Weekly Vulnerabilities Reports > April 3 to 9, 2023
Overview
553 new vulnerabilities reported during this period, including 103 critical vulnerabilities and 139 high severity vulnerabilities. This weekly summary report vulnerabilities in 454 products from 224 vendors including Google, Cisco, Tenda, Debian, and Fedoraproject. Vulnerabilities are notably categorized as "Out-of-bounds Write", "Cross-site Scripting", "SQL Injection", "Out-of-bounds Read", and "Untrusted Search Path".
- 461 reported vulnerabilities are remotely exploitables.
- 2 reported vulnerabilities have public exploit available.
- 125 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
- 306 reported vulnerabilities are exploitable by an anonymous user.
- Google has the most reported vulnerabilities, with 44 reported vulnerabilities.
- Tenda has the most reported critical vulnerabilities, with 21 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
103 Critical Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2023-04-04 | CVE-2023-1748 | Getnexx | Use of Hard-coded Credentials vulnerability in Getnexx products The listed versions of Nexx Smart Home devices use hard-coded credentials. | 10.0 |
2023-04-09 | CVE-2012-10011 | Contus | Unspecified vulnerability in Contus HD FLV Player A vulnerability was found in HD FLV PLayer Plugin up to 1.7 on WordPress. | 9.8 |
2023-04-09 | CVE-2023-27718 | Dlink | Out-of-bounds Write vulnerability in Dlink Dir878 Firmware 1.30B08 D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_498308 function. | 9.8 |
2023-04-09 | CVE-2023-27719 | Dlink | Out-of-bounds Write vulnerability in Dlink Dir878 Firmware 1.30B08 D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_478360 function. | 9.8 |
2023-04-09 | CVE-2023-27720 | Dlink | Out-of-bounds Write vulnerability in Dlink Dir-878 Firmware 1.30B08 D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function. | 9.8 |
2023-04-09 | CVE-2023-1962 | Best Online News Portal Project | Unspecified vulnerability in Best Online News Portal Project Best Online News Portal 1.0 A vulnerability classified as critical was found in SourceCodester Best Online News Portal 1.0. | 9.8 |
2023-04-09 | CVE-2023-1963 | Phpgurukul | SQL Injection vulnerability in PHPgurukul Bank Locker Management System 1.0 A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. | 9.8 |
2023-04-08 | CVE-2023-1958 | Oretnom23 | Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0 A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. | 9.8 |
2023-04-08 | CVE-2023-1955 | Oretnom23 | Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0 A vulnerability classified as critical has been found in SourceCodester Online Computer and Laptop Store 1.0. | 9.8 |
2023-04-08 | CVE-2013-10023 | Editorial Calendar Project | Unspecified vulnerability in Editorial Calendar Project Editorial Calendar A vulnerability was found in Editorial Calendar Plugin up to 2.6 on WordPress. | 9.8 |
2023-04-08 | CVE-2023-1952 | Oretnom23 | Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0 A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0. | 9.8 |
2023-04-08 | CVE-2023-1949 | Phpgurukul | Unspecified vulnerability in PHPgurukul BP Monitoring Management System 1.0 A vulnerability, which was classified as critical, was found in PHPGurukul BP Monitoring Management System 1.0. | 9.8 |
2023-04-08 | CVE-2023-1950 | Phpgurukul | Unspecified vulnerability in PHPgurukul BP Monitoring Management System 1.0 A vulnerability has been found in PHPGurukul BP Monitoring Management System 1.0 and classified as critical. | 9.8 |
2023-04-08 | CVE-2023-1951 | Oretnom23 | SQL Injection vulnerability in Oretnom23 Online Computer and Laptop Store 1.0 A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. | 9.8 |
2023-04-07 | CVE-2023-1947 | Taogogo | Code Injection vulnerability in Taogogo Taocms 3.0.2 A vulnerability was found in taoCMS 3.0.2. | 9.8 |
2023-04-07 | CVE-2023-27033 | Cdesigner Project | Unrestricted Upload of File with Dangerous Type vulnerability in Cdesigner Project Cdesigner 3.1.3/3.2.1 Prestashop cdesigner v3.1.3 to v3.1.8 was discovered to contain a code injection vulnerability via the component CdesignerSaverotateModuleFrontController::initContent(). | 9.8 |
2023-04-07 | CVE-2023-1941 | Simple AND Beautiful Shopping Cart System Project | Unspecified vulnerability in Simple and Beautiful Shopping Cart System Project Simple and Beautiful Shopping Cart System 1.0 A vulnerability, which was classified as critical, has been found in SourceCodester Simple and Beautiful Shopping Cart System 1.0. | 9.8 |
2023-04-07 | CVE-2023-1942 | Oretnom23 | Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0 A vulnerability has been found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. | 9.8 |
2023-04-07 | CVE-2023-28706 | Apache | Code Injection vulnerability in Apache Airflow Hive Provider Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 6.0.0. | 9.8 |
2023-04-07 | CVE-2023-26978 | Totolink | Command Injection vulnerability in Totolink A7100Ru Firmware 7.4Cu.2313B20191024 TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pppoeAcName parameter at /setting/setWanIeCfg. | 9.8 |
2023-04-07 | CVE-2023-29478 | Bibliocraftmod | Path Traversal vulnerability in Bibliocraftmod Bibliocraft BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesystem. | 9.8 |
2023-04-07 | CVE-2023-26848 | Totolink | Command Injection vulnerability in Totolink A7100Ru Firmware 7.4Cu.2313B20191024 TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the org parameter at setting/delStaticDhcpRules. | 9.8 |
2023-04-07 | CVE-2023-24797 | Dlink | Out-of-bounds Write vulnerability in Dlink Dir-882 A1 Firmware 110B02 D-Link DIR882 DIR882A1_FW110B02 was discovered to contain a stack overflow in the sub_48AC20 function. | 9.8 |
2023-04-07 | CVE-2023-24798 | Dlink | Out-of-bounds Write vulnerability in Dlink Dir-878 Firmware 1.20B05 D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_475FB0 function. | 9.8 |
2023-04-07 | CVE-2023-24799 | Dlink | Out-of-bounds Write vulnerability in Dlink Dir-878 Firmware 1.20B05 D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_48AF78 function. | 9.8 |
2023-04-07 | CVE-2023-24800 | Dlink | Out-of-bounds Write vulnerability in Dlink Dir-878 Firmware 1.20B05 D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_495220 function. | 9.8 |
2023-04-07 | CVE-2023-25210 | Tenda | Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28 Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the fromSetSysTime function. | 9.8 |
2023-04-07 | CVE-2023-25211 | Tenda | Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28 Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the R7WebsSecurityHandler function. | 9.8 |
2023-04-07 | CVE-2023-25212 | Tenda | Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28 Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the fromSetWirelessRepeat function. | 9.8 |
2023-04-07 | CVE-2023-25213 | Tenda | Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28 Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the check_param_changed function. | 9.8 |
2023-04-07 | CVE-2023-25214 | Tenda | Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28 Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the setSchedWifi function. | 9.8 |
2023-04-07 | CVE-2023-25215 | Tenda | Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28 Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the saveParentControlInfo function. | 9.8 |
2023-04-07 | CVE-2023-25216 | Tenda | Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28 Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the formSetFirewallCfg function. | 9.8 |
2023-04-07 | CVE-2023-25217 | Tenda | Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28 Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the formWifiBasicSet function. | 9.8 |
2023-04-07 | CVE-2023-25218 | Tenda | Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28 Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the form_fast_setting_wifi_set function. | 9.8 |
2023-04-07 | CVE-2023-25219 | Tenda | Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28 Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the fromDhcpListClient function. | 9.8 |
2023-04-07 | CVE-2023-25220 | Tenda | Out-of-bounds Write vulnerability in Tenda AC5 Firmware 15.03.06.28 Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the add_white_node function. | 9.8 |
2023-04-07 | CVE-2023-27012 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13Cn Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the setSchedWifi function. | 9.8 |
2023-04-07 | CVE-2023-27013 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13Cn Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the get_parentControl_list_Info function. | 9.8 |
2023-04-07 | CVE-2023-27014 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13Cn Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_46AC38 function. | 9.8 |
2023-04-07 | CVE-2023-27015 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13Cn Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_4A75C0 function. | 9.8 |
2023-04-07 | CVE-2023-27016 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13Cn Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the R7WebsSecurityHandler function. | 9.8 |
2023-04-07 | CVE-2023-27017 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13Cn Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45DC58 function. | 9.8 |
2023-04-07 | CVE-2023-27018 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13Cn Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45EC1C function. | 9.8 |
2023-04-07 | CVE-2023-27019 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13Cn Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_458FBC function. | 9.8 |
2023-04-07 | CVE-2023-27020 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13Cn Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the saveParentControlInfo function. | 9.8 |
2023-04-07 | CVE-2023-27021 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13Cn Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the formSetFirewallCfg function. | 9.8 |
2023-04-06 | CVE-2023-29473 | Atos | Command Injection vulnerability in Atos Unify Openscape 4000 and Unify Openscape 4000 Manager webservice in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, aka OSFOURK-23710. | 9.8 |
2023-04-06 | CVE-2023-29474 | Atos | Command Injection vulnerability in Atos Unify Openscape 4000 and Unify Openscape 4000 Manager inventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, aka OSFOURK-23552. | 9.8 |
2023-04-06 | CVE-2023-29475 | Atos | Command Injection vulnerability in Atos Unify Openscape 4000 and Unify Openscape 4000 Manager inventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, aka OSFOURK-23543. | 9.8 |
2023-04-06 | CVE-2023-28500 | Adobe | Deserialization of Untrusted Data vulnerability in Adobe Livecycle ES4 A Java insecure deserialization vulnerability in Adobe LiveCycle ES4 version 11.0 and earlier allows unauthenticated remote attackers to gain operating system code execution by submitting specially crafted Java serialized objects to a specific URL. | 9.8 |
2023-04-06 | CVE-2023-29017 | VM2 Project | Unspecified vulnerability in VM2 Project VM2 vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. | 9.8 |
2023-04-06 | CVE-2023-0580 | ABB | Insecure Storage of Sensitive Information vulnerability in ABB MY Control System 5.0/5.13 Insecure Storage of Sensitive Information vulnerability in ABB My Control System (on-premise) allows an attacker who successfully exploited this vulnerability to gain access to the secure application data or take control of the application. Of the services that make up the My Control System (on-premise) application, the following ones are affected by this vulnerability: User Interface System Monitoring1 Asset Inventory This issue affects My Control System (on-premise): from 5.0;0 through 5.13. | 9.8 |
2023-04-06 | CVE-2023-24538 | Golang | Code Injection vulnerability in Golang GO Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. | 9.8 |
2023-04-06 | CVE-2023-0750 | Lynx Technik | Missing Encryption of Sensitive Data vulnerability in Lynx-Technik Yellobrik PEC 1864 Firmware Yellobrik PEC-1864 implements authentication checks via javascript in the frontend interface. When the device can be accessed over the network an attacker could bypass authentication. This would allow an attacker to : - Change the password, resulting in a DOS of the users - Change the streaming source, compromising the integrity of the stream - Change the streaming destination, compromising the confidentiality of the stream This issue affects Yellowbrik: PEC 1864. | 9.8 |
2023-04-06 | CVE-2023-1908 | Simple Mobile Comparison Website Project | Unspecified vulnerability in Simple Mobile Comparison Website Project Simple Mobile Comparison Website 1.0 A vulnerability was found in SourceCodester Simple Mobile Comparison Website 1.0. | 9.8 |
2023-04-05 | CVE-2022-31890 | Enhancesoft | SQL Injection vulnerability in Enhancesoft Audit LOG SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae via the order parameter to the getOrder function. | 9.8 |
2023-04-05 | CVE-2023-1708 | Gitlab | Command Injection vulnerability in Gitlab An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-printable characters gets copied from clipboard, allowing unexpected commands to be executed on victim machine. | 9.8 |
2023-04-05 | CVE-2023-1782 | Hashicorp | Missing Authorization vulnerability in Hashicorp Nomad 1.5.0 HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. | 9.8 |
2023-04-05 | CVE-2023-24720 | Readium | Unrestricted Upload of File with Dangerous Type vulnerability in Readium Readium-Js 0.32.0 An arbitrary file upload vulnerability in readium-js v0.32.0 allows attackers to execute arbitrary code via uploading a crafted EPUB file. | 9.8 |
2023-04-05 | CVE-2022-4939 | Wclovers | Unspecified vulnerability in Wclovers Wcfm Membership THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, due to a missing capability check on the wp_ajax_nopriv_wcfm_ajax_controller AJAX action that controls membership settings. | 9.8 |
2023-04-05 | CVE-2023-1877 | Microweber | Unspecified vulnerability in Microweber Command Injection in GitHub repository microweber/microweber prior to 1.3.3. | 9.8 |
