6.6
    Medium

    CVE-2023-37941

    Last Modified: 13 Feb 2025

    If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. The Superset metadata db is an 'internal' component that is typically only accessible directly by the system administrator and the superset process itself. Gaining access to that database should be difficult and require significant privileges. This vulnerability impacts Apache Superset versions 1.5.0 up to and including 2.1.0. Users are recommended to upgrade to version 2.1.1 or later.

    Published:6 Sept 2023
    9.1
    Critical

    CVE-2023-37908

    Last Modified: 21 Nov 2024

    XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. The cleaning of attributes during XHTML rendering, introduced in version 14.6-rc-1, allowed the injection of arbitrary HTML code and thus cross-site scripting via invalid attribute names. This can be exploited, e.g., via the link syntax in any content that supports XWiki syntax like comments in XWiki. When a user moves the mouse over a malicious link, the malicious JavaScript code is executed in the context of the user session. When this user is a privileged user who has programming rights, this allows server-side code execution with programming rights, impacting the confidentiality, integrity and availability of the XWiki instance. While this attribute was correctly recognized as not allowed, the attribute was still printed with a prefix `data-xwiki-translated-attribute-` without further cleaning or validation. This problem has been patched in XWiki 14.10.4 and 15.0 RC1 by removing characters not allowed in data attributes and then validating the cleaned attribute again. There are no known workarounds apart from upgrading to a version including the fix.

    Published:25 Oct 2023
    9.8
    Critical

    CVE-2023-37903

    Last Modified: 3 Nov 2025

    vm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect function allows attackers to escape the sandbox and run arbitrary code. This may result in Remote Code Execution, assuming the attacker has arbitrary code execution primitive inside the context of vm2 sandbox. There are no patches and no known workarounds. Users are advised to find an alternative software.

    Published:21 Jul 2023
    Low

    CVE-2023-37800

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published:10 Jul 2023
    5.4
    Medium

    CVE-2023-37790

    Last Modified: 21 Nov 2024

    Jaspersoft Clarity PPM version 14.3.0.298 was discovered to contain an arbitrary file upload vulnerability via the Profile Picture Upload function.

    Published:8 Nov 2023
    4.8
    Medium

    CVE-2023-37786

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Geeklog v2.2.2 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Mail Settings[backend], Mail Settings[host], Mail Settings[port] and Mail Settings[auth] parameters of the /admin/configuration.php.

    Published:13 Jul 2023
    Unknown

    CVE-2023-37779

    https://github.com/jyoti818680/CVE-2023-37779

    Unknown

    CVE-2023-37778

    https://github.com/jyoti818680/CVE-2023-37778

    8.8
    High

    CVE-2023-37772

    Last Modified: 21 Nov 2024

    Online Shopping Portal Project v3.1 was discovered to contain a SQL injection vulnerability via the Email parameter at /shopping/login.php.

    Published:1 Aug 2023
    9.8
    Critical

    CVE-2023-37771

    Last Modified: 21 Nov 2024

    Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php.

    Published:31 Jul 2023
    9.8
    Critical

    CVE-2023-37759

    Last Modified: 9 Oct 2023

    Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticated attackers to register as an Admin account via a crafted POST request.

    Source:0xBr
    Published:8 Sept 2023
    9.8
    Critical

    CVE-2023-37756

    Last Modified: 21 Nov 2024

    I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation. Attackers are able to easily guess users' passwords via a bruteforce attack.

    Published:14 Sept 2023
    9.8
    Critical

    CVE-2023-37755

    Last Modified: 21 Nov 2024

    i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or prompt to ask users to change the default password and account name. Unauthenticated attackers can exploit this vulnerability to obtain Administrator privileges, resulting in them being able to perform arbitrary system operations or cause a Denial of Service (DoS).

    Published:14 Sept 2023
    6.5
    Medium

    CVE-2023-37739

    Last Modified: 21 Nov 2024

    i-doit Pro v25 and below was discovered to be vulnerable to path traversal.

    Published:14 Sept 2023
    9.8
    Critical

    CVE-2023-37635

    Last Modified: 21 Nov 2024

    UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application.

    Published:23 Oct 2023
    9.8
    Critical

    CVE-2023-37629

    Last Modified: 21 Jul 2023

    Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pig.php."

    Source:1337kid
    Published:12 Jul 2023
    5.4
    Medium

    CVE-2023-37625

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in Netbox v3.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Link templates.

    Published:10 Aug 2023
    Low

    CVE-2023-37621

    Last Modified: 16 Apr 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published:10 Jul 2023
    7.5
    High

    CVE-2023-37599

    Last Modified: 21 Nov 2024

    An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory

    Published:13 Jul 2023
    4.5
    Medium

    CVE-2023-37598

    Last Modified: 21 Nov 2024

    A Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete new virtual fax function.

