6.1
    Medium

    CVE-2023-39709

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Member section.

    Published:28 Aug 2023
    6.1
    Medium

    CVE-2023-39708

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Add New parameter under the New Buy section.

    Published:28 Aug 2023
    5.4
    Medium

    CVE-2023-39707

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Add Expense parameter under the Expense section.

    Published:25 Aug 2023
    5.6
    Medium

    CVE-2023-39593

    Last Modified: 10 Jul 2025

    Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

    Published:17 Oct 2024
    7.5
    High

    CVE-2023-39539

    Last Modified: 16 Dec 2025

    AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability. 

    Published:6 Dec 2023
    9.1
    Critical

    CVE-2023-39526

    Last Modified: 21 Nov 2024

    PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to remote code execution through SQL injection and arbitrary file write in the back office. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known workarounds.

    Published:7 Aug 2023
    7.2
    High

    CVE-2023-39362

    Last Modified: 9 Oct 2023

    Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, under certain conditions, an authenticated privileged user, can use a malicious string in the SNMP options of a Device, performing command injection and obtaining remote code execution on the underlying server. The `lib/snmp.php` file has a set of functions, with similar behavior, that accept in input some variables and place them into an `exec` call without a proper escape or validation. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Source:Antonio Francesco Sardella
    Published:5 Sept 2023
    9.8
    Critical

    CVE-2023-39361

    Last Modified: 13 Feb 2025

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an enabled state, there could be the potential for significant damage. Attackers may exploit this vulnerability, and there may be possibilities for actions such as the usurpation of administrative privileges or remote code execution. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published:5 Sept 2023
    7.5
    High

    CVE-2023-39325

    Last Modified: 13 Feb 2025

    A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing. With the fix applied, HTTP/2 servers now bound the number of simultaneously executing handler goroutines to the stream concurrency limit (MaxConcurrentStreams). New requests arriving when at the limit (which can only happen after the client has reset an existing, in-flight request) will be queued until a handler exits. If the request queue grows too large, the server will terminate the connection. This issue is also fixed in golang.org/x/net/http2 for users manually configuring HTTP/2. The default stream concurrency limit is 250 streams (requests) per HTTP/2 connection. This value may be adjusted using the golang.org/x/net/http2 package; see the Server.MaxConcurrentStreams setting and the ConfigureServer function.

    Published:10 Oct 2023
    9.8
    Critical

    CVE-2023-39320

    Last Modified: 13 Feb 2025

    The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as well as modules downloaded directly using VCS software.

    Published:6 Sept 2023
    7.8
    High

    CVE-2023-39147

    Last Modified: 2 Aug 2023

    An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.

    Source:Daniel Barros
    Published:1 Aug 2023
    7.5
    High

    CVE-2023-39144

    Last Modified: 21 Nov 2024

    Element55 KnowMore appliances version 21 and older was discovered to store passwords in plaintext.

    Published:3 Aug 2023
    9.8
    Critical

    CVE-2023-39143

    Last Modified: 5 May 2025

    PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).

    Published:4 Aug 2023
    7.5
    High

    CVE-2023-39141

    Last Modified: 21 Nov 2024

    webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.

    Published:22 Aug 2023
    9.8
    Critical

    CVE-2023-39115

    Last Modified: 4 Aug 2023

    install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document.

    Source:Rajdip Dey Sarkar
    Published:16 Aug 2023
    7.8
    High

    CVE-2023-39063

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in RaidenFTPD 2.4.4005 allows a local attacker to execute arbitrary code via the Server name field of the Step by step setup wizard.

    Published:11 Sept 2023
    6.1
    Medium

    CVE-2023-39062

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in Spipu HTML2PDF before v.5.2.8 allows a remote attacker to execute arbitrary code via a crafted script to the forms.php.

    Published:28 Aug 2023
    7.5
    High

    CVE-2023-39026

    Last Modified: 4 Sept 2023

    Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component.