2023-04-05 | CVE-2023-1886 | Phpmyfaq | Unspecified vulnerability in PHPmyfaq Authentication Bypass by Capture-replay in GitHub repository thorsten/phpmyfaq prior to 3.1.12. | 9.8 |
2023-04-05 | CVE-2023-1788 | Firefly III | Unspecified vulnerability in Firefly-Iii Firefly III Insufficient Session Expiration in GitHub repository firefly-iii/firefly-iii prior to 6. | 9.8 |
2023-04-05 | CVE-2023-20073 | Cisco | Unrestricted Upload of File with Dangerous Type vulnerability in Cisco products A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device. | 9.8 |
2023-04-05 | CVE-2023-25330 | Mybatis | SQL Injection vulnerability in Mybatis A SQL injection vulnerability in Mybatis plus below 3.5.3.1 allows remote attackers to execute arbitrary SQL commands via the tenant ID valuer. | 9.8 |
2023-04-05 | CVE-2023-1849 | Online Payroll System Project | Unspecified vulnerability in Online Payroll System Project Online Payroll System 1.0 A vulnerability was found in SourceCodester Online Payroll System 1.0. | 9.8 |
2023-04-05 | CVE-2023-1850 | Online Payroll System Project | SQL Injection vulnerability in Online Payroll System Project Online Payroll System 1.0 A vulnerability was found in SourceCodester Online Payroll System 1.0. | 9.8 |
2023-04-05 | CVE-2023-1854 | Online Graduate Tracer System Project | Unspecified vulnerability in Online Graduate Tracer System Project Online Graduate Tracer System 1.0 A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. | 9.8 |
2023-04-05 | CVE-2023-1856 | AIR Cargo Management System Project | SQL Injection vulnerability in AIR Cargo Management System Project AIR Cargo Management System 1.0 A vulnerability has been found in SourceCodester Air Cargo Management System 1.0 and classified as critical. | 9.8 |
2023-04-05 | CVE-2023-1845 | Online Payroll System Project | Unspecified vulnerability in Online Payroll System Project Online Payroll System 1.0 A vulnerability, which was classified as critical, was found in SourceCodester Online Payroll System 1.0. | 9.8 |
2023-04-05 | CVE-2023-1846 | Online Payroll System Project | Unspecified vulnerability in Online Payroll System Project Online Payroll System 1.0 A vulnerability has been found in SourceCodester Online Payroll System 1.0 and classified as critical. | 9.8 |
2023-04-05 | CVE-2023-1847 | Online Payroll System Project | Unspecified vulnerability in Online Payroll System Project Online Payroll System 1.0 A vulnerability was found in SourceCodester Online Payroll System 1.0 and classified as critical. | 9.8 |
2023-04-05 | CVE-2023-1848 | Online Payroll System Project | Unspecified vulnerability in Online Payroll System Project Online Payroll System 1.0 A vulnerability was found in SourceCodester Online Payroll System 1.0. | 9.8 |
2023-04-05 | CVE-2023-29374 | Langchain | Injection vulnerability in Langchain In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec method. | 9.8 |
2023-04-04 | CVE-2023-27488 | Envoyproxy | Unspecified vulnerability in Envoyproxy Envoy Envoy is an open source edge and service proxy designed for cloud-native applications. | 9.8 |
2023-04-04 | CVE-2023-28613 | Samsung | Integer Overflow or Wraparound vulnerability in Samsung products An issue was discovered in Samsung Exynos Mobile Processor and Baseband Modem Processor for Exynos 1280, Exynos 2200, and Exynos Modem 5300. | 9.8 |
2023-04-04 | CVE-2020-19279 | Wide Project | Path Traversal vulnerability in Wide Project Wide Directory Traversal vulnerability found in B3log Wide allows a an attacker to escalate privileges via symbolic links. | 9.8 |
2023-04-04 | CVE-2020-19692 | Nginx | Classic Buffer Overflow vulnerability in Nginx NJS 20190627 Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_module.c file. | 9.8 |
2023-04-04 | CVE-2020-19693 | Espruino | Out-of-bounds Write vulnerability in Espruino 20190628 An issue found in Espruino Espruino 6ea4c0a allows an attacker to execute arbitrrary code via oldFunc parameter of the jswrap_object.c:jswrap_function_replacewith endpoint. | 9.8 |
2023-04-04 | CVE-2020-19695 | Nginx | Classic Buffer Overflow vulnerability in Nginx NJS Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c function. | 9.8 |
2023-04-04 | CVE-2020-20913 | Mingsoft | SQL Injection vulnerability in Mingsoft Mcms 4.7.2 SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic_title parameter. | 9.8 |
2023-04-04 | CVE-2020-20914 | Publiccms | SQL Injection vulnerability in Publiccms 4.0 SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter. | 9.8 |
2023-04-04 | CVE-2020-20915 | Publiccms | SQL Injection vulnerability in Publiccms 4.0 SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminControl. | 9.8 |
2023-04-04 | CVE-2021-28235 | Etcd | Improper Authentication vulnerability in Etcd 3.4.10 Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function. | 9.8 |
2023-04-04 | CVE-2021-31707 | Kitesky | Unrestricted Upload of File with Dangerous Type vulnerability in Kitesky Kitecms Permissions vulnerability found in KiteCMS allows a remote attacker to execute arbitrary code via the upload file type. | 9.8 |
2023-04-04 | CVE-2023-26921 | Quectel | OS Command Injection vulnerability in Quectel Ag550Qcn Firmware OS Command Injection vulnerability in quectel AG550QCN allows attackers to execute arbitrary commands via ql_atfwd. | 9.8 |
2023-04-04 | CVE-2020-29312 | Zend | Deserialization of Untrusted Data vulnerability in Zend Framework An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. | 9.8 |
2023-04-04 | CVE-2023-26750 | Yiiframework | SQL Injection vulnerability in Yiiframework YII SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. | 9.8 |
2023-04-04 | CVE-2023-26866 | Greenpacket | Command Injection vulnerability in Greenpacket Ot-235 Firmware and Wr-1200 Firmware GreenPacket OH736's WR-1200 Indoor Unit, OT-235 with firmware versions M-IDU-1.6.0.3_V1.1 and MH-46360-2.0.3-R5-GP respectively are vulnerable to remote command injection. | 9.8 |
2023-04-04 | CVE-2023-1827 | Centralized Covid Vaccination Records System Project | Unspecified vulnerability in Centralized Covid Vaccination Records System Project Centralized Covid Vaccination Records System 1.0 A vulnerability has been found in SourceCodester Centralized Covid Vaccination Records System 1.0 and classified as critical. | 9.8 |
2023-04-04 | CVE-2023-1671 | Sophos | Command Injection vulnerability in Sophos web Appliance A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code. | 9.8 |
2023-04-04 | CVE-2023-1826 | Oretnom23 | Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0 A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. | 9.8 |
2023-04-03 | CVE-2022-43939 | Hitachi | Unspecified vulnerability in Hitachi Vantara Pentaho Business Analytics Server 9.4.0.0 Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented. | 9.8 |
2023-04-03 | CVE-2022-38922 | ISS Oberlausitz | SQL Injection vulnerability in Iss-Oberlausitz Bluepage CMS 3.9 BluePage CMS thru 3.9 processes an insufficiently sanitized HTTP Header Cookie value allowing MySQL Injection in the 'users-cookie-settings' token using a Time-based blind SLEEP payload. | 9.8 |
2023-04-03 | CVE-2022-38923 | ISS Oberlausitz | SQL Injection vulnerability in Iss-Oberlausitz Bluepage CMS 3.9 BluePage CMS thru v3.9 processes an insufficiently sanitized HTTP Header allowing MySQL Injection in the 'User-Agent' field using a Time-based blind SLEEP payload. | 9.8 |
2023-04-03 | CVE-2023-26119 | Htmlunit | Unspecified vulnerability in Htmlunit Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage. | 9.8 |
2023-04-04 | CVE-2020-21487 | Netgate | Cross-site Scripting vulnerability in Netgate Pfsense and Pfsense Acme Package Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php. | 9.6 |
2023-04-09 | CVE-2023-1964 | Phpgurukul | Unspecified vulnerability in PHPgurukul Bank Locker Management System 1.0 A vulnerability classified as critical has been found in PHPGurukul Bank Locker Management System 1.0. | 9.1 |
2023-04-07 | CVE-2023-1940 | Simple AND Beautiful Shopping Cart System Project | Unspecified vulnerability in Simple and Beautiful Shopping Cart System Project Simple and Beautiful Shopping Cart System 1.0 A vulnerability classified as critical was found in SourceCodester Simple and Beautiful Shopping Cart System 1.0. | 9.1 |
2023-04-04 | CVE-2023-27493 | Envoyproxy | HTTP Request Smuggling vulnerability in Envoyproxy Envoy Envoy is an open source edge and service proxy designed for cloud-native applications. | 9.1 |
2023-04-04 | CVE-2023-27491 | Envoyproxy | HTTP Request Smuggling vulnerability in Envoyproxy Envoy Envoy is an open source edge and service proxy designed for cloud-native applications. | 9.1 |
2023-04-04 | CVE-2023-27487 | Envoyproxy | Unspecified vulnerability in Envoyproxy Envoy Envoy is an open source edge and service proxy designed for cloud-native applications. | 9.1 |
139 High Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2023-04-09 | CVE-2012-10010 | Bestwebsoft | Unspecified vulnerability in Bestwebsoft Contact Form 3.21 A vulnerability was found in BestWebSoft Contact Form 3.21. | 8.8 |
2023-04-08 | CVE-2013-10025 | Exit Strategy Project | Unspecified vulnerability in Exit Strategy Project Exit Strategy 1.55 A vulnerability was found in Exit Strategy Plugin 1.55 on WordPress and classified as problematic. | 8.8 |
2023-04-08 | CVE-2023-1960 | Oretnom23 | Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0 A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. | 8.8 |
2023-04-08 | CVE-2023-1957 | Oretnom23 | Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0 A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. | 8.8 |
2023-04-08 | CVE-2023-1959 | Oretnom23 | SQL Injection vulnerability in Oretnom23 Online Computer and Laptop Store 1.0 A vulnerability has been found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. | 8.8 |
2023-04-08 | CVE-2023-1953 | Oretnom23 | Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0 A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0. | 8.8 |
2023-04-08 | CVE-2023-1954 | Oretnom23 | Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0 A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0. | 8.8 |
2023-04-08 | CVE-2023-1956 | Oretnom23 | Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0 A vulnerability classified as critical was found in SourceCodester Online Computer and Laptop Store 1.0. | 8.8 |
2023-04-07 | CVE-2023-26817 | Pgyer | Unspecified vulnerability in Pgyer Codefever codefever before 2023.2.7-commit-b1c2e7f was discovered to contain a remote code execution (RCE) vulnerability via the component /controllers/api/user.php. | 8.8 |
2023-04-06 | CVE-2023-29008 | Svelte | Cross-Site Request Forgery (CSRF) vulnerability in Svelte Sveltekit 1.15.0/1.15.1 The SvelteKit framework offers developers an option to create simple REST APIs. | 8.8 |
2023-04-06 | CVE-2020-36071 | Tailor Management System Project | SQL Injection vulnerability in Tailor Management System Project Tailor Management System 1.0 SQL injection vulnerability found in Tailor Management System v.1 allows a remote authenticated attacker to execute arbitrary code via the customer parameter of the email.php page. | 8.8 |
2023-04-06 | CVE-2020-36072 | Tailor Management System Project | SQL Injection vulnerability in Tailor Management System Project Tailor Management System 1.0 SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via the id parameter. | 8.8 |
2023-04-06 | CVE-2020-36073 | Tailor Management System Project | SQL Injection vulnerability in Tailor Management System Project Tailor Management System 1.0 SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via the detail parameter of the document.php page. | 8.8 |
2023-04-06 | CVE-2020-36074 | Tailor Mangement System Project | SQL Injection vulnerability in Tailor Mangement System Project Tailor Mangement System 1.0 SQL injection vulnerability found in Tailor Mangement System v.1 allows a remote attacker to execute arbitrary code via the title parameter. | 8.8 |
2023-04-06 | CVE-2022-46793 | Adtribes | Unspecified vulnerability in Adtribes Product Feed PRO for Woocommerce Cross-Site Request Forgery (CSRF) vulnerability in AdTribes.Io Product Feed PRO for WooCommerce plugin <= 12.4.4 versions. | 8.8 |
2023-04-06 | CVE-2023-23801 | Hasthemes | Unspecified vulnerability in Hasthemes Really Simple Google TAG Manager Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Really Simple Google Tag Manager plugin <= 1.0.6 versions. | 8.8 |
2023-04-06 | CVE-2023-29421 | Bzip3 Project | Out-of-bounds Write vulnerability in Bzip3 Project Bzip3 An issue was discovered in libbzip3.a in bzip3 before 1.2.3. | 8.8 |
2023-04-05 | CVE-2022-31888 | Enhancesoft | Session Fixation vulnerability in Enhancesoft Osticket Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2. | 8.8 |
2023-04-05 | CVE-2022-4941 | Wclovers | Unspecified vulnerability in Wclovers Wcfm Membership The WCFM Membership plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.10 due to missing nonce checks on various AJAX actions. | 8.8 |
2023-04-05 | CVE-2023-20102 | Cisco | Deserialization of Untrusted Data vulnerability in Cisco products A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system. | 8.8 |
2023-04-05 | CVE-2023-1522 | Genetec | SQL Injection vulnerability in Genetec Security Center 5.11.2 SQL Injection in the Hardware Inventory report of Security Center 5.11.2. | 8.8 |
2023-04-05 | CVE-2023-29006 | Glpi Project | Unspecified vulnerability in Glpi-Project Order The Order GLPI plugin allows users to manage order management within GLPI. | 8.8 |
2023-04-05 | CVE-2022-4935 | Wclovers | Missing Authorization vulnerability in Wclovers Wcfm Marketplace The WCFM Marketplace plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 3.4.11 due to missing capability checks on various AJAX actions. | 8.8 |
2023-04-05 | CVE-2022-4936 | Wclovers | Unspecified vulnerability in Wclovers Wcfm Marketplace The WCFM Marketplace plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.11 due to missing nonce checks on various AJAX actions. | 8.8 |
2023-04-05 | CVE-2022-4937 | Wclovers | Missing Authorization vulnerability in Wclovers Frontend Manager for Woocommerce Along With Bookings Subscription Listings Compatible The WCFM Frontend Manager plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 6.6.0 due to missing capability checks on various AJAX actions. | 8.8 |
