CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2020-27544

    Last Modified: 21 Nov 2024

    An issue was discovered in FoldingAtHome Client Advanced Control GUI before commit 9b619ae64443997948a36dda01b420578de1af77, allows remote attackers to execute arbitrary code via crafted payload to function parse_message in file Connection.py.

    Published: 11 Aug 2023
    7.5
    High

    CVE-2020-35139

    Last Modified: 15 Apr 2025

    An issue was discovered in OFPBundleCtrlMsg in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service (DoS) (infinite loop).

    Published: 11 Aug 2023
    7.5
    High

    CVE-2020-35141

    Last Modified: 15 Apr 2025

    An issue was discovered in OFPQueueGetConfigReply in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service (DoS) (infinite loop).

    Published: 11 Aug 2023
    9.8
    Critical

    CVE-2020-36034

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php.

    Published: 11 Aug 2023
    9.8
    Critical

    CVE-2020-36082

    Last Modified: 21 Nov 2024

    File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module.

    Published: 11 Aug 2023
    8.8
    High

    CVE-2020-23595

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) vulnerability in yzmcms version 5.6, allows remote attackers to escalate privileges and gain sensitive information sitemodel/add.html endpoint.

    Published: 11 Aug 2023
    7.8
    High

    CVE-2020-24222

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in jfif_decode() function in rockcarry ffjpeg through version 1.0.0, allows local attackers to execute arbitrary code due to an issue with ALIGN.

    Published: 11 Aug 2023
    5.4
    Medium

    CVE-2020-28849

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in ChurchCRM version 4.2.1, allows remote attckers to execute arbitrary code and gain sensitive information via crafted payload in Add New Deposit field in View All Deposit module.

    Published: 11 Aug 2023
    6.1
    Medium

    CVE-2021-27524

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in margox braft-editor version 2.3.8, allows remote attackers to execute arbitrary code via the embed media feature.

    Published: 11 Aug 2023
    8.8
    High

    CVE-2020-36037

    Last Modified: 21 Nov 2024

    An issue was disocvered in wuzhicms version 4.1.0, allows remote attackers to execte arbitrary code via the setting parameter to the ueditor in index.php.

    Published: 11 Aug 2023
    7.5
    High

    CVE-2020-36136

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in cskaza cszcms version 1.2.9, allows attackers to gain sensitive information via pm_sendmail parameter in csz_model.php.

    Published: 11 Aug 2023
    5.5
    Medium

    CVE-2021-28025

    Last Modified: 21 Nov 2024

    Integer Overflow vulnerability in qsvghandler.cpp in Qt qtsvg versions 5.15.1, 6.0.0, 6.0.2, and 6.2, allows local attackers to cause a denial of service (DoS).

    Published: 11 Aug 2023
    5.6
    Medium

    CVE-2023-25775

    Last Modified: 13 Feb 2025

    Improper access control in the Intel(R) Ethernet Controller RDMA driver for linux before version 1.9.30 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

    Published: 11 Aug 2023
    5.7
    Medium

    CVE-2023-28736

    Last Modified: 21 Nov 2024

    Buffer overflow in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 11 Aug 2023
    3.4
    Low

    CVE-2023-28938

    Last Modified: 21 Nov 2024

    Uncontrolled resource consumption in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a priviledged user to potentially enable denial of service via local access.

    Published: 11 Aug 2023
    9.1
    Critical

    CVE-2023-40260

    Last Modified: 21 Nov 2024

    EmpowerID before 7.205.0.1 allows an attacker to bypass an MFA (multi factor authentication) requirement if the first factor (username and password) is known, because the first factor is sufficient to change an account's email address, and the product would then send MFA codes to the new email address (which may be attacker-controlled). NOTE: this is different from CVE-2023-4177, which claims to be about "some unknown processing of the component Multi-Factor Authentication Code Handler" and thus cannot be correlated with other vulnerability information.

    Published: 11 Aug 2023
    —
    Unknown

    CVE-2023-40270

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-38831. Reason: This candidate is a reservation duplicate of CVE-2023-38831. Notes: All CVE users should reference CVE-2023-38831 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 11 Aug 2023
    6.5
    Medium

    CVE-2020-36023

    Last Modified: 3 Nov 2025

    An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::cvtGlyph function.

    Published: 11 Aug 2023
    5.5
    Medium

    CVE-2020-36024

    Last Modified: 3 Nov 2025

    An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::convertToType1 function.

    Published: 11 Aug 2023
    9.8
    Critical

    CVE-2023-40267

    Last Modified: 3 Nov 2025

    GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.

    Published: 11 Aug 2023
    7.2
    High

    CVE-2023-35179

    Last Modified: 21 Nov 2024

    A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. 

