Weekly Vulnerabilities Reports > May 29 to June 4, 2023
Overview
513 new vulnerabilities reported during this period, including 75 critical vulnerabilities and 193 high severity vulnerabilities. This weekly summary report vulnerabilities in 388 products from 232 vendors including Mozilla, H3C, Google, Jetbrains, and Splunk. Vulnerabilities are notably categorized as "Cross-site Scripting", "Out-of-bounds Write", "Path Traversal", "SQL Injection", and "Cross-Site Request Forgery (CSRF)".
- 442 reported vulnerabilities are remotely exploitables.
- 117 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
- 320 reported vulnerabilities are exploitable by an anonymous user.
- Mozilla has the most reported vulnerabilities, with 67 reported vulnerabilities.
- Tenda has the most reported critical vulnerabilities, with 5 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
75 Critical Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2023-05-31 | CVE-2023-2909 | Asustor | Path Traversal vulnerability in Asustor ADM EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. | 10.0 |
2023-06-01 | CVE-2023-32713 | Splunk | Improper Privilege Management vulnerability in Splunk APP for Stream In Splunk App for Stream versions below 8.1.1, a low-privileged user could use a vulnerability in the streamfwd process within the Splunk App for Stream to escalate their privileges on the machine that runs the Splunk Enterprise instance, up to and including the root user. | 9.9 |
2023-06-04 | CVE-2015-10111 | Kibokolabs | Unspecified vulnerability in Kibokolabs Watu Quiz A vulnerability was found in Watu Quiz Plugin up to 2.6.7 on WordPress. | 9.8 |
2023-06-04 | CVE-2023-3094 | Agro School Management System Project | Unspecified vulnerability in Agro-School Management System Project Agro-School Management System 1.0 A vulnerability classified as critical has been found in code-projects Agro-School Management System 1.0. | 9.8 |
2023-06-03 | CVE-2023-2781 | Wisetr | Missing Authentication for Critical Function vulnerability in Wisetr User Email Verification for Woocommerce The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate_user_by_email in versions up to, and including, 3.5.0. | 9.8 |
2023-06-02 | CVE-2023-33669 | Tenda | Out-of-bounds Write vulnerability in Tenda AC8 Firmware 16.03.34.06 Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the timeZone parameter in the sub_44db3c function. | 9.8 |
2023-06-02 | CVE-2023-33670 | Tenda | Out-of-bounds Write vulnerability in Tenda AC8 Firmware 16.03.34.06 Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sub_4a79ec function. | 9.8 |
2023-06-02 | CVE-2023-33671 | Tenda | Out-of-bounds Write vulnerability in Tenda AC8 Firmware 16.03.34.06 Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the deviceId parameter in the saveParentControlInfo function. | 9.8 |
2023-06-02 | CVE-2023-33673 | Tenda | Out-of-bounds Write vulnerability in Tenda AC8 Firmware 16.03.34.06 Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function. | 9.8 |
2023-06-02 | CVE-2023-33675 | Tenda | Out-of-bounds Write vulnerability in Tenda AC8 Firmware 16.03.34.06 Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the get_parentControl_list_Info function. | 9.8 |
2023-06-02 | CVE-2023-33762 | Simpleredak | SQL Injection vulnerability in Simpleredak 2.47.23.05 eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a SQL injection vulnerability via the Activity parameter. | 9.8 |
2023-06-02 | CVE-2023-3069 | Corebos | Improper Authentication vulnerability in Corebos 5.4/5.5/7.0 Unverified Password Change in GitHub repository tsolucio/corebos prior to 8. | 9.8 |
2023-06-02 | CVE-2023-3068 | Retro Cellphone Online Store Project | Unspecified vulnerability in Retro Cellphone Online Store Project Retro Cellphone Online Store 1.0 A vulnerability classified as critical has been found in Campcodes Retro Cellphone Online Store 1.0. | 9.8 |
