9.8
    Critical

    CVE-2023-41507

    Last Modified: 21 Nov 2024

    Super Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component via the products, distance, lat, and lng parameters.

    Published:5 Sept 2023
    6.5
    Medium

    CVE-2023-41474

    Last Modified: 12 Jun 2025

    Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component.

    Published:25 Jan 2024
    5.4
    Medium

    CVE-2023-41436

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in CSZCMS v.1.3.0 allows a local attacker to execute arbitrary code via a crafted script to the Additional Meta Tag parameter in the Pages Content Menu component.

    Published:15 Sept 2023
    6.1
    Medium

    CVE-2023-41425

    Last Modified: 22 Apr 2025

    Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.

    Source:Milad karimi
    Published:7 Nov 2023
    7.2
    High

    CVE-2023-41362

    Last Modified: 21 Nov 2024

    MyBB before 1.8.36 allows Code Injection by users with certain high privileges. Templates in Admin CP intentionally use eval, and there was some validation of the input to eval, but type juggling interfered with this when using PCRE within PHP.

    Published:29 Aug 2023
    9.6
    Critical

    CVE-2023-41265

    Last Modified: 31 Oct 2025

    An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their privilege by tunneling HTTP requests in the raw HTTP request. This allows them to send requests that get executed by the backend server hosting the repository application. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.

    Published:29 Aug 2023
    6.1
    Medium

    CVE-2023-41080

    Last Modified: 29 Oct 2025

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, EOL versions may also be affected. The vulnerability is limited to the ROOT (default) web application.

    Published:25 Aug 2023
    7.8
    High

    CVE-2023-41064

    Last Modified: 6 Nov 2025

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9 and iPadOS 15.7.9, macOS Big Sur 11.7.10. Processing a maliciously crafted image may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

    Published:7 Sept 2023
    3.3
    Low

    CVE-2023-41044

    Last Modified: 21 Nov 2024

    Graylog is a free and open log management platform. A partial path traversal vulnerability exists in Graylog's `Support Bundle` feature. The vulnerability is caused by incorrect user input validation in an HTTP API resource. Graylog's Support Bundle feature allows an attacker with valid Admin role credentials to download or delete files in sibling directories of the support bundle directory. The default `data_dir` in operating system packages (DEB, RPM) is set to `/var/lib/graylog-server`. The data directory for the Support Bundle feature is always `<data_dir>/support-bundle`. Due to the partial path traversal vulnerability, an attacker with valid Admin role credentials can read or delete files in directories that start with a `/var/lib/graylog-server/support-bundle` directory name. The vulnerability would allow the download or deletion of files in the following example directories: `/var/lib/graylog-server/support-bundle-test` and `/var/lib/graylog-server/support-bundlesdirectory`. For the Graylog Docker images, the `data_dir` is set to `/usr/share/graylog/data` by default. This vulnerability is fixed in Graylog version 5.1.3 and later. Users are advised to upgrade. Users unable to upgrade should block all HTTP requests to the following HTTP API endpoints by using a reverse proxy server in front of Graylog. `GET /api/system/debug/support/bundle/download/{filename}` and `DELETE /api/system/debug/support/bundle/{filename}`.

    Published:31 Aug 2023
    9.8
    Critical

    CVE-2023-40989

    Last Modified: 21 Nov 2024

    SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component.

    Published:22 Sept 2023
    8.8
    High

    CVE-2023-40933

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function.

    Published:19 Sept 2023
    6.5
    Medium

    CVE-2023-40931

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php

    Published:19 Sept 2023
    6.8
    Medium

    CVE-2023-40930

    Last Modified: 21 Nov 2024

    An issue in the directory /system/bin/blkid of Skyworth v3.0 allows attackers to perform a directory traversal via mounting the Udisk to /mnt/.

    Published:20 Sept 2023
    7.5
    High

    CVE-2023-40924

    Last Modified: 21 Nov 2024

    SolarView Compact < 6.00 is vulnerable to Directory Traversal.

    Published:8 Sept 2023
    6.1
    Medium

    CVE-2023-40869

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in mooSocial mooSocial Software 3.1.6 and 3.1.7 allows a remote attacker to execute arbitrary code via a crafted script to the edit_menu, copuon, and group_categorias functions.

    Published:14 Sept 2023
    8.8
    High

    CVE-2023-40868

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery vulnerability in mooSocial MooSocial Software v.Demo allows a remote attacker to execute arbitrary code via the Delete Account and Deactivate functions.