2023-04-05 | CVE-2022-4938 | Wclovers | Unspecified vulnerability in Wclovers Frontend Manager for Woocommerce Along With Bookings Subscription Listings Compatible The WCFM Frontend Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.6.0 due to missing nonce checks on various AJAX actions. | 8.8 |
2023-04-05 | CVE-2023-28634 | Glpi Project | Unspecified vulnerability in Glpi-Project Glpi GLPI is a free asset and IT management software package. | 8.8 |
2023-04-04 | CVE-2023-0480 | Vitalpbx | Cross-Site Request Forgery (CSRF) vulnerability in Vitalpbx 3.2.3 VitalPBX version 3.2.3-8 allows an unauthenticated external attacker to obtain the instance administrator's account. | 8.8 |
2023-04-04 | CVE-2023-0265 | Uvdesk | Unrestricted Upload of File with Dangerous Type vulnerability in Uvdesk Community-Skeleton 1.1.1 Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. | 8.8 |
2023-04-04 | CVE-2023-29003 | Svelte | Cross-Site Request Forgery (CSRF) vulnerability in Svelte Sveltekit 1.15.0 SvelteKit is a web development framework. | 8.8 |
2023-04-04 | CVE-2023-1810 | Google Fedoraproject Debian | Out-of-bounds Write vulnerability in multiple products Heap buffer overflow in Visuals in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | 8.8 |
2023-04-04 | CVE-2023-1811 | Google Fedoraproject Debian | Use After Free vulnerability in multiple products Use after free in Frames in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. | 8.8 |
2023-04-04 | CVE-2023-1812 | Google Fedoraproject Debian | Out-of-bounds Write vulnerability in multiple products Out of bounds memory access in DOM Bindings in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. | 8.8 |
2023-04-04 | CVE-2023-1815 | Google Fedoraproject Debian | Use After Free vulnerability in multiple products Use after free in Networking APIs in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. | 8.8 |
2023-04-04 | CVE-2023-1818 | Google Fedoraproject Debian | Use After Free vulnerability in multiple products Use after free in Vulkan in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 8.8 |
2023-04-04 | CVE-2023-1820 | Google Fedoraproject Debian | Out-of-bounds Write vulnerability in multiple products Heap buffer overflow in Browser History in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. | 8.8 |
2023-04-04 | CVE-2020-19278 | MM Wiki Project | Cross-Site Request Forgery (CSRF) vulnerability in Mm-Wiki Project Mm-Wiki 0.1.2 Cross Site Request Forgery vulnerability found in Phachon mm-wiki v.0.1.2 allows a remote attacker to execute arbitrary code via the system/user/save parameter. | 8.8 |
2023-04-04 | CVE-2020-21060 | Phpmywind | SQL Injection vulnerability in PHPmywind 5.6 SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function of the administrator management page. | 8.8 |
2023-04-04 | CVE-2020-21514 | Fluentd | Unspecified vulnerability in Fluentd and Fluentd-Ui An issue was discovered in Fluent Fluentd v.1.8.0 and Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code due to a default password. | 8.8 |
2023-04-04 | CVE-2023-25355 | Coredial | Incorrect Default Permissions vulnerability in Coredial Sipxcom CoreDial sipXcom up to and including 21.04 is vulnerable to Insecure Permissions. | 8.8 |
2023-04-04 | CVE-2023-25356 | Coredial | Argument Injection or Modification vulnerability in Coredial Sipxcom CoreDial sipXcom up to and including 21.04 is vulnerable to Improper Neutralization of Argument Delimiters in a Command. | 8.8 |
2023-04-04 | CVE-2022-41633 | Peepso | Unspecified vulnerability in Peepso Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin <= 6.0.2.0 versions. | 8.8 |
2023-04-03 | CVE-2022-43938 | Hitachi | Code Injection vulnerability in Hitachi Vantara Pentaho Business Analytics Server 9.4.0.0 Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of Pentaho Reports (*.prpt) through the JVM script manager. | 8.8 |
2023-04-03 | CVE-2022-43940 | Hitachi | Incorrect Authorization vulnerability in Hitachi Vantara Pentaho Business Analytics Server 9.4.0.0 Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly perform an authorization check in the data source management service. | 8.8 |
2023-04-03 | CVE-2023-28854 | Nophp Project | Unspecified vulnerability in Nophp Project Nophp nophp is a PHP web framework. | 8.8 |
2023-04-03 | CVE-2022-43773 | Hitachi | Incorrect Permission Assignment for Critical Resource vulnerability in Hitachi Vantara Pentaho Business Analytics Server 9.4.0.0 Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x is installed with a sample HSQLDB data source configured with stored procedures enabled. | 8.8 |
2023-04-03 | CVE-2022-38072 | Admesh Project Slic3R | Improper Validation of Array Index vulnerability in multiple products An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. | 8.8 |
2023-04-03 | CVE-2023-0820 | Bestwebsoft | Unspecified vulnerability in Bestwebsoft User Role The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role. | 8.8 |
2023-04-04 | CVE-2023-28840 | Mobyproject | Unspecified vulnerability in Mobyproject Moby Moby is an open source container framework developed by Docker Inc. | 8.7 |
2023-04-04 | CVE-2023-0835 | Markdown PDF Project | Cross-site Scripting vulnerability in Markdown-Pdf Project Markdown-Pdf 11.0.0 markdown-pdf version 11.0.0 allows an external attacker to remotely obtain arbitrary local files. | 8.2 |
2023-04-04 | CVE-2023-27089 | Ehuacui BBS Project | Cross-site Scripting vulnerability in Ehuacui-Bbs Project Ehuacui-Bbs Cross Site Scripting vulnerability found in Ehuacui BBS allows attackers to cause a denial of service via a crafted payload in the login parameter. | 8.2 |
2023-04-07 | CVE-2022-33959 | IBM | Unspecified vulnerability in IBM Sterling Order Management 10 IBM Sterling Order Management 10.0 could allow a user to bypass validation and perform unauthorized actions on behalf of other users. | 8.1 |
2023-04-05 | CVE-2023-28838 | Glpi Project | Unspecified vulnerability in Glpi-Project Glpi GLPI is a free asset and IT management software package. | 8.1 |
2023-04-05 | CVE-2023-28632 | Glpi Project | Unspecified vulnerability in Glpi-Project Glpi GLPI is a free asset and IT management software package. | 8.1 |
2023-04-07 | CVE-2023-28051 | Dell | Unspecified vulnerability in Dell Power Manager 3.10/3.3 Dell Power Manager, versions 3.10 and prior, contains an Improper Access Control vulnerability. | 7.8 |
2023-04-06 | CVE-2023-20655 | Improper Privilege Management vulnerability in Google Android In mmsdk, there is a possible escalation of privilege due to a parcel format mismatch. | 7.8 | |
2023-04-06 | CVE-2023-0652 | Cloudflare | Link Following vulnerability in Cloudflare Warp Due to a hardlink created in the ProgramData folder during the repair process of the software, the installer (MSI) of WARP Client for Windows (<= 2022.12.582.0) allowed a malicious attacker to forge the destination of the hardlink and escalate privileges, overwriting SYSTEM protected files. As Cloudflare WARP client for Windows (up to version 2022.5.309.0) allowed creation of mount points from its ProgramData folder, during installation of the WARP client, it was possible to escalate privileges and overwrite SYSTEM protected files. | 7.8 |
2023-04-06 | CVE-2023-25542 | Dell | Unspecified vulnerability in Dell Trusted Device Agent Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability. | 7.8 |
2023-04-05 | CVE-2023-20122 | Cisco | OS Command Injection vulnerability in Cisco Identity Services Engine 3.2 Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system. | 7.8 |
2023-04-05 | CVE-2022-43664 | Justsystems | Unspecified vulnerability in Justsystems Ichitaro 2022 1.0.1.57600 A use-after-free vulnerability exists within the way Ichitaro Word Processor 2022, version 1.0.1.57600, processes protected documents. | 7.8 |
2023-04-05 | CVE-2022-45115 | Justsystems | Unspecified vulnerability in Justsystems Ichitaro 2022 1.0.1.57600 A buffer overflow vulnerability exists in the Attribute Arena functionality of Ichitaro 2022 1.0.1.57600. | 7.8 |
2023-04-05 | CVE-2023-22291 | Justsystems | Unspecified vulnerability in Justsystems Ichitaro 2022 1.0.1.57600 An invalid free vulnerability exists in the Frame stream parser functionality of Ichitaro 2022 1.0.1.57600. | 7.8 |
2023-04-05 | CVE-2023-22660 | Justsystems | Unspecified vulnerability in Justsystems Ichitaro 2022 1.0.1.57600 A heap-based buffer overflow vulnerability exists in the way Ichitaro version 2022 1.0.1.57600 processes certain LayoutBox stream record types. | 7.8 |
2023-04-05 | CVE-2023-1412 | Cloudflare | Link Following vulnerability in Cloudflare Warp An unprivileged (non-admin) user can exploit an Improper Access Control vulnerability in the Cloudflare WARP Client for Windows (<= 2022.12.582.0) to perform privileged operations with SYSTEM context by working with a combination of opportunistic locks (oplock) and symbolic links (which can both be created by an unprivileged user). After installing the Cloudflare WARP Client (admin privileges required), an MSI-Installer is placed under C:\Windows\Installer. | 7.8 |
2023-04-04 | CVE-2023-29323 | Openbsd Opensmtpd | ascii_load_sockaddr in smtpd in OpenBSD before 7.1 errata 024 and 7.2 before errata 020, and OpenSMTPD Portable before 7.0.0-portable commit f748277, can abort upon a connection from a local, scoped IPv6 address. | 7.8 |
2023-04-04 | CVE-2022-48222 | Gbgplc | Uncontrolled Search Path Element vulnerability in Gbgplc Acuant Acufill SDK An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. | 7.8 |
2023-04-04 | CVE-2022-48227 | Gbgplc | Improper Privilege Management vulnerability in Gbgplc Acuant Asureid Sentinel An issue was discovered in Acuant AsureID Sentinel before 5.2.149. | 7.8 |
2023-04-04 | CVE-2022-48226 | Gbgplc | Improper Privilege Management vulnerability in Gbgplc Acuant Acufill SDK An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. | 7.8 |
2023-04-04 | CVE-2023-26733 | Tinytiff Project | Classic Buffer Overflow vulnerability in Tinytiff Project Tinytiff 3.0.0.0 Buffer Overflow vulnerability found in tinyTIFF v.3.0 allows a local attacker to cause a denial of service via the TinyTiffReader_readNextFrame function in tinytiffreader.c file. | 7.8 |
2023-04-04 | CVE-2023-26991 | Swftools | Use After Free vulnerability in Swftools 0.9.2 SWFTools v0.9.2 was discovered to contain a stack-use-after-scope in the swf_ReadSWF2 function in lib/rfxswf.c. | 7.8 |
2023-04-04 | CVE-2023-27759 | Wondershare | Untrusted Search Path vulnerability in Wondershare Edrawmind 10.0.6 An issue found in Wondershare Technology Co, Ltd Edrawmind v.10.0.6 allows a remote attacker to executea arbitrary commands via the WindowsCodescs.dll file. | 7.8 |
2023-04-04 | CVE-2023-27760 | Wondershare | Untrusted Search Path vulnerability in Wondershare Filmora 12.0.9 An issue found in Wondershare Technology Co, Ltd Filmora v.12.0.9 allows a remote attacker to execute arbitrary commands via the filmora_setup_full846.exe. | 7.8 |
2023-04-04 | CVE-2023-27761 | Wondershare | Untrusted Search Path vulnerability in Wondershare Uniconverter 14.0.0 An issue found in Wondershare Technology Co., Ltd UniConverter v.14.0.0 allows a remote attacker to execute arbitrary commands via the uniconverter14_64bit_setup_full14204.exe file. | 7.8 |
2023-04-04 | CVE-2023-27762 | Wondershare | Untrusted Search Path vulnerability in Wondershare Democreator 6.0.0 An issue found in Wondershare Technology Co., Ltd DemoCreator v.6.0.0 allows a remote attacker to execute arbitrary commands via the democreator_setup_full7743.exe file. | 7.8 |
2023-04-04 | CVE-2023-27763 | Wondershare | Untrusted Search Path vulnerability in Wondershare Mobiletrans 4.0.2 An issue found in Wondershare Technology Co.,Ltd MobileTrans v.4.0.2 allows a remote attacker to execute arbitrary commands via the mobiletrans_setup_full5793.exe file. | 7.8 |
2023-04-04 | CVE-2023-27764 | Wondershare | Untrusted Search Path vulnerability in Wondershare Repairit 3.5.4 An issue found in Wondershare Technology Co.,Ltd Repairit v.3.5.4 allows a remote attacker to execute arbitrary commands via the repairit_setup_full5913.exe file. | 7.8 |
2023-04-04 | CVE-2023-27765 | Wondershare | Untrusted Search Path vulnerability in Wondershare Recoverit 10.6.3 An issue found in Wondershare Technology Co.,Ltd Recoverit v.10.6.3 allows a remote attacker to execute arbitrary commands via the recoverit_setup_full4134.exe file. | 7.8 |
2023-04-04 | CVE-2023-27766 | Wondershare | Untrusted Search Path vulnerability in Wondershare Anireel 1.5.4 An issue found in Wondershare Technology Co.,Ltd Anireel 1.5.4 allows a remote attacker to execute arbitrary commands via the anireel_setup_full9589.exe file. | 7.8 |
2023-04-04 | CVE-2023-27767 | Wondershare | Untrusted Search Path vulnerability in Wondershare Dr.Fone 12.4.9 An issue found in Wondershare Technology Co.,Ltd Dr.Fone v.12.4.9 allows a remote attacker to execute arbitrary commands via the drfone_setup_full3360.exe file. | 7.8 |
2023-04-04 | CVE-2023-27768 | Wondershare | Untrusted Search Path vulnerability in Wondershare Pdfelement 9.1.1 An issue found in Wondershare Technology Co.,Ltd PDFelement v9.1.1 allows a remote attacker to execute arbitrary commands via the pdfelement-pro_setup_full5239.exe file. | 7.8 |
2023-04-04 | CVE-2023-27769 | Wondershare | Untrusted Search Path vulnerability in Wondershare PDF Reader 1.0.1 An issue found in Wondershare Technology Co.,Ltd PDF Reader v.1.0.1 allows a remote attacker to execute arbitrary commands via the pdfreader_setup_full13143.exe file. | 7.8 |
2023-04-04 | CVE-2023-27770 | Wondershare | Untrusted Search Path vulnerability in Wondershare Edraw-Max 12.0.4 An issue found in Wondershare Technology Co.,Ltd Edraw-max v.12.0.4 allows a remote attacker to execute arbitrary commands via the edraw-max_setup_full5371.exe file. | 7.8 |
2023-04-04 | CVE-2023-27771 | Wondershare | Untrusted Search Path vulnerability in Wondershare Creative Centerr 1.0.8 An issue found in Wondershare Technology Co.,Ltd Creative Centerr v.1.0.8 allows a remote attacker to execute arbitrary commands via the wondershareCC_setup_full10819.exe file. | 7.8 |