2023-06-02 | CVE-2023-30149 | Ebewe | SQL Injection vulnerability in Ebewe City Autocomplete 1.8.12 SQL injection vulnerability in the City Autocomplete (cityautocomplete) module from ebewe.net for PrestaShop, prior to version 1.8.12 (for PrestaShop version 1.5/1.6) or prior to 2.0.3 (for PrestaShop version 1.7), allows remote attackers to execute arbitrary SQL commands via the type, input_name. | 9.8 |
2023-06-02 | CVE-2023-33476 | Readymedia Project | Out-of-bounds Write vulnerability in Readymedia Project Readymedia ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. | 9.8 |
2023-06-02 | CVE-2023-34362 | Progress | SQL Injection vulnerability in Progress Moveit Cloud and Moveit Transfer In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. | 9.8 |
2023-06-02 | CVE-2023-3061 | Agro School Management System Project | Unspecified vulnerability in Agro-School Management System Project Agro-School Management System 1.0 A vulnerability was found in code-projects Agro-School Management System 1.0 and classified as critical. | 9.8 |
2023-06-02 | CVE-2023-3062 | Agro School Management System Project | Unspecified vulnerability in Agro-School Management System Project Agro-School Management System 1.0 A vulnerability was found in code-projects Agro-School Management System 1.0. | 9.8 |
2023-06-02 | CVE-2023-3057 | Iuok | Unspecified vulnerability in Iuok Yfcmf-Tp6 A vulnerability was found in YFCMF up to 3.0.4. | 9.8 |
2023-06-02 | CVE-2023-3059 | Online Exam Form Submission Project | Unspecified vulnerability in Online Exam Form Submission Project Online Exam Form Submission 1.0 A vulnerability, which was classified as critical, was found in SourceCodester Online Exam Form Submission 1.0. | 9.8 |
2023-06-02 | CVE-2023-3056 | Iuok | Unspecified vulnerability in Iuok Yfcmf-Tp6 A vulnerability was found in YFCMF up to 3.0.4. | 9.8 |
2023-06-02 | CVE-2023-30603 | Hitrontech | Unspecified vulnerability in Hitrontech Coda-5310 Firmware 7.2.4.7.1B3 Hitron Technologies CODA-5310 Telnet function with the default account and password, and there is no warning or prompt to ask users to change the default password and account. | 9.8 |
2023-06-02 | CVE-2023-29746 | Thethaiger | Unspecified vulnerability in Thethaiger the Thaiger 1.2 An issue found in The Thaiger v.1.2 for Android allows unauthorized apps to cause a code execution attack by manipulating the SharedPreference files. | 9.8 |
2023-06-01 | CVE-2023-29736 | Timmystudios | Path Traversal vulnerability in Timmystudios Keyboard Themes 1.275.1.164 Keyboard Themes 1.275.1.164 for Android contains a dictionary traversal vulnerability that allows unauthorized apps to overwrite arbitrary files in its internal storage and achieve arbitrary code execution. | 9.8 |
2023-06-01 | CVE-2023-33963 | Dataease | Deserialization of Untrusted Data vulnerability in Dataease DataEase is an open source data visualization and analysis tool. | 9.8 |
2023-06-01 | CVE-2014-125104 | Automattic | Unspecified vulnerability in Automattic Vaultpress A vulnerability was found in VaultPress Plugin up to 1.6.0 on WordPress. | 9.8 |
2023-06-01 | CVE-2023-3028 | Hopechart | Improper Authentication vulnerability in Hopechart Hqt401 Firmware 201808021036 Insufficient authentication in the MQTT backend (broker) allows an attacker to access and even manipulate the telemetry data of the entire fleet of vehicles using the HopeChart HQT-401 telematics unit. | 9.8 |
2023-06-01 | CVE-2023-24584 | Gallagher | Classic Buffer Overflow vulnerability in Gallagher Controller 6000 Firmware Controller 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature. | 9.8 |
2023-06-01 | CVE-2023-33778 | Draytek | Use of Hard-coded Credentials vulnerability in Draytek products Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected device to their own account. | 9.8 |
2023-06-01 | CVE-2023-23952 | Broadcom | Command Injection vulnerability in Broadcom Advanced Secure Gateway and Content Analysis Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability. | 9.8 |
