5.5
    Medium

    CVE-2023-46018

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in receiverReg.php in Code-Projects Blood Bank 1.0 \allows attackers to run arbitrary SQL commands via 'remail' parameter.

    Published:13 Nov 2023
    5.5
    Medium

    CVE-2023-46017

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in receiverLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'remail' and 'rpassword' parameters.

    Published:13 Nov 2023
    6.1
    Medium

    CVE-2023-46016

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'search' parameter in the application URL.

    Published:13 Nov 2023
    6.1
    Medium

    CVE-2023-46015

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in index.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via 'msg' parameter in application URL.

    Published:13 Nov 2023
    5.5
    Medium

    CVE-2023-46014

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in hospitalLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'hemail' and 'hpassword' parameters.

    Published:13 Nov 2023
    9.8
    Critical

    CVE-2023-46012

    Last Modified: 30 Jun 2025

    Buffer Overflow vulnerability LINKSYS EA7500 3.0.1.207964 allows a remote attacker to execute arbitrary code via an HTTP request to the IGD UPnP.

    Published:7 May 2024
    5.4
    Medium

    CVE-2023-46003

    Last Modified: 21 Nov 2024

    I-doit pro 25 and below is vulnerable to Cross Site Scripting (XSS) via index.php.

    Published:21 Oct 2023
    9.6
    Critical

    CVE-2023-45992

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack, combined with a certain admin activity, could allow the attacker to gain full admin privileges on the exploited system.

    Published:19 Oct 2023
    7.5
    High

    CVE-2023-45966

    Last Modified: 21 Nov 2024

    umputun remark42 version 1.12.1 and before has a Blind Server-Side Request Forgery (SSRF) vulnerability.

    Published:23 Oct 2023
    9.8
    Critical

    CVE-2023-45878

    Last Modified: 8 Jan 2025

    GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The endpoint accepts the img, path, and gibbonPersonID parameters. The img parameter is expected to be a base64 encoded image. If the path parameter is set, the defined path is used as the destination folder, concatenated with the absolute path of the installation directory. The content of the img parameter is base64 decoded and written to the defined file path. This allows creation of PHP files that permit Remote Code Execution (unauthenticated).

    Published:14 Nov 2023
    6.3
    Medium

    CVE-2023-45866

    Last Modified: 4 Nov 2025

    Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.

    Published:7 Dec 2023
    6.5
    Medium

    CVE-2023-45857

    Last Modified: 21 Nov 2024

    An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.

    Published:8 Nov 2023
    5.4
    Medium

    CVE-2023-45828

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in RumbleTalk RumbleTalk Live Group Chat rumbletalk-chat-a-chat-with-themes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RumbleTalk Live Group Chat: from n/a through <= 6.2.5.

    Published:2 Jan 2025
    7.3
    High

    CVE-2023-45827

    Last Modified: 21 Nov 2024

    Dot diver is a lightweight, powerful, and dependency-free TypeScript utility library that provides types and functions to work with object paths in dot notation. In versions prior to 1.0.2 there is a Prototype Pollution vulnerability in the `setByPath` function which can leads to remote code execution (RCE). This issue has been addressed in commit `98daf567` which has been included in release 1.0.2. Users are advised to upgrade. There are no known workarounds to this vulnerability.

    Published:6 Nov 2023
    4.3
    Medium

    CVE-2023-45806

    Last Modified: 21 Nov 2024

    Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, if a user has been quoted and uses a `|` in their full name, they might be able to trigger a bug that generates a lot of duplicate content in all the posts they've been quoted by updating their full name again. Version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches contain a patch for this issue. No known workaround exists, although one can stop the "bleeding" by ensuring users only use alphanumeric characters in their full name field.

    Published:10 Nov 2023
    5.9
    Medium

    CVE-2023-45802

    Last Modified: 25 Aug 2025

    When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not reclaimed immediately. Instead, de-allocation was deferred to connection close. A client could send new requests and resets, keeping the connection busy and open and causing the memory footprint to keep on growing. On connection close, all resources were reclaimed, but the process might run out of memory before that. This was found by the reporter during testing of CVE-2023-44487 (HTTP/2 Rapid Reset Exploit) with their own test client. During "normal" HTTP/2 use, the probability to hit this bug is very low. The kept memory would not become noticeable before the connection closes or times out. Users are recommended to upgrade to version 2.4.58, which fixes the issue.

