CVE Feed

    Dashboard / CVE

    9.1
    Critical

    CVE-2023-39400

    Last Modified: 21 Nov 2024

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

    Published: 13 Aug 2023
    9.1
    Critical

    CVE-2023-39399

    Last Modified: 21 Nov 2024

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

    Published: 13 Aug 2023
    9.1
    Critical

    CVE-2023-39398

    Last Modified: 21 Nov 2024

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

    Published: 13 Aug 2023
    7.5
    High

    CVE-2023-39397

    Last Modified: 21 Nov 2024

    Input parameter verification vulnerability in the communication system. Successful exploitation of this vulnerability may affect availability.

    Published: 13 Aug 2023
    7.5
    High

    CVE-2023-39395

    Last Modified: 21 Nov 2024

    Mismatch vulnerability in the serialization process in the communication system. Successful exploitation of this vulnerability may affect availability.

    Published: 13 Aug 2023
    7.5
    High

    CVE-2023-39394

    Last Modified: 21 Nov 2024

    Vulnerability of API privilege escalation in the wifienhance module. Successful exploitation of this vulnerability may cause the arp list to be modified.

    Published: 13 Aug 2023
    7.5
    High

    CVE-2023-39391

    Last Modified: 21 Nov 2024

    Vulnerability of system file information leakage in the USB Service module. Successful exploitation of this vulnerability may affect confidentiality.

    Published: 13 Aug 2023
    7.5
    High

    CVE-2023-39390

    Last Modified: 21 Nov 2024

    Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart.

    Published: 13 Aug 2023
    5.3
    Medium

    CVE-2023-39387

    Last Modified: 21 Nov 2024

    Vulnerability of permission control in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up windows.

    Published: 13 Aug 2023
    7.5
    High

    CVE-2023-39386

    Last Modified: 21 Nov 2024

    Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause newly installed apps to fail to restart.

    Published: 13 Aug 2023
    9.1
    Critical

    CVE-2023-39385

    Last Modified: 21 Nov 2024

    Vulnerability of configuration defects in the media module of certain products.. Successful exploitation of this vulnerability may cause unauthorized access.

    Published: 13 Aug 2023
    7.5
    High

    CVE-2023-39384

    Last Modified: 21 Nov 2024

    Vulnerability of incomplete permission verification in the input method module. Successful exploitation of this vulnerability may cause features to perform abnormally.

    Published: 13 Aug 2023
    7.5
    High

    CVE-2023-39383

    Last Modified: 21 Nov 2024

    Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' data security.

    Published: 13 Aug 2023
    7.5
    High

    CVE-2023-39382

    Last Modified: 21 Nov 2024

    Input verification vulnerability in the audio module. Successful exploitation of this vulnerability may cause virtual machines (VMs) to restart.

    Published: 13 Aug 2023
    7.5
    High

    CVE-2023-39381

    Last Modified: 21 Nov 2024

    Input verification vulnerability in the storage module. Successful exploitation of this vulnerability may cause the device to restart.

    Published: 13 Aug 2023
    7.5
    High

    CVE-2023-39380

    Last Modified: 21 Nov 2024

    Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally.

    Published: 13 Aug 2023
    9.8
    Critical

    CVE-2023-39405

    Last Modified: 21 Nov 2024

    Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of this vulnerability may cause other apps to be executed with escalated privileges.

    Published: 13 Aug 2023
    7.5
    High

    CVE-2023-39396

    Last Modified: 21 Nov 2024

    Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability.

    Published: 13 Aug 2023
    7.5
    High

    CVE-2023-39393

    Last Modified: 21 Nov 2024

    Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability may cause ServiceWifiResources to be maliciously modified and overwritten.

    Published: 13 Aug 2023
    7.5
    High

    CVE-2023-39392

    Last Modified: 21 Nov 2024

    Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciously modified and overwritten.

    Published: 13 Aug 2023
    7.5
    High

    CVE-2023-39389

    Last Modified: 21 Nov 2024

    Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause home screen unavailability.

    Published: 13 Aug 2023
    7.5
    High

    CVE-2023-39388

    Last Modified: 21 Nov 2024

    Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause home screen unavailability.