2023-04-04 | CVE-2023-26775 | Monitorr | Unrestricted Upload of File with Dangerous Type vulnerability in Monitorr 1.7.6M File Upload vulnerability found in Monitorr v.1.7.6 allows a remote attacker t oexecute arbitrary code via a crafted file upload to the assets/php/upload.php endpoint. | 7.8 |
2023-04-04 | CVE-2023-25941 | Dell | Unspecified vulnerability in Dell EMC Powerscale Onefs Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability. | 7.8 |
2023-04-04 | CVE-2023-25940 | Dell | Unspecified vulnerability in Dell EMC Powerscale Onefs 9.5.0.0 Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access vulnerability in isi_gather_info. | 7.8 |
2023-04-03 | CVE-2023-1579 | GNU | Out-of-bounds Write vulnerability in GNU Binutils 2.39 Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64. | 7.8 |
2023-04-03 | CVE-2023-0975 | Trellix | Improper Preservation of Permissions vulnerability in Trellix Agent 5.7.7/5.7.8 A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace one of the Agent’s executables before it can be executed. | 7.8 |
2023-04-03 | CVE-2023-26269 | Apache | Unspecified vulnerability in Apache James Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. | 7.8 |
2023-04-09 | CVE-2023-27727 | F5 | Out-of-bounds Read vulnerability in F5 NJS 0.7.10 Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_function_frame at src/njs_function.h. | 7.5 |
2023-04-09 | CVE-2023-27728 | F5 | Out-of-bounds Read vulnerability in F5 NJS 0.7.10 Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_dump_is_recursive at src/njs_vmcode.c. | 7.5 |
2023-04-09 | CVE-2023-27729 | F5 | Unspecified vulnerability in F5 NJS 0.7.10 Nginx NJS v0.7.10 was discovered to contain an illegal memcpy via the function njs_vmcode_return at src/njs_vmcode.c. | 7.5 |
2023-04-09 | CVE-2023-27730 | F5 | Out-of-bounds Read vulnerability in F5 NJS 0.7.10 Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_lvlhsh_find at src/njs_lvlhsh.c. | 7.5 |
2023-04-08 | CVE-2013-10024 | Exit Strategy Project | Unspecified vulnerability in Exit Strategy Project Exit Strategy 1.55 A vulnerability has been found in Exit Strategy Plugin 1.55 on WordPress and classified as problematic. | 7.5 |
2023-04-07 | CVE-2023-27180 | Gdidees | Unspecified vulnerability in Gdidees CMS 3.9.1 GDidees CMS v3.9.1 was discovered to contain a source code disclosure vulnerability by the backup feature which is accessible via /_admin/backup.php. | 7.5 |
2023-04-07 | CVE-2023-28707 | Apache | Improper Input Validation vulnerability in Apache Apache-Airflow-Providers-Apache-Drill Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider: before 2.3.2. | 7.5 |
2023-04-07 | CVE-2023-28710 | Apache | Improper Input Validation vulnerability in Apache Apache-Airflow-Providers-Apache-Spark Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Spark Provider.This issue affects Apache Airflow Spark Provider: before 4.0.1. | 7.5 |
2023-04-07 | CVE-2022-34333 | IBM | Unspecified vulnerability in IBM Sterling Order Management 10 IBM Sterling Order Management 10.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. | 7.5 |
2023-04-07 | CVE-2023-26820 | Siteproxy Project | Path Traversal vulnerability in Siteproxy Project Siteproxy 1.0 siteproxy v1.0 was discovered to contain a path traversal vulnerability via the component index.js. | 7.5 |
2023-04-06 | CVE-2020-19678 | Oisf Pfsense | Path Traversal vulnerability in multiple products Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain sensitive information via the file parameter to suricata/suricata_logs_browser.php. | 7.5 |
2023-04-06 | CVE-2023-24537 | Golang | Integer Overflow or Wraparound vulnerability in Golang GO Calling any of the Parse functions on Go source code which contains //line directives with very large line numbers can cause an infinite loop due to integer overflow. | 7.5 |
2023-04-06 | CVE-2023-24534 | Golang | Resource Exhaustion vulnerability in Golang GO HTTP and MIME header parsing can allocate large amounts of memory, even when parsing small inputs, potentially leading to a denial of service. | 7.5 |
2023-04-06 | CVE-2023-24536 | Golang | Allocation of Resources Without Limits or Throttling vulnerability in Golang GO Multipart form parsing can consume large amounts of CPU and memory when processing form inputs containing very large numbers of parts. | 7.5 |
2023-04-06 | CVE-2023-1802 | Docker | Cleartext Transmission of Sensitive Information vulnerability in Docker Desktop 4.17.0/4.17.1 In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed. A targeted network sniffing attack can lead to a disclosure of sensitive information. | 7.5 |
2023-04-05 | CVE-2023-1733 | Gitlab | Unspecified vulnerability in Gitlab A denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 15.8.5, 15.9 to 15.9.4 and 15.10 to 15.10.1. | 7.5 |
2023-04-05 | CVE-2023-28342 | Zohocorp | Unspecified vulnerability in Zohocorp Manageengine Adselfservice Plus Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API. | 7.5 |
2023-04-05 | CVE-2023-20051 | Cisco | Unspecified vulnerability in Cisco Packet Data Network Gateway 21.26.0/21.27.0 A vulnerability in the Vector Packet Processor (VPP) of Cisco Packet Data Network Gateway (PGW) could allow an unauthenticated, remote attacker to stop ICMP traffic from being processed over an IPsec connection. | 7.5 |
2023-04-05 | CVE-2023-1858 | Earnings AND Expense Tracker APP Project | Unspecified vulnerability in Earnings and Expense Tracker APP Project Earnings and Expense Tracker APP 1.0 A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0. | 7.5 |
2023-04-04 | CVE-2023-27496 | Envoyproxy | Unspecified vulnerability in Envoyproxy Envoy Envoy is an open source edge and service proxy designed for cloud-native applications. | 7.5 |
2023-04-04 | CVE-2020-23257 | Espruino | Classic Buffer Overflow vulnerability in Espruino 2.05.41 Buffer Overflow vulnerability found in Espruino 2v05.41 allows an attacker to cause a denial of service via the function jsvGarbageCollectMarkUsed in file src/jsvar.c. | 7.5 |
2023-04-04 | CVE-2020-23258 | Jsish | Out-of-bounds Write vulnerability in Jsish 3.0.11 An issue found in Jsish v.3.0.11 allows a remote attacker to cause a denial of service via the Jsi_ValueIsNumber function in ./src/jsiValue.c file. | 7.5 |
2023-04-04 | CVE-2020-23259 | Jsish | NULL Pointer Dereference vulnerability in Jsish An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the Jsi_Strlen function in the src/jsiChar.c file. | 7.5 |
2023-04-04 | CVE-2020-23260 | Jsish | Out-of-bounds Write vulnerability in Jsish An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the StringReplaceCmd function in the src/jsiChar.c file. | 7.5 |
2023-04-04 | CVE-2022-48221 | Gbgplc | Race Condition vulnerability in Gbgplc Acuant Acufill SDK An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. | 7.5 |
2023-04-04 | CVE-2023-26855 | Churchcrm | Use of Insufficiently Random Values vulnerability in Churchcrm 4.5.3 The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers to use precomputed hash tables or dictionary attacks to crack the hashed passwords. | 7.5 |
2023-04-04 | CVE-2023-26976 | Tenda | Out-of-bounds Write vulnerability in Tenda AC6 Firmware 15.03.05.09 Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function. | 7.5 |
2023-04-03 | CVE-2023-29218 | Unspecified vulnerability in Twitter Recommendation Algorithm 20230331 The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arranging for multiple Twitter accounts to coordinate negative signals regarding a target account, such as unfollowing, muting, blocking, and reporting, as exploited in the wild in March and April 2023. | 7.5 | |
2023-04-03 | CVE-2022-36440 | Frrouting Fedoraproject Debian | Reachable Assertion vulnerability in multiple products A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. | 7.5 |
2023-04-03 | CVE-2023-28625 | Openidc | Unspecified vulnerability in Openidc MOD Auth Openidc mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. | 7.5 |
2023-04-04 | CVE-2022-48224 | Gbgplc | Uncontrolled Search Path Element vulnerability in Gbgplc Acuant Acufill SDK An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. | 7.3 |
2023-04-04 | CVE-2022-48225 | Gbgplc | Uncontrolled Search Path Element vulnerability in Gbgplc Acuant Acufill SDK An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. | 7.3 |
2023-04-05 | CVE-2023-0670 | Ulearn Project | Unrestricted Upload of File with Dangerous Type vulnerability in Ulearn Project Ulearn Ulearn version a5a7ca20de859051ea0470542844980a66dfc05d allows an attacker with administrator permissions to obtain remote code execution on the server through the image upload functionality. | 7.2 |
2023-04-05 | CVE-2023-20103 | Cisco | Improper Input Validation vulnerability in Cisco Secure Network Analytics 2.1.1/7.4.1 A vulnerability in Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary code as a root user on an affected device. | 7.2 |
2023-04-05 | CVE-2023-20117 | Cisco | OS Command Injection vulnerability in Cisco Rv320 Firmware and Rv325 Firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. | 7.2 |
2023-04-05 | CVE-2023-20124 | Cisco | Command Injection vulnerability in Cisco products A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. | 7.2 |
2023-04-05 | CVE-2023-20128 | Cisco | OS Command Injection vulnerability in Cisco Rv320 Firmware and Rv325 Firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. | 7.2 |
2023-04-05 | CVE-2023-26856 | Dynamic Transaction Queuing System Project | SQL Injection vulnerability in Dynamic Transaction Queuing System Project Dynamic Transaction Queuing System 1.0 Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/ajax.php?action=login. | 7.2 |
2023-04-05 | CVE-2023-26857 | Dynamic Transaction Queuing System Project | Unrestricted Upload of File with Dangerous Type vulnerability in Dynamic Transaction Queuing System Project Dynamic Transaction Queuing System 1.0 An arbitrary file upload vulnerability in /admin/ajax.php?action=save_uploads of Dynamic Transaction Queuing System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | 7.2 |
2023-04-04 | CVE-2023-27091 | Teacms Project | Improper Authentication vulnerability in Teacms Project Teacms 2.3.3 An unauthorized access issue found in XiaoBingby TeaCMS 2.3.3 allows attackers to escalate privileges via the id and keywords parameter(s). | 7.2 |
2023-04-04 | CVE-2021-3267 | Kitesky | Unrestricted Upload of File with Dangerous Type vulnerability in Kitesky Kitecms 1.1 File Upload vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the uploadFile function. | 7.2 |
2023-04-04 | CVE-2022-4934 | Sophos | Command Injection vulnerability in Sophos web Appliance A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to execute arbitrary code. | 7.2 |
2023-04-03 | CVE-2022-43769 | Hitachi | Code Injection vulnerability in Hitachi Vantara Pentaho Business Analytics Server 9.4.0.0 Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream. | 7.2 |
2023-04-03 | CVE-2023-1124 | Wpeasycart | Unspecified vulnerability in Wpeasycart WP Easycart The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticated users with admin privileges to perform LFI attacks. | 7.2 |
2023-04-07 | CVE-2023-27876 | IBM | Unspecified vulnerability in IBM Tririga Application Platform 4.0 IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. | 7.1 |
2023-04-06 | CVE-2023-28046 | Dell | Unspecified vulnerability in Dell Display Manager 2.0.0/2.1.0 Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder deletion vulnerability during uninstallation A local low privilege attacker could potentially exploit this vulnerability, leading to the deletion of arbitrary files on the operating system with high privileges. | 7.1 |
2023-04-05 | CVE-2023-1838 | Linux Netapp | Use After Free vulnerability in multiple products A use-after-free flaw was found in vhost_net_set_backend in drivers/vhost/net.c in virtio network subcomponent in the Linux kernel due to a double fget. | 7.1 |
2023-04-04 | CVE-2023-1750 | Getnexx | Authorization Bypass Through User-Controlled Key vulnerability in Getnexx products The listed versions of Nexx Smart Home devices lack proper access control when executing actions. | 7.1 |
2023-04-04 | CVE-2023-25303 | Atlauncher | Path Traversal vulnerability in Atlauncher ATLauncher <= 3.4.26.0 is vulnerable to Directory Traversal. | 7.1 |
2023-04-04 | CVE-2023-25305 | Polymc | Path Traversal vulnerability in Polymc PolyMC Launcher <= 1.4.3 is vulnerable to Directory Traversal. | 7.1 |
306 Medium Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2023-04-05 | CVE-2023-29389 | Toyota | Injection vulnerability in Toyota Rav4 Firmware 2021 Toyota RAV4 2021 vehicles automatically trust messages from other ECUs on a CAN bus, which allows physically proximate attackers to drive a vehicle by accessing the control CAN bus after pulling the bumper away and reaching the headlight connector, and then sending forged "Key is validated" messages via CAN Injection, as exploited in the wild in (for example) July 2022. | 6.8 |
2023-04-04 | CVE-2023-28841 | Mobyproject | Unspecified vulnerability in Mobyproject Moby Moby is an open source container framework developed by Docker Inc. | 6.8 |
2023-04-04 | CVE-2023-28842 | Mobyproject | Unspecified vulnerability in Mobyproject Moby Moby) is an open source container framework developed by Docker Inc. | 6.8 |
2023-04-06 | CVE-2022-32599 | Out-of-bounds Write vulnerability in Google Android In rpmb, there is a possible out of bounds write due to a logic error. | 6.7 | |
2023-04-06 | CVE-2023-20652 | Out-of-bounds Write vulnerability in Google Android In keyinstall, there is a possible out of bounds write due to a missing bounds check. | 6.7 | |
2023-04-06 | CVE-2023-20653 | Out-of-bounds Write vulnerability in Google Android In keyinstall, there is a possible out of bounds write due to a missing bounds check. | 6.7 | |
2023-04-06 | CVE-2023-20654 | Out-of-bounds Write vulnerability in Google Android In keyinstall, there is a possible out of bounds write due to a missing bounds check. | 6.7 | |
2023-04-06 | CVE-2023-20656 | Out-of-bounds Write vulnerability in Google Android In geniezone, there is a possible out of bounds write due to a logic error. | 6.7 | |
