7.8
    High

    CVE-2023-36664

    Last Modified: 28 Aug 2026

    Artifex Ghostscript before 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).

    Published:25 Jun 2023
    9.1
    Critical

    CVE-2023-36645

    Last Modified: 24 Apr 2025

    SQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow component in customer function.

    Published:4 Apr 2024
    7.5
    High

    CVE-2023-36644

    Last Modified: 24 Apr 2025

    Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all order confirmations from the online shop via the printmail plugin.

    Published:4 Apr 2024
    7.5
    High

    CVE-2023-36643

    Last Modified: 24 Apr 2025

    Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all orders from the online shop via oordershow component in customer function.

    Published:4 Apr 2024
    8.8
    High

    CVE-2023-36542

    Last Modified: 13 Feb 2025

    Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an authenticated and authorized user to configure a location that enables custom code execution. The resolution introduces a new Required Permission for referencing remote resources, restricting configuration of these components to privileged users. The permission prevents unprivileged users from configuring Processors and Controller Services annotated with the new Reference Remote Resources restriction. Upgrading to Apache NiFi 1.23.0 is the recommended mitigation.

    Published:29 Jul 2023
    4.3
    Medium

    CVE-2023-36531

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in LiquidPoll LiquidPoll – Advanced Polls for Creators and Brands allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LiquidPoll – Advanced Polls for Creators and Brands: from n/a through 3.3.68.

    Published:13 Dec 2024
    4.3
    Medium

    CVE-2023-36482

    Last Modified: 21 Nov 2024

    An issue was discovered in Samsung NFC S3NRN4V, S3NSN4V, S3NSEN4, SEN82AB, and S3NRN82. A buffer copy without checking its input size can cause an NFC service restart.

    Published:8 Aug 2023
    9.1
    Critical

    CVE-2023-36471

    Last Modified: 26 Nov 2024

    Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki since version 14.6RC1 allowed form and input HTML tags. In the context of XWiki, this allows an attacker without script right to either create forms that can be used for phishing attacks or also in the context of a sheet, the attacker could add an input like `{{html}}<input type="hidden" name="content" value="{{groovy}}println(&quot;Hello from Groovy!&quot;)" />{{/html}}` that would allow remote code execution when it is submitted by an admin (the sheet is rendered as part of the edit form). The attacker would need to ensure that the edit form looks plausible, though, which can be non-trivial as without script right the attacker cannot display the regular content of the document. This has been patched in XWiki 14.10.6 and 15.2RC1 by removing the central form-related tags from the list of allowed tags. Users are advised to upgrade. As a workaround an admin can manually disallow the tags by adding `form, input, select, textarea, button` to the configuration option `xml.htmlElementSanitizer.forbidTags` in the `xwiki.properties` configuration file.

    Published:29 Jun 2023
    7
    High

    CVE-2023-36427

    Last Modified: 8 Oct 2025

    Windows Hyper-V Elevation of Privilege Vulnerability

    Published:14 Nov 2023
    7.8
    High

    CVE-2023-36424

    Last Modified: 14 Apr 2026

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    Published:14 Nov 2023
    7.8
    High

    CVE-2023-36407

    Last Modified: 8 Oct 2025

    Windows Hyper-V Elevation of Privilege Vulnerability

    Published:14 Nov 2023
    9.9
    Critical

    CVE-2023-36355

    Last Modified: 3 Jul 2023

    TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

    Source:Amirhossein Bahramizadeh
    Published:22 Jun 2023
    8.8
    High

    CVE-2023-36348

    Last Modified: 3 Jul 2023

    POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter.

    Source:yuyudhn
    Published:23 Jun 2023
    6.1
    Medium

    CVE-2023-36346

    Last Modified: 3 Jul 2023

    POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parameter at print.php.

    Source:Amirhossein Bahramizadeh
    Published:23 Jun 2023
    8.8
    High

    CVE-2023-36319

    Last Modified: 21 Nov 2024

    File Upload vulnerability in Openupload Stable v.0.4.3 allows a remote attacker to execute arbitrary code via the action parameter of the compress-inc.php file.