    Published: 13 Aug 2023
    6.1
    Medium

    CVE-2023-23208

    Last Modified: 21 Nov 2024

    Genesys Administrator Extension (GAX) before 9.0.105.15 is vulnerable to Cross Site Scripting (XSS) via the Business Structure page of the iWD plugin, aka GAX-11261.

    Published: 13 Aug 2023
    6.4
    Medium

    CVE-2023-4265

    Last Modified: 13 Feb 2025

    Potential buffer overflow vulnerabilities in the following locations: https://github.com/zephyrproject-rtos/zephyr/blob/main/drivers/usb/device/usb_dc_native_posix.c#L359 https://github.com/zephyrproject-rtos/zephyr/blob/main/drivers/usb/device/usb_dc_native_posix.c#L359 https://github.com/zephyrproject-rtos/zephyr/blob/main/subsys/usb/device/class/netusb/function_rndis... https://github.com/zephyrproject-rtos/zephyr/blob/main/subsys/usb/device/class/netusb/function_rndis.c#L841

    Published: 12 Aug 2023
    8.8
    High

    CVE-2023-4293

    Last Modified: 8 Apr 2026

    The Premium Packages - Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.7.4 due to insufficient restriction on the 'wpdmpp_update_profile' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'profile[role]' parameter during a profile update.

    Published: 12 Aug 2023
    9.8
    Critical

    CVE-2023-3452

    Last Modified: 8 Apr 2026

    The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. This allows unauthenticated attackers to include and execute arbitrary remote code on the server, provided that allow_url_include is enabled. Local File Inclusion is also possible, albeit less useful because it requires that the attacker be able to upload a malicious php file via FTP or some other means into a directory readable by the web server.

    Published: 12 Aug 2023
    5.5
    Medium

    CVE-2023-4569

    Last Modified: 27 Feb 2025

    A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue may allow a local attacker to cause double-deactivations of catchall elements, which can result in a memory leak.

    Published: 12 Aug 2023
    5.4
    Medium

    CVE-2023-0871

    Last Modified: 21 Nov 2024

    XXE injection in /rtc/post/ endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to XML external entity (XXE) injection, which can be used for instance to force Horizon to make arbitrary HTTP requests to internal and external services. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet. OpenNMS thanks Erik Wynter and Moshe Apelbaum for reporting this issue.

    Published: 11 Aug 2023
    7.5
    High

    CVE-2023-39949

    Last Modified: 13 Feb 2025

    eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5, improper validation of sequence numbers may lead to remotely reachable assertion failure. This can remotely crash any Fast-DDS process. Versions 2.9.1 and 2.6.5 contain a patch for this issue.

    Published: 11 Aug 2023
    7.5
    High

    CVE-2023-39948

    Last Modified: 13 Feb 2025

    eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0 and 2.6.5, the `BadParamException` thrown by Fast CDR is not caught in Fast DDS. This can remotely crash any Fast DDS process. Versions 2.10.0 and 2.6.5 contain a patch for this issue.

    Published: 11 Aug 2023
    8.2
    High

    CVE-2023-39947

    Last Modified: 13 Feb 2025

    eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6, even after the fix at commit 3492270, malformed `PID_PROPERTY_LIST` parameters cause heap overflow at a different program counter. This can remotely crash any Fast-DDS process. Versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6 contain a patch for this issue.

    Published: 11 Aug 2023
    8.2
    High

    CVE-2023-39946

    Last Modified: 13 Feb 2025

    eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6, heap can be overflowed by providing a PID_PROPERTY_LIST parameter that contains a CDR string with length larger than the size of actual content. In `eprosima::fastdds::dds::ParameterPropertyList_t::push_back_helper`, `memcpy` is called to first copy the octet'ized length and then to copy the data into `properties_.data`. At the second memcpy, both `data` and `size` can be controlled by anyone that sends the CDR string to the discovery multicast port. This can remotely crash any Fast-DDS process. Versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6 contain a patch for this issue.

    Published: 11 Aug 2023
    6.4
    Medium

    CVE-2023-32267

    Last Modified: 21 Nov 2024

    A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Management Center. The vulnerability could be remotely exploited.

