5.5
    Medium

    CVE-2023-4166

    Last Modified: 21 Nov 2024

    A vulnerability has been found in Tongda OA and classified as critical. This vulnerability affects unknown code of the file general/system/seal_manage/dianju/delete_log.php. The manipulation of the argument DELETE_STR leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-236182 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published:5 Aug 2023
    5.5
    Medium

    CVE-2023-4165

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in Tongda OA. This affects an unknown part of the file general/system/seal_manage/iweboffice/delete_seal.php. The manipulation of the argument DELETE_STR leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-236181 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published:5 Aug 2023
    7.8
    High

    CVE-2023-4147

    Last Modified: 25 Feb 2026

    A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID. This flaw allows a local user to crash or escalate their privileges on the system.

    Published:23 Jul 2023
    7.8
    High

    CVE-2023-4128

    Last Modified: 14 Nov 2023

    ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-4206, CVE-2023-4207, CVE-2023-4208. Reason: This record is a duplicate of CVE-2023-4206, CVE-2023-4207, CVE-2023-4208. Notes: All CVE users should reference CVE-2023-4206, CVE-2023-4207, CVE-2023-4208 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

    Published:29 Jul 2023
    4.3
    Medium

    CVE-2023-4119

    Last Modified: 4 Aug 2023

    A vulnerability has been found in Academy LMS 6.0 and classified as problematic. This vulnerability affects unknown code of the file /academy/home/courses. The manipulation of the argument query/sort_by leads to cross site scripting. The attack can be initiated remotely. VDB-235966 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Source:CraCkEr
    Published:3 Aug 2023
    4.3
    Medium

    CVE-2023-4117

    Last Modified: 4 Aug 2023

    A vulnerability, which was classified as problematic, has been found in PHP Jabbers Rental Property Booking 2.0. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-235964. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Source:CraCkEr
    Published:3 Aug 2023
    4.3
    Medium

    CVE-2023-4116

    Last Modified: 4 Aug 2023

    A vulnerability classified as problematic was found in PHP Jabbers Taxi Booking 2.0. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-235963. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Source:CraCkEr
    Published:3 Aug 2023
    4.3
    Medium

    CVE-2023-4115

    Last Modified: 4 Aug 2023

    A vulnerability classified as problematic has been found in PHP Jabbers Cleaning Business 1.0. Affected is an unknown function of the file /index.php. The manipulation of the argument index leads to cross site scripting. It is possible to launch the attack remotely. VDB-235962 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Source:CraCkEr
    Published:3 Aug 2023
    4.3
    Medium

    CVE-2023-4114

    Last Modified: 4 Aug 2023

    A vulnerability was found in PHP Jabbers Night Club Booking Software 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-235961 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Source:CraCkEr
    Published:3 Aug 2023
    4.3
    Medium

    CVE-2023-4113

    Last Modified: 4 Aug 2023

    A vulnerability was found in PHP Jabbers Service Booking Script 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-235960. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Source:CraCkEr
    Published:3 Aug 2023
    4.3
    Medium

    CVE-2023-4112

    Last Modified: 4 Aug 2023

    A vulnerability was found in PHP Jabbers Shuttle Booking Software 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-235959. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Source:CraCkEr
    Published:3 Aug 2023
    7.3
    High

    CVE-2023-3971

    Last Modified: 20 Nov 2025

    An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.

    Published:27 Jul 2023
    4.8
    Medium

    CVE-2023-3897

    Last Modified: 19 Feb 2024

    Username enumeration is possible through Bypassing CAPTCHA in On-premise SureMDM Solution on Windows deployment allows attacker to enumerate local user information via error message. This issue affects SureMDM On-premise: 6.31 and below version

    Source:Jonas Benjamin Friedli
    Published:25 Jul 2023
    6.3
    Medium

    CVE-2023-3881

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in Campcodes Beauty Salon Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/forgot-password.php. The manipulation of the argument contactno leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235243.

    Published:25 Jul 2023
    3.5
    Low

    CVE-2023-3849

    Last Modified: 28 Jul 2023

    A vulnerability, which was classified as problematic, was found in mooSocial mooDating 1.2. Affected is an unknown function of the file /find-a-match of the component URL Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-235200. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.

    Source:CraCkEr
    Published:23 Jul 2023
    3.5
    Low

    CVE-2023-3848

    Last Modified: 28 Jul 2023

    A vulnerability, which was classified as problematic, has been found in mooSocial mooDating 1.2. This issue affects some unknown processing of the file /users/view of the component URL Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-235199. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.