    Published:19 Sept 2023
    5.5
    Medium

    CVE-2023-36308

    Last Modified: 4 Nov 2025

    disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence

    Published:5 Sept 2023
    6.1
    Medium

    CVE-2023-36306

    Last Modified: 4 Aug 2023

    A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle.php, details.php, index.php, search.php, export.php, reports.php, and statistics.php components.

    Source:Pedro
    Published:8 Aug 2023
    9.8
    Critical

    CVE-2023-36281

    Last Modified: 21 Nov 2024

    An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This is related to __subclasses__ or a template.

    Published:22 Aug 2023
    5.5
    Medium

    CVE-2023-36266

    Last Modified: 28 Jul 2023

    An issue was discovered in Keeper Password Manager for Desktop version 16.10.2 (fixed in 17.2), and the KeeperFill Browser Extensions version 16.5.4 (fixed in 17.2), allows local attackers to gain sensitive information via plaintext password storage in memory after the user is already logged in, and may persist after logout. NOTE: the vendor disputes this for two reasons: the information is inherently available during a logged-in session when the attacker can read from arbitrary memory locations, and information only remains available after logout because of memory-management limitations of web browsers (not because the Keeper technology itself is retaining the information).

    Source:H4rk3nz0
    Published:12 Jul 2023
    7.8
    High

    CVE-2023-36250

    Last Modified: 21 Nov 2024

    CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via crafted .tsv file when creating a new record.

    Published:14 Sept 2023
    Low

    CVE-2023-36169

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published:21 Jun 2023
    Low

    CVE-2023-36168

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published:21 Jun 2023
    Low

    CVE-2023-36167

    Last Modified: 11 Jul 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Source:Idan Malihi
    Published:21 Jun 2023
    Low

    CVE-2023-36166

    Last Modified: 11 Jul 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Source:Idan Malihi
    Published:21 Jun 2023
    Low

    CVE-2023-36165

    Last Modified: 11 Jul 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Source:Idan Malihi
    Published:21 Jun 2023
    Low

    CVE-2023-36164

    Last Modified: 11 Jul 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Source:Idan Malihi
    Published:21 Jun 2023
    6.1
    Medium

    CVE-2023-36163

    Last Modified: 11 Jul 2023

    Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the mc parameter of the URL.

    Source:Idan Malihi
    Published:11 Jul 2023
    6.1
    Medium

    CVE-2023-36159

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers to run arbitrary code via the First Name, Middle Name and Last Name fields on the Create User page.

    Published:3 Aug 2023
    6.1
    Medium

    CVE-2023-36158

    Last Modified: 24 Feb 2025

    Cross Site Scripting (XSS) vulnerability in sourcecodester Toll Tax Management System 1.0 allows remote attackers to run arbitrary code via the First Name and Last Name fields on the My Account page.

    Published:3 Aug 2023
    5.4
    Medium

    CVE-2023-36146

    Last Modified: 27 Nov 2024

    A Stored Cross-Site Scripting (XSS) vulnerability was found in Multilaser RE 170 using firmware 2.2.6733.

    Published:30 Jun 2023
    7.5
    High

    CVE-2023-36144

    Last Modified: 27 Nov 2024

    An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the device, exposing critical information about the device configuration.

    Published:30 Jun 2023
    8.8
    High

    CVE-2023-36143

    Last Modified: 27 Nov 2024

    Maxprint Maxlink 1200G v3.4.11E has an OS command injection vulnerability in the "Diagnostic tool" functionality of the device.

    Published:30 Jun 2023
    7.8
    High

    CVE-2023-36123

    Last Modified: 21 Nov 2024

    Directory Traversal vulnerability in Hex-Dragon Plain Craft Launcher 2 version Alpha 1.3.9, allows local attackers to execute arbitrary code and gain sensitive information.

