7
    High

    CVE-2023-27470

    Last Modified: 21 Nov 2024

    BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PROGRAMDATA%\GetSupportService_N-Central\PushUpdates, leading to arbitrary file deletion.

    Published:11 Sept 2023
    9.8
    Critical

    CVE-2023-27372

    Last Modified: 21 Jun 2023

    SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.

    Source:nuts7
    Published:28 Feb 2023
    7.8
    High

    CVE-2023-27363

    Last Modified: 11 Aug 2025

    Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the exportXFAData method. The application exposes a JavaScript interface that allows writing arbitrary files. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-19697.

    Published:3 May 2024
    9.8
    Critical

    CVE-2023-27350

    Last Modified: 25 Apr 2023

    This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.

    Source:MaanVader
    Published:20 Apr 2023
    7.5
    High

    CVE-2023-27327

    Last Modified: 6 Aug 2025

    Parallels Desktop Toolgate Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate component. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the current user on the host system. Was ZDI-CAN-18964.

    Published:3 May 2024
    8.2
    High

    CVE-2023-27326

    Last Modified: 6 Aug 2025

    Parallels Desktop Toolgate Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate component. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the current user on the host system. . Was ZDI-CAN-18933.

    Published:3 May 2024
    9.1
    Critical

    CVE-2023-27290

    Last Modified: 7 Apr 2023

    Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: 248737.

    Source:Shahid Parvez (zippon)
    Published:3 Mar 2023
    8.8
    High

    CVE-2023-27253

    Last Modified: 20 Jul 2023

    A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.

    Source:Emir Polat
    Published:17 Mar 2023
    8.8
    High

    CVE-2023-27216

    Last Modified: 10 Feb 2025

    An issue found in D-Link DSL-3782 v.1.03 allows remote authenticated users to execute arbitrary code as root via the network settings page.

    Published:12 Apr 2023
    7.5
    High

    CVE-2023-27179

    Last Modified: 20 Apr 2023

    GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php.

    Source:Hadi Mene
    Published:11 Apr 2023
    6.5
    Medium

    CVE-2023-27167

    Last Modified: 8 Apr 2023

    Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/absence?search_month=1.

    Source:Yuriy (Vander) Tsarenko
    Published:29 Mar 2023
    6.5
    Medium

    CVE-2023-27163

    Last Modified: 18 Feb 2025

    request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.

    Published:31 Mar 2023
    Unknown

    CVE-2023-27146

    https://github.com/astrocombat1607/CVE-2023-27146-LocalPotato-Priviledge-Escalation

    9.8
    Critical

    CVE-2023-27100

    Last Modified: 28 Apr 2023

    Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.

    Source:FabDotNET
    Published:22 Mar 2023
    6.5
    Medium

    CVE-2023-27035

    Last Modified: 30 Jan 2025

    An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page.

    Published:1 May 2023
    7.8
    High

    CVE-2023-27010

    Last Modified: 7 Apr 2023

    Wondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst. This vulnerability allows attackers to escalate privileges via modifying or overwriting the executable.

    Source:Thurein Soe
    Published:13 Mar 2023
    8.1
    High

    CVE-2023-26984

    Last Modified: 18 Feb 2025

    An issue in the password reset function of Peppermint v0.2.4 allows attackers to access the emails and passwords of the Tickets page via a crafted request.

    Published:29 Mar 2023
    5.4
    Medium

    CVE-2023-26982

    Last Modified: 18 Feb 2025

    Trudesk v1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter under the Create Ticket function.

    Published:29 Mar 2023
    7.5
    High

    CVE-2023-26976

    Last Modified: 13 Feb 2025

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

    Published:4 Apr 2023
    9.8
    Critical

    CVE-2023-26918

    Last Modified: 20 Apr 2023

    Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as LocalSystem. This occurs because %ProgramFiles%\FileReplicationPro allows Everyone:(F) access.

    Source:Andrea Intilangelo
    Published:13 Apr 2023
    9.8
    Critical

    CVE-2023-26866

    Last Modified: 13 Feb 2025

    GreenPacket OH736's WR-1200 Indoor Unit, OT-235 with firmware versions M-IDU-1.6.0.3_V1.1 and MH-46360-2.0.3-R5-GP respectively are vulnerable to remote command injection. Commands are executed using pre-login execution and executed with root privileges allowing complete takeover.

    Published:4 Apr 2023
    7.2
    High

    CVE-2023-26852

    Last Modified: 10 Feb 2025

    An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by uploading a crafted PHP file.