    Published:14 Sept 2023
    7.5
    High

    CVE-2023-40626

    Last Modified: 4 Dec 2024

    The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information.

    Published:29 Nov 2023
    5.3
    Medium

    CVE-2023-40600

    Last Modified: 29 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exactly WWW EWWW Image Optimizer. It works only when debug.log is turned on.This issue affects EWWW Image Optimizer: from n/a through 7.2.0.

    Published:30 Nov 2023
    7.8
    High

    CVE-2023-40477

    Last Modified: 4 Nov 2025

    RARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of recovery volumes. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-21233.

    Published:3 May 2024
    7.5
    High

    CVE-2023-40459

    Last Modified: 29 May 2025

    The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable.

    Published:4 Dec 2023
    8.6
    High

    CVE-2023-40448

    Last Modified: 4 Nov 2025

    The issue was addressed with improved handling of protocols. This issue is fixed in tvOS 17, iOS 16.7 and iPadOS 16.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. A remote attacker may be able to break out of Web Content sandbox.

    Published:26 Sept 2023
    5.5
    Medium

    CVE-2023-40429

    Last Modified: 4 Nov 2025

    A permissions issue was addressed with improved validation. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An app may be able to access sensitive user data.

    Published:26 Sept 2023
    7.8
    High

    CVE-2023-40404

    Last Modified: 13 Feb 2025

    A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sonoma 14.1. An app may be able to execute arbitrary code with kernel privileges.

    Published:25 Oct 2023
    4.3
    Medium

    CVE-2023-40362

    Last Modified: 20 Jun 2025

    An issue was discovered in CentralSquare Click2Gov Building Permit before October 2023. Lack of access control protections allows remote attackers to arbitrarily delete the contractors from any user's account when the user ID and contractor information is known.

    Published:12 Jan 2024
    7.8
    High

    CVE-2023-40361

    Last Modified: 21 Nov 2024

    SECUDOS Qiata (DOMOS OS) 4.13 has Insecure Permissions for the previewRm.sh daily cronjob. To exploit this, an attacker needs access as a low-privileged user to the underlying DOMOS system. Every user on the system has write permission for previewRm.sh, which is executed by the root user.

    Published:20 Oct 2023
    5.4
    Medium

    CVE-2023-40355

    Last Modified: 17 Jun 2025

    Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authenticated attackers to execute arbitrary code and obtain sensitive information via the logic for switching between the Standard and Ajax versions.

    Published:7 Feb 2024
    7.5
    High

    CVE-2023-40297

    Last Modified: 15 Apr 2026

    Stakater Forecastle 1.0.139 and before allows %5C../ directory traversal in the website component.

    Published:15 May 2024
    7.5
    High

    CVE-2023-40296

    Last Modified: 21 Nov 2024

    async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in ReceiveFrom and Receive in udpsocket.hpp when processing malformed UDP packets.

    Published:14 Aug 2023
    6.5
    Medium

    CVE-2023-40294

    Last Modified: 21 Nov 2024

    libboron in Boron 2.0.8 has a heap-based buffer overflow in ur_parseBlockI at i_parse_blk.c.

    Published:14 Aug 2023
    7.2
    High

    CVE-2023-40289

    Last Modified: 18 Jun 2025

    A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevate privileges from a user with BMC administrative privileges.

    Published:27 Mar 2024
    7.5
    High

    CVE-2023-40279

    Last Modified: 15 Apr 2024

    An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to main.do.

    Source:VB
    Published:19 Mar 2024
    7.5
    High

    CVE-2023-40278

    Last Modified: 15 Apr 2024

    An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp component of OpenClinic GA. By changing the AppointmentUid parameter, an attacker can determine whether a specific appointment exists based on the error message.

    Source:VB
    Published:19 Mar 2024
    5.3
    Medium

    CVE-2023-40167

    Last Modified: 13 Feb 2025

    Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accepts the `+` character proceeding the content-length value in a HTTP/1 header field. This is more permissive than allowed by the RFC and other servers routinely reject such requests with 400 responses. There is no known exploit scenario, but it is conceivable that request smuggling could result if jetty is used in combination with a server that does not close the connection after sending such a 400 response. Versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1 contain a patch for this issue. There is no workaround as there is no known exploit scenario.