    Published:6 Oct 2023
    9.8
    Critical

    CVE-2023-36109

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in JerryScript version 3.0, allows remote attackers to execute arbitrary code via ecma_stringbuilder_append_raw component at /jerry-core/ecma/base/ecma-helpers-string.c.

    Published:20 Sept 2023
    6.1
    Medium

    CVE-2023-36085

    Last Modified: 21 Nov 2024

    The sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdentityServer/core/" endpoint. By modifying the HTTP Host header, an attacker can change webpage links and even redirect users to arbitrary or malicious locations. This can lead to phishing attacks, malware distribution, and unauthorized access to sensitive resources.

    Published:24 Oct 2023
    9.8
    Critical

    CVE-2023-36076

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in smanga version 3.1.9 and earlier, allows remote attackers to execute arbitrary code and gain sensitive information via mediaId, mangaId, and userId parameters in php/history/add.php.

    Published:1 Sept 2023
    8.8
    High

    CVE-2023-36025

    Last Modified: 28 Oct 2025

    Windows SmartScreen Security Feature Bypass Vulnerability

    Published:14 Nov 2023
    6.7
    Medium

    CVE-2023-36003

    Last Modified: 1 Jan 2025

    XAML Diagnostics Elevation of Privilege Vulnerability

    Published:12 Dec 2023
    8.8
    High

    CVE-2023-35985

    Last Modified: 4 Nov 2025

    An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to a failure to properly validate a dangerous extension. A specially crafted malicious file can create files at arbitrary locations, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially-crafted malicious site if the browser plugin extension is enabled.

    Published:27 Nov 2023
    5
    Medium

    CVE-2023-35887

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks. This issue affects Apache MINA: from 1.0 before 2.10. Users are recommended to upgrade to 2.10

    Published:10 Jul 2023
    9.8
    Critical

    CVE-2023-35885

    Last Modified: 9 Dec 2024

    CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.

    Published:20 Jun 2023
    9.8
    Critical

    CVE-2023-35854

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is that they have "found no evidence or detail of a security vulnerability."

    Published:20 Jun 2023
    7.5
    High

    CVE-2023-35844

    Last Modified: 12 Dec 2024

    packages/backend/src/routers in Lightdash before 0.510.3 has insecure file endpoints, e.g., they allow .. directory traversal and do not ensure that an intended file extension (.csv or .png) is used.

    Published:19 Jun 2023
    7.5
    High

    CVE-2023-35843

    Last Modified: 12 Dec 2024

    NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the server by manipulating the path parameter of the /download route. This vulnerability could allow an attacker to access sensitive files and data on the server, including configuration files, source code, and other sensitive information.

    Published:19 Jun 2023
    6.5
    Medium

    CVE-2023-35840

    Last Modified: 12 Dec 2024

    _joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.

    Published:19 Jun 2023
    7
    High

    CVE-2023-35828

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesas_usb3_remove in drivers/usb/gadget/udc/renesas_usb3.c.

    Published:18 Jun 2023
    9.8
    Critical

    CVE-2023-35813

    Last Modified: 17 Dec 2024

    Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.

    Published:17 Jun 2023
    9.8
    Critical

    CVE-2023-35803

    Last Modified: 21 Nov 2024

    IQ Engine before 10.6r2 on Extreme Network AP devices has a Buffer Overflow.

    Published:4 Oct 2023
    8.1
    High

    CVE-2023-35801

    Last Modified: 29 Nov 2024

    A directory traversal vulnerability in Safe Software FME Server before 2022.2.5 allows an attacker to bypass validation when editing a network-based resource connection, resulting in the unauthorized reading and writing of arbitrary files. Successful exploitation requires an attacker to have access to a user account with write privileges. FME Flow 2023.0 is also a fixed version.

    Published:23 Jun 2023
    8.8
    High

    CVE-2023-35794

    Last Modified: 21 Nov 2024

    An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) can be accessed without authentication. Specifically, there is no session cookie validation on the Access Controller; instead, there is only Basic Authentication to the SSH console.

    Published:27 Oct 2023