    Published:19 Oct 2023
    7.8
    High

    CVE-2023-45779

    Last Modified: 21 Nov 2024

    In the APEX module framework of AOSP, there is a possible malicious update to platform components due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. More details on this can be found in the referenced links.

    Published:4 Dec 2023
    7.8
    High

    CVE-2023-45777

    Last Modified: 21 Nov 2024

    In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to launch arbitrary activities using system privileges due to Parcel Mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:4 Dec 2023
    8.5
    High

    CVE-2023-45657

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in POSIMYTH Nexter allows SQL Injection.This issue affects Nexter: from n/a through 2.0.3.

    Published:6 Nov 2023
    8.6
    High

    CVE-2023-45612

    Last Modified: 21 Nov 2024

    In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE

    Published:9 Oct 2023
    6.1
    Medium

    CVE-2023-45542

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in mooSocial 3.1.8 allows a remote attacker to obtain sensitive information via a crafted script to the q parameter in the Search function.

    Published:16 Oct 2023
    6.5
    Medium

    CVE-2023-45540

    Last Modified: 21 Nov 2024

    An issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted script to the comment field of the List of Leave requests page.

    Published:16 Oct 2023
    8.2
    High

    CVE-2023-45539

    Last Modified: 21 Nov 2024

    HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unspecified other impact upon misinterpretation of a path_end rule, such as routing index.html#.png to a static server.

    Published:28 Nov 2023
    5.3
    Medium

    CVE-2023-45503

    Last Modified: 18 Apr 2025

    SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via crafted payload to resetPassword, forgotPasswordProcess, saveUser, saveRole, deleteUser, deleteRole, deleteComment, deleteUser, allowComment, saveRole, forgotPasswordProcess, resetPassword, saveUser, addComment, saveRole, and saveUser endpoints.

    Published:15 Apr 2024
    5.4
    Medium

    CVE-2023-45471

    Last Modified: 21 Nov 2024

    The QAD Search Server is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to, and including, 1.0.0.315 due to insufficient checks on indexes. This makes it possible for unauthenticated attackers to create a new index and inject a malicious web script into its name, that will execute whenever a user accesses the search page.

    Published:20 Oct 2023
    7.5
    High

    CVE-2023-45288

    Last Modified: 15 Apr 2026

    An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed MaxHeaderBytes, no memory is allocated to store the excess headers, but they are still parsed. This permits an attacker to cause an HTTP/2 endpoint to read arbitrary amounts of header data, all associated with a request which is going to be rejected. These headers can include Huffman-encoded data which is significantly more expensive for the receiver to decode than for an attacker to send. The fix sets a limit on the amount of excess header frames we will process before closing a connection.

    Published:3 Apr 2024
    9.1
    Critical

    CVE-2023-45278

    Last Modified: 21 Nov 2024

    Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafted HTTP DELETE request.

    Published:19 Oct 2023
    7.5
    High

    CVE-2023-45277

    Last Modified: 21 Nov 2024

    Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buckets, freely navigate system directories, and read arbitrary files.

    Published:19 Oct 2023
    9.8
    Critical

    CVE-2023-45239

    Last Modified: 13 Feb 2025

    A lack of input validation exists in tac_plus prior to commit 4fdf178 which, when pre or post auth commands are enabled, allows an attacker who can control the username, rem-addr, or NAC address sent to tac_plus to inject shell commands and gain remote code execution on the tac_plus server.

    Published:6 Oct 2023
    7.4
    High

    CVE-2023-45185

    Last Modified: 21 Nov 2024

    IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code. Due to improper authority checks the attacker could perform operations on the PC under the user's authority. IBM X-Force ID: 268273.

    Published:14 Dec 2023
    6.2
    Medium

    CVE-2023-45184

    Last Modified: 21 Nov 2024

    IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to obtain a decryption key due to improper authority checks. IBM X-Force ID: 268270.

    Published:14 Dec 2023
    7.4
    High

    CVE-2023-45182

    Last Modified: 21 Nov 2024

    IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is vulnerable to having its key for an encrypted password decoded. By somehow gaining access to the encrypted password, a local attacker could exploit this vulnerability to obtain the password to other systems. IBM X-Force ID: 268265.