2023-05-31 | CVE-2021-45039 | Uniview | Classic Buffer Overflow vulnerability in Uniview Camera Firmware Multiple models of the Uniview IP Camera (e.g., IPC_G6103 B6103.16.10.B25.201218, IPC_G61, IPC21, IPC23, IPC32, IPC36, IPC62, and IPC_HCMN) offer an undocumented UDP service on port 7788 that allows a remote unauthenticated attacker to overflow an internal buffer and achieve code execution. | 9.8 |
2023-05-31 | CVE-2023-33730 | Escanav | Cleartext Transmission of Sensitive Information vulnerability in Escanav Escan Management Console 14.0.1400.2281 Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacker to retrieve password of any admin or normal user in plain text format. | 9.8 |
2023-05-31 | CVE-2023-33735 | Dlink | Unspecified vulnerability in Dlink Dir-846 Firmware 100A52 D-Link DIR-846 v1.00A52 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in the /HNAP1 interface. | 9.8 |
2023-05-31 | CVE-2023-34257 | BMC | Unspecified vulnerability in BMC Patrol Agent An issue was discovered in BMC Patrol through 23.1.00. | 9.8 |
2023-05-31 | CVE-2023-33966 | Deno | Incorrect Default Permissions vulnerability in Deno and Deno Runtime Deno is a runtime for JavaScript and TypeScript. | 9.8 |
2023-05-31 | CVE-2023-33967 | Megaease | SQL Injection vulnerability in Megaease Easeprobe EaseProbe is a tool that can do health/status checking. | 9.8 |
2023-05-31 | CVE-2023-29747 | Story Saver FOR Instagram Video Downloader Project | Unspecified vulnerability in Story Saver for Instagram - Video Downloader Project Story Saver for Instagram - Video Downloader 1.0.6 Story Saver for Instragram - Video Downloader 1.0.6 for Android exists exposed component, the component provides the method to modify the SharedPreference file. | 9.8 |
2023-05-31 | CVE-2023-34218 | Jetbrains | Unspecified vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible | 9.8 |
2023-05-31 | CVE-2023-3015 | VIP Video Analysis Project | Unspecified vulnerability in VIP Video Analysis Project VIP Video Analysis 1.0 A vulnerability has been found in yiwent Vip Video Analysis 1.0 and classified as critical. | 9.8 |
2023-05-31 | CVE-2023-33486 | Totolink | Command Injection vulnerability in Totolink X5000R Firmware 9.1.0U.6118B20201102/9.1.0U.6369B20230113 TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpModeCfg. | 9.8 |
2023-05-31 | CVE-2023-33487 | Totolink | Command Injection vulnerability in Totolink X5000R Firmware 9.1.0U.6118B20201102/9.1.0U.6369B20230113 TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagnosisCfg.This vulnerability allows an attacker to execute arbitrary commands through the "ip" parameter. | 9.8 |
2023-05-31 | CVE-2023-33508 | Kramerav | Unrestricted Upload of File with Dangerous Type vulnerability in Kramerav VIA GO2 Firmware KramerAV VIA GO² < 4.0.1.1326 is vulnerable to unauthenticated file upload resulting in Remote Code Execution (RCE). | 9.8 |
2023-05-31 | CVE-2023-33509 | Kramerav | SQL Injection vulnerability in Kramerav VIA GO2 Firmware KramerAV VIA GO² < 4.0.1.1326 is vulnerable to SQL Injection. | 9.8 |
2023-05-31 | CVE-2023-3007 | Student Management System Project | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Student Management System Project Student Management System 1.0 A vulnerability was found in ningzichun Student Management System 1.0. | 9.8 |
2023-05-31 | CVE-2023-3008 | Student Management System Project | Unspecified vulnerability in Student Management System Project Student Management System 1.0 A vulnerability classified as critical has been found in ningzichun Student Management System 1.0. | 9.8 |
2023-05-31 | CVE-2023-3003 | Train Station Ticketing System Project | Unspecified vulnerability in Train Station Ticketing System Project Train Station Ticketing System 1.0 A vulnerability classified as critical was found in SourceCodester Train Station Ticketing System 1.0. | 9.8 |
2023-05-31 | CVE-2023-3004 | Simple Chat System Project | Unspecified vulnerability in Simple Chat System Project Simple Chat System 1.0 A vulnerability, which was classified as critical, has been found in SourceCodester Simple Chat System 1.0. | 9.8 |