    Source:Bryce Raindayzz Harty
    Published:22 Aug 2023
    Unknown

    CVE-2023-39024

    https://github.com/BenTheCyberOne/CVE-2023-39024-5-POC

    8.8
    High

    CVE-2023-38891

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php.

    Published:14 Sept 2023
    8.8
    High

    CVE-2023-38890

    Last Modified: 8 Dec 2025

    Online Shopping Portal Project 3.1 allows remote attackers to execute arbitrary SQL commands/queries via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username field, enabling SQL Injection attacks.

    Published:18 Aug 2023
    6.5
    Medium

    CVE-2023-38873

    Last Modified: 21 Nov 2024

    The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer is vulnerable to Clickjacking. Clickjacking, also known as a "UI redress attack", is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they were intending to click on the top-level page. Thus, the attacker is "hijacking" clicks meant for their page and routing them to another page, most likely owned by another application, domain, or both.

    Published:28 Sept 2023
    5.5
    Medium

    CVE-2023-38840

    Last Modified: 21 Nov 2024

    Bitwarden Desktop 2023.7.0 and below allows an attacker with local access to obtain sensitive information via the Bitwarden.exe process.

    Published:15 Aug 2023
    8.8
    High

    CVE-2023-38836

    Last Modified: 9 Oct 2023

    File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks.

    Source:1337kid
    Published:21 Aug 2023
    7.8
    High

    CVE-2023-38831

    Last Modified: 31 Oct 2025

    RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023.

    Published:23 Aug 2023
    8.8
    High

    CVE-2023-38829

    Last Modified: 21 Nov 2024

    An issue in NETIS SYSTEMS WF2409E v.3.6.42541 allows a remote attacker to execute arbitrary code via the ping and traceroute functions of the diagnostic tools component in the admin management interface.

    Published:11 Sept 2023
    Unknown

    CVE-2023-38822

    https://github.com/TraiLeR2/Corsair---DLL-Planting-CVE-2023-38822

    Unknown

    CVE-2023-38821

    https://github.com/TraiLeR2/CoD-MW-Warzone-2---CVE-2023-38821

    Unknown

    CVE-2023-38820

    https://github.com/TraiLeR2/DLL-Planting-Slack-4.33.73-CVE-2023-38820

    7.8
    High

    CVE-2023-38817

    Last Modified: 21 Nov 2024

    An issue in Inspect Element Ltd Echo.ac v.5.2.1.0 allows a local attacker to gain privileges via a crafted command to the echo_driver.sys component. NOTE: the vendor's position is that the reported ability for user-mode applications to execute code as NT AUTHORITY\SYSTEM was "deactivated by Microsoft itself."

    Published:11 Oct 2023
    7.2
    High

    CVE-2023-38743

    Last Modified: 5 May 2025

    Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine.

    Published:11 Sept 2023
    7.3
    High

    CVE-2023-38709

    Last Modified: 4 Nov 2025

    Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.

    Published:4 Apr 2024
    9.8
    Critical

    CVE-2023-38646

    Last Modified: 21 Nov 2024

    Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

    Published:21 Jul 2023
    9.8
    Critical

    CVE-2023-38632

    Last Modified: 21 Nov 2024

    async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in tcpsocket.hpp when processing malformed TCP packets.

    Published:21 Jul 2023
    7.5
    High

    CVE-2023-38609

    Last Modified: 13 Feb 2025

    An injection issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.5. An app may be able to bypass certain Privacy preferences.

    Published:28 Jul 2023
    8.8
    High

    CVE-2023-38600

    Last Modified: 5 May 2025

    The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Ventura 13.5, Safari 16.6, watchOS 9.6. Processing web content may lead to arbitrary code execution.

    Published:27 Jul 2023
    7.5
    High

    CVE-2023-38571

    Last Modified: 13 Feb 2025

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Big Sur 11.7.9, macOS Monterey 12.6.8, macOS Ventura 13.5. An app may be able to bypass Privacy preferences.

