8.8
    High

    CVE-2023-35793

    Last Modified: 21 Nov 2024

    An issue was discovered in Cassia Access Controller 2.1.1.2303271039. Establishing a web SSH session to gateways is vulnerable to Cross Site Request Forgery (CSRF) attacks.

    Published:26 Sept 2023
    7.8
    High

    CVE-2023-35788

    Last Modified: 5 May 2025

    An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.

    Published:29 May 2023
    8.8
    High

    CVE-2023-35744

    Last Modified: 13 May 2025

    D-Link DAP-2622 DDP Configuration Restore Server IPv6 Address Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-20071.

    Published:3 May 2024
    7.8
    High

    CVE-2023-35687

    Last Modified: 21 Nov 2024

    In MtpPropertyValue of MtpProperty.h, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:11 Sept 2023
    8.8
    High

    CVE-2023-35674

    Last Modified: 23 Oct 2025

    In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:11 Sept 2023
    5.5
    Medium

    CVE-2023-35671

    Last Modified: 21 Nov 2024

    In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number and expiry details when the device is in locked screen mode due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:11 Sept 2023
    6.5
    Medium

    CVE-2023-35636

    Last Modified: 1 Jan 2025

    Microsoft Outlook Information Disclosure Vulnerability

    Published:12 Dec 2023
    7.8
    High

    CVE-2023-35317

    Last Modified: 1 Jan 2025

    Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability

    Published:11 Jul 2023
    7.2
    High

    CVE-2023-35086

    Last Modified: 21 Nov 2024

    It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly using input as a format string when calling syslog in logmessage_normal function, in the do_detwan_cgi module of httpd. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service. This issue affects RT-AX56U V2: 3.0.0.4.386_50460; RT-AC86U: 3.0.0.4_386_51529.

    Published:21 Jul 2023
    9.8
    Critical

    CVE-2023-35085

    Last Modified: 4 Dec 2024

    An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default settings enabled could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.50 and earlier) All UniFi Switches (Version 6.5.32 and earlier) -USW Flex Mini excluded. Mitigation: Update UniFi Access Points to Version 6.5.62 or later. Update the UniFi Switches to Version 6.5.59 or later.

    Published:10 Aug 2023
    9.8
    Critical

    CVE-2023-35082

    Last Modified: 31 Oct 2025

    An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

    Published:15 Aug 2023
    7.8
    High

    CVE-2023-35080

    Last Modified: 7 Jan 2025

    A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, denial of service, or information disclosure.

    Published:14 Nov 2023
    9.8
    Critical

    CVE-2023-35078

    Last Modified: 31 Oct 2025

    An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

    Published:25 Jul 2023
    7.8
    High

    CVE-2023-35001

    Last Modified: 13 Feb 2025

    Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability; nft_byteorder poorly handled vm register contents when CAP_NET_ADMIN is in any user or network namespace

    Published:5 Jul 2023
    9.7
    Critical

    CVE-2023-34992

    Last Modified: 14 Jan 2026

    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests.

    Published:10 Oct 2023
    5.3
    Medium

    CVE-2023-34965

    Last Modified: 3 Jan 2025

    SSPanel-Uim 2023.3 does not restrict access to the /link/ interface which can lead to a leak of user information.

    Published:13 Jun 2023
    9.8
    Critical

    CVE-2023-34960

    Last Modified: 21 Nov 2024

    A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.

    Published:1 Aug 2023
    6.5
    Medium

    CVE-2023-34927

    Last Modified: 2 Apr 2024

    Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily change the victim user's password via supplying a crafted URL.

    Source:Van Lam Nguyen
    Published:22 Jun 2023
    7.5
    High

    CVE-2023-34924

    Last Modified: 3 Dec 2024

    H3C Magic B1STW B1STV100R012 was discovered to contain a stack overflow via the function SetAPInfoById. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published:26 Jun 2023
    7.8
    High

    CVE-2023-34853

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVar variable.

    Published:22 Aug 2023
    9.8
    Critical

    CVE-2023-34852

    Last Modified: 18 Dec 2024

    PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.

    Published:15 Jun 2023
    5.4
    Medium

    CVE-2023-34845

    Last Modified: 21 Nov 2024

    Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content. This vulnerability allows attackers to execute arbitrary web scripts or HTML via uploading a crafted SVG file. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through self-registration).

    Published:16 Jun 2023
    7.5
    High

    CVE-2023-34843

    Last Modified: 27 Nov 2024

    Traggo Server 0.3.0 is vulnerable to directory traversal via a crafted GET request.

    Published:28 Jun 2023
    6.1
    Medium

    CVE-2023-34840

    Last Modified: 27 Nov 2024

    angular-ui-notification v0.1.0, v0.2.0, and v0.3.6 was discovered to contain a cross-site scripting (XSS) vulnerability.

    Published:30 Jun 2023
    6.8
    Medium

    CVE-2023-34839

    Last Modified: 2 Dec 2024

    A Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain privileges via a Custom CSRF exploit to create new user function in the application.

    Published:27 Jun 2023
    5.4
    Medium

    CVE-2023-34838

    Last Modified: 2 Dec 2024

    A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Description parameter.