2023-05-31 | CVE-2023-25539 | Dell | OS Command Injection vulnerability in Dell Networker Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client. | 9.8 |
2023-05-31 | CVE-2023-2987 | Wordapp | Insufficient Verification of Data Authenticity vulnerability in Wordapp 1.5.0 The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptographic signature on the 'wa_pdx_op_config_set' function in versions up to, and including, 1.5.0. | 9.8 |
2023-05-31 | CVE-2022-47526 | FOX IT | Path Traversal vulnerability in Fox-It FOX Datadiode Firmware 3.4.3 Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a path traversal vulnerability with resultant arbitrary writing of files. | 9.8 |
2023-05-30 | CVE-2023-29727 | Applika | Unspecified vulnerability in Applika Call Blocker 6.6.3 The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its database that is related to user privacy settings and affects the implementation of the normal functionality of the application. | 9.8 |
2023-05-30 | CVE-2023-29728 | Applika | Unspecified vulnerability in Applika Call Blocker 6.6.3 The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of privilege attack. | 9.8 |
2023-05-30 | CVE-2023-29739 | Amdroidapp | Unspecified vulnerability in Amdroidapp Alarm Clock for Heavy Sleepers 5.3.2 An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the component. | 9.8 |
2023-05-30 | CVE-2023-29741 | Bestweather Project | Unspecified vulnerability in Bestweather Project Bestweather 7.3.1 An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause an escalation of privileges attack by manipulating the database. | 9.8 |
2023-05-30 | CVE-2023-33734 | Bluecms Project | SQL Injection vulnerability in Bluecms Project Bluecms 1.6 BlueCMS v1.6 was discovered to contain a SQL injection vulnerability via the keywords parameter at search.php. | 9.8 |
2023-05-30 | CVE-2023-34152 | Imagemagick Fedoraproject Redhat | OS Command Injection vulnerability in multiple products A vulnerability was found in ImageMagick. | 9.8 |
2023-05-30 | CVE-2022-36246 | Shopbeat | Unspecified vulnerability in Shopbeat Shop Beat Media Player 2.5.95 Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Insecure Permissions. | 9.8 |
2023-05-30 | CVE-2023-29732 | Loka | Incorrect Default Permissions vulnerability in Loka Solive 1.6.14/1.6.16/1.6.20 SoLive 1.6.14 thru 1.6.20 for Android exists exposed component, the component provides the method to modify the SharedPreference file. | 9.8 |
2023-05-30 | CVE-2023-29734 | MWM | Improper Privilege Management vulnerability in MWM Edjing MIX 7.09.01 An issue found in edjing Mix v.7.09.01 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the database. | 9.8 |
2023-05-30 | CVE-2023-33975 | Riot OS | Out-of-bounds Write vulnerability in Riot-Os Riot RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. | 9.8 |
2023-05-30 | CVE-2023-2972 | Antfu | Unspecified vulnerability in Antfu Utils Prototype Pollution in GitHub repository antfu/utils prior to 0.7.3. | 9.8 |
2023-05-30 | CVE-2023-33189 | Pomerium | Unspecified vulnerability in Pomerium Pomerium is an identity and context-aware access proxy. | 9.8 |
2023-05-30 | CVE-2023-32692 | Codeigniter | Code Injection vulnerability in Codeigniter CodeIgniter is a PHP full-stack web framework. | 9.8 |
2023-05-29 | CVE-2022-24627 | Audiocodes | SQL Injection vulnerability in Audiocodes Device Manager Express An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. | 9.8 |
2023-05-29 | CVE-2022-24629 | Audiocodes | Path Traversal vulnerability in Audiocodes Device Manager Express An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. | 9.8 |
2023-05-29 | CVE-2019-19791 | Lemonldap NG | Unspecified vulnerability in Lemonldap-Ng Lemonldap::Ng In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoints (when some LemonLDAP::NG setup options are used). | 9.8 |