    Published: 11 Aug 2023
    8.2
    High

    CVE-2023-39945

    Last Modified: 13 Feb 2025

    eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.0, 2.10.2, 2.9.2, and 2.6.5, a data submessage sent to PDP port raises unhandled `BadParamException` in fastcdr, which in turn crashes fastdds. Versions 2.11.0, 2.10.2, 2.9.2, and 2.6.5 contain a patch for this issue.

    Published: 11 Aug 2023
    7.5
    High

    CVE-2023-39534

    Last Modified: 13 Feb 2025

    eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0, 2.9.2, and 2.6.5, a malformed GAP submessage can trigger assertion failure, crashing FastDDS. Version 2.10.0, 2.9.2, and 2.6.5 contain a patch for this issue.

    Published: 11 Aug 2023
    4.8
    Medium

    CVE-2023-3937

    Last Modified: 21 Nov 2024

    Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser

    Published: 11 Aug 2023
    7.2
    High

    CVE-2023-3864

    Last Modified: 21 Nov 2024

    Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal.

    Published: 11 Aug 2023
    7.5
    High

    CVE-2023-39553

    Last Modified: 13 Feb 2025

    Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider. Apache Airflow Drill Provider is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection with DrillHook giving an opportunity to read files on the Airflow server. This issue affects Apache Airflow Drill Provider: before 2.4.3. It is recommended to upgrade to a version that is not affected.

    Published: 11 Aug 2023
    4.5
    Medium

    CVE-2023-4108

    Last Modified: 21 Nov 2024

    Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged

    Published: 11 Aug 2023
    6.7
    Medium

    CVE-2023-4107

    Last Modified: 21 Nov 2024

    Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user manager to update a system admin's details such as email, first name and last name.

    Published: 11 Aug 2023
    6.3
    Medium

    CVE-2023-4106

    Last Modified: 21 Nov 2024

    Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to view, join, edit, export and archive public playbooks.

    Published: 11 Aug 2023
    3.1
    Low

    CVE-2023-4105

    Last Modified: 21 Nov 2024

    Mattermost fails to delete the attachments when deleting a message in a thread allowing a simple user to still be able to access and download the attachment of a deleted message

    Published: 11 Aug 2023
    7.5
    High

    CVE-2023-40254

    Last Modified: 21 Nov 2024

    Download of Code Without Integrity Check vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Malicious Software Update.This issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Genian NAC V5.0: from V5.0.0 through V5.0.42 (Revision 117460); Genian NAC Suite V5.0: from V5.0.0 through V5.0.54; Genian ZTNA: from V6.0.0 through V6.0.15.

    Published: 11 Aug 2023
    6
    Medium

    CVE-2023-40253

    Last Modified: 21 Nov 2024

    Improper Authentication vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Authentication Abuse.This issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Genian NAC V5.0: from V5.0.0 through V5.0.42 (Revision 117460); Genian NAC Suite V5.0: from V5.0.0 through V5.0.54; Genian ZTNA: from V6.0.0 through V6.0.15.

    Published: 11 Aug 2023
    6.7
    Medium

    CVE-2023-32663

    Last Modified: 21 Nov 2024

    Incorrect default permissions in some Intel(R) RealSense(TM) SDKs in version 2.53.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 11 Aug 2023
    6.7
    Medium

    CVE-2023-32543

    Last Modified: 21 Nov 2024

    Incorrect default permissions in the Intel(R) ITS sofware before version 3.1 may allow authenticated user to potentially enable escalation of privilege via local access.

    Published: 11 Aug 2023
    6.7
    Medium

    CVE-2023-32547

    Last Modified: 21 Nov 2024

    Incorrect default permissions in the MAVinci Desktop Software for Intel(R) Falcon 8+ before version 6.2 may allow authenticated user to potentially enable escalation of privilege via local access.

    Published: 11 Aug 2023
    5
    Medium

    CVE-2023-32609

    Last Modified: 21 Nov 2024

    Improper access control in the Intel Unite(R) android application before version 4.2.3504 may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 11 Aug 2023
    4.6
    Medium

    CVE-2023-34349

    Last Modified: 21 Nov 2024

    Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 11 Aug 2023
    6
    Medium

    CVE-2023-32285

    Last Modified: 21 Nov 2024

    Improper access control in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access.

    Published: 11 Aug 2023