7.5
    High

    CVE-2023-47355

    Last Modified: 20 Jun 2025

    The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers for PowerOff, Reboot, and Recovery (e.g., com.eypcnnapps.quickreboot.widget.PowerOff) that are susceptible to unauthorized broadcasts because of missing input validation.

    Published:5 Feb 2024
    5.3
    Medium

    CVE-2023-47268

    Last Modified: 11 May 2026

    In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrary code on a host where the project is sliced and G-code exported.

    Published:8 May 2026
    9.8
    Critical

    CVE-2023-47253

    Last Modified: 7 Jul 2025

    Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValoresPopHidden parameter.

    Published:6 Nov 2023
    9.8
    Critical

    CVE-2023-47248

    Last Modified: 13 Feb 2025

    Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (for example user-supplied input files). This vulnerability only affects PyArrow, not other Apache Arrow implementations or bindings. It is recommended that users of PyArrow upgrade to 14.0.1. Similarly, it is recommended that downstream libraries upgrade their dependency requirements to PyArrow 14.0.1 or later. PyPI packages are already available, and we hope that conda-forge packages will be available soon. If it is not possible to upgrade, we provide a separate package `pyarrow-hotfix` that disables the vulnerability on older PyArrow versions. See https://pypi.org/project/pyarrow-hotfix/ for instructions.

    Published:9 Nov 2023
    9.8
    Critical

    CVE-2023-47246

    Last Modified: 31 Oct 2025

    In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

    Published:10 Nov 2023
    5.8
    Medium

    CVE-2023-47218

    Last Modified: 10 Dec 2025

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.5.2645 build 20240116 and later QuTS hero h5.1.5.2647 build 20240118 and later QuTScloud c5.1.5.2651 and later

    Published:13 Feb 2024
    8.8
    High

    CVE-2023-47179

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in mdalabar WooODT Lite byconsole-woo-order-delivery-time allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooODT Lite: from n/a through <= 2.4.6.

    Published:2 Jan 2025
    8.4
    High

    CVE-2023-47129

    Last Modified: 21 Nov 2024

    Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded. This only affects forms using the "Forms" feature and not just _any_ arbitrary form. This does not affect the control panel. This issue has been patched in 3.4.13 and 4.33.0.

    Published:10 Nov 2023
    4.7
    Medium

    CVE-2023-47125

    Last Modified: 21 Nov 2024

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions DOM processing instructions are not handled correctly. This allows bypassing the cross-site scripting mechanism of typo3/html-sanitizer. This vulnerability has been addressed in versions 1.5.3 and 2.1.4. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published:14 Nov 2023
    5.3
    Medium

    CVE-2023-47119

    Last Modified: 21 Nov 2024

    Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, some links can inject arbitrary HTML tags when rendered through our Onebox engine. The issue is patched in version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches. There are no known workarounds.

    Published:10 Nov 2023
    7.5
    High

    CVE-2023-47108

    Last Modified: 28 Oct 2025

    OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. Starting in version 0.37.0 and prior to version 0.46.0, the grpc Unary Server Interceptor out of the box adds labels `net.peer.sock.addr` and `net.peer.sock.port` that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent. An attacker can easily flood the peer address and port for requests. Version 0.46.0 contains a fix for this issue. As a workaround to stop being affected, a view removing the attributes can be used. The other possibility is to disable grpc metrics instrumentation by passing `otelgrpc.WithMeterProvider` option with `noop.NewMeterProvider`.

    Published:10 Nov 2023
    5.3
    Medium

    CVE-2023-47102

    Last Modified: 29 Sept 2025

    UrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a username is not valid.

    Published:7 Nov 2023
    6.5
    Medium

    CVE-2023-47014

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) vulnerability in Sourcecodester Sticky Notes App Using PHP with Source Code v.1.0 allows a local attacker to obtain sensitive information via a crafted payload to add-note.php.

    Published:22 Nov 2023
    6.1
    Medium

    CVE-2023-46998

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in BootBox Bootbox.js v.3.2 through 6.0 allows a remote attacker to execute arbitrary code via a crafted payload to alert(), confirm(), prompt() functions.