    Source:CraCkEr
    Published:23 Jul 2023
    3.5
    Low

    CVE-2023-3847

    Last Modified: 28 Jul 2023

    A vulnerability classified as problematic was found in mooSocial mooDating 1.2. This vulnerability affects unknown code of the file /users of the component URL Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. VDB-235198 is the identifier assigned to this vulnerability. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.

    Source:CraCkEr
    Published:23 Jul 2023
    3.5
    Low

    CVE-2023-3846

    Last Modified: 28 Jul 2023

    A vulnerability classified as problematic has been found in mooSocial mooDating 1.2. This affects an unknown part of the file /pages of the component URL Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-235197 was assigned to this vulnerability. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.

    Source:CraCkEr
    Published:23 Jul 2023
    3.5
    Low

    CVE-2023-3845

    Last Modified: 28 Jul 2023

    A vulnerability was found in mooSocial mooDating 1.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /friends/ajax_invite of the component URL Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-235196. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.

    Source:CraCkEr
    Published:23 Jul 2023
    3.5
    Low

    CVE-2023-3844

    Last Modified: 28 Jul 2023

    A vulnerability was found in mooSocial mooDating 1.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /friends of the component URL Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-235195. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.

    Source:CraCkEr
    Published:23 Jul 2023
    3.5
    Low

    CVE-2023-3843

    Last Modified: 28 Jul 2023

    A vulnerability was found in mooSocial mooDating 1.2. It has been classified as problematic. Affected is an unknown function of the file /matchmakings/question of the component URL Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. VDB-235194 is the identifier assigned to this vulnerability. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.

    Source:CraCkEr
    Published:23 Jul 2023
    6.3
    Medium

    CVE-2023-3836

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in Dahua Smart Park Management up to 20230713. This vulnerability affects unknown code of the file /emap/devicePoint_addImgIco?hasSubsystem=true. The manipulation of the argument upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235162 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published:22 Jul 2023
    9.4
    Critical

    CVE-2023-3824

    Last Modified: 13 Feb 2025

    In PHP version 8.0.* before 8.0.30,  8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insufficient length checking may lead to a stack buffer overflow, leading potentially to memory corruption or RCE.

    Published:3 Aug 2023
    8.6
    High

    CVE-2023-3722

    Last Modified: 21 Nov 2024

    An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.

    Published:19 Jul 2023
    9.9
    Critical

    CVE-2023-3710

    Last Modified: 14 Mar 2024

    Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).

    Source:ByteHunter
    Published:12 Sept 2023
    7.3
    High

    CVE-2023-3643

    Last Modified: 3 Mar 2026

    A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233889 was assigned to this vulnerability.

    Source:andersoncezar048
    Published:12 Jul 2023
    7
    High

    CVE-2023-3640

    Last Modified: 21 Jul 2026

    A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data. Based on the previous CVE-2023-0597, the 'Randomize per-cpu entry area' feature was implemented in /arch/x86/mm/cpu_entry_area.c, which works through the init_cea_offsets() function when KASLR is enabled. However, despite this feature, there is still a risk of per-cpu entry area leaks. This issue could allow a local user to gain access to some important data with memory in an expected location and potentially escalate their privileges on the system.

    Published:23 Jun 2023
    5.9
    Medium

    CVE-2023-3635

    Last Modified: 21 Nov 2024

    GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.

    Published:12 Jul 2023
    7.8
    High

    CVE-2023-3609

    Last Modified: 30 Jul 2026

    A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_bind_filter(). If an attacker can control the reference counter and set it to zero, they can cause the reference to be freed, leading to a use-after-free vulnerability. We recommend upgrading past commit 04c55383fa5689357bcdd2c8036725a55ed632bc.

    Published:21 Jul 2023
    9.8
    Critical

    CVE-2023-3519

    Last Modified: 24 Oct 2025

    Unauthenticated remote code execution

    Published:19 Jul 2023
    9.8
    Critical

    CVE-2023-3460

    Last Modified: 18 Aug 2025

    The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

    Source:Gurjot Singh
    Published:4 Jul 2023
    9.8
    Critical

    CVE-2023-3452

    Last Modified: 8 Apr 2026

    The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. This allows unauthenticated attackers to include and execute arbitrary remote code on the server, provided that allow_url_include is enabled. Local File Inclusion is also possible, albeit less useful because it requires that the attacker be able to upload a malicious php file via FTP or some other means into a directory readable by the web server.