2023-05-29 | CVE-2023-2962 | Faculty Evaluation System Project | Unspecified vulnerability in Faculty Evaluation System Project Faculty Evaluation System 1.0 A vulnerability, which was classified as critical, has been found in SourceCodester Faculty Evaluation System 1.0. | 9.8 |
2023-05-29 | CVE-2023-2955 | Students Online Internship Timesheet System Project | Unspecified vulnerability in Students Online Internship Timesheet System Project Students Online Internship Timesheet System 1.0 A vulnerability, which was classified as critical, was found in SourceCodester Students Online Internship Timesheet System 1.0. | 9.8 |
2023-05-31 | CVE-2023-28347 | Faronics | Cross-site Scripting vulnerability in Faronics Insight 10.0.19045 An issue was discovered in Faronics Insight 10.0.19045 on Windows. | 9.6 |
2023-06-01 | CVE-2023-29722 | Glitter Unicorn Wallpaper Project | Unspecified vulnerability in Glitter Unicorn Wallpaper Project Glitter Unicorn Wallpaper 7.0/8.0 The Glitter Unicorn Wallpaper app for Android 7.0 thru 8.0 allows unauthorized apps to actively request permission to modify data in the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the app is opened. | 9.1 |
2023-05-30 | CVE-2022-36247 | Shopbeat | Authorization Bypass Through User-Controlled Key vulnerability in Shopbeat Shop Beat Media Player 2.5.95 Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to IDOR via controlpanel.shopbeat.co.za. | 9.1 |
2023-05-30 | CVE-2023-33193 | Emby | HTTP Request Smuggling vulnerability in Emby Emby.Releases Emby Server is a user-installable home media server which stores and organizes a user's media files of virtually any format and makes them available for viewing at home and abroad on a broad range of client devices. | 9.1 |
2023-05-30 | CVE-2023-34205 | Moov | Improper Verification of Cryptographic Signature vulnerability in Moov Signedxml 1.0.0 In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canonicalized XML. | 9.1 |
2023-06-03 | CVE-2023-3086 | Teampass | Unspecified vulnerability in Teampass Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | 9.0 |
2023-06-02 | CVE-2022-45938 | Xfinity | Cross-site Scripting vulnerability in Xfinity Comcast Defined Technologies Microeisbss 2021 An issue was discovered in Comcast Defined Technologies microeisbss through 2021. | 9.0 |
193 High Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2023-06-04 | CVE-2013-10027 | Wordpress | Unspecified vulnerability in Wordpress Blogger Importer 0.5 A vulnerability was found in Blogger Importer Plugin up to 0.5 on WordPress. | 8.8 |
2023-06-03 | CVE-2023-3052 | Azexo | Cross-Site Request Forgery (CSRF) vulnerability in Azexo Page Builder With Image MAP BY Azexo 1.27.133 The Page Builder by AZEXO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.27.133. | 8.8 |
2023-06-02 | CVE-2023-0767 | Mozilla | Unspecified vulnerability in Mozilla Firefox ESR An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled. | 8.8 |
2023-06-02 | CVE-2023-23605 | Mozilla | Out-of-bounds Write vulnerability in Mozilla Firefox Memory safety bugs present in Firefox 108 and Firefox ESR 102.6. | 8.8 |
2023-06-02 | CVE-2023-23606 | Mozilla | Out-of-bounds Write vulnerability in Mozilla Firefox Memory safety bugs present in Firefox 108. | 8.8 |
2023-06-02 | CVE-2023-25729 | Mozilla | Unspecified vulnerability in Mozilla Firefox ESR Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them without user interaction via <code>ExpandedPrincipals</code>. | 8.8 |
2023-06-02 | CVE-2023-25731 | Mozilla | Unspecified vulnerability in Mozilla Firefox Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global objects in privileged code. | 8.8 |
2023-06-02 | CVE-2023-25732 | Mozilla | Out-of-bounds Write vulnerability in Mozilla Firefox ESR When encoding data from an <code>inputStream</code> in <code>xpcom</code> the size of the input being encoded was not correctly calculated potentially leading to an out of bounds memory write. | 8.8 |
2023-06-02 | CVE-2023-25735 | Mozilla | Use After Free vulnerability in Mozilla Firefox ESR Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free after unwrapping the proxy. | 8.8 |
