8.8
    High

    CVE-2023-30765

    Last Modified: 27 Jan 2025

    ​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access controls that could allow an attacker to alter privilege management configurations, resulting in privilege escalation.

    Published:10 Jul 2023
    8.8
    High

    CVE-2023-30628

    Last Modified: 12 Feb 2025

    Kiwi TCMS is an open source test management system. In kiwitcms/Kiwi v12.2 and prior and kiwitcms/enterprise v12.2 and prior, the `changelog.yml` workflow is vulnerable to command injection attacks because of using an untrusted `github.head_ref` field. The `github.head_ref` value is an attacker-controlled value. Assigning the value to `zzz";echo${IFS}"hello";#` can lead to command injection. Since the permission is not restricted, the attacker has a write-access to the repository. Commit 834c86dfd1b2492ccad7ebbfd6304bfec895fed2 of the kiwitcms/Kiwi repository and commit e39f7e156fdaf6fec09a15ea6f4e8fec8cdbf751 of the kiwitcms/enterprise repository contain a fix for this issue.

    Published:24 Apr 2023
    9.8
    Critical

    CVE-2023-30547

    Last Modified: 5 Feb 2025

    vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. There exists a vulnerability in exception sanitization of vm2 for versions up to 3.9.16, allowing attackers to raise an unsanitized host exception inside `handleException()` which can be used to escape the sandbox and run arbitrary code in host context. This vulnerability was patched in the release of version `3.9.17` of `vm2`. There are no known workarounds for this vulnerability. Users are advised to upgrade.

    Published:17 Apr 2023
    7.8
    High

    CVE-2023-30533

    Last Modified: 4 Feb 2025

    SheetJS Community Edition before 0.19.3 allows Prototype Pollution via a crafted file. In other words. 0.19.2 and earlier are affected, whereas 0.19.3 and later are unaffected.

    Published:24 Apr 2023
    4.3
    Medium

    CVE-2023-30486

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in HashThemes Square allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Square: from n/a through 2.0.0.

    Published:9 Dec 2024
    7.2
    High

    CVE-2023-30459

    Last Modified: 6 Feb 2025

    SmartPTT SCADA 1.1.0.0 allows remote code execution (when the attacker has administrator privileges) by writing a malicious C# script and executing it on the server (via server settings in the administrator control panel on port 8101, by default).

    Published:14 Apr 2023
    5.3
    Medium

    CVE-2023-30458

    Last Modified: 4 Feb 2025

    A username enumeration issue was discovered in Medicine Tracker System 1.0. The login functionality allows a malicious user to guess a valid username due to a different response time from invalid usernames. When one enters a valid username, the response time increases depending on the length of the supplied password.

    Published:24 Apr 2023
    7.5
    High

    CVE-2023-30383

    Last Modified: 21 Nov 2024

    TP-LINK Archer C50v2 Archer C50(US)_V2_160801, TP-LINK Archer C20v1 Archer_C20_V1_150707, and TP-LINK Archer C2v1 Archer_C2_US__V1_170228 were discovered to contain a buffer overflow which may lead to a Denial of Service (DoS) when parsing crafted data.

    Published:18 Jul 2023
    7.5
    High

    CVE-2023-30367

    Last Modified: 21 Nov 2024

    Multi-Remote Next Generation Connection Manager (mRemoteNG) is free software that enables users to store and manage multi-protocol connection configurations to remotely connect to systems. mRemoteNG configuration files can be stored in an encrypted state on disk. mRemoteNG version <= v1.76.20 and <= 1.77.3-dev loads configuration files in plain text into memory (after decrypting them if necessary) at application start-up, even if no connection has been established yet. This allows attackers to access contents of configuration files in plain text through a memory dump and thus compromise user credentials when no custom password encryption key has been set. This also bypasses the connection configuration file encryption setting by dumping already decrypted configurations from memory.

    Published:26 Jul 2023
    8.8
    High

    CVE-2023-30350

    Last Modified: 2 May 2023

    FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin password.

    Source:Daniele Linguaglossa
    Published:28 May 2023
    4.8
    Medium

    CVE-2023-30347

    Last Modified: 6 Dec 2024

    Cross Site Scripting (XSS) vulnerability in Neox Contact Center 2.3.9, via the serach_sms_api_name parameter to the SMA API search.

