CVE Feed

    Dashboard / CVE

    7.4
    High

    CVE-2023-26309

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability in the webview component of OnePlus Store app.

    Published: 10 Aug 2023
    8.8
    High

    CVE-2023-31209

    Last Modified: 21 Nov 2024

    Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authenticated users.

    Published: 10 Aug 2023
    8.8
    High

    CVE-2023-4276

    Last Modified: 8 Apr 2026

    The Absolute Privacy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing nonce validation on the 'abpr_profileShortcode' function. This makes it possible for unauthenticated attackers to change user email and password via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 10 Aug 2023
    8.8
    High

    CVE-2023-4277

    Last Modified: 8 Apr 2026

    The Realia plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.0. This is due to missing nonce validation on the 'process_change_profile_form' function. This makes it possible for unauthenticated attackers to change user email via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 10 Aug 2023
    6.8
    Medium

    CVE-2023-30705

    Last Modified: 21 Nov 2024

    Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.56.6?allows local attackers to access privileged content providers as Galaxy Store permission.

    Published: 10 Aug 2023
    3.8
    Low

    CVE-2023-30704

    Last Modified: 21 Nov 2024

    Improper Authorization vulnerability in Samsung Internet prior to version 22.0.0.35 allows physical attacker access downloaded files in Secret Mode without user authentication.

    Published: 10 Aug 2023
    3.3
    Low

    CVE-2023-30703

    Last Modified: 21 Nov 2024

    Improper URL validation vulnerability in Samsung Members prior to version 14.0.07.1 allows attackers to access sensitive information.

    Published: 10 Aug 2023
    6.7
    Medium

    CVE-2023-30702

    Last Modified: 21 Nov 2024

    Stack overflow vulnerability in SSHDCPAPP TA prior to &quot;SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023&quot; in Windows Update for Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 allows local attacker to execute arbitrary code.

    Published: 10 Aug 2023
    4.7
    Medium

    CVE-2023-30701

    Last Modified: 21 Nov 2024

    PendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker to arbitrary file access.

    Published: 10 Aug 2023
    5.3
    Medium

    CVE-2023-30700

    Last Modified: 21 Nov 2024

    PendingIntent hijacking vulnerability in SemWifiApTimeOutImpl in framework prior to SMR Aug-2023 Release 1 allows local attackers to access ContentProvider without proper permission.

    Published: 10 Aug 2023
    7.5
    High

    CVE-2023-30699

    Last Modified: 21 Nov 2024

    Out-of-bounds write vulnerability in parser_hvcC function of libsimba library prior to SMR Aug-2023 Release 1 allows code execution by remote attackers.

    Published: 10 Aug 2023
    5.5
    Medium

    CVE-2023-30698

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in TelephonyUI prior to SMR Aug-2023 Release 1 allows local attacker to connect BLE without privilege.

    Published: 10 Aug 2023
    4.4
    Medium

    CVE-2023-30697

    Last Modified: 21 Nov 2024

    An improper input validation in IpcTxCfgSetSimlockPayload in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.

    Published: 10 Aug 2023
    4.4
    Medium

    CVE-2023-30696

    Last Modified: 21 Nov 2024

    An improper input validation in IpcTxGetVerifyAkey in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.

    Published: 10 Aug 2023
    6.7
    Medium

    CVE-2023-30695

    Last Modified: 21 Nov 2024

    Out-of-bounds Write vulnerability in SSHDCPAPP TA prior to &quot;SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023&quot; in Windows Update for Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 allows local attacker to execute arbitrary code.

    Published: 10 Aug 2023
    6.7
    Medium

    CVE-2023-30694

    Last Modified: 21 Nov 2024

    Out-of-bounds Write in IpcTxPcscTransmitApdu of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

    Published: 10 Aug 2023
    6.7
    Medium

    CVE-2023-30693

    Last Modified: 21 Nov 2024

    Out-of-bounds Write in DoOemFactorySendFactoryBypassCommand of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

    Published: 10 Aug 2023
    8.4
    High

    CVE-2023-30691

    Last Modified: 21 Nov 2024

    Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to privilege escalation.

    Published: 10 Aug 2023
    6.7
    Medium

    CVE-2023-30689

    Last Modified: 21 Nov 2024

    Out-of-bounds Write in BuildOemEmbmsGetSigStrengthResponse of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

    Published: 10 Aug 2023
    6.7
    Medium

    CVE-2023-30688

    Last Modified: 21 Nov 2024

    Out-of-bounds Write in MakeUiccAuthForOem of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

    Published: 10 Aug 2023
    6.7
    Medium

    CVE-2023-30687

    Last Modified: 21 Nov 2024

    Out-of-bounds Write in RmtUimApdu of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

    Published: 10 Aug 2023
    6.7
    Medium

    CVE-2023-30686

    Last Modified: 21 Nov 2024

    Out-of-bounds Write in ReqDataRaw of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

    Published: 10 Aug 2023
    4.3
    Medium

    CVE-2023-30685

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakcers to change TTY mode.

    Published: 10 Aug 2023
    4.3
    Medium

    CVE-2023-30684

    Last Modified: 21 Nov 2024

    Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call acceptRingingCall API without permission.

    Published: 10 Aug 2023
    4.3
    Medium

    CVE-2023-30683

    Last Modified: 21 Nov 2024

    Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without permission.

    Published: 10 Aug 2023
    4.3
    Medium

    CVE-2023-30682

    Last Modified: 21 Nov 2024

    Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API without permission.