2023-06-02 | CVE-2023-25737 | Mozilla | Unspecified vulnerability in Mozilla Firefox ESR An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> could have lead to undefined behavior. | 8.8 |
2023-06-02 | CVE-2023-25739 | Mozilla | Use After Free vulnerability in Mozilla Firefox ESR Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in <code>ScriptLoadContext</code>. | 8.8 |
2023-06-02 | CVE-2023-25740 | Mozilla | Unspecified vulnerability in Mozilla Firefox After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. | 8.8 |
2023-06-02 | CVE-2023-25744 | Mozilla | Out-of-bounds Write vulnerability in Mozilla Firefox ESR Mmemory safety bugs present in Firefox 109 and Firefox ESR 102.7. | 8.8 |
2023-06-02 | CVE-2023-25745 | Mozilla | Out-of-bounds Write vulnerability in Mozilla Firefox Memory safety bugs present in Firefox 109. | 8.8 |
2023-06-02 | CVE-2023-25746 | Mozilla | Out-of-bounds Write vulnerability in Mozilla Firefox ESR Memory safety bugs present in Firefox ESR 102.7. | 8.8 |
2023-06-02 | CVE-2023-28161 | Mozilla | Improper Preservation of Permissions vulnerability in Mozilla Firefox If temporary "one-time" permissions, such as the ability to use the Camera, were granted to a document loaded using a file: URL, that permission persisted in that tab for all other documents loaded from a file: URL. | 8.8 |
2023-06-02 | CVE-2023-28162 | Mozilla | Incorrect Type Conversion or Cast vulnerability in Mozilla Firefox While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic type. | 8.8 |
2023-06-02 | CVE-2023-28176 | Mozilla | Out-of-bounds Write vulnerability in Mozilla Firefox Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. | 8.8 |
2023-06-02 | CVE-2023-28177 | Mozilla | Out-of-bounds Write vulnerability in Mozilla Firefox Memory safety bugs present in Firefox 110. | 8.8 |
2023-06-02 | CVE-2023-29536 | Mozilla | Use After Free vulnerability in Mozilla products An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertion, memory corruption, or a potentially exploitable crash. | 8.8 |
2023-06-02 | CVE-2023-29539 | Mozilla | NULL Pointer Dereference vulnerability in Mozilla products When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. | 8.8 |
2023-06-02 | CVE-2023-29541 | Mozilla | Improper Encoding or Escaping of Output vulnerability in Mozilla products Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands. | 8.8 |
2023-06-02 | CVE-2023-29543 | Mozilla | Use After Free vulnerability in Mozilla Firefox and Focus An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vector. | 8.8 |
2023-06-02 | CVE-2023-29550 | Mozilla | Unspecified vulnerability in Mozilla products Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. | 8.8 |
2023-06-02 | CVE-2023-29551 | Mozilla | Out-of-bounds Write vulnerability in Mozilla Firefox and Focus Memory safety bugs present in Firefox 111. | 8.8 |
2023-06-02 | CVE-2023-32207 | Mozilla | Authentication Bypass by Spoofing vulnerability in Mozilla Firefox A missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permissions. | 8.8 |
2023-06-02 | CVE-2023-32213 | Mozilla | Use of Uninitialized Resource vulnerability in Mozilla Firefox When reading a file, an uninitialized value could have been used as read limit. | 8.8 |
2023-06-02 | CVE-2023-32215 | Mozilla | Out-of-bounds Write vulnerability in Mozilla Firefox Memory safety bugs present in Firefox 112 and Firefox ESR 102.10. | 8.8 |
2023-06-02 | CVE-2023-3032 | Mobatime | Unrestricted Upload of File with Dangerous Type vulnerability in Mobatime web Application 06.7.22 Unrestricted Upload of File with Dangerous Type vulnerability in Mobatime web application (Documentary proof upload modules) allows a malicious user to Upload a Web Shell to a Web Server.This issue affects Mobatime web application: through 06.7.22. | 8.8 |