    Published:14 Dec 2023
    9.8
    Critical

    CVE-2023-45158

    Last Modified: 21 Nov 2024

    An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifySendHandler for logging (not the default configuration), a crafted web request may execute an arbitrary OS command on the web server using the product.

    Published:16 Oct 2023
    7.5
    High

    CVE-2023-45131

    Last Modified: 22 Jul 2025

    Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticated POST request to MessageBus. This issue is patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Source:İbrahimsql
    Published:16 Oct 2023
    3.2
    Low

    CVE-2023-44976

    Last Modified: 15 Apr 2026

    Hangzhou Shunwang Rentdrv2 before 2024-12-24 allows local users to terminate EDR processes and possibly have unspecified other impact via DeviceIoControl with control code 0x22E010, as exploited in the wild in October 2023.

    Published:1 Aug 2025
    5.3
    Medium

    CVE-2023-44962

    Last Modified: 21 Nov 2024

    File Upload vulnerability in Koha Library Software 23.05.04 and before allows a remote attacker to read arbitrary files via the upload-cover-image.pl component.

    Published:11 Oct 2023
    6.1
    Medium

    CVE-2023-44813

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a crafted payload to the mode parameter of the invite friend login function.

    Published:9 Oct 2023
    6.1
    Medium

    CVE-2023-44812

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a crafted payload to the admin_redirect_url parameter of the user login function.

    Published:9 Oct 2023
    8.8
    High

    CVE-2023-44811

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) vulnerability in MooSocial v.3.1.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the admin Password Change Function.

    Published:9 Oct 2023
    5.4
    Medium

    CVE-2023-44771

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Page Layout.

    Published:6 Oct 2023
    5.4
    Medium

    CVE-2023-44770

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows an attacker to execute arbitrary code via a crafted script to the Organizer - Spare alias.

    Published:6 Oct 2023
    5.4
    Medium

    CVE-2023-44769

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Spare aliases from Alias.

    Published:24 Oct 2023
    4.8
    Medium

    CVE-2023-44767

    Last Modified: 21 Nov 2024

    A File upload vulnerability in RiteCMS 3.0 allows a local attacker to upload a SVG file with XSS content.

    Published:24 Oct 2023
    4.8
    Medium

    CVE-2023-44766

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a crafted script to the SEO - Extra from Page Settings. NOTE: the vendor disputes this because this SEO-related header change can only be made by an admin, and allowing an admin to place JavaScript there is an intentional customization feature.

    Published:6 Oct 2023
    5.4
    Medium

    CVE-2023-44765

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability in Concrete CMS versions 8.5.12 and below, and 9.0 through 9.2.1 allows an attacker to execute arbitrary code via a crafted script to Plural Handle of the Data Objects from System & Settings.

    Published:6 Oct 2023
    5.4
    Medium

    CVE-2023-44764

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability in Concrete CMS before 9.2.3 exists via the Name parameter during installation (aka Site of Installation or Settings).

    Published:6 Oct 2023
    5.4
    Medium

    CVE-2023-44763

    Last Modified: 21 Nov 2024

    Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting (XSS). NOTE: the vendor's position is that a customer is supposed to know that "pdf" should be excluded from the allowed file types, even though pdf is one of the allowed file types in the default configuration.

    Published:10 Oct 2023
    5.4
    Medium

    CVE-2023-44762

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability in Concrete CMS from versions 9.2.0 to 9.2.2 allows an attacker to execute arbitrary code via a crafted script to the Tags from Settings - Tags.

    Published:6 Oct 2023
    5.4
    Medium

    CVE-2023-44761

    Last Modified: 21 Nov 2024

    Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS versions affected to 8.5.13 and below, and 9.0.0 through 9.2.1 allow a local attacker to execute arbitrary code via a crafted script to the Forms of the Data objects.

    Published:6 Oct 2023
    4.8
    Medium

    CVE-2023-44760

    Last Modified: 21 Nov 2024

    Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS v.9.2.1 allow an attacker to execute arbitrary code via a crafted script to the Header and Footer Tracking Codes of the SEO & Statistics. NOTE: the vendor disputes this because these header/footer changes can only be made by an admin, and allowing an admin to place JavaScript there is an intentional customization feature. Also, the exploitation method claimed by "sromanhu" does not provide any access to a Concrete CMS session, because the Concrete CMS session cookie is configured as HttpOnly.

    Published:23 Oct 2023