2023-04-06 | CVE-2023-20657 | Out-of-bounds Write vulnerability in Google Android In mtee, there is a possible out of bounds write due to a missing bounds check. | 6.7 | |
2023-04-06 | CVE-2023-20658 | Out-of-bounds Write vulnerability in Google Android 12.0/13.0 In isp, there is a possible out of bounds write due to a missing bounds check. | 6.7 | |
2023-04-06 | CVE-2023-20659 | Google Yoctoproject Linux | Out-of-bounds Write vulnerability in multiple products In wlan, there is a possible out of bounds write due to a missing bounds check. | 6.7 |
2023-04-06 | CVE-2023-20661 | Google Yoctoproject Linux | Integer Overflow or Wraparound vulnerability in multiple products In wlan, there is a possible out of bounds write due to an integer overflow. | 6.7 |
2023-04-06 | CVE-2023-20662 | Google Yoctoproject Linux | Integer Overflow or Wraparound vulnerability in multiple products In wlan, there is a possible out of bounds write due to an integer overflow. | 6.7 |
2023-04-06 | CVE-2023-20663 | Google Yoctoproject Linux | Integer Overflow or Wraparound vulnerability in multiple products In wlan, there is a possible out of bounds write due to an integer overflow. | 6.7 |
2023-04-06 | CVE-2023-20664 | Use After Free vulnerability in Google Android In gz, there is a possible double free due to a use after free. | 6.7 | |
2023-04-06 | CVE-2023-20666 | Out-of-bounds Write vulnerability in Google Android 12.0/13.0 In display drm, there is a possible out of bounds write due to a missing bounds check. | 6.7 | |
2023-04-06 | CVE-2023-20670 | Out-of-bounds Write vulnerability in Google Android 12.0/13.0 In audio, there is a possible out of bounds write due to a missing bounds check. | 6.7 | |
2023-04-06 | CVE-2023-20680 | Unspecified vulnerability in Google Android 11.0/12.0/13.0 In adsp, there is a possible out of bounds write due to improper input validation. | 6.7 | |
2023-04-06 | CVE-2023-20681 | Out-of-bounds Write vulnerability in Google Android 12.0/13.0 In adsp, there is a possible out of bounds write due to improper input validation. | 6.7 | |
2023-04-06 | CVE-2023-20682 | Google Yoctoproject Linux | Integer Overflow or Wraparound vulnerability in multiple products In wlan, there is a possible out of bounds write due to an integer overflow. | 6.7 |
2023-04-05 | CVE-2023-20121 | Cisco | OS Command Injection vulnerability in Cisco Identity Services Engine and Prime Infrastructure Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system. | 6.7 |
2023-04-05 | CVE-2023-20153 | Cisco | OS Command Injection vulnerability in Cisco Identity Services Engine 3.2 Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. | 6.7 |
2023-04-05 | CVE-2023-20152 | Cisco | OS Command Injection vulnerability in Cisco Identity Services Engine 3.2 Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. | 6.7 |
2023-04-05 | CVE-2023-20022 | Cisco | OS Command Injection vulnerability in Cisco Identity Services Engine 3.2 Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. | 6.7 |
2023-04-05 | CVE-2023-20023 | Cisco | OS Command Injection vulnerability in Cisco Identity Services Engine 3.2 Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. | 6.7 |
2023-04-05 | CVE-2023-20021 | Cisco | OS Command Injection vulnerability in Cisco Identity Services Engine 3.2 Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. | 6.7 |
2023-04-04 | CVE-2022-48223 | Gbgplc | Uncontrolled Search Path Element vulnerability in Gbgplc Acuant Acufill SDK An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. | 6.7 |
2023-04-08 | CVE-2023-24626 | GNU | Unspecified vulnerability in GNU Screen socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process. | 6.5 |
2023-04-07 | CVE-2023-1801 | Tcpdump | Out-of-bounds Write vulnerability in Tcpdump 4.99.3 The SMB protocol decoder in tcpdump version 4.99.3 can perform an out-of-bounds write when decoding a crafted network packet. | 6.5 |
2023-04-07 | CVE-2023-1909 | Phpgurukul | Unspecified vulnerability in PHPgurukul BP Monitoring Management System 1.0 A vulnerability, which was classified as critical, was found in PHPGurukul BP Monitoring Management System 1.0. | 6.5 |
2023-04-07 | CVE-2022-43928 | IBM | Unspecified vulnerability in IBM DB2 Mirror for I 7.4/7.5 The IBM Toolbox for Java (Db2 Mirror for i 7.4 and 7.5) could allow a user to obtain sensitive information, caused by utilizing a Java string for processing. | 6.5 |
2023-04-06 | CVE-2023-29010 | Budibase | Unspecified vulnerability in Budibase Budibase is a low code platform for creating internal tools, workflows, and admin panels. | 6.5 |
2023-04-06 | CVE-2023-29415 | Bzip3 Project Debian | An issue was discovered in libbzip3.a in bzip3 before 1.3.0. | 6.5 |
2023-04-06 | CVE-2023-29416 | Bzip3 Project | Out-of-bounds Write vulnerability in Bzip3 Project Bzip3 An issue was discovered in libbzip3.a in bzip3 before 1.3.0. | 6.5 |
2023-04-06 | CVE-2023-29417 | Bzip3 Project | Out-of-bounds Read vulnerability in Bzip3 Project Bzip3 1.2.2 An issue was discovered in libbzip3.a in bzip3 1.2.2. | 6.5 |
2023-04-06 | CVE-2023-29418 | Bzip3 Project | Out-of-bounds Read vulnerability in Bzip3 Project Bzip3 An issue was discovered in libbzip3.a in bzip3 before 1.2.3. | 6.5 |
2023-04-06 | CVE-2023-29419 | Bzip3 Project | Out-of-bounds Read vulnerability in Bzip3 Project Bzip3 An issue was discovered in libbzip3.a in bzip3 before 1.2.3. | 6.5 |
2023-04-06 | CVE-2023-29420 | Bzip3 Project | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Bzip3 Project Bzip3 An issue was discovered in libbzip3.a in bzip3 before 1.2.3. | 6.5 |
2023-04-05 | CVE-2023-0959 | Imaworldhealth | Improper Privilege Management vulnerability in Imaworldhealth Bhima 1.27.0 Bhima version 1.27.0 allows a remote attacker to update the privileges of any account registered in the application via a malicious link sent to an administrator. | 6.5 |
2023-04-05 | CVE-2023-0967 | Imaworldhealth | Authorization Bypass Through User-Controlled Key vulnerability in Imaworldhealth Bhima 1.27.0 Bhima version 1.27.0 allows an attacker authenticated with normal user permissions to view sensitive data of other application users and data that should only be viewed by the administrator. | 6.5 |
2023-04-05 | CVE-2022-4940 | Wclovers | Unspecified vulnerability in Wclovers Wcfm Membership The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks on various AJAX actions. | 6.5 |
2023-04-05 | CVE-2023-28855 | Teclib Edition | Improper Privilege Management vulnerability in Teclib-Edition Fields Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. | 6.5 |
2023-04-05 | CVE-2023-20127 | Cisco | Unspecified vulnerability in Cisco Prime Infrastructure Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. | 6.5 |
2023-04-05 | CVE-2023-20129 | Cisco | Path Traversal vulnerability in Cisco Prime Infrastructure Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. | 6.5 |
2023-04-05 | CVE-2023-20130 | Cisco | Cross-Site Request Forgery (CSRF) vulnerability in Cisco Prime Infrastructure Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. | 6.5 |
2023-04-05 | CVE-2023-20134 | Cisco | Unrestricted Upload of File with Dangerous Type vulnerability in Cisco Webex Meetings Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack or upload arbitrary files as recordings. | 6.5 |
2023-04-05 | CVE-2023-1865 | Plugin | Unspecified vulnerability in Plugin Yourchannel 1.2.3 The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when resetting plugin settings via the yrc_nuke GET parameter in versions up to, and including, 1.2.3. | 6.5 |
2023-04-05 | CVE-2023-0382 | M Files | Resource Exhaustion vulnerability in M-Files Server User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption. | 6.5 |
2023-04-04 | CVE-2023-1813 | Google Fedoraproject Debian | Inappropriate implementation in Extensions in Google Chrome prior to 112.0.5615.49 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. | 6.5 |
2023-04-04 | CVE-2023-1814 | Google Fedoraproject Debian | Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass download checking via a crafted HTML page. | 6.5 |
2023-04-04 | CVE-2023-1816 | Google Fedoraproject Debian | Incorrect security UI in Picture In Picture in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially perform navigation spoofing via a crafted HTML page. | 6.5 |
2023-04-04 | CVE-2023-1817 | Google Fedoraproject Debian | Insufficient policy enforcement in Intents in Google Chrome on Android prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | 6.5 |
2023-04-04 | CVE-2023-1819 | Google Fedoraproject Debian | Out-of-bounds Read vulnerability in multiple products Out of bounds read in Accessibility in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. | 6.5 |
2023-04-04 | CVE-2023-1821 | Google Fedoraproject Debian | Inappropriate implementation in WebShare in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page. | 6.5 |
2023-04-04 | CVE-2023-1822 | Google Fedoraproject Debian | Incorrect security UI in Navigation in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform domain spoofing via a crafted HTML page. | 6.5 |
2023-04-04 | CVE-2023-1823 | Google Fedoraproject Debian | Inappropriate implementation in FedCM in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | 6.5 |
2023-04-04 | CVE-2023-28853 | Joinmastodon | Unspecified vulnerability in Joinmastodon Mastodon Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. | 6.5 |
2023-04-04 | CVE-2023-27492 | Envoyproxy | Unspecified vulnerability in Envoyproxy Envoy Envoy is an open source edge and service proxy designed for cloud-native applications. | 6.5 |
2023-04-04 | CVE-2023-1749 | Getnexx | Authorization Bypass Through User-Controlled Key vulnerability in Getnexx products The listed versions of Nexx Smart Home devices lack proper access control when executing actions. | 6.5 |
2023-04-04 | CVE-2020-19850 | Monospace | Resource Exhaustion vulnerability in Monospace Directus 2.2.0 An issue found in Directus API v.2.2.0 allows a remote attacker to cause a denial of service via a great amount of HTTP requests. | 6.5 |
2023-04-04 | CVE-2023-28997 | Nextcloud | Unspecified vulnerability in Nextcloud Desktop The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. | 6.5 |
2023-04-04 | CVE-2023-29000 | Nextcloud | Unspecified vulnerability in Nextcloud Desktop The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. | 6.5 |
2023-04-04 | CVE-2023-25942 | Dell | Unspecified vulnerability in Dell EMC Powerscale Onefs Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerability. | 6.5 |
2023-04-03 | CVE-2023-0614 | Samba | Cleartext Storage of Sensitive Information vulnerability in Samba The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC. | 6.5 |
2023-04-03 | CVE-2022-43771 | Hitachi | Path Traversal vulnerability in Hitachi Vantara Pentaho Business Analytics Server Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x, using the Pentaho Data Access plugin exposes a service endpoint for CSV import which allows a user supplied path to access resources that are out of bounds. | 6.5 |
2023-04-03 | CVE-2022-43772 | Hitachi | Information Exposure Through Log Files vulnerability in Hitachi Vantara Pentaho Business Analytics Server Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Data Plugin expose the username and password of clusters in clear text into system logs. | 6.5 |
2023-04-03 | CVE-2022-43941 | Hitachi | XXE vulnerability in Hitachi Vantara Pentaho Business Analytics Server 9.4.0.0 Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML External Entity Reference. | 6.5 |
2023-04-03 | CVE-2023-0977 | Trellix | Out-of-bounds Write vulnerability in Trellix Agent 5.7.7/5.7.8 A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote user to alter the page heap in the macmnsvc process memory block resulting in the service becoming unavailable. | 6.5 |
2023-04-03 | CVE-2023-1330 | Inisev | Unspecified vulnerability in Inisev Redirection The Redirection WordPress plugin before 1.1.4 does not add nonce verification in place when adding the redirect, which could allow attackers to add redirects via a CSRF attack. | 6.5 |
2023-04-06 | CVE-2023-20684 | Race Condition vulnerability in Google Android 12.0/13.0 In vdec, there is a possible use after free due to a race condition. | 6.4 | |
2023-04-06 | CVE-2023-20685 | Race Condition vulnerability in Google Android 12.0/13.0 In vdec, there is a possible use after free due to a race condition. | 6.4 | |
2023-04-06 | CVE-2023-20686 | Race Condition vulnerability in Google Android 12.0/13.0 In display drm, there is a possible double free due to a race condition. | 6.4 | |
2023-04-06 | CVE-2023-20687 | Race Condition vulnerability in Google Android 12.0/13.0 In display drm, there is a possible double free due to a race condition. | 6.4 | |
2023-04-04 | CVE-2023-28999 | Nextcloud | Missing Encryption of Sensitive Data vulnerability in Nextcloud Desktop Nextcloud is an open-source productivity platform. | 6.4 |
2023-04-05 | CVE-2023-1855 | Linux Debian | Use After Free vulnerability in multiple products A use-after-free flaw was found in xgene_hwmon_remove in drivers/hwmon/xgene-hwmon.c in the Hardware Monitoring Linux Kernel Driver (xgene-hwmon). | 6.3 |
2023-04-03 | CVE-2023-1611 | Fedoraproject Linux | Use After Free vulnerability in multiple products A use-after-free flaw was found in btrfs_search_slot in fs/btrfs/ctree.c in btrfs in the Linux Kernel.This flaw allows an attacker to crash the system and possibly cause a kernel information lea | 6.3 |
2023-04-03 | CVE-2022-3960 | Hitachi | Code Injection vulnerability in Hitachi Vantara Pentaho Business Analytics Server 9.4.0.0 Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of the Community Dashboard Editor (CDE) plugin. | 6.3 |
2023-04-09 | CVE-2014-125095 | Bestwebsoft | Unspecified vulnerability in Bestwebsoft Contact Form 1.3.4 A vulnerability was found in BestWebSoft Contact Form Plugin 1.3.4 on WordPress and classified as problematic. | 6.1 |
2023-04-08 | CVE-2023-1961 | Oretnom23 | Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0 A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0. | 6.1 |
2023-04-08 | CVE-2015-10098 | Wpmudev | Unspecified vulnerability in Wpmudev Broken Link Checker A vulnerability was found in Broken Link Checker Plugin up to 1.10.5 on WordPress. | 6.1 |