    Published:12 Apr 2023
    5.5
    Medium

    CVE-2023-26818

    Last Modified: 21 Jan 2025

    Telegram 9.3.1 and 9.4.0 allows attackers to access restricted files, microphone ,or video recording via the DYLD_INSERT_LIBRARIES flag.

    Published:19 May 2023
    9.8
    Critical

    CVE-2023-26785

    Last Modified: 10 Jul 2025

    MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

    Published:17 Oct 2024
    6.1
    Medium

    CVE-2023-26692

    Last Modified: 8 Apr 2023

    ZCBS Zijper Collectie Beheer Systeem (ZCBS), Zijper Publication Management System (ZPBS), and Zijper Image Bank Management System (ZBBS) 4.14k is vulnerable to Cross Site Scripting (XSS).

    Source:Abdulaziz Saad
    Published:30 Mar 2023
    7.2
    High

    CVE-2023-26609

    Last Modified: 6 Apr 2023

    ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin/mft/wireless_mft ap field.

    Published:27 Feb 2023
    7.1
    High

    CVE-2023-26607

    Last Modified: 5 May 2025

    In the Linux kernel 6.0.8, there is an out-of-bounds read in ntfs_attr_find in fs/ntfs/attrib.c.

    Published:26 Feb 2023
    9.8
    Critical

    CVE-2023-26602

    Last Modified: 16 Apr 2025

    ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snmpset for NET-SNMP-EXTEND-MIB with /bin/sh for command execution.

    Source:ub3rsick
    Published:26 Feb 2023
    9.8
    Critical

    CVE-2023-26563

    Last Modified: 21 Nov 2024

    The Syncfusion EJ2 Node File Provider 0102271 is vulnerable to filesystem-server.js directory traversal. As a result, an unauthenticated attacker can: - On Windows, list files in any directory, read any file, delete any file, upload any file to any directory accessible by the web server. - On Linux, read any file, download any directory, delete any file, upload any file to any directory accessible by the web server.

    Published:12 Jul 2023
    8.1
    High

    CVE-2023-26493

    Last Modified: 19 Feb 2025

    Cocos Engine is an open-source framework for building 2D & 3D real-time rendering and interactive content. In the github repo for Cocos Engine the `web-interface-check.yml` was subject to command injection. The `web-interface-check.yml` was triggered when a pull request was opened or updated and contained the user controllable field `(${{ github.head_ref }} – the name of the fork’s branch)`. This would allow an attacker to take over the GitHub Runner and run custom commands (potentially stealing secrets such as GITHUB_TOKEN) and altering the repository. The workflow has since been removed for the repository. There are no actions required of users.

    Published:27 Mar 2023
    9.1
    Critical

    CVE-2023-26482

    Last Modified: 11 Feb 2025

    Nextcloud server is an open source home cloud implementation. In affected versions a missing scope validation allowed users to create workflows which are designed to be only available for administrators. Some workflows are designed to be RCE by invoking defined scripts, in order to generate PDFs, invoking webhooks or running scripts on the server. Due to this combination depending on the available apps the issue can result in a RCE at the end. It is recommended that the Nextcloud Server is upgraded to 24.0.10 or 25.0.4. Users unable to upgrade should disable app `workflow_scripts` and `workflow_pdf_converter` as a mitigation.

    Published:30 Mar 2023
    9.8
    Critical

    CVE-2023-26469

    Last Modified: 21 Nov 2024

    In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.

    Published:17 Aug 2023
    8.6
    High

    CVE-2023-26360

    Last Modified: 23 Oct 2025

    Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

    Published:23 Mar 2023
    9.8
    Critical

    CVE-2023-26326

    Last Modified: 12 Mar 2025

    The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present.

    Published:23 Feb 2023
    7.8
    High

    CVE-2023-26269

    Last Modified: 13 Feb 2025

    Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation by a malicious local user. Administrators are advised to disable JMX, or set up a JMX password. Note that version 3.7.4 onward will set up a JMX password automatically for Guice users.

    Published:3 Apr 2023
    7.2
    High

    CVE-2023-26262

    Last Modified: 27 Feb 2025

    An issue was discovered in Sitecore XP/XM 10.3. As an authenticated Sitecore user, a unrestricted language file upload vulnerability exists the can lead to direct code execution on the content management (CM) server.

    Published:14 Mar 2023
    9.8
    Critical

    CVE-2023-26258

    Last Modified: 25 Nov 2024

    Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as administrator.

    Published:3 Jul 2023
    7.5
    High

    CVE-2023-26256

    Last Modified: 21 Mar 2025

    An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying the fileName parameter to the snjFooterNavigationConfig endpoint, it is possible to traverse and read the file system.