2023-06-02 | CVE-2023-3033 | Mobatime | Incorrect Authorization vulnerability in Mobatime web Application 06.7.22 Incorrect Authorization vulnerability in Mobatime web application allows Privilege Escalation, Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mobatime web application: through 06.7.22. | 8.8 |
2023-06-02 | CVE-2023-27745 | Southrivertech | Unspecified vulnerability in Southrivertech Titan FTP Server Nextgen 1.2.1050 An issue in South River Technologies TitanFTP Before v2.0.1.2102 allows attackers with low-level privileges to perform Administrative actions by sending requests to the user server. | 8.8 |
2023-06-02 | CVE-2023-2201 | Salephpscripts | SQL Injection vulnerability in Salephpscripts web Directory Free The Web Directory Free for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 1.6.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 8.8 |
2023-06-01 | CVE-2023-32707 | Splunk | Unspecified vulnerability in Splunk and Splunk Cloud Platform In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_user’ capability assigned to it can escalate their privileges to that of the admin user by providing specially crafted web requests. | 8.8 |
2023-06-01 | CVE-2023-32708 | Splunk | Interpretation Conflict vulnerability in Splunk and Splunk Cloud Platform In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can trigger an HTTP response splitting vulnerability with the ‘rest’ SPL command that lets them potentially access other REST endpoints in the system arbitrarily. | 8.8 |
2023-06-01 | CVE-2023-33965 | Txthinking | OS Command Injection vulnerability in Txthinking Brook Brook is a cross-platform programmable network tool. | 8.8 |
2023-06-01 | CVE-2015-10109 | Cincopa | Cross-Site Request Forgery (CSRF) vulnerability in Cincopa Video and Media Plug-In A vulnerability was found in Video Playlist and Gallery Plugin up to 1.136 on WordPress. | 8.8 |
2023-06-01 | CVE-2023-22648 | Suse | Unspecified vulnerability in Suse Rancher 2.6.10/2.7.0/2.7.1 A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while they are logged in the Rancher UI. | 8.8 |
2023-06-01 | CVE-2023-3029 | Pythagorean OA Office System Project | Unspecified vulnerability in Pythagorean OA Office System Project Pythagorean OA Office System A vulnerability has been found in Guangdong Pythagorean OA Office System up to 4.50.31 and classified as problematic. | 8.8 |
2023-06-01 | CVE-2023-28657 | Contec | Unspecified vulnerability in Contec Conprosys HMI System Improper access control vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. | 8.8 |
2023-06-01 | CVE-2023-28937 | Saison | Use of Hard-coded Credentials vulnerability in Saison Dataspider Servista DataSpider Servista version 4.4 and earlier uses a hard-coded cryptographic key. | 8.8 |
2023-05-31 | CVE-2015-10108 | Inline Google Spreadsheet Viewer Project | Unspecified vulnerability in Inline Google Spreadsheet Viewer Project Inline Google Spreadsheet Viewer 0.9.6 A vulnerability was found in meitar Inline Google Spreadsheet Viewer Plugin up to 0.9.6 on WordPress and classified as problematic. | 8.8 |
2023-05-31 | CVE-2023-33718 | Mp4V2 Project | Memory Leak vulnerability in Mp4V2 Project Mp4V2 2.1.3 mp4v2 v2.1.3 was discovered to contain a memory leak via MP4File::ReadString() at mp4file_io.cpp | 8.8 |
2023-05-31 | CVE-2023-33722 | Edimax | Command Injection vulnerability in Edimax Br-6288Acl Firmware 1.12 EDIMAX BR-6288ACL v1.12 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the pppUserName parameter. | 8.8 |
2023-05-31 | CVE-2023-3018 | Oretnom23 | Unspecified vulnerability in Oretnom23 Lost and Found Information System 1.0 A vulnerability was found in SourceCodester Lost and Found Information System 1.0. | 8.8 |
2023-05-31 | CVE-2023-33485 | Totolink | Out-of-bounds Write vulnerability in Totolink X5000R Firmware 9.1.0U.6118B20201102/9.1.0U.6369B20230113 TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a post-authentication buffer overflow via parameter sPort/ePort in the addEffect function. | 8.8 |