    Published:12 Aug 2023
    4.7
    Medium

    CVE-2023-3450

    Last Modified: 21 Nov 2024

    A vulnerability was found in Ruijie RG-BCR860 2.5.13 and classified as critical. This issue affects some unknown processing of the component Network Diagnostic Page. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-232547. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published:28 Jun 2023
    7.8
    High

    CVE-2023-3390

    Last Modified: 22 Jul 2026

    A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction causing a use-after-free vulnerability. This flaw allows a local attacker with user access to cause a privilege escalation issue. We recommend upgrading past commit 1240eb93f0616b21c675416516ff3d74798fdc97

    Published:8 Jun 2023
    8.2
    High

    CVE-2023-3350

    Last Modified: 21 Nov 2024

    A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the log file, an attacker could retrieve the SQL query sent to the application in plaint text. This log file contains the password hashes coded with AES-CBC-128 bits algorithm, which can be decrypted with a .NET function, obtaining the username's password in plain text.

    Published:3 Oct 2023
    6.5
    Medium

    CVE-2023-3338

    Last Modified: 5 Mar 2025

    A null pointer dereference flaw was found in the Linux kernel's DECnet networking protocol. This issue could allow a remote user to crash the system.

    Published:26 Jun 2023
    6.1
    Medium

    CVE-2023-3320

    Last Modified: 20 Jun 2023

    The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing nonce validation in the ~/admin/views/admin.php file. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Source:Amirhossein Bahramizadeh
    Published:20 Jun 2023
    5.5
    Medium

    CVE-2023-3280

    Last Modified: 21 Nov 2024

    A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to disable the agent.

    Published:13 Sept 2023
    7.8
    High

    CVE-2023-3269

    Last Modified: 5 Mar 2025

    A vulnerability exists in the memory management subsystem of the Linux kernel. The lock handling for accessing and updating virtual memory areas (VMAs) is incorrect, leading to use-after-free problems. This issue can be successfully exploited to execute arbitrary kernel code, escalate containers, and gain root privileges.

    Published:5 Jul 2023
    4.3
    Medium

    CVE-2023-3244

    Last Modified: 8 Apr 2026

    The Comments Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the restore_settings function called via an AJAX action in versions up to, and including, 1.2.0. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to reset the plugin's settings. NOTE: this issue is was only partially patched in version 1.2.0, as the nonce is still present to subscriber-level users.

    Published:17 Aug 2023
    5.3
    Medium

    CVE-2023-3219

    Last Modified: 4 Aug 2023

    The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the post.

    Source:Miguel Santareno
    Published:10 Jul 2023
    6.3
    Medium

    CVE-2023-3187

    Last Modified: 13 Jun 2023

    A vulnerability, which was classified as critical, has been found in PHPGurukul Teachers Record Management System 1.0. Affected by this issue is some unknown functionality of the file /changeimage.php of the component Profile Picture Handler. The manipulation of the argument newpic leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-231176.

    Source:AFFAN AHMED
    Published:9 Jun 2023
    2.4
    Low

    CVE-2023-3184

    Last Modified: 19 Jun 2023

    A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save. The manipulation of the argument firstname/middlename/lastname/username leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-231164.

    Source:AFFAN AHMED
    Published:9 Jun 2023
    3.5
    Low

    CVE-2023-3163

    Last Modified: 21 Nov 2024

    A vulnerability was found in y_project RuoYi up to 4.7.7. It has been classified as problematic. Affected is the function filterKeyword. The manipulation of the argument value leads to resource consumption. VDB-231090 is the identifier assigned to this vulnerability.

    Published:8 Jun 2023
    9.4
    Critical

    CVE-2023-3128

    Last Modified: 13 Feb 2025

    Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

    Published:22 Jun 2023
    8.8
    High

    CVE-2023-3124

    Last Modified: 8 Apr 2026

    The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level capabilities to update arbitrary site options, which can lead to privilege escalation.

    Published:7 Jun 2023
    8.8
    High

    CVE-2023-3079

    Last Modified: 24 Oct 2025

    Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published:5 Jun 2023
    9.8
    Critical

    CVE-2023-3076

    Last Modified: 21 Nov 2024

    The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plugin's pro features.

    Published:10 Jul 2023
    9.8
    Critical

    CVE-2023-3047

    Last Modified: 22 May 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TMT Lockcell allows SQL Injection. This issue affects Lockcell: before 15.

    Published:13 Jun 2023
    5.4
    Medium

    CVE-2023-3009

    Last Modified: 10 Jan 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

    Published:31 May 2023