2023-04-08 | CVE-2023-1948 | Phpgurukul | Unspecified vulnerability in PHPgurukul BP Monitoring Management System 1.0 A vulnerability, which was classified as problematic, has been found in PHPGurukul BP Monitoring Management System 1.0. | 6.1 |
2023-04-07 | CVE-2023-1946 | Survey Application System Project | Unspecified vulnerability in Survey Application System Project Survey Application System 1.0 A vulnerability was found in SourceCodester Survey Application System 1.0 and classified as problematic. | 6.1 |
2023-04-07 | CVE-2023-28781 | Cimatti | Unspecified vulnerability in Cimatti Wordpress Contact Forms Unauth. | 6.1 |
2023-04-07 | CVE-2023-28789 | Cimatti | Unspecified vulnerability in Cimatti Wordpress Contact Forms Unauth. | 6.1 |
2023-04-07 | CVE-2023-28792 | I13Websolution | Unspecified vulnerability in I13Websolution Continuous Image Carosel With Lightbox Unauth. | 6.1 |
2023-04-07 | CVE-2023-29171 | Magic Post Thumbnail | Unspecified vulnerability in Magic-Post-Thumbnail Magic Post Thumbnail Unauth. | 6.1 |
2023-04-07 | CVE-2023-29172 | WP Property Hive | Unspecified vulnerability in Wp-Property-Hive Propertyhive Unauth. | 6.1 |
2023-04-07 | CVE-2023-29388 | Implecode | Unspecified vulnerability in Implecode Product Catalog Simple Unauth. | 6.1 |
2023-04-07 | CVE-2023-25711 | Wpglobus | Unspecified vulnerability in Wpglobus Translate Options Unauth. | 6.1 |
2023-04-07 | CVE-2023-25713 | Fullworksplugins | Unspecified vulnerability in Fullworksplugins Quick Paypal Payments Unauth. | 6.1 |
2023-04-07 | CVE-2023-25020 | Kibokolabs | Unspecified vulnerability in Kibokolabs Arigato Autoresponder and Newsletter Unauth. | 6.1 |
2023-04-07 | CVE-2023-25041 | Cththemes | Unspecified vulnerability in Cththemes Monolit Unauth. | 6.1 |
2023-04-07 | CVE-2023-28993 | Albo Pretorio ON Line Project | Unspecified vulnerability in Albo Pretorio on Line Project Albo Pretorio on Line Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ignazio Scimone Albo Pretorio On Line plugin <= 4.6.1 versions. | 6.1 |
2023-04-07 | CVE-2023-29236 | Cththemes | Unspecified vulnerability in Cththemes Outdoor Unauth. | 6.1 |
2023-04-06 | CVE-2014-125094 | Phpminiadmin Project | Unspecified vulnerability in PHPminiadmin Project PHPminiadmin 1.7.110429/1.7.111025/1.8.120510 A vulnerability classified as problematic was found in phpMiniAdmin up to 1.8.120510. | 6.1 |
2023-04-06 | CVE-2023-29014 | Intranda | Unspecified vulnerability in Intranda Goobi Viewer Core The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. | 6.1 |
2023-04-06 | CVE-2023-29015 | Intranda | Unspecified vulnerability in Intranda Goobi Viewer Core The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. | 6.1 |
2023-04-06 | CVE-2023-29016 | Intranda | Unspecified vulnerability in Intranda Goobi Viewer Core The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. | 6.1 |
2023-04-06 | CVE-2023-1912 | Limit Login Attempts Project | Unspecified vulnerability in Limit Login Attempts Project Limit Login Attempts The Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging feature in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. | 6.1 |
2023-04-06 | CVE-2023-22985 | Simple Guestbook Management System Project | Cross-site Scripting vulnerability in Simple Guestbook Management System Project Simple Guestbook Management System 1.0 Sourcecodester Simple Guestbook Management System version 1 is vulnerable to Cross Site Scripting (XSS) via Name, Referrer, Location, and Comments. | 6.1 |
2023-04-06 | CVE-2023-23979 | Fullworksplugins | Unspecified vulnerability in Fullworksplugins Quick Event Manager Unauth. | 6.1 |
2023-04-05 | CVE-2022-31889 | Enhancesoft | Cross-site Scripting vulnerability in Enhancesoft Audit LOG Cross Site Scripting (XSS) vulnerability in audit/templates/auditlogs.tmpl.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae. | 6.1 |
2023-04-05 | CVE-2022-3513 | Gitlab | Cross-site Scripting vulnerability in Gitlab An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. | 6.1 |
2023-04-05 | CVE-2023-0523 | Gitlab | Cross-site Scripting vulnerability in Gitlab An issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. | 6.1 |
2023-04-05 | CVE-2023-20137 | Cisco | Cross-site Scripting vulnerability in Cisco products Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. | 6.1 |
2023-04-05 | CVE-2023-20138 | Cisco | Cross-site Scripting vulnerability in Cisco products Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. | 6.1 |
2023-04-05 | CVE-2023-20139 | Cisco | Cross-site Scripting vulnerability in Cisco products Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. | 6.1 |
2023-04-05 | CVE-2023-20140 | Cisco | Cross-site Scripting vulnerability in Cisco products Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. | 6.1 |
2023-04-05 | CVE-2023-20141 | Cisco | Cross-site Scripting vulnerability in Cisco products Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. | 6.1 |
2023-04-05 | CVE-2023-20142 | Cisco | Cross-site Scripting vulnerability in Cisco products Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. | 6.1 |
2023-04-05 | CVE-2023-20143 | Cisco | Cross-site Scripting vulnerability in Cisco products Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. | 6.1 |
2023-04-05 | CVE-2023-20144 | Cisco | Cross-site Scripting vulnerability in Cisco products Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. | 6.1 |
2023-04-05 | CVE-2023-20145 | Cisco | Cross-site Scripting vulnerability in Cisco products Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. | 6.1 |
2023-04-05 | CVE-2023-20146 | Cisco | Cross-site Scripting vulnerability in Cisco products Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. | 6.1 |
2023-04-05 | CVE-2023-20147 | Cisco | Cross-site Scripting vulnerability in Cisco products Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. | 6.1 |
2023-04-05 | CVE-2023-20148 | Cisco | Cross-site Scripting vulnerability in Cisco products Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. | 6.1 |
2023-04-05 | CVE-2023-20149 | Cisco | Cross-site Scripting vulnerability in Cisco products Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. | 6.1 |
2023-04-05 | CVE-2023-20150 | Cisco | Cross-site Scripting vulnerability in Cisco products Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. | 6.1 |
2023-04-05 | CVE-2023-20151 | Cisco | Cross-site Scripting vulnerability in Cisco products Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. | 6.1 |
2023-04-05 | CVE-2023-28639 | Glpi Project | Unspecified vulnerability in Glpi-Project Glpi GLPI is a free asset and IT management software package. | 6.1 |
2023-04-05 | CVE-2023-1880 | Phpmyfaq | Unspecified vulnerability in PHPmyfaq Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.12. | 6.1 |
2023-04-05 | CVE-2023-1884 | Phpmyfaq | Unspecified vulnerability in PHPmyfaq Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.12. | 6.1 |
2023-04-05 | CVE-2023-20068 | Cisco | Cross-site Scripting vulnerability in Cisco Prime Infrastructure A vulnerability in the web-based management interface of Cisco Prime Infrastructure Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface on an affected device. | 6.1 |
2023-04-05 | CVE-2023-26789 | Veritas | Cross-site Scripting vulnerability in Veritas Netbackup Opscenter 9.1.0.1 Veritas NetBackUp OpsCenter Version 9.1.0.1 is vulnerable to Reflected Cross-site scripting (XSS). | 6.1 |
2023-04-05 | CVE-2013-10022 | Bestwebsoft | Unspecified vulnerability in Bestwebsoft Contact Form 3.51 A vulnerability, which was classified as problematic, has been found in BestWebSoft Contact Form Plugin 3.51 on WordPress. | 6.1 |
2023-04-05 | CVE-2023-1860 | Keysight | Unspecified vulnerability in Keysight Hawkeye 3.3.16.28 A vulnerability was found in Keysight IXIA Hawkeye 3.3.16.28. | 6.1 |
2023-04-05 | CVE-2023-1851 | Online Payroll System Project | Unspecified vulnerability in Online Payroll System Project Online Payroll System 1.0 A vulnerability classified as problematic has been found in SourceCodester Online Payroll System 1.0. | 6.1 |
2023-04-05 | CVE-2023-1852 | Online Payroll System Project | Unspecified vulnerability in Online Payroll System Project Online Payroll System 1.0 A vulnerability classified as problematic was found in SourceCodester Online Payroll System 1.0. | 6.1 |
2023-04-05 | CVE-2023-1853 | Online Payroll System Project | Unspecified vulnerability in Online Payroll System Project Online Payroll System 1.0 A vulnerability, which was classified as problematic, has been found in SourceCodester Online Payroll System 1.0. | 6.1 |
2023-04-05 | CVE-2023-1857 | Oretnom23 | Unspecified vulnerability in Oretnom23 Online Computer and Laptop Store 1.0 A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as problematic. | 6.1 |
2023-04-04 | CVE-2023-0357 | Helpy IO | Cross-site Scripting vulnerability in Helpy.Io Helpy 2.8.0 Helpy version 2.8.0 allows an unauthenticated remote attacker to exploit an XSS stored in the application. | 6.1 |
2023-04-04 | CVE-2023-0486 | Vitalpbx | Cross-site Scripting vulnerability in Vitalpbx 3.2.3 VitalPBX version 3.2.3-8 allows an unauthenticated external attacker to obtain the instance's administrator account via a malicious link. | 6.1 |
2023-04-04 | CVE-2023-0738 | Orangescrum | Cross-site Scripting vulnerability in Orangescrum 2.0.11 OrangeScrum version 2.0.11 allows an external attacker to obtain arbitrary user accounts from the application. | 6.1 |
2023-04-04 | CVE-2023-0325 | Uvdesk | Cross-site Scripting vulnerability in Uvdesk Community-Skeleton 1.1.1 Uvdesk version 1.1.1 allows an unauthenticated remote attacker to exploit a stored XSS in the application. | 6.1 |
2023-04-04 | CVE-2020-19697 | Ipandao | Cross-site Scripting vulnerability in Ipandao Editor.Md 1.5.0 Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script in the <iframe>src parameter. | 6.1 |
2023-04-04 | CVE-2020-19698 | Ipandao | Cross-site Scripting vulnerability in Ipandao Editor.Md 1.5.0 Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the editor parameter. | 6.1 |
2023-04-04 | CVE-2020-19699 | Kiftd Project | Cross-site Scripting vulnerability in Kiftd Project Kiftd 1.0.18 Cross Site Scripting vulnerability found in KOHGYLW Kiftd v.1.0.18 allows a remote attacker to execute arbitrary code via the <ifram> tag in the upload file page. | 6.1 |
2023-04-04 | CVE-2020-20521 | Kitesky | Cross-site Scripting vulnerability in Kitesky Kitecms 1.1.1 Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the comment parameter. | 6.1 |
2023-04-04 | CVE-2020-20522 | Kitesky | Cross-site Scripting vulnerability in Kitesky Kitecms 1.1 Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the registering user parameter. | 6.1 |
2023-04-04 | CVE-2020-22533 | Easycorp | Cross-site Scripting vulnerability in Easycorp Zentao Cross Site Scripting vulnerability found in Zentao allows a remote attacker to execute arbitrary code via the lang parameter | 6.1 |
2023-04-04 | CVE-2020-23327 | Zblogcn | Cross-site Scripting vulnerability in Zblogcn Zblogphp 1.0 Cross Site Scripting vulnerability found in ZblogCN ZblogPHP v.1.0 allows a local attacker to execute arbitrary code via a crafted payload in title parameter of the module management model. | 6.1 |
2023-04-04 | CVE-2023-26777 | Uptime Kuma Project | Cross-site Scripting vulnerability in Uptime Kuma Project Uptime Kuma 1.19.6 Cross Site Scripting vulnerability found in : louislam Uptime Kuma v.1.19.6 and before allows a remote attacker to execute arbitrary commands via the description, title, footer, and incident creation parameter of the status_page.js endpoint. | 6.1 |
2023-04-04 | CVE-2023-26776 | Monitorr | Cross-site Scripting vulnerability in Monitorr 1.7.6M Cross Site Scripting vulnerability found in Monitorr v.1.7.6 allows a remote attacker to execute arbitrary code via the title parameter of the post_receiver-services.php file. | 6.1 |
2023-04-04 | CVE-2022-47870 | RED Gate | Cross-site Scripting vulnerability in Red-Gate SQL Monitor 12.1.31.893 A Cross Site Scripting (XSS) vulnerability in the web SQL monitor login page in Redgate SQL Monitor 12.1.31.893 allows remote attackers to inject arbitrary web Script or HTML via the returnUrl parameter. | 6.1 |
2023-04-04 | CVE-2023-28998 | Nextcloud | Unspecified vulnerability in Nextcloud Desktop The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. | 6.1 |
2023-04-03 | CVE-2022-4771 | Hitachi | Cross-site Scripting vulnerability in Hitachi Vantara Pentaho Business Analytics Server 9.4.0.0 Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow a malicious URL to inject content into the Pentaho User Console through session variables. | 6.1 |
2023-04-03 | CVE-2023-1377 | Solidres | Unspecified vulnerability in Solidres The Solidres WordPress plugin through 0.9.4 does not sanitise and escape numerous parameter before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin | 6.1 |
2023-04-03 | CVE-2023-1766 | Akbim | Unspecified vulnerability in Akbim Panon Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Akbim Computer Panon allows Reflected XSS.This issue affects Panon: before 1.0.2. | 6.1 |
2023-04-03 | CVE-2022-27665 | Progress | Cross-site Scripting vulnerability in Progress WS FTP Server 8.6.0 Reflected XSS (via AngularJS sandbox escape expressions) exists in Progress Ipswitch WS_FTP Server 8.6.0. | 6.1 |
2023-04-05 | CVE-2023-20030 | Cisco | XXE vulnerability in Cisco Identity Services Engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information, conduct a server-side request forgery (SSRF) attack through an affected device, or negatively impact the responsiveness of the web-based management interface itself. | 6.0 |
2023-04-03 | CVE-2023-0922 | Samba | Cleartext Transmission of Sensitive Information vulnerability in Samba The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only connection. | 5.9 |
2023-04-03 | CVE-2023-26112 | Configobj Project | Unspecified vulnerability in Configobj Project Configobj All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate function, using (.+?)\((.*)\). **Note:** This is only exploitable in the case of a developer, putting the offending value in a server side configuration file. | 5.9 |
2023-04-07 | CVE-2022-43309 | Supermicro | Incorrect Permission Assignment for Critical Resource vulnerability in Supermicro products Supermicro X11SSL-CF HW Rev 1.01, BMC firmware v1.63 was discovered to contain insecure permissions. | 5.5 |
