary database records.

    Published: 14 Aug 2023
    7.5
    High

    CVE-2023-3263

    Last Modified: 21 Nov 2024

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the mishandling of special characters when parsing credentials.Successful exploitation allows the malicious agent to obtain a valid authorization token and read information relating to the state of the relays and power distribution.

    Published: 14 Aug 2023
    6.7
    Medium

    CVE-2023-3262

    Last Modified: 21 Nov 2024

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database.A malicious agent with the ability to execute operating system commands on the device can leverage this vulnerability to read, modify, or delete arbitrary database records.

    Published: 14 Aug 2023
    7.5
    High

    CVE-2023-3261

    Last Modified: 21 Nov 2024

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 library.Successful exploitation could cause denial of service or unexpected behavior with respect to all interactions relying on the targeted vulnerable binary, including the ability to log in via the web server.

    Published: 14 Aug 2023
    7.2
    High

    CVE-2023-3260

    Last Modified: 21 Nov 2024

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulnerability to execute arbitrary command on the underlying Linux operating system.

    Published: 14 Aug 2023
    9.8
    Critical

    CVE-2023-3259

    Last Modified: 21 Nov 2024

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass. By manipulating the IP address field in the "iBootPduSiteAuth" cookie, a malicious agent can direct the device to connect to a rouge database.Successful exploitation allows the malicious agent to take actions with administrator privileges including, but not limited to, manipulating power levels, modifying user accounts, and exporting confidential user information

    Published: 14 Aug 2023
    7.5
    High

    CVE-2023-39829

    Last Modified: 21 Nov 2024

    Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the wpapsk_crypto2_4g parameter in the fromSetWirelessRepeat function.

    Published: 14 Aug 2023
    7.5
    High

    CVE-2023-40518

    Last Modified: 21 Nov 2024

    LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.

    Published: 14 Aug 2023
    9.8
    Critical

    CVE-2023-40359

    Last Modified: 21 Nov 2024

    xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e., neither alphanumeric nor underscore), aka a pointer/overflow issue. This can only occur for xterm installations that are configured at compile time to use a certain experimental feature.

    Published: 14 Aug 2023
    6.5
    Medium

    CVE-2023-28480

    Last Modified: 21 Nov 2024

    An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform allows users to define new User Defined Functions (UDFs) from C/C++ code. To support this functionality TigerGraph allows users to upload custom C/C++ code which is then compiled and installed into the platform. An attacker who has filesystem access on a remote TigerGraph system can alter the behavior of the database against the will of the database administrator; thus effectively bypassing the built in RBAC controls.

    Published: 14 Aug 2023
    8.8
    High

    CVE-2023-28481

    Last Modified: 21 Nov 2024

    An issue was discovered in Tigergraph Enterprise 3.7.0. There is unsecured write access to SSH authorized keys file. Any code running as the tigergraph user is able to add their SSH public key into the authorised keys file. This allows an attacker to obtain password-less SSH key access by using their own SSH key.

    Published: 14 Aug 2023
    6.5
    Medium

    CVE-2023-28482

    Last Modified: 21 Nov 2024

    An issue was discovered in Tigergraph Enterprise 3.7.0. A single TigerGraph instance can host multiple graphs that are accessed by multiple different users. The TigerGraph platform does not protect the confidentiality of any data uploaded to the remote server. In this scenario, any user that has permissions to upload data can browse data uploaded by any other user (irrespective of their permissions).

    Published: 14 Aug 2023
    8.8
    High

    CVE-2023-28483

    Last Modified: 21 Nov 2024

    An issue was discovered in Tigergraph Enterprise 3.7.0. The GSQL query language provides users with the ability to write data to files on a remote TigerGraph server. The locations that a query is allowed to write to are configurable via the GSQL.FileOutputPolicy configuration setting. GSQL queries that contain UDFs can bypass this configuration setting and, as a consequence, can write to any file location to which the administrative user has access.

    Published: 14 Aug 2023
    9.8
    Critical

    CVE-2023-39293

    Last Modified: 21 Nov 2024

    A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system.

    Published: 14 Aug 2023
    7.8
    High

    CVE-2023-40283

    Last Modified: 18 Sept 2026

    An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled.

    Published: 14 Aug 2023
    7.5
    High

    CVE-2023-30188

    Last Modified: 21 Nov 2024

    Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted JavaScript file.

    Published: 14 Aug 2023
    9.8
    Critical

    CVE-2023-29468

    Last Modified: 5 May 2025

    The Texas Instruments (TI) WiLink WL18xx MCP driver does not limit the number of information elements (IEs) of type XCC_EXT_1_IE_ID or XCC_EXT_2_IE_ID that can be parsed in a management frame. Using a specially crafted frame, a buffer overflow can be triggered that can potentially lead to remote code execution. This affects WILINK8-WIFI-MCP8 version 8.5_SP3 and earlier.

    Published: 14 Aug 2023
    9.8
    Critical

    CVE-2023-30186

    Last Modified: 21 Nov 2024

    A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.

    Published: 14 Aug 2023
    9.8
    Critical

    CVE-2023-30187

    Last Modified: 21 Nov 2024

    An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.

    Published: 14 Aug 2023
    7.5
    High

    CVE-2023-31041

    Last Modified: 21 Nov 2024

    An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information could optionally be stored in cleartext, which might lead to possible information disclosure.