    Published:13 Jul 2023
    8.1
    High

    CVE-2023-37597

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete user grouplist function.

    Published:11 Jul 2023
    8.1
    High

    CVE-2023-37596

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via a crafted script to the deleteuser function.

    Published:11 Jul 2023
    9.8
    Critical

    CVE-2023-37582

    Last Modified: 23 Apr 2025

    The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1. When NameServer address are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function on the NameServer component to execute commands as the system users that RocketMQ is running as. It is recommended for users to upgrade their NameServer version to 5.1.2 or above for RocketMQ 5.x or 4.9.7 or above for RocketMQ 4.x to prevent these attacks.

    Published:12 Jul 2023
    8.8
    High

    CVE-2023-37569

    Last Modified: 8 Aug 2023

    This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component. A remote authenticated attacker could exploit this by injecting OS commands on the targeted system. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code on targeted system.

    Source:thewhiteh4t
    Published:8 Aug 2023
    7.5
    High

    CVE-2023-37478

    Last Modified: 21 Nov 2024

    pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar archives. This can result in a package that appears safe on the npm registry or when installed via npm being replaced with a compromised or malicious version when installed via pnpm. This issue has been patched in version(s) 7.33.4 and 8.6.8.

    Published:1 Aug 2023
    7.5
    High

    CVE-2023-37474

    Last Modified: 4 Sept 2025

    Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path Traversal attack technique allows an attacker access to files, directories, and commands that reside outside the web document root directory. This issue has been addressed in commit `043e3c7d` which has been included in release 1.8.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published:14 Jul 2023
    6.8
    Medium

    CVE-2023-37467

    Last Modified: 21 Nov 2024

    Discourse is an open source discussion platform. Prior to version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a CSP (Content Security Policy) nonce reuse vulnerability was discovered could allow cross-site scripting (XSS) attacks to bypass CSP protection for anonymous (i.e. unauthenticated) users. There are no known XSS vectors at the moment, but should one be discovered, this vulnerability would allow the XSS attack to bypass CSP and execute successfully. This vulnerability isn't applicable to logged-in users. Version 3.1.0.beta7 contains a patch. The stable branch doesn't have this vulnerability. A workaround to prevent the vulnerability is to disable Google Tag Manager, i.e., unset the `gtm container id` setting.

    Published:28 Jul 2023
    8.1
    High

    CVE-2023-37460

    Last Modified: 21 Nov 2024

    Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API. Prior to version 4.8.0, using AbstractUnArchiver for extracting an archive might lead to an arbitrary file creation and possibly remote code execution. When extracting an archive with an entry that already exists in the destination directory as a symbolic link whose target does not exist - the `resolveFile()` function will return the symlink's source instead of its target, which will pass the verification that ensures the file will not be extracted outside of the destination directory. Later `Files.newOutputStream()`, that follows symlinks by default, will actually write the entry's content to the symlink's target. Whoever uses plexus archiver to extract an untrusted archive is vulnerable to an arbitrary file creation and possibly remote code execution. Version 4.8.0 contains a patch for this issue.

    Published:25 Jul 2023
    6.5
    Medium

    CVE-2023-37456

    Last Modified: 21 Nov 2024

    The session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS < 115.

    Published:12 Jul 2023
    8.1
    High

    CVE-2023-37273

    Last Modified: 25 Feb 2026

    Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. Running Auto-GPT version prior to 0.4.3 by cloning the git repo and executing `docker compose run auto-gpt` in the repo root uses a different docker-compose.yml file from the one suggested in the official docker set up instructions. The docker-compose.yml file located in the repo root mounts itself into the docker container without write protection. This means that if malicious custom python code is executed via the `execute_python_file` and `execute_python_code` commands, it can overwrite the docker-compose.yml file and abuse it to gain control of the host system the next time Auto-GPT is started. The issue has been patched in version 0.4.3.

    Published:13 Jul 2023
    2
    Low

    CVE-2023-37269

    Last Modified: 15 Jul 2023

    Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Users with the `backend.manage_branding` permission can upload SVGs as the application logo. Prior to version 1.2.3, SVG uploads were not sanitized, which could have allowed a stored cross-site scripting (XSS) attack. To exploit the vulnerability, an attacker would already need to have developer or super user level permissions in Winter CMS. This means they would already have extensive access and control within the system. Additionally, to execute the XSS, the attacker would need to convince the victim to directly visit the URL of the maliciously uploaded SVG, and the application would have to be using local storage where uploaded files are served under the same domain as the application itself instead of a CDN. This is because all SVGs in Winter CMS are rendered through an `img` tag, which prevents any payloads from being executed directly. These two factors significantly limit the potential harm of this vulnerability. This issue has been patched in v1.2.3 through the inclusion of full support for SVG uploads and automatic sanitization of uploaded SVG files. As a workaround, one may apply the patches manually.