2023-04-07 | CVE-2020-11935 | Canonical Debian | It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. | 5.5 |
2023-04-06 | CVE-2023-29465 | Sagemath | Unspecified vulnerability in Sagemath Flintqs 1.0 SageMath FlintQS 1.0 relies on pathnames under TMPDIR (typically world-writable), which (for example) allows a local user to overwrite files with the privileges of a different user (who is running FlintQS). | 5.5 |
2023-04-04 | CVE-2023-26974 | Irfanview | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview 4.62 Irfanview v4.62 allows a user-mode write access violation via a crafted JPEG 2000 file starting at JPEG2000+0x0000000000001bf0. | 5.5 |
2023-04-04 | CVE-2022-48228 | Gbgplc | Information Exposure Through Log Files vulnerability in Gbgplc Acuant Asureid Sentinel An issue was discovered in Acuant AsureID Sentinel before 5.2.149. | 5.5 |
2023-04-04 | CVE-2023-27734 | EDB Debugger Project | Unspecified vulnerability in Edb-Debugger Project Edb-Debugger 1.3.0 An issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbols function in plugins/BinaryInfo/symbols.cpp. | 5.5 |
2023-04-07 | CVE-2022-43914 | IBM | Unspecified vulnerability in IBM Tririga Application Platform IBM TRIRIGA Application Platform 4.0 is vulnerable to cross-site scripting. | 5.4 |
2023-04-07 | CVE-2023-27620 | Robogallery | Unspecified vulnerability in Robogallery Robo Gallery Auth. | 5.4 |
2023-04-07 | CVE-2023-23885 | Fullworksplugins | Unspecified vulnerability in Fullworksplugins Quick Contact Form Auth. | 5.4 |
2023-04-07 | CVE-2023-25061 | Kibokolabs | Unspecified vulnerability in Kibokolabs Arigato Autoresponder and Newsletter Auth. | 5.4 |
2023-04-06 | CVE-2023-23891 | Oceanwp | Unspecified vulnerability in Oceanwp Ocean Extra Auth. | 5.4 |
2023-04-06 | CVE-2023-24374 | Material Design Icons FOR Page Builders Project | Unspecified vulnerability in Material Design Icons for Page Builders Project Material Design Icons for Page Builders Auth. | 5.4 |
2023-04-06 | CVE-2023-24378 | Codeat | Unspecified vulnerability in Codeat Glossary Auth. | 5.4 |
2023-04-06 | CVE-2023-23898 | Creativethemes | Unspecified vulnerability in Creativethemes Blocksy Companion Auth. | 5.4 |
2023-04-06 | CVE-2023-24411 | Bnecreative | Cross-site Scripting vulnerability in Bnecreative BNE Testimonials Auth. | 5.4 |
2023-04-06 | CVE-2023-24003 | Timersys | Unspecified vulnerability in Timersys WP Popups Auth. | 5.4 |
2023-04-06 | CVE-2023-23815 | Multi Column TAG MAP Project | Unspecified vulnerability in Multi-Column TAG MAP Project Multi-Column TAG MAP Auth. | 5.4 |
2023-04-05 | CVE-2023-24747 | Jflyfox | Cross-site Scripting vulnerability in Jflyfox Jfinal CMS 5.1 Jfinal CMS v5.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/dict/list. | 5.4 |
2023-04-05 | CVE-2023-20096 | Cisco | Cross-site Scripting vulnerability in Cisco Unified Contact Center Express A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. | 5.4 |
2023-04-05 | CVE-2023-28849 | Glpi Project | Unspecified vulnerability in Glpi-Project Glpi GLPI is a free asset and IT management software package. | 5.4 |
2023-04-05 | CVE-2023-20131 | Cisco | Cross-site Scripting vulnerability in Cisco Prime Infrastructure Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. | 5.4 |
2023-04-05 | CVE-2023-20132 | Cisco | Cross-site Scripting vulnerability in Cisco Webex Meetings Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack or upload arbitrary files as recordings. | 5.4 |
2023-04-05 | CVE-2023-1878 | Phpmyfaq | Unspecified vulnerability in PHPmyfaq Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12. | 5.4 |
2023-04-05 | CVE-2023-1879 | Phpmyfaq | Unspecified vulnerability in PHPmyfaq Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12. | 5.4 |
2023-04-05 | CVE-2023-1881 | Microweber | Unspecified vulnerability in Microweber Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.3. | 5.4 |
2023-04-05 | CVE-2023-1882 | Phpmyfaq | Cross-site Scripting vulnerability in PHPmyfaq Cross-site Scripting (XSS) - DOM in GitHub repository thorsten/phpmyfaq prior to 3.1.12. | 5.4 |
2023-04-05 | CVE-2023-1883 | Phpmyfaq | Unspecified vulnerability in PHPmyfaq Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.12. | 5.4 |
2023-04-05 | CVE-2023-1885 | Phpmyfaq | Unspecified vulnerability in PHPmyfaq Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12. | 5.4 |
2023-04-05 | CVE-2023-1757 | Phpmyfaq | Unspecified vulnerability in PHPmyfaq Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12. | 5.4 |
2023-04-05 | CVE-2023-1758 | Phpmyfaq | Unspecified vulnerability in PHPmyfaq Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository thorsten/phpmyfaq prior to 3.1.12. | 5.4 |
2023-04-05 | CVE-2023-28633 | Glpi Project | Unspecified vulnerability in Glpi-Project Glpi GLPI is a free asset and IT management software package. | 5.4 |
2023-04-05 | CVE-2023-1756 | Phpmyfaq | Unspecified vulnerability in PHPmyfaq Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12. | 5.4 |
2023-04-05 | CVE-2023-26536 | Followmedarling | Unspecified vulnerability in Followmedarling Spotify-Play-Button-For-Wordpress Auth. | 5.4 |
2023-04-05 | CVE-2023-28069 | Dell | Unspecified vulnerability in Dell Streaming Data Platform Dell Streaming Data Platform prior to 1.4 contains Open Redirect vulnerability. | 5.4 |
2023-04-04 | CVE-2020-19277 | MM Wiki Project | Cross-site Scripting vulnerability in Mm-Wiki Project Mm-Wiki 0.1.2 Cross Site Scripting vulnerability found in Phachon mm-wiki v.0.1.2 allows a remote attacker to execute arbitrary code via javascript code in the markdown editor. | 5.4 |
2023-04-04 | CVE-2023-28848 | Nextcloud | Unspecified vulnerability in Nextcloud User Oidc user_oidc is the OIDC connect user backend for Nextcloud, an open source collaboration platform. | 5.4 |
2023-04-04 | CVE-2023-23977 | Heateor | Unspecified vulnerability in Heateor Social Comments Auth. | 5.4 |
2023-04-04 | CVE-2023-23685 | Radiustheme | Unspecified vulnerability in Radiustheme Portfolio Auth. | 5.4 |
2023-04-04 | CVE-2023-23686 | Simple Staff List Project | Unspecified vulnerability in Simple Staff List Project Simple Staff List Auth. | 5.4 |
2023-04-04 | CVE-2023-23878 | Flippercode | Unspecified vulnerability in Flippercode WP Google MAP Auth. | 5.4 |
2023-04-04 | CVE-2020-36692 | Sophos | Cross-site Scripting vulnerability in Sophos web Appliance A reflected XSS via POST vulnerability in report scheduler of Sophos Web Appliance versions older than 4.3.10.4 allows execution of JavaScript code in the victim browser via a malicious form that must be manually submitted by the victim while logged in to SWA. | 5.4 |
2023-04-03 | CVE-2023-24724 | SAS | Cross-site Scripting vulnerability in SAS web Administration Interface 9.4 A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insufficient validation and sanitization of data input into the user creation and editing form fields. | 5.4 |
2023-04-03 | CVE-2023-28850 | Pimcore | Unspecified vulnerability in Pimcore Perspective Editor Pimcore Perspective Editor provides an editor for Pimcore that allows users to add/remove/edit custom views and perspectives. | 5.4 |
2023-04-03 | CVE-2023-28851 | Bigfork | Cross-site Scripting vulnerability in Bigfork Silverstripe Form Capture Silverstripe Form Capture provides a method to capture simple silverstripe forms and an admin interface for users. | 5.4 |
2023-04-03 | CVE-2023-28836 | Torchbox | Unspecified vulnerability in Torchbox Wagtail Wagtail is an open source content management system built on Django. | 5.4 |
2023-04-03 | CVE-2023-0399 | Image Over Image FOR Wpbakery Page Builder Project | Unspecified vulnerability in Image Over Image for Wpbakery Page Builder Project Image Over Image for Wpbakery Page Builder The Image Over Image For WPBakery Page Builder WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | 5.4 |
2023-04-07 | CVE-2023-23761 | Github | Improper Authentication vulnerability in Github Enterprise Server An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to modify other users' secret gists by authenticating through an SSH certificate authority. | 5.3 |
2023-04-07 | CVE-2023-23762 | Github | Incorrect Comparison vulnerability in Github Enterprise Server An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff. | 5.3 |
2023-04-05 | CVE-2023-1167 | Gitlab | Missing Authorization vulnerability in Gitlab Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR. | 5.3 |
2023-04-05 | CVE-2023-1710 | Gitlab | Unspecified vulnerability in Gitlab A sensitive information disclosure vulnerability in GitLab affecting all versions from 15.0 prior to 15.8.5, 15.9 prior to 15.9.4 and 15.10 prior to 15.10.1 allows an attacker to view the count of internal notes for a given issue. | 5.3 |
2023-04-05 | CVE-2023-1787 | Gitlab | Unspecified vulnerability in Gitlab An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. | 5.3 |
2023-04-05 | CVE-2023-0319 | Gitlab | Incorrect Authorization vulnerability in Gitlab An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1, allowing to read environment names supposed to be restricted to project memebers only. | 5.3 |
2023-04-05 | CVE-2023-0842 | Xml2Js Project | Unspecified vulnerability in Xml2Js Project Xml2Js 0.4.23 xml2js version 0.4.23 allows an external attacker to edit or add new properties to an object. | 5.3 |
2023-04-05 | CVE-2023-1868 | Plugin | Unspecified vulnerability in Plugin Yourchannel 1.2.3 The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when clearing the plugin cache via the yrc_clear_cache GET parameter in versions up to, and including, 1.2.3. | 5.3 |
2023-04-04 | CVE-2023-1751 | Getnexx | Unspecified vulnerability in Getnexx products The listed versions of Nexx Smart Home devices use a WebSocket server that does not validate if the bearer token in the Authorization header belongs to the device attempting to associate. | 5.3 |
2023-04-04 | CVE-2023-26437 | Powerdns | Unspecified vulnerability in Powerdns Recursor Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue affects Recursor: through 4.6.5, through 4.7.4 , through 4.8.3. | 5.3 |
2023-04-04 | CVE-2023-1768 | Tribe29 Checkmk | Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk 1.6.0 causes the symmetric encryption of agent data to fail silently and transmit the data in plaintext in certain configurations. | 5.3 |
2023-04-03 | CVE-2023-26916 | Cesnet Fedoraproject | NULL Pointer Dereference vulnerability in multiple products libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at lys_parse_mem.c. | 5.3 |
2023-04-07 | CVE-2023-27801 | H3C | Out-of-bounds Write vulnerability in H3C Magic R100 Firmware V100R005 H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the DelDNSHnList interface at /goform/aspForm. | 4.9 |
2023-04-07 | CVE-2023-27802 | H3C | Out-of-bounds Write vulnerability in H3C Magic R100 Firmware V100R005 H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the EditvsList parameter at /goform/aspForm. | 4.9 |
2023-04-07 | CVE-2023-27803 | H3C | Out-of-bounds Write vulnerability in H3C Magic R100 Firmware V100R005 H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the EdittriggerList interface at /goform/aspForm. | 4.9 |
2023-04-07 | CVE-2023-27804 | H3C | Out-of-bounds Write vulnerability in H3C Magic R100 Firmware V100R005 H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the DelvsList interface at /goform/aspForm. | 4.9 |
2023-04-07 | CVE-2023-27805 | H3C | Out-of-bounds Write vulnerability in H3C Magic R100 Firmware V100R005 H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the EditSTList interface at /goform/aspForm. | 4.9 |
2023-04-07 | CVE-2023-27806 | H3C | Out-of-bounds Write vulnerability in H3C Magic R100 Firmware V100R005 H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the ipqos_lanip_dellist interface at /goform/aspForm. | 4.9 |
2023-04-07 | CVE-2023-27807 | H3C | Out-of-bounds Write vulnerability in H3C Magic R100 Firmware V100R005 H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the Delstlist interface at /goform/aspForm. | 4.9 |
2023-04-07 | CVE-2023-27808 | H3C | Out-of-bounds Write vulnerability in H3C Magic R100 Firmware V100R005 H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the DeltriggerList interface at /goform/aspForm. | 4.9 |
2023-04-07 | CVE-2023-27810 | H3C | Out-of-bounds Write vulnerability in H3C Magic R100 Firmware V100R005 H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the ipqos_lanip_editlist interface at /goform/aspForm. | 4.9 |
2023-04-05 | CVE-2023-1098 | Gitlab | Unspecified vulnerability in Gitlab An information disclosure vulnerability has been discovered in GitLab EE/CE affecting all versions starting from 11.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 will allow an admin to leak password from repository mirror configuration. | 4.9 |
2023-04-03 | CVE-2023-28837 | Torchbox | Unspecified vulnerability in Torchbox Wagtail Wagtail is an open source content management system built on Django. | 4.9 |
2023-04-07 | CVE-2023-29170 | Piwebsolution | Unspecified vulnerability in Piwebsolution Product Enquiry for Woocommerce 2.2.7 Auth. | 4.8 |
2023-04-07 | CVE-2023-23799 | Easy Panorama Project | Unspecified vulnerability in Easy Panorama Project Easy Panorama Auth. | 4.8 |
2023-04-07 | CVE-2023-25442 | Zeno Font Resizer Project | Unspecified vulnerability in Zeno Font Resizer Project Zeno Font Resizer Auth. | 4.8 |
2023-04-07 | CVE-2023-25464 | Streamweasels | Unspecified vulnerability in Streamweasels Twitch Player 2.0.9/2.1.0 Auth. | 4.8 |
2023-04-07 | CVE-2023-25702 | Fullworksplugins | Unspecified vulnerability in Fullworksplugins Quick Paypal Payments Auth. | 4.8 |
2023-04-07 | CVE-2023-25705 | Goprayer | Unspecified vulnerability in Goprayer WP Prayer Auth. | 4.8 |
2023-04-07 | CVE-2023-25712 | WP Buddy | Cross-site Scripting vulnerability in Wp-Buddy Google Analytics Opt-Out Auth. | 4.8 |
2023-04-07 | CVE-2023-29094 | Piwebsolution | Unspecified vulnerability in Piwebsolution Product Page Shipping Calculator for Woocommerce Auth. | 4.8 |
2023-04-07 | CVE-2023-23994 | Auto Hide Admin BAR Project | Unspecified vulnerability in Auto Hide Admin BAR Project Auto Hide Admin BAR Auth. | 4.8 |