    Published:7 Nov 2023
    6.7
    Medium

    CVE-2023-46988

    Last Modified: 1 Oct 2025

    Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating the fileExt parameter in the /example/editor endpoint, leading to unauthorized access to sensitive files and potential Denial of Service (DoS).

    Published:1 Apr 2025
    9.8
    Critical

    CVE-2023-46980

    Last Modified: 21 Nov 2024

    An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the userID parameter.

    Published:3 Nov 2023
    5.4
    Medium

    CVE-2023-46974

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in Best Courier Management System v.1.000 allows a remote attacker to execute arbitrary code via a crafted payload to the page parameter in the URL.

    Published:7 Dec 2023
    9.8
    Critical

    CVE-2023-46954

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in Relativity ODA LLC RelativityOne v.12.1.537.3 Patch 2 and earlier allows a remote attacker to execute arbitrary code via the name parameter.

    Published:3 Nov 2023
    5.4
    Medium

    CVE-2023-46948

    Last Modified: 15 Apr 2026

    A reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attacker to execute arbitrary JavaScript code via the skin parameter in the about.jsp and genrequest.jsp components.

    Published:23 Sept 2024
    7.3
    High

    CVE-2023-46870

    Last Modified: 15 Apr 2026

    extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Bluetooth LE 3.0.0, 3.1.0, 4.0.0, 4.1.0, and 4.1.1 have set incorrect file permission, which allows attackers to do code execution via modified bash and python scripts.

    Published:13 May 2024
    7.2
    High

    CVE-2023-46865

    Last Modified: 21 Nov 2024

    /api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image.

    Published:30 Oct 2023
    7.2
    High

    CVE-2023-46818

    Last Modified: 21 Nov 2024

    An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled.

    Published:27 Oct 2023
    7
    High

    CVE-2023-46813

    Last Modified: 25 Feb 2026

    An issue was discovered in the Linux kernel before 6.5.9, exploitable by local users with userspace access to MMIO registers. Incorrect access checking in the #VC handler and instruction emulation of the SEV-ES emulation of MMIO accesses could lead to arbitrary write access to kernel memory (and thus privilege escalation). This depends on a race condition through which userspace can replace an instruction before the #VC handler reads it.

    Published:27 Oct 2023
    8.2
    High

    CVE-2023-46805

    Last Modified: 31 Oct 2025

    An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

    Published:12 Jan 2024
    6.5
    Medium

    CVE-2023-46749

    Last Modified: 3 Nov 2025

    Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+, or ensure `blockSemicolon` is enabled (this is the default).

    Published:12 Jan 2024
    9.8
    Critical

    CVE-2023-46747

    Last Modified: 27 Oct 2025

    Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Published:26 Oct 2023
    8.1
    High

    CVE-2023-46694

    Last Modified: 15 Apr 2026

    Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, potentially enabling them to execute remote commands. This flaw exists due to the application's failure to enforce proper authentication controls when accessing the Ckeditor file manager functionality.

    Published:28 May 2024
    5.4
    Medium

    CVE-2023-46615

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in Kalli Dan. KD Coming Soon.This issue affects KD Coming Soon: from n/a through 1.7.

    Published:12 Feb 2024
    10
    Critical

    CVE-2023-46604

    Last Modified: 4 Nov 2025

    The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.

    Published:27 Oct 2023
    9.1
    Critical

    CVE-2023-46501

    Last Modified: 21 Nov 2024

    An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin password function.

    Published:7 Nov 2023
    8.8
    High

    CVE-2023-46478

    Last Modified: 21 Nov 2024

    An issue in minCal v.1.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the customer_data parameter.

    Published:30 Oct 2023
    7.2
    High

    CVE-2023-46474

    Last Modified: 3 Jun 2025

    File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted PHP file uploaded to the start_import.php file.

    Published:11 Jan 2024
    9.8
    Critical

    CVE-2023-46454

    Last Modified: 21 Nov 2024

    In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package information functionality.

    Published:12 Dec 2023
    5.4
    Medium

    CVE-2023-46451

    Last Modified: 21 Nov 2024

    Best Courier Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the change username field.