    Published:28 Jul 2023
    8.8
    High

    CVE-2023-38545

    Last Modified: 12 May 2026

    This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255 bytes. If the host name is detected to be longer, curl switches to local name resolving and instead passes on the resolved address only. Due to this bug, the local variable that means "let the host resolve the name" could get the wrong value during a slow SOCKS5 handshake, and contrary to the intention, copy the too long host name to the target buffer instead of copying just the resolved address there. The target buffer being a heap based buffer, and the host name coming from the URL that curl has been told to operate with.

    Published:11 Oct 2023
    6.3
    Medium

    CVE-2023-38501

    Last Modified: 28 Jul 2023

    copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k304=...` and `?setck=...`. The worst-case outcome of this is being able to move or delete existing files on the server, or upload new files, using the account of the person who clicks the malicious link. It is recommended to change the passwords of one's copyparty accounts, unless one have inspected one's logs and found no trace of attacks. Version 1.8.7 contains a patch for the issue.

    Source:Vartamtezidis Theodoros
    Published:25 Jul 2023
    7.8
    High

    CVE-2023-38497

    Last Modified: 13 Feb 2025

    Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

    Published:3 Aug 2023
    6.8
    Medium

    CVE-2023-38490

    Last Modified: 21 Nov 2024

    Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 only affects Kirby sites that use the `Xml` data handler (e.g. `Data::decode($string, 'xml')`) or the `Xml::parse()` method in site or plugin code. The Kirby core does not use any of the affected methods. XML External Entities (XXE) is a little used feature in the XML markup language that allows to include data from external files in an XML structure. If the name of the external file can be controlled by an attacker, this becomes a vulnerability that can be abused for various system impacts like the disclosure of internal or confidential data that is stored on the server (arbitrary file disclosure) or to perform network requests on behalf of the server (server-side request forgery, SSRF). Kirby's `Xml::parse()` method used PHP's `LIBXML_NOENT` constant, which enabled the processing of XML external entities during the parsing operation. The `Xml::parse()` method is used in the `Xml` data handler (e.g. `Data::decode($string, 'xml')`). Both the vulnerable method and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to parse RSS feeds or other XML files. If those files are of an external origin (e.g. uploaded by a user or retrieved from an external URL), attackers may be able to include an external entity in the XML file that will then be processed in the parsing process. Kirby sites that don't use XML parsing in site or plugin code are *not* affected. The problem has been patched in Kirby 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6. In all of the mentioned releases, the maintainers have removed the `LIBXML_NOENT` constant as processing of external entities is out of scope of the parsing logic. This protects all uses of the method against the described vulnerability.

    Published:27 Jul 2023
    7.5
    High

    CVE-2023-38434

    Last Modified: 21 Nov 2024

    xHTTP 72f812d has a double free in close_connection in xhttp.c via a malformed HTTP request method.

    Published:18 Jul 2023
    9.8
    Critical

    CVE-2023-38408

    Last Modified: 21 Nov 2024

    The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.

    Published:19 Jul 2023
    5.3
    Medium

    CVE-2023-38357

    Last Modified: 20 Jul 2023

    Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized access to user sessions.

    Source:RedTeam Pentesting GmbH
    Published:1 Aug 2023
    8.8
    High

    CVE-2023-38146

    Last Modified: 30 Oct 2025

    Windows Themes Remote Code Execution Vulnerability

    Published:12 Sept 2023
    8.8
    High

    CVE-2023-38120

    Last Modified: 12 Aug 2025

    Adtran SR400ac ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adtran SR400ac routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ping command, which is available over JSON-RPC. A crafted host parameter can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-20525.

    Published:3 May 2024
    7
    High

    CVE-2023-38041

    Last Modified: 7 Mar 2025

    A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system.

    Published:25 Oct 2023
    7.5
    High

    CVE-2023-38039

    Last Modified: 2 Dec 2025

    When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.

    Published:13 Sept 2023
    9.8
    Critical

    CVE-2023-38035

    Last Modified: 31 Oct 2025

    A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

    Published:21 Aug 2023
    7.1
    High

    CVE-2023-37979

    Last Modified: 4 Aug 2023

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions.

    Source:Mehran Seifalinia
    Published:27 Jul 2023