    Published:22 Jun 2023
    9.8
    Critical

    CVE-2023-30333

    Last Modified: 23 Jan 2025

    An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code via a crafted file.

    Published:18 May 2023
    9.8
    Critical

    CVE-2023-30330

    Last Modified: 2 May 2023

    SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defaultframe/2.0/defaultframe_filter.php.

    Source:Felipe Alcantara
    Published:12 May 2023
    9.8
    Critical

    CVE-2023-30258

    Last Modified: 13 Apr 2025

    Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.

    Source:CodeSecLab
    Published:23 Jun 2023
    6.1
    Medium

    CVE-2023-30256

    Last Modified: 23 May 2023

    Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.

    Source:Astik Rawat
    Published:11 May 2023
    8.8
    High

    CVE-2023-30253

    Last Modified: 14 Jan 2025

    Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.

    Published:29 May 2023
    5.5
    Medium

    CVE-2023-30226

    Last Modified: 21 Nov 2024

    An issue was discovered in function get_gnu_verneed in rizinorg Rizin prior to 0.5.0 verneed_entry allows attackers to cause a denial of service via crafted elf file.

    Published:12 Jul 2023
    6.1
    Medium

    CVE-2023-30212

    Last Modified: 3 Feb 2025

    OURPHP <= 7.2.0 is vulnerale to Cross Site Scripting (XSS) via /client/manage/ourphp_out.php.

    Published:26 Apr 2023
    7.5
    High

    CVE-2023-30198

    Last Modified: 26 Jun 2023

    Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download.php.

    Source:Amirhossein Bahramizadeh
    Published:12 Jun 2023
    Unknown

    CVE-2023-30190

    https://github.com/MojithaR/CVE-2023-30190-FOLLINA

    9.8
    Critical

    CVE-2023-30185

    Last Modified: 29 Jan 2025

    CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.

    Published:8 May 2023
    7.5
    High

    CVE-2023-30146

    Last Modified: 21 Nov 2024

    Assmann Digitus Plug&View IP Camera HT-IP211HDP, version 2.000.022 allows unauthenticated attackers to download a copy of the camera's settings and the administrator credentials.

    Published:4 Aug 2023
    9.8
    Critical

    CVE-2023-30145

    Last Modified: 15 Jun 2023

    Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.

    Source:PARAG BAGUL
    Published:26 May 2023
    9.8
    Critical

    CVE-2023-30092

    Last Modified: 29 Jan 2025

    SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter.

    Published:8 May 2023
    Unknown

    CVE-2023-30033

    https://github.com/phucodeexp/CVE-2023-30033

    5.4
    Medium

    CVE-2023-29983

    Last Modified: 2 May 2023

    Cross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary code via the auditlog tab in the admin panel.

    Source:Lucas Noki (0xPrototype)
    Published:12 May 2023
    8.8
    High

    CVE-2023-29930

    Last Modified: 27 Jan 2025

    An issue was found in Genesys CIC Polycom phone provisioning TFTP Server all version allows a remote attacker to execute arbitrary code via the login crednetials to the TFTP server configuration page.

    Published:10 May 2023
    7.5
    High

    CVE-2023-29929

    Last Modified: 15 Apr 2026

    Buffer Overflow vulnerability found in Kemptechnologies Loadmaster before v.7.2.60.0 allows a remote attacker to casue a denial of service via the libkemplink.so, isreverse library.

    Published:21 Aug 2024
    5.3
    Medium

    CVE-2023-29923

    Last Modified: 5 Feb 2025

    PowerJob V4.3.1 is vulnerable to Insecure Permissions. via the list job interface.

    Published:19 Apr 2023
    5.3
    Medium

    CVE-2023-29922

    Last Modified: 5 Feb 2025

    PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create user/save interface.

    Published:19 Apr 2023
    9.8
    Critical

    CVE-2023-29919

    Last Modified: 17 Jan 2025

    SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted.

    Published:23 May 2023
    5.4
    Medium

    CVE-2023-29918

    Last Modified: 31 Jul 2023

    RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.

    Source:Ranjeet Jaiswal
    Published:2 May 2023
    8.8
    High

    CVE-2023-29849

    Last Modified: 28 Apr 2023

    Bang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice, menuID, staffID, or itemqty parameter.

    Source:Rahad Chowdhury
    Published:24 Apr 2023
    4.8
    Medium

    CVE-2023-29848

    Last Modified: 28 Apr 2023

    Bang Resto 1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the itemName parameter in the admin/menu.php Add New Menu function.