    Published: 14 Aug 2023
    9.8
    Critical

    CVE-2023-32748

    Last Modified: 21 Nov 2024

    The Linux DVS server component of Mitel MiVoice Connect through 19.3 SP2 (22.24.1500.0) could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access control.

    Published: 14 Aug 2023
    4.8
    Medium

    CVE-2023-37070

    Last Modified: 21 Nov 2024

    Code Projects Hospital Information System 1.0 is vulnerable to Cross Site Scripting (XSS)

    Published: 14 Aug 2023
    9.8
    Critical

    CVE-2023-37847

    Last Modified: 1 Aug 2025

    novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.

    Published: 14 Aug 2023
    9.8
    Critical

    CVE-2023-39292

    Last Modified: 21 Nov 2024

    A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to access sensitive information and execute arbitrary database and management operations.

    Published: 14 Aug 2023
    7.5
    High

    CVE-2023-39827

    Last Modified: 21 Nov 2024

    Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the rule_info parameter in the formAddMacfilterRule function.

    Published: 14 Aug 2023
    7.5
    High

    CVE-2023-39828

    Last Modified: 21 Nov 2024

    Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet function.

    Published: 14 Aug 2023
    7.5
    High

    CVE-2023-39908

    Last Modified: 21 Nov 2024

    The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations on object metadata. This may lead to disclosure of uninitialized and previously used memory.

    Published: 14 Aug 2023
    7.5
    High

    CVE-2023-40274

    Last Modified: 21 Nov 2024

    An issue was discovered in zola 0.13.0 through 0.17.2. The custom implementation of a web server, available via the "zola serve" command, allows directory traversal. The handle_request function, used by the server to process HTTP requests, does not account for sequences of special path control characters (../) in the URL when serving a file, which allows one to escape the webroot of the server and read arbitrary files from the filesystem.

    Published: 14 Aug 2023
    6.8
    Medium

    CVE-2023-40291

    Last Modified: 21 Nov 2024

    Harman Infotainment 20190525031613 allows root access via SSH over a USB-to-Ethernet dongle with a password that is an internal project name.

    Published: 14 Aug 2023
    4.3
    Medium

    CVE-2023-40292

    Last Modified: 21 Nov 2024

    Harman Infotainment 20190525031613 and later discloses the IP address via CarPlay CTRL packets.

    Published: 14 Aug 2023
    6.8
    Medium

    CVE-2023-40293

    Last Modified: 21 Nov 2024

    Harman Infotainment 20190525031613 and later allows command injection via unauthenticated RPC with a D-Bus connection object.

    Published: 14 Aug 2023
    6.5
    Medium

    CVE-2023-40294

    Last Modified: 21 Nov 2024

    libboron in Boron 2.0.8 has a heap-based buffer overflow in ur_parseBlockI at i_parse_blk.c.

    Published: 14 Aug 2023
    8.8
    High

    CVE-2023-40295

    Last Modified: 21 Nov 2024

    libboron in Boron 2.0.8 has a heap-based buffer overflow in ur_strInitUtf8 at string.c.

    Published: 14 Aug 2023
    7.5
    High

    CVE-2023-40296

    Last Modified: 21 Nov 2024

    async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in ReceiveFrom and Receive in udpsocket.hpp when processing malformed UDP packets.

    Published: 14 Aug 2023
    7.8
    High

    CVE-2023-40303

    Last Modified: 21 Nov 2024

    GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process.

    Published: 14 Aug 2023
    6.5
    Medium

    CVE-2023-40354

    Last Modified: 21 Nov 2024

    An issue was discovered in MariaDB MaxScale before 23.02.3. A user enters an encrypted password on a "maxctrl create service" command line, but this password is then stored in cleartext in the resulting .cnf file under /var/lib/maxscale/maxscale.cnf.d. The fixed versions are 2.5.28, 6.4.9, 22.08.8, and 23.02.3.

    Published: 14 Aug 2023
    6.5
    Medium

    CVE-2023-40453

    Last Modified: 21 Nov 2024

    Docker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, which might potentially trick an administrator into performing an unsafe action (via escape sequence injection), or might have a data size that causes a denial of service to a bastion node. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 14 Aug 2023
    9.1
    Critical

    CVE-2021-46895

    Last Modified: 21 Nov 2024

    Vulnerability of defects introduced in the design process in the Multi-Device Task Center. Successful exploitation of this vulnerability will cause the hopped app to bypass the app lock and reset the device that initiates the hop.

    Published: 13 Aug 2023
    7.5
    High

    CVE-2023-39406

    Last Modified: 21 Nov 2024

    Permission control vulnerability in the XLayout component. Successful exploitation of this vulnerability may cause apps to forcibly restart.

    Published: 13 Aug 2023
    7.5
    High

    CVE-2023-39404

    Last Modified: 21 Nov 2024

    Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart.

    Published: 13 Aug 2023
    9.1
    Critical

    CVE-2023-39403

    Last Modified: 21 Nov 2024

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

    Published: 13 Aug 2023
    9.1
    Critical

    CVE-2023-39402

    Last Modified: 21 Nov 2024

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

    Published: 13 Aug 2023
    9.1
    Critical

    CVE-2023-39401

    Last Modified: 21 Nov 2024

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

    Published: 13 Aug 2023