2023-05-31 | CVE-2023-2545 | Featherplugins | Missing Authorization vulnerability in Featherplugins Feather Login Page 1.0.7/1.1.1 The Feather Login Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'getListOfUsers' function in versions starting from 1.0.7 up to, and including, 1.1.1. | 8.8 |
2023-05-31 | CVE-2023-2549 | Featherplugins | Cross-Site Request Forgery (CSRF) vulnerability in Featherplugins Feather Login Page 1.0.7/1.1.1 The Feather Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions starting from 1.0.7 up to, and including, 1.1.1. | 8.8 |
2023-05-31 | CVE-2012-10015 | Bestwebsoft | Unspecified vulnerability in Bestwebsoft Twitter A vulnerability was found in BestWebSoft Twitter Plugin up to 2.14 on WordPress. | 8.8 |
2023-05-31 | CVE-2023-28349 | Faronics | Origin Validation Error vulnerability in Faronics Insight 10.0.19045 An issue was discovered in Faronics Insight 10.0.19045 on Windows. | 8.8 |
2023-05-31 | CVE-2023-28353 | Faronics | Unrestricted Upload of File with Dangerous Type vulnerability in Faronics Insight 10.0.19045 An issue was discovered in Faronics Insight 10.0.19045 on Windows. | 8.8 |
2023-05-30 | CVE-2023-2929 | Out-of-bounds Write vulnerability in Google Chrome Out of bounds write in Swiftshader in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 8.8 | |
2023-05-30 | CVE-2023-2930 | Use After Free vulnerability in Google Chrome Use after free in Extensions in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. | 8.8 | |
2023-05-30 | CVE-2023-2931 | Use After Free vulnerability in Google Chrome Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | 8.8 | |
2023-05-30 | CVE-2023-2932 | Use After Free vulnerability in Google Chrome Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | 8.8 | |
2023-05-30 | CVE-2023-2933 | Use After Free vulnerability in Google Chrome Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | 8.8 | |
2023-05-30 | CVE-2023-2934 | Out-of-bounds Write vulnerability in Google Chrome Out of bounds memory access in Mojo in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 8.8 | |
2023-05-30 | CVE-2023-2935 | Type Confusion vulnerability in Google Chrome Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 8.8 | |
2023-05-30 | CVE-2023-2936 | Type Confusion vulnerability in Google Chrome Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 8.8 | |
2023-05-30 | CVE-2022-36250 | Shopbeat | Cross-Site Request Forgery (CSRF) vulnerability in Shopbeat Shop Beat Media Player 2.5.95 Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Cross Site Request Forgery (CSRF). | 8.8 |
2023-05-30 | CVE-2023-33177 | Xibosignage | Path Traversal vulnerability in Xibosignage Xibo Xibo is a content management system (CMS). | 8.8 |
2023-05-30 | CVE-2023-32696 | Okfn | Improper Privilege Management vulnerability in Okfn Ckan CKAN is an open-source data management system for powering data hubs and data portals. | 8.8 |
2023-05-30 | CVE-2023-2980 | Abstrium | Injection vulnerability in Abstrium Pydio Cells 4.2.0 A vulnerability classified as critical was found in Abstrium Pydio Cells 4.2.0. | 8.8 |
2023-05-30 | CVE-2023-2983 | Pimcore | Unspecified vulnerability in Pimcore Privilege Defined With Unsafe Actions in GitHub repository pimcore/pimcore prior to 10.5.23. | 8.8 |
2023-05-30 | CVE-2023-2984 | Pimcore | Unspecified vulnerability in Pimcore Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22. | 8.8 |
2023-05-30 | CVE-2023-2979 | Abstrium | Unspecified vulnerability in Abstrium Pydio Cells 4.2.0 A vulnerability classified as critical has been found in Abstrium Pydio Cells 4.2.0. | 8.8 |
2023-05-30 | CVE-2023-0766 | Newsletter Popup Project | Unspecified vulnerability in Newsletter Popup Project Newsletter Popup The Newsletter Popup WordPress plugin through 1.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks as the wp_newsletter_show_localrecord page is not protected with a nonce. | 8.8 |
2023-05-30 | CVE-2023-1938 | Wpfastestcache | Unspecified vulnerability in Wpfastestcache WP Fastest Cache The WP Fastest Cache WordPress plugin before 1