    Source:Rahad Chowdhury
    Published:24 Apr 2023
    5.4
    Medium

    CVE-2023-29839

    Last Modified: 7 Apr 2025

    A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function.

    Published:3 May 2023
    9.8
    Critical

    CVE-2023-29809

    Last Modified: 9 May 2023

    SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbitrary code via a crafted script in the request.

    Source:Lucas Noki (0xPrototype)
    Published:12 May 2023
    6.1
    Medium

    CVE-2023-29808

    Last Modified: 24 Jan 2025

    Cross Site Scripting (XSS) vulnerability in vogtmh cmaps (companymaps) 8.0 allows attackers to execute arbitrary code.

    Published:12 May 2023
    9.8
    Critical

    CVE-2023-29689

    Last Modified: 8 Aug 2023

    PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.

    Source:Daniel Barros
    Published:4 Aug 2023
    9.1
    Critical

    CVE-2023-29528

    Last Modified: 4 Feb 2025

    XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1 and massively improved in version 14.6-rc-1, allowed the injection of arbitrary HTML code and thus cross-site scripting via invalid HTML comments. As a consequence, any code relying on this "restricted" mode for security is vulnerable to JavaScript injection ("cross-site scripting"/XSS). When a privileged user with programming rights visits such a comment in XWiki, the malicious JavaScript code is executed in the context of the user session. This allows server-side code execution with programming rights, impacting the confidentiality, integrity and availability of the XWiki instance. This problem has been patched in XWiki 14.10, HTML comments are now removed in restricted mode and a check has been introduced that ensures that comments don't start with `>`. There are no known workarounds apart from upgrading to a version including the fix.

    Published:20 Apr 2023
    5.3
    Medium

    CVE-2023-29489

    Last Modified: 21 Nov 2024

    An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31.

    Published:27 Apr 2023
    9.8
    Critical

    CVE-2023-29478

    Last Modified: 11 Feb 2025

    BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesystem. This includes the Minecraft mods folder, which results in code execution.

    Published:7 Apr 2023
    7.1
    High

    CVE-2023-29439

    Last Modified: 9 Jan 2025

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.35 versions.

    Published:16 May 2023
    5.3
    Medium

    CVE-2023-29409

    Last Modified: 13 Feb 2025

    Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures. With fix, the size of RSA keys transmitted during handshakes is restricted to <= 8192 bits. Based on a survey of publicly trusted RSA keys, there are currently only three certificates in circulation with keys larger than this, and all three appear to be test certificates that are not actively deployed. It is possible there are larger keys in use in private PKIs, but we target the web PKI, so causing breakage here in the interests of increasing the default safety of users of crypto/tls seems reasonable.

    Published:2 Aug 2023
    6.5
    Medium

    CVE-2023-29406

    Last Modified: 13 Feb 2025

    The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value.

    Published:11 Jul 2023
    4.3
    Medium

    CVE-2023-29401

    Last Modified: 6 Jan 2025

    The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition header. For example, a filename of "setup.bat&quot;;x=.txt" will be sent as a file named "setup.bat". If the FileAttachment function is called with names provided by an untrusted source, this may permit an attacker to cause a file to be served with a name different than provided. Maliciously crafted attachment file name can modify the Content-Disposition header.

    Published:8 Jun 2023
    9.1
    Critical

    CVE-2023-29386

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Julien Crego Manager for Icomoon.This issue affects Manager for Icomoon: from n/a through 2.0.

    Published:26 Mar 2024
    10
    Critical

    CVE-2023-29384

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in HM Plugin WordPress Job Board and Recruitment Plugin – JobWP.This issue affects WordPress Job Board and Recruitment Plugin – JobWP: from n/a through 2.0.

    Published:20 Dec 2023
    9.8
    Critical

    CVE-2023-29375

    Last Modified: 12 Feb 2025

    An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potentially dangerous file upload through the SharePoint connector.

    Published:10 Apr 2023
    8.4
    High

    CVE-2023-29360

    Last Modified: 28 Oct 2025

    Microsoft Streaming Service Elevation of Privilege Vulnerability

    Published:13 Jun 2023
    9.8
    Critical

    CVE-2023-29357

    Last Modified: 28 Oct 2025

    Microsoft SharePoint Server Elevation of Privilege Vulnerability

    Published:13 Jun 2023