    Source:abhishek morla
    Published:7 Jul 2023
    7
    High

    CVE-2023-37250

    Last Modified: 21 Nov 2024

    Unity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per User" mode. The application intentionally launches DLLs from a user-owned directory but intended to always perform integrity verification of those DLLs. This affects Parsec Loader versions through 8. Parsec Loader 9 is a fixed version.

    Published:20 Aug 2023
    4.8
    Medium

    CVE-2023-37191

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Group and Description parameters.

    Published:11 Jul 2023
    4.8
    Medium

    CVE-2023-37190

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Virtual Fax Name and Caller ID Name parameters under the New Virtual Fax feature.

    Published:11 Jul 2023
    4.8
    Medium

    CVE-2023-37189

    Last Modified: 21 Nov 2024

    A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the Name or Prefix fields under the Create New Rate module.

    Published:11 Jul 2023
    6.1
    Medium

    CVE-2023-37164

    Last Modified: 21 Nov 2024

    Diafan CMS v6.0 was discovered to contain a reflected cross-site scripting via the cat_id parameter at /shop/?module=shop&action=search.

    Published:20 Jul 2023
    Unknown

    CVE-2023-37073

    https://github.com/Hamza0X/CVE-2023-37073

    9.8
    Critical

    CVE-2023-37068

    Last Modified: 21 Nov 2024

    Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username and password fields, enabling SQL Injection attacks.

    Published:9 Aug 2023
    7.8
    High

    CVE-2023-36900

    Last Modified: 1 Jan 2025

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    Published:8 Aug 2023
    8.8
    High

    CVE-2023-36899

    Last Modified: 1 Jan 2025

    ASP.NET Elevation of Privilege Vulnerability

    Published:8 Aug 2023
    7.5
    High

    CVE-2023-36884

    Last Modified: 28 Oct 2025

    Windows Search Remote Code Execution Vulnerability

    Published:11 Jul 2023
    7.8
    High

    CVE-2023-36874

    Last Modified: 28 Oct 2025

    Windows Error Reporting Service Elevation of Privilege Vulnerability

    Published:11 Jul 2023
    5.3
    Medium

    CVE-2023-36846

    Last Modified: 26 Feb 2026

    A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain  part of the file system, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on SRX Series: * All versions prior to 20.4R3-S8; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S6; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S3; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R2-S2, 22.3R3; * 22.4 versions prior to 22.4R2-S1, 22.4R3.

    Published:17 Aug 2023
    9.8
    Critical

    CVE-2023-36845

    Last Modified: 24 Oct 2025

    A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request which sets the variable PHPRC an attacker is able to modify the PHP execution environment allowing the injection und execution of code. This issue affects Juniper Networks Junos OS on EX Series and SRX Series: * All versions prior to 20.4R3-S9; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S7; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S4; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R2-S2, 22.3R3-S1; * 22.4 versions prior to 22.4R2-S1, 22.4R3; * 23.2 versions prior to 23.2R1-S1, 23.2R2.

    Published:17 Aug 2023
    5.3
    Medium

    CVE-2023-36844

    Last Modified: 24 Oct 2025

    A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on EX Series: * All versions prior to 20.4R3-S9; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S7; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S4; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R3-S1; * 22.4 versions prior to 22.4R2-S2, 22.4R3; * 23.2 versions prior to 23.2R1-S1, 23.2R2.

    Published:17 Aug 2023
    9.8
    Critical

    CVE-2023-36812

    Last Modified: 13 Feb 2025

    OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Execution vulnerability by writing user-controlled input to Gnuplot configuration file and running Gnuplot with the generated configuration. This issue has been patched in commit `07c4641471c` and further refined in commit `fa88d3e4b`. These patches are available in the `2.4.2` release. Users are advised to upgrade. User unable to upgrade may disable Gunuplot via the config option`tsd.core.enable_ui = true` and remove the shell files `mygnuplot.bat` and `mygnuplot.sh`.

    Published:30 Jun 2023
    8.6
    High

    CVE-2023-36808

    Last Modified: 21 Nov 2024

    GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Machine form and GLPI inventory request can be used to perform a SQL injection attack. Version 10.0.8 has a patch for this issue. As a workaround, one may disable native inventory.

    Published:5 Jul 2023
    7.8
    High

    CVE-2023-36802

    Last Modified: 30 Oct 2025

    Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

    Published:12 Sept 2023
    8
    High

    CVE-2023-36745

    Last Modified: 30 Oct 2025

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Published:12 Sept 2023
    7.8
    High

    CVE-2023-36723

    Last Modified: 14 Apr 2025

    Windows Container Manager Service Elevation of Privilege Vulnerability

    Published:10 Oct 2023