    Published: 10 Aug 2023
    5.3
    Medium

    CVE-2023-40014

    Last Modified: 21 Nov 2024

    OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 4.0.0 and prior to version 4.9.3, contracts using `ERC2771Context` along with a custom trusted forwarder may see `_msgSender` return `address(0)` in calls that originate from the forwarder with calldata shorter than 20 bytes. This combination of circumstances does not appear to be common, in particular it is not the case for `MinimalForwarder` from OpenZeppelin Contracts, or any deployed forwarder the team is aware of, given that the signer address is appended to all calls that originate from these forwarders. The problem has been patched in v4.9.3.

    Published: 10 Aug 2023
    7.8
    High

    CVE-2023-28129

    Last Modified: 21 Nov 2024

    DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user.

    Published: 10 Aug 2023
    9.8
    Critical

    CVE-2023-32560

    Last Modified: 6 Mar 2025

    An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. Thanks to a Researcher at Tenable for finding and reporting. Fixed in version 6.4.1.

    Published: 10 Aug 2023
    7.5
    High

    CVE-2023-32561

    Last Modified: 6 Mar 2025

    A previously generated artifact by an administrator could be accessed by an attacker. The contents of this artifact could lead to authentication bypass. Fixed in version 6.4.1.

    Published: 10 Aug 2023
    9.8
    Critical

    CVE-2023-32562

    Last Modified: 6 Mar 2025

    An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. Fixed in version 6.4.1.

    Published: 10 Aug 2023
    9.8
    Critical

    CVE-2023-32563

    Last Modified: 13 Feb 2025

    An unauthenticated attacker could achieve the code execution through a RemoteControl server.

    Published: 10 Aug 2023
    9.8
    Critical

    CVE-2023-32564

    Last Modified: 21 Nov 2024

    An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.

    Published: 10 Aug 2023
    9.1
    Critical

    CVE-2023-32565

    Last Modified: 21 Nov 2024

    An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in version 6.4.1.

    Published: 10 Aug 2023
    9.1
    Critical

    CVE-2023-32566

    Last Modified: 21 Nov 2024

    An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in version 6.4.1.

    Published: 10 Aug 2023
    9.8
    Critical

    CVE-2023-32567

    Last Modified: 21 Nov 2024

    Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236

    Published: 10 Aug 2023
    9.8
    Critical

    CVE-2023-35085

    Last Modified: 4 Dec 2024

    An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default settings enabled could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.50 and earlier) All UniFi Switches (Version 6.5.32 and earlier) -USW Flex Mini excluded. Mitigation: Update UniFi Access Points to Version 6.5.62 or later. Update the UniFi Switches to Version 6.5.59 or later.

    Published: 10 Aug 2023
    9.8
    Critical

    CVE-2023-38034

    Last Modified: 4 Dec 2024

    A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.53 and earlier) All UniFi Switches (Version 6.5.32 and earlier) -USW Flex Mini excluded. Mitigation: Update UniFi Access Points to Version 6.5.62 or later. Update UniFi Switches to Version 6.5.59 or later.

    Published: 10 Aug 2023
    6.6
    Medium

    CVE-2023-23342

    Last Modified: 21 Nov 2024

    If certain local files are manipulated in a certain manner, the validation to use the cryptographic keys can be circumvented. 

    Published: 10 Aug 2023
    7.5
    High

    CVE-2023-39966

    Last Modified: 21 Nov 2024

    1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, an arbitrary file write vulnerability could lead to direct control of the server. In the `api/v1/file.go` file, there is a function called `SaveContentthat,It `recieves JSON data sent by users in the form of a POST request. And the lack of parameter filtering allows for arbitrary file write operations. Version 1.5.0 contains a patch for this issue.

    Published: 10 Aug 2023
    6.5
    Medium

    CVE-2023-39965

    Last Modified: 21 Nov 2024

    1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, authenticated attackers can download arbitrary files through the API interface. This code has unauthorized access. Attackers can freely download the file content on the target system. This may cause a large amount of information leakage. Version 1.5.0 has a patch for this issue.

    Published: 10 Aug 2023
    7.5
    High

    CVE-2023-39964

    Last Modified: 21 Nov 2024

    1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, arbitrary file reads allow an attacker to read arbitrary important configuration files on the server. In the `api/v1/file.go` file, there is a function called `LoadFromFile`, which directly reads the file by obtaining the requested path `parameter[path]`. The request parameters are not filtered, resulting in a background arbitrary file reading vulnerability. Version 1.5.0 has a patch for this issue.

    Published: 10 Aug 2023
    8.1
    High

    CVE-2023-39963

    Last Modified: 21 Nov 2024

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 20.0.0 and prior to versions 20.0.14.15, 21.0.9.13, 22.2.10.14, 23.0.12.8, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1, a missing password confirmation allowed an attacker, after successfully stealing a session from a logged in user, to create app passwords for the victim. Nextcloud server versions 25.0.9, 26.0.4, and 27.0.1 and Nextcloud Enterprise Server versions 20.0.14.15, 21.0.9.13, 22.2.10.14, 23.0.12.9, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1 contain a patch for this issue. No known workarounds are available.

    Published: 10 Aug 2023
    7.7
    High

    CVE-2023-39962

    Last Modified: 21 Nov 2024

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 19.0.0 and prior to versions 19.0.13.10, 20.0.14.15, 21.0.9.13, 22.2.10.14, 23.0.12.8, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1, a malicious user could delete any personal or global external storage, making them inaccessible for everyone else as well. Nextcloud server versions 25.0.9, 26.0.4, and 27.0.1 and Nextcloud Enterprise Server versions 19.0.13.10, 20.0.14.15, 21.0.9.13, 22.2.10.14, 23.0.12.9, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1 contain a patch for this issue. As a workaround, disable app files_external. This also makes the external storage inaccessible but retains the configurations until a patched version has been deployed.

    Published: 10 Aug 2023
    3.5
    Low

    CVE-2023-39961

    Last Modified: 21 Nov 2024

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 24.0.4 and prior to versions 25.0.9, 26.0.4, and 27.0.1, when a folder with images or an image was shared without download permissions, the user could add the image inline into a text file and download it. Nextcloud Server versions 25.0.9, 26.0.4, and 27.0.1 and Nextcloud Enterprise Server versions 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1 contain a patch for this issue. No known workarounds are available.

    Published: 10 Aug 2023
    3.5
    Low

    CVE-2023-39959

    Last Modified: 21 Nov 2024

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.9, 26.0.4, and 27.0.1, unauthenticated users could send a DAV request which reveals whether a calendar or an address book with the given identifier exists for the victim. Nextcloud Server versions 25.0.9, 26.0.4, and 27.0.1 and Nextcloud Enterprise Server versions 25.0.9, 26.0.4, and 27.0.1 contain a patch for this issue. No known workarounds are available.

    Published: 10 Aug 2023
    5.8
    Medium

    CVE-2023-39958

    Last Modified: 21 Nov 2024

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 22.0.0 and prior to versions 22.2.10.13, 23.0.12.8, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1, missing protection allows an attacker to brute force the client secrets of configured OAuth2 clients. Nextcloud Server versions 25.0.9, 26.0.4, and 27.0.1 and Nextcloud Enterprise Server versions 22.2.10.13, 23.0.12.8, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1 contain a patch for this issue. No known workarounds are available.

    Published: 10 Aug 2023
    7.8
    High

    CVE-2023-39957

    Last Modified: 21 Nov 2024

    Nextcloud Talk Android allows users to place video and audio calls through Nextcloud on Android. Prior to version 17.0.0, an unprotected intend allowed malicious third party apps to trick the Talk Android app into writing files outside of its intended cache directory. Nextcloud Talk Android version 17.0.0 has a patch for this issue. No known workarounds are available.

    Published: 10 Aug 2023
    3.5
    Low

    CVE-2023-39955

    Last Modified: 21 Nov 2024

    Notes is a note-taking app for Nextcloud, an open-source cloud platform. Starting in version 4.4.0 and prior to version 4.8.0, when creating a note file with HTML, the content is rendered in the preview instead of the file being offered to download. Nextcloud Notes app version 4.8.0 contains a patch for the issue. No known workarounds are available.

    Published: 10 Aug 2023
    3.8
    Low

    CVE-2023-39954

    Last Modified: 21 Nov 2024

    user_oidc provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. Starting in version 1.0.0 and prior to version 1.3.3, an attacker that obtained at least read access to a snapshot of the database can impersonate the Nextcloud server towards linked servers. user_oidc 1.3.3 contains a patch. No known workarounds are available.

    Published: 10 Aug 2023
    4.8
    Medium

    CVE-2023-39953

    Last Modified: 21 Nov 2024

    user_oidc provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. Starting in version 1.0.0 and prior to version 1.3.3, missing verification of the issuer would have allowed an attacker to perform a man-in-the-middle attack returning corrupted or known token they also have access to. user_oidc 1.3.3 contains a patch. No known workarounds are available.

    Published: 10 Aug 2023
    6.5
    Medium

    CVE-2023-39952

    Last Modified: 21 Nov 2024

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 22.0.0 and prior to versions 22.2.10.13, 23.0.12.8, 24.0.12.4, 25.0.8, 26.0.3, and 27.0.1, a user can access files inside a subfolder of a groupfolder accessible to them, even if advanced permissions would block access to the subfolder. Nextcloud Server versions 25.0.8, 26.0.3, and 27.0.1 and Nextcloud Enterprise Server versions 22.2.10.13, 23.0.12.8, 24.0.12.4, 25.0.8, 26.0.3, and 27.0.1 contain a patch for this issue. No known workarounds are available.

    Published: 10 Aug 2023
    5.9
    Medium

    CVE-2023-38397

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eggemplo Gestion-Pymes plugin <= 1.5.6 versions.

    Published: 10 Aug 2023
    7.8
    High

    CVE-2023-38246

    Last Modified: 28 May 2026

    Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Aug 2023
    7.8
    High

    CVE-2023-29320

    Last Modified: 28 May 2026

    Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Violation of Secure Design Principles vulnerability that could result in arbitrary code execution in the context of the current user by bypassing the API blacklisting feature. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Aug 2023