2023-04-07 | CVE-2023-25031 | Kibokolabs | Unspecified vulnerability in Kibokolabs Arigato Autoresponder and Newsletter Auth. | 4.8 |
2023-04-07 | CVE-2023-25049 | Implecode | Unspecified vulnerability in Implecode Ecommerce Product Catalog Auth. | 4.8 |
2023-04-07 | CVE-2023-25716 | Announce From THE Dashboard Project | Cross-site Scripting vulnerability in Announce From the Dashboard Project Announce From the Dashboard Auth (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gqevu6bsiz Announce from the Dashboard plugin <= 1.5.1 versions. | 4.8 |
2023-04-07 | CVE-2023-25022 | Kibokolabs | Unspecified vulnerability in Kibokolabs Watu Quiz Auth. | 4.8 |
2023-04-07 | CVE-2023-25023 | Saleswonder | Cross-site Scripting vulnerability in Saleswonder Webinar Ignition Auth. | 4.8 |
2023-04-07 | CVE-2023-25024 | Icegram | Unspecified vulnerability in Icegram Collect Auth. | 4.8 |
2023-04-07 | CVE-2023-25027 | Kibokolabs | Unspecified vulnerability in Kibokolabs Chained Quiz Auth. | 4.8 |
2023-04-07 | CVE-2023-24398 | Snapcreek | Unspecified vulnerability in Snapcreek EZP Coming Soon Page 1.0.7.3 Auth. | 4.8 |
2023-04-07 | CVE-2023-25046 | Podlove | Unspecified vulnerability in Podlove Podcast Publisher Auth. | 4.8 |
2023-04-07 | CVE-2023-24402 | Wpbookingsystem | Unspecified vulnerability in Wpbookingsystem WP Booking System Auth. | 4.8 |
2023-04-07 | CVE-2023-25059 | Avalex | Unspecified vulnerability in Avalex Auth. | 4.8 |
2023-04-06 | CVE-2023-1913 | Webfactoryltd | Unspecified vulnerability in Webfactoryltd Maps Widget for Google Maps The Maps Widget for Google Maps for WordPress is vulnerable to Stored Cross-Site Scripting via widget settings in versions up to, and including, 4.24 due to insufficient input sanitization and output escaping. | 4.8 |
2023-04-06 | CVE-2023-24396 | Vikwp | Cross-site Scripting vulnerability in Vikwp Vikbooking Hotel Booking Engine & PMS Auth. | 4.8 |
2023-04-06 | CVE-2023-25062 | Pinpoint | Unspecified vulnerability in Pinpoint Booking System Auth. | 4.8 |
2023-04-06 | CVE-2023-24383 | Kibokolabs | Unspecified vulnerability in Kibokolabs Namaste! LMS Auth. | 4.8 |
2023-04-06 | CVE-2023-24387 | Wpdevart | Unspecified vulnerability in Wpdevart Organization Chart Auth. | 4.8 |
2023-04-06 | CVE-2023-24403 | Wpforthewin | Unspecified vulnerability in Wpforthewin Bbpress Voting Auth. | 4.8 |
2023-04-06 | CVE-2023-24002 | Wpdevart | Unspecified vulnerability in Wpdevart Youtube Embed, Playlist and Popup Auth. | 4.8 |
2023-04-06 | CVE-2023-24004 | Wpdevart | Unspecified vulnerability in Wpdevart Download Image and Video Lightbox, Image Popup Auth. | 4.8 |
2023-04-06 | CVE-2023-23980 | Mailoptin | Unspecified vulnerability in Mailoptin Auth. | 4.8 |
2023-04-06 | CVE-2023-23996 | Properfraction | Cross-site Scripting vulnerability in Properfraction Profilepress Auth. | 4.8 |
2023-04-06 | CVE-2023-23998 | E4Jconnect | Unspecified vulnerability in E4Jconnect Vikrentcar Auth. | 4.8 |
2023-04-06 | CVE-2023-24001 | Modal Dialog Project | Unspecified vulnerability in Modal Dialog Project Modal Dialog Auth. | 4.8 |
2023-04-06 | CVE-2023-24006 | Linksoftwarellc | Unspecified vulnerability in Linksoftwarellc WP Terms Popup Auth. | 4.8 |
2023-04-06 | CVE-2023-23971 | Codepeople | Unspecified vulnerability in Codepeople WP Time Slots Booking Form Auth. | 4.8 |
2023-04-06 | CVE-2023-23972 | Wpdevart | Unspecified vulnerability in Wpdevart Social Like BOX and Page Auth. | 4.8 |
2023-04-06 | CVE-2023-23987 | Wpeverest | Unspecified vulnerability in Wpeverest User Registration Auth. | 4.8 |
2023-04-06 | CVE-2023-23981 | Quantumcloud | Unspecified vulnerability in Quantumcloud Conversational Forms for Chatbot Auth. | 4.8 |
2023-04-06 | CVE-2023-23982 | Wpfrom Email Project | Unspecified vulnerability in Wpfrom Email Project Wpfrom Email Auth. | 4.8 |
2023-04-05 | CVE-2023-28636 | Glpi Project | Unspecified vulnerability in Glpi-Project Glpi GLPI is a free asset and IT management software package. | 4.8 |
2023-04-05 | CVE-2023-28852 | Glpi Project | Unspecified vulnerability in Glpi-Project Glpi GLPI is a free asset and IT management software package. | 4.8 |
2023-04-05 | CVE-2023-1869 | Plugin | Cross-site Scripting vulnerability in Plugin Yourchannel 1.2.3 The YourChannel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. | 4.8 |
2023-04-04 | CVE-2023-1840 | Followmedarling | Unspecified vulnerability in Followmedarling Spotify-Play-Button-For-Wordpress The Sp*tify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.07 due to insufficient input sanitization and output escaping. | 4.8 |
2023-04-04 | CVE-2023-23870 | Wpdevart | Unspecified vulnerability in Wpdevart Responsive Vertical Icon Menu Auth. | 4.8 |
2023-04-04 | CVE-2023-23821 | Interactive Polish MAP Project | Unspecified vulnerability in Interactive Polish MAP Project Interactive Polish MAP Auth. | 4.8 |
2023-04-03 | CVE-2023-26529 | Dupeoff Project | Unspecified vulnerability in Dupeoff Project Dupeoff Auth. | 4.8 |
2023-04-05 | CVE-2023-1582 | Linux | Race Condition vulnerability in Linux Kernel A race problem was found in fs/proc/task_mmu.c in the memory management sub-component in the Linux kernel. | 4.7 |
2023-04-05 | CVE-2023-0450 | Gitlab | Unspecified vulnerability in Gitlab An issue has been discovered in GitLab affecting all versions starting from 8.1 to 15.8.5, and from 15.9 to 15.9.4, and from 15.10 to 15.10.1. | 4.6 |
2023-04-05 | CVE-2023-20123 | Cisco | Authentication Bypass by Capture-replay vulnerability in Cisco DUO and DUO Authentication for Windows Logon and RDP A vulnerability in the offline access mode of Cisco Duo Two-Factor Authentication for macOS and Duo Authentication for Windows Logon and RDP could allow an unauthenticated, physical attacker to replay valid user session credentials and gain unauthorized access to an affected macOS or Windows device. | 4.6 |
2023-04-06 | CVE-2023-20660 | Google Yoctoproject Linux | Integer Overflow or Wraparound vulnerability in multiple products In wlan, there is a possible out of bounds read due to an integer overflow. | 4.4 |
2023-04-06 | CVE-2023-20665 | Out-of-bounds Read vulnerability in Google Android 12.0/13.0 In ril, there is a possible out of bounds read due to a missing bounds check. | 4.4 | |
2023-04-06 | CVE-2023-20674 | Google Yoctoproject Linux | Out-of-bounds Read vulnerability in multiple products In wlan, there is a possible out of bounds read due to a missing bounds check. | 4.4 |
2023-04-06 | CVE-2023-20675 | Google Yoctoproject Linux | Out-of-bounds Read vulnerability in multiple products In wlan, there is a possible out of bounds read due to a missing bounds check. | 4.4 |
2023-04-06 | CVE-2023-20676 | Google Yoctoproject Linux | Out-of-bounds Read vulnerability in multiple products In wlan, there is a possible out of bounds read due to a missing bounds check. | 4.4 |
2023-04-06 | CVE-2023-20679 | Google Yoctoproject Linux | Out-of-bounds Read vulnerability in multiple products In wlan, there is a possible out of bounds read due to a missing bounds check. | 4.4 |
2023-04-06 | CVE-2023-20688 | Out-of-bounds Read vulnerability in Google Android 11.0/12.0/13.0 In power, there is a possible out of bounds read due to a missing bounds check. | 4.4 | |
2023-04-06 | CVE-2023-20677 | Google Yoctoproject Linux | Out-of-bounds Read vulnerability in multiple products In wlan, there is a possible out of bounds read due to a missing bounds check. | 4.4 |
2023-04-08 | CVE-2023-30450 | Redpanda | Unspecified vulnerability in Redpanda rpk in Redpanda before 23.1.2 mishandles the redpanda.rpc_server_tls field, leading to (for example) situations in which there is a data type mismatch that cannot be automatically fixed by rpk, and instead a user must reconfigure (while a cluster is turned off) in order to have TLS on broker RPC ports. | 4.3 |
2023-04-07 | CVE-2023-1937 | MY Blog Project | Unspecified vulnerability in My-Blog Project My-Blog A vulnerability, which was classified as problematic, was found in zhenfeng13 My-Blog. | 4.3 |
2023-04-06 | CVE-2023-1927 | Wpfastestcache | Unspecified vulnerability in Wpfastestcache WP Fastest Cache The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. | 4.3 |
2023-04-06 | CVE-2023-1928 | Wpfastestcache | Unspecified vulnerability in Wpfastestcache WP Fastest Cache The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the wpfc_preload_single_callback function in versions up to, and including, 1.1.2. | 4.3 |
2023-04-06 | CVE-2023-1929 | Wpfastestcache | Unspecified vulnerability in Wpfastestcache WP Fastest Cache The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the wpfc_purgecache_varnish_callback function in versions up to, and including, 1.1.2. | 4.3 |
2023-04-06 | CVE-2023-1930 | Wpfastestcache | Unspecified vulnerability in Wpfastestcache WP Fastest Cache The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the wpfc_clear_cache_of_allsites_callback function in versions up to, and including, 1.1.2. | 4.3 |
2023-04-06 | CVE-2023-1931 | Wpfastestcache | Unspecified vulnerability in Wpfastestcache WP Fastest Cache The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the deleteCssAndJsCacheToolbar function in versions up to, and including, 1.1.2. | 4.3 |
2023-04-06 | CVE-2023-1918 | Wpfastestcache | Unspecified vulnerability in Wpfastestcache WP Fastest Cache The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. | 4.3 |
2023-04-06 | CVE-2023-1919 | Wpfastestcache | Unspecified vulnerability in Wpfastestcache WP Fastest Cache The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. | 4.3 |
2023-04-06 | CVE-2023-1920 | Wpfastestcache | Unspecified vulnerability in Wpfastestcache WP Fastest Cache The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. | 4.3 |
2023-04-06 | CVE-2023-1921 | Wpfastestcache | Unspecified vulnerability in Wpfastestcache WP Fastest Cache The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. | 4.3 |
2023-04-06 | CVE-2023-1922 | Wpfastestcache | Unspecified vulnerability in Wpfastestcache WP Fastest Cache The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. | 4.3 |
2023-04-06 | CVE-2023-1923 | Wpfastestcache | Cross-Site Request Forgery (CSRF) vulnerability in Wpfastestcache WP Fastest Cache The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. | 4.3 |
2023-04-06 | CVE-2023-1924 | Wpfastestcache | Unspecified vulnerability in Wpfastestcache WP Fastest Cache The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. | 4.3 |
2023-04-06 | CVE-2023-1925 | Wpfastestcache | Unspecified vulnerability in Wpfastestcache WP Fastest Cache The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. | 4.3 |
2023-04-06 | CVE-2023-1926 | Wpfastestcache | Unspecified vulnerability in Wpfastestcache WP Fastest Cache The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. | 4.3 |
2023-04-05 | CVE-2023-1071 | Gitlab | Incorrect Authorization vulnerability in Gitlab An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. | 4.3 |
2023-04-05 | CVE-2023-1417 | Gitlab | Incorrect Authorization vulnerability in Gitlab An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. | 4.3 |
2023-04-05 | CVE-2023-0944 | Imaworldhealth | Incorrect Permission Assignment for Critical Resource vulnerability in Imaworldhealth Bhima 1.27.0 Bhima version 1.27.0 allows an authenticated attacker with regular user permissions to update arbitrary user session data such as username, email and password. | 4.3 |
2023-04-05 | CVE-2023-1887 | Phpmyfaq | Unspecified vulnerability in PHPmyfaq Business Logic Errors in GitHub repository thorsten/phpmyfaq prior to 3.1.12. | 4.3 |
2023-04-05 | CVE-2023-1866 | Plugin | Unspecified vulnerability in Plugin Yourchannel 1.2.3 The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. | 4.3 |
2023-04-05 | CVE-2023-1867 | Plugin | Unspecified vulnerability in Plugin Yourchannel 1.2.3 The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. | 4.3 |
2023-04-05 | CVE-2023-1870 | Plugin | Unspecified vulnerability in Plugin Yourchannel 1.2.3 The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. | 4.3 |
2023-04-05 | CVE-2023-1871 | Plugin | Unspecified vulnerability in Plugin Yourchannel 1.2.3 The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. | 4.3 |
2023-04-04 | CVE-2023-1752 | Getnexx | Improper Authentication vulnerability in Getnexx products The listed versions of Nexx Smart Home devices could allow any user to register an already registered alarm or associated device with only the device’s MAC address. | 4.3 |
2023-04-03 | CVE-2023-0225 | Samba | Incorrect Permission Assignment for Critical Resource vulnerability in Samba A flaw was found in Samba. | 4.3 |
2023-04-03 | CVE-2022-4769 | Hitachi | Information Exposure Through an Error Message vulnerability in Hitachi Vantara Pentaho Business Analytics Server Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the target path on host when a file is uploaded with an invalid character in its name. | 4.3 |
2023-04-03 | CVE-2022-4770 | Hitachi | Information Exposure Through an Error Message vulnerability in Hitachi Vantara Pentaho Business Analytics Server Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the full parametrized SQL query in an error message when an invalid character is used within a Pentaho Report (*.prpt). | 4.3 |
2023-04-03 | CVE-2023-28834 | Nextcloud | Unspecified vulnerability in Nextcloud Server Nextcloud Server is an open source personal cloud server. | 4.3 |
5 Low Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2023-04-05 | CVE-2023-0838 | Gitlab | Unspecified vulnerability in Gitlab An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. | 3.8 |
2023-04-05 | CVE-2022-3375 | Gitlab | Unspecified vulnerability in Gitlab An issue has been discovered in GitLab affecting all versions starting from 11.10 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. | 3.7 |
2023-04-06 | CVE-2022-46781 | ARM | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in ARM products An issue was discovered in the Arm Mali GPU Kernel Driver. | 3.3 |
2023-04-06 | CVE-2023-26083 | ARM | Memory Leak vulnerability in ARM products Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata. | 3.3 |
2023-04-04 | CVE-2022-48435 | Jetbrains | Unspecified vulnerability in Jetbrains PHPstorm 2021.3.1 In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file | 3.3 |