    Published:31 Oct 2023
    5.4
    Medium

    CVE-2023-46450

    Last Modified: 21 Nov 2024

    Sourcecodester Free and Open Source inventory management system 1.0 is vulnerable to Cross Site Scripting (XSS) via the Add supplier function.

    Published:26 Oct 2023
    8.8
    High

    CVE-2023-46449

    Last Modified: 21 Nov 2024

    Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function.

    Published:26 Oct 2023
    4.3
    Medium

    CVE-2023-46447

    Last Modified: 20 Jun 2025

    The POPS! Rebel application 5.0 for Android, in POPS! Rebel Bluetooth Glucose Monitoring System, sends unencrypted glucose measurements over BLE.

    Published:20 Jan 2024
    4.3
    Medium

    CVE-2023-46442

    Last Modified: 15 Apr 2026

    An infinite loop in the retrieveActiveBody function of Soot before v4.4.1 under Java 8 allows attackers to cause a Denial of Service (DoS).

    Published:24 May 2024
    9.9
    Critical

    CVE-2023-46404

    Last Modified: 21 Nov 2024

    PCRS <= 3.11 (d0de1e) “Questions” page and “Code editor” page are vulnerable to remote code execution (RCE) by escaping Python sandboxing.

    Published:3 Nov 2023
    9.8
    Critical

    CVE-2023-46371

    Last Modified: 21 Nov 2024

    TP-Link device TL-WDR7660 2.0.30 and TL-WR886N 2.0.12 has a stack overflow vulnerability via the function upgradeInfoJsonToBin.

    Published:24 Oct 2023
    5.4
    Medium

    CVE-2023-46344

    Last Modified: 7 May 2025

    A vulnerability in Solar-Log Base 15 Firmware 6.0.1 Build 161, and possibly other Solar-Log Base products, allows an attacker to escalate their privileges by exploiting a stored cross-site scripting (XSS) vulnerability in the switch group function under /#ilang=DE&b=c_smartenergy_swgroups in the web portal. The vulnerability can be exploited to gain the rights of an installer or PM, which can then be used to gain administrative access to the web portal and execute further attacks. NOTE: The vendor states that this vulnerability has been fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL Base.

    Published:2 Feb 2024
    8.1
    High

    CVE-2023-46304

    Last Modified: 22 Apr 2025

    modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).

    Published:30 Apr 2024
    8.8
    High

    CVE-2023-46229

    Last Modified: 21 Nov 2024

    LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.

    Published:19 Oct 2023
    5.3
    Medium

    CVE-2023-46197

    Last Modified: 28 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path Traversal.This issue affects Popup by Supsystic: from n/a through 1.10.19.

    Published:17 May 2024
    8
    High

    CVE-2023-46136

    Last Modified: 20 May 2026

    Werkzeug is a comprehensive WSGI web application library. In versions on the 3.x branch prior to 3.0.1 and on the 2.x branch prior to 2.3.8, if an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are appended chunk by chunk into internal bytearray and lookup for boundary is performed on growing buffer. This allows an attacker to cause a denial of service by sending crafted multipart data to an endpoint that will parse it. The amount of CPU time required can block worker processes from handling legitimate requests. This vulnerability has been patched in version 3.0.1 and 2.3.8.

    Published:24 Oct 2023
    7.5
    High

    CVE-2023-46024

    Last Modified: 20 Mar 2024

    SQL Injection vulnerability in index.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to run arbitrary SQL commands and obtain sensitive information via the 'searchdata' parameter.

    Source:Ersin Erenler
    Published:14 Nov 2023
    7.8
    High

    CVE-2023-46022

    Last Modified: 20 Mar 2024

    SQL Injection vulnerability in delete.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via the 'bid' parameter.

    Source:Ersin Erenler
    Published:14 Nov 2023
    5.5
    Medium

    CVE-2023-46021

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in cancel.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary commands via the 'reqid' parameter.

    Published:13 Nov 2023
    6.1
    Medium

    CVE-2023-46020

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in updateprofile.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'rename', 'remail', 'rphone' and 'rcity' parameters.

    Published:13 Nov 2023
    6.1
    Medium

    CVE-2023-46019

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'error' parameter.

    Published:13 Nov 2023