    Published:28 Feb 2023
    7.5
    High

    CVE-2023-26255

    Last Modified: 18 Mar 2025

    An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying the fileName parameter to the snjCustomDesignConfig endpoint, it is possible to traverse and read the file system.

    Published:28 Feb 2023
    3.5
    Low

    CVE-2023-26209

    Last Modified: 21 Nov 2024

    A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiDeceptor 3.1.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.

    Published:9 Mar 2023
    3.5
    Low

    CVE-2023-26208

    Last Modified: 21 Nov 2024

    A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.

    Published:9 Mar 2023
    5.3
    Medium

    CVE-2023-26144

    Last Modified: 21 Nov 2024

    Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This vulnerability allows an attacker to degrade system performance. **Note:** It was not proven that this vulnerability can crash the process.

    Published:18 Sept 2023
    6.5
    Medium

    CVE-2023-26136

    Last Modified: 27 Aug 2025

    Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.

    Published:1 Jul 2023
    3.3
    Low

    CVE-2023-26083

    Last Modified: 3 Nov 2025

    Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata.

    Published:6 Apr 2023
    8.1
    High

    CVE-2023-26067

    Last Modified: 11 Feb 2025

    Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).

    Published:10 Apr 2023
    2.4
    Low

    CVE-2023-26049

    Last Modified: 13 Feb 2025

    Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggle cookies within other cookies, or otherwise perform unintended behavior by tampering with the cookie parsing mechanism. If Jetty sees a cookie VALUE that starts with `"` (double quote), it will continue to read the cookie string until it sees a closing quote -- even if a semicolon is encountered. So, a cookie header such as: `DISPLAY_LANGUAGE="b; JSESSIONID=1337; c=d"` will be parsed as one cookie, with the name DISPLAY_LANGUAGE and a value of b; JSESSIONID=1337; c=d instead of 3 separate cookies. This has security implications because if, say, JSESSIONID is an HttpOnly cookie, and the DISPLAY_LANGUAGE cookie value is rendered on the page, an attacker can smuggle the JSESSIONID cookie into the DISPLAY_LANGUAGE cookie and thereby exfiltrate it. This is significant when an intermediary is enacting some policy based on cookies, so a smuggled cookie can bypass that policy yet still be seen by the Jetty server or its logging system. This issue has been addressed in versions 9.4.51, 10.0.14, 11.0.14, and 12.0.0.beta0 and users are advised to upgrade. There are no known workarounds for this issue.

    Published:18 Apr 2023
    5.3
    Medium

    CVE-2023-26048

    Last Modified: 13 Feb 2025

    Jetty is a java based web server and servlet engine. In affected versions servlets with multipart support (e.g. annotated with `@MultipartConfig`) that call `HttpServletRequest.getParameter()` or `HttpServletRequest.getParts()` may cause `OutOfMemoryError` when the client sends a multipart request with a part that has a name but no filename and very large content. This happens even with the default settings of `fileSizeThreshold=0` which should stream the whole part content to disk. An attacker client may send a large multipart request and cause the server to throw `OutOfMemoryError`. However, the server may be able to recover after the `OutOfMemoryError` and continue its service -- although it may take some time. This issue has been patched in versions 9.4.51, 10.0.14, and 11.0.14. Users are advised to upgrade. Users unable to upgrade may set the multipart parameter `maxRequestSize` which must be set to a non-negative value, so the whole multipart content is limited (although still read into memory).

    Published:18 Apr 2023
    7.1
    High

    CVE-2023-26039

    Last Modified: 10 Mar 2025

    ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain an OS Command Injection via daemonControl() in (/web/api/app/Controller/HostController.php). Any authenticated user can construct an api command to execute any shell command as the web user. This issue is patched in versions 1.36.33 and 1.37.33.

    Published:25 Feb 2023
    7.2
    High

    CVE-2023-26035

    Last Modified: 13 Feb 2025

    ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Execution via Missing Authorization. There are no permissions check on the snapshot action, which expects an id to fetch an existing monitor but can be passed an object to create a new one instead. TriggerOn ends up calling shell_exec using the supplied Id. This issue is fixed in This issue is fixed in versions 1.36.33 and 1.37.33.

    Published:25 Feb 2023
    7.3
    High

    CVE-2023-25950

    Last Modified: 11 Feb 2025

    HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a legitimate user's request. As a result, the attacker may obtain sensitive information or cause a denial-of-service (DoS) condition.

    Published:11 Apr 2023