    Published:15 Sept 2023
    5.5
    Medium

    CVE-2023-40133

    Last Modified: 21 Nov 2024

    In multiple locations of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:27 Oct 2023
    7.8
    High

    CVE-2023-40130

    Last Modified: 17 Dec 2025

    In notifyTimeout of CallRedirectionProcessor, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege and background activity launch with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:27 Oct 2023
    3.3
    Low

    CVE-2023-40127

    Last Modified: 21 Nov 2024

    In multiple locations, there is a possible way to access screenshots due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:27 Oct 2023
    7.8
    High

    CVE-2023-40109

    Last Modified: 16 Dec 2024

    In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published:15 Feb 2024
    7.8
    High

    CVE-2023-40084

    Last Modified: 21 Nov 2024

    In run of MDnsSdListener.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:4 Dec 2023
    10
    Critical

    CVE-2023-40044

    Last Modified: 31 Oct 2025

    In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.

    Published:27 Sept 2023
    6.5
    Medium

    CVE-2023-40037

    Last Modified: 13 Feb 2025

    Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and authorized user can bypass connection URL validation using custom input formatting. The resolution enhances connection URL validation and introduces validation for additional related properties. Upgrading to Apache NiFi 1.23.1 is the recommended mitigation.

    Published:18 Aug 2023
    7.8
    High

    CVE-2023-40031

    Last Modified: 21 Nov 2024

    Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer write overflow in `Utf8_16_Read::convert`. This issue may lead to arbitrary code execution. As of time of publication, no known patches are available in existing versions of Notepad++.

    Published:25 Aug 2023
    9.9
    Critical

    CVE-2023-40029

    Last Modified: 21 Nov 2024

    Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively using Argo CD / kubectl apply. As a result, the full secret body is stored in`kubectl.kubernetes.io/last-applied-configuration` annotation. pull request #7139 introduced the ability to manage cluster labels and annotations. Since clusters are stored as secrets it also exposes the `kubectl.kubernetes.io/last-applied-configuration` annotation which includes full secret body. In order to view the cluster annotations via the Argo CD API, the user must have `clusters, get` RBAC access. **Note:** In many cases, cluster secrets do not contain any actually-secret information. But sometimes, as in bearer-token auth, the contents might be very sensitive. The bug has been patched in versions 2.8.3, 2.7.14, and 2.6.15. Users are advised to upgrade. Users unable to upgrade should update/deploy cluster secret with `server-side-apply` flag which does not use or rely on `kubectl.kubernetes.io/last-applied-configuration` annotation. Note: annotation for existing secrets will require manual removal.

    Published:5 Sept 2023
    4.9
    Medium

    CVE-2023-40028

    Last Modified: 11 Aug 2025

    Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload files that are symlinks. This can be exploited to perform an arbitrary file read of any file on the host operating system. Site administrators can check for exploitation of this issue by looking for unknown symlinks within Ghost's `content/` folder. Version 5.59.1 contains a fix for this issue. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Source:İbrahimsql
    Published:15 Aug 2023
    8.3
    High

    CVE-2023-40000

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7.

    Published:16 Apr 2024
    7.5
    High

    CVE-2023-39910

    Last Modified: 21 Nov 2024

    The cryptocurrency wallet entropy seeding mechanism used in Libbitcoin Explorer 3.0.0 through 3.6.0 is weak, aka the Milk Sad issue. The use of an mt19937 Mersenne Twister PRNG restricts the internal entropy to 32 bits regardless of settings. This allows remote attackers to recover any wallet private keys generated from "bx seed" entropy output and steal funds. (Affected users need to move funds to a secure new cryptocurrency wallet.) NOTE: the vendor's position is that there was sufficient documentation advising against "bx seed" but others disagree. NOTE: this was exploited in the wild in June and July 2023.

    Published:9 Aug 2023
    Unknown

    CVE-2023-39725

    https://github.com/anky-123/CVE-2023-39725

    6.1
    Medium

    CVE-2023-39714

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Member section.

    Published:1 Sept 2023
    6.1
    Medium

    CVE-2023-39712

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Put section.

    Published:8 Sept 2023
    6.1
    Medium

    CVE-2023-39711

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Subtotal and Paidbill parameters under the Add New Put section.

    Published:7 Sept 2023
    6.1
    Medium

    CVE-2023-39710

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Customer section.

    Published:1 Sept 2023