    Published:27 Jun 2023
    5.4
    Medium

    CVE-2023-34837

    Last Modified: 13 Feb 2025

    A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a vulnerable parameter GrpPath.

    Published:27 Jun 2023
    5.4
    Medium

    CVE-2023-34836

    Last Modified: 5 Dec 2024

    A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Dtltyp and ListName parameters.

    Published:27 Jun 2023
    5.4
    Medium

    CVE-2023-34835

    Last Modified: 5 Dec 2024

    A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary JavaScript code via a vulnerable delete_file parameter.

    Published:27 Jun 2023
    5.3
    Medium

    CVE-2023-34834

    Last Modified: 23 Jun 2023

    A Directory Browsing vulnerability in MCL-Net version 4.3.5.8788 webserver running on default port 5080, allows attackers to gain sensitive information about the configured databases via the "/file" endpoint.

    Source:Victor A. Morales
    Published:29 Jun 2023
    5.4
    Medium

    CVE-2023-34830

    Last Modified: 5 Dec 2024

    i-doit Open v24 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the timeout parameter on the login page.

    Published:27 Jun 2023
    Unknown

    CVE-2023-34804

    https://github.com/Shahibakes/Cve-2023-34804

    5.4
    Medium

    CVE-2023-34732

    Last Modified: 9 Jul 2025

    An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to execute brute force attacks to discover user passwords.

    Published:12 May 2025
    7.5
    High

    CVE-2023-34723

    Last Modified: 8 Sept 2023

    An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information via /config/system.conf.

    Source:The Security Team [exploitsecurity.io]
    Published:25 Aug 2023
    9.8
    Critical

    CVE-2023-34635

    Last Modified: 20 Jul 2023

    Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user input in the username field of the login page.

    Source:Ansh Jain
    Published:31 Jul 2023
    7.8
    High

    CVE-2023-34634

    Last Modified: 28 Jul 2023

    Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .greenshot file is opened.

    Source:p4r4bellum
    Published:1 Aug 2023
    Unknown

    CVE-2023-34632

    https://github.com/ssophiz/CVE-2023-34632

    9.8
    Critical

    CVE-2023-34600

    Last Modified: 9 Dec 2024

    Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.

    Published:20 Jun 2023
    6.1
    Medium

    CVE-2023-34599

    Last Modified: 26 Nov 2024

    Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to execute arbitrary Javascript code.

    Published:29 Jun 2023
    9.8
    Critical

    CVE-2023-34598

    Last Modified: 26 Nov 2024

    Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the installation folder in the server's response.

    Published:29 Jun 2023
    Unknown

    CVE-2023-34584

    https://github.com/fu2x2000/-CVE-2023-34584

    9.8
    Critical

    CVE-2023-34581

    Last Modified: 12 Apr 2024

    Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2

    Source:ASHIK KUNJUMON
    Published:12 Jun 2023
    5.4
    Medium

    CVE-2023-34537

    Last Modified: 3 Jan 2025

    A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick user on browser and/or exfiltrate data.

    Published:13 Jun 2023
    9.8
    Critical

    CVE-2023-34478

    Last Modified: 13 Feb 2025

    Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+

    Published:24 Jul 2023
    8.8
    High

    CVE-2023-34468

    Last Modified: 13 Feb 2025

    The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The resolution validates the Database URL and rejects H2 JDBC locations. You are recommended to upgrade to version 1.22.0 or later which fixes this issue.

    Published:12 Jun 2023
    8.8
    High

    CVE-2023-34446

    Last Modified: 21 Nov 2024

    iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, when displaying `pages/preferences.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0.

    Published:25 Oct 2023
    9.8
    Critical

    CVE-2023-34362

    Last Modified: 27 Oct 2025

    In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, and execute SQL statements that alter or delete database elements. NOTE: this is exploited in the wild in May and June 2023; exploitation of unpatched systems can occur via HTTP or HTTPS. All versions (e.g., 2020.0 and 2019x) before the five explicitly mentioned versions are affected, including older unsupported versions.

    Published:2 Jun 2023
    7.8
    High

    CVE-2023-34312

    Last Modified: 9 Jan 2025

    In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from inter-process communication, which leads to a write-what-where condition.

    Published:1 Jun 2023
    8.8
    High

    CVE-2023-34233

    Last Modified: 6 Jan 2025

    The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Versions prior to 3.0.2 are vulnerable to command injection via single sign-on(SSO) browser URL authentication. In order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a malicious resource and (2) redirecting users to utilize the resource. The attacker could set up a malicious, publicly accessible server which responds to the SSO URL with an attack payload. If the attacker then tricked a user into visiting the maliciously crafted connection URL, the user’s local machine would render the malicious payload, leading to a remote code execution. This attack scenario can be mitigated through URL whitelisting as well as common anti-phishing resources. Version 3.0.2 contains a patch for this issue.

    Published:8 Jun 2023
    6.5
    Medium

    CVE-2023-34212

    Last Modified: 13 Feb 2025

    The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 allow an authenticated and authorized user to configure URL and library properties that enable deserialization of untrusted data from a remote location. The resolution validates the JNDI URL and restricts locations to a set of allowed schemes. You are recommended to upgrade to version 1.22.0 or later which fixes this issue.

    Published:12 Jun 2023