    Published: 10 Aug 2023
    4.4
    Medium

    CVE-2023-30681

    Last Modified: 21 Nov 2024

    An improper input validation vulnerability within initialize function in HAL VaultKeeper prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.

    Published: 10 Aug 2023
    8.4
    High

    CVE-2023-30680

    Last Modified: 21 Nov 2024

    Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privilege.

    Published: 10 Aug 2023
    7.8
    High

    CVE-2023-30679

    Last Modified: 21 Nov 2024

    Improper access control in HDCP trustlet prior to SMR Aug-2023 Release 1 allows local attackers to execute arbitrary code.

    Published: 10 Aug 2023
    6.7
    Medium

    CVE-2023-30654

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in SLocationService prior to SMR Aug-2023 Release 1 allows local attacker to update fake location.

    Published: 10 Aug 2023
    6.1
    Medium

    CVE-2023-36309

    Last Modified: 21 Nov 2024

    There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Document Creator v1.0.

    Published: 10 Aug 2023
    6.1
    Medium

    CVE-2023-36310

    Last Modified: 21 Nov 2024

    There is a Cross Site Scripting (XSS) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0.

    Published: 10 Aug 2023
    9.8
    Critical

    CVE-2023-36311

    Last Modified: 21 Nov 2024

    There is a SQL injection (SQLi) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0.

    Published: 10 Aug 2023
    5.4
    Medium

    CVE-2023-36312

    Last Modified: 21 Nov 2024

    There is a Cross Site Scripting (XSS) vulnerability in the value-enum-o_bf_include_timezone parameter of index.php in PHPJabbers Callback Widget v1.0.

    Published: 10 Aug 2023
    6.1
    Medium

    CVE-2023-36313

    Last Modified: 21 Nov 2024

    PHPJabbers Document Creator v1.0 is vulnerable to Cross Site Scripting (XSS) via all post parameters of "Export Requests" aside from "request_feed".

    Published: 10 Aug 2023
    6.1
    Medium

    CVE-2023-36314

    Last Modified: 21 Nov 2024

    There is a Cross Site Scripting (XSS) vulnerability in the value-text-o_sms_email_request_message parameters of index.php in PHPJabbers Callback Widget v1.0.

    Published: 10 Aug 2023
    6.1
    Medium

    CVE-2023-36315

    Last Modified: 21 Nov 2024

    There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Callback Widget v1.0.

    Published: 10 Aug 2023
    7.8
    High

    CVE-2022-47636

    Last Modified: 21 Nov 2024

    A DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739. When a user open a .oml file (OutSystems Modeling Language), the application will load the following DLLs from the same directory av_libGLESv2.dll, libcef.DLL, user32.dll, and d3d10warp.dll. Using a crafted DLL, it is possible to execute arbitrary code in the context of the current logged in user.

    Published: 10 Aug 2023
    9.8
    Critical

    CVE-2023-37069

    Last Modified: 21 Nov 2024

    Code-Projects Online Hospital Management System V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the login id and password fields during the login process, enabling an attacker to inject malicious SQL code.

    Published: 10 Aug 2023
    5.4
    Medium

    CVE-2023-37625

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in Netbox v3.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Link templates.

    Published: 10 Aug 2023
    9.8
    Critical

    CVE-2023-37734

    Last Modified: 21 Nov 2024

    EZ softmagic MP3 Audio Converter 2.7.3.700 was discovered to contain a buffer overflow.

    Published: 10 Aug 2023
    5.5
    Medium

    CVE-2023-38210

    Last Modified: 27 Feb 2025

    Adobe XMP Toolkit versions 2022.06 is affected by a Uncontrolled Resource Consumption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Aug 2023
    6.1
    Medium

    CVE-2023-38333

    Last Modified: 7 Mar 2025

    Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.

    Published: 10 Aug 2023
    7.5
    High

    CVE-2023-38830

    Last Modified: 21 Nov 2024

    An information leak in PHPJabbers Yacht Listing Script v1.0 allows attackers to export clients' credit card numbers from the Reservations module.

    Published: 10 Aug 2023
    9.8
    Critical

    CVE-2023-39776

    Last Modified: 21 Nov 2024

    A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uploading a crafted file.

    Published: 10 Aug 2023
    9.8
    Critical

    CVE-2023-39805

    Last Modified: 21 Nov 2024

    iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.

    Published: 10 Aug 2023
    9.8
    Critical

    CVE-2023-39806

    Last Modified: 21 Nov 2024

    iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.

    Published: 10 Aug 2023
    5.5
    Medium

    CVE-2023-40216

    Last Modified: 21 Nov 2024

    OpenBSD 7.3 before errata 014 is missing an argument-count bounds check in console terminal emulation. This could cause incorrect memory access and a kernel crash after receiving crafted DCS or CSI terminal escape sequences.

    Published: 10 Aug 2023
    6.1
    Medium

    CVE-2023-40224

    Last Modified: 3 Dec 2024

    MISP 2.4.174 allows XSS in app/View/Events/index.ctp.

    Published: 10 Aug 2023
    6.5
    Medium

    CVE-2023-40235

    Last Modified: 21 Nov 2024

    An NTLM Hash Disclosure was discovered in ArchiMate Archi before 5.1.0. When parsing the XMLNS value of an ArchiMate project file, if the namespace does not match the expected ArchiMate URL, the parser will access the provided resource. If the provided resource is a UNC path pointing to a share server that does not accept a guest account, the host will try to authenticate on the share by using the current user's session. NOTE: this issue occurs because Archi uses an unsafe configuration of the Eclipse Modeling Framework.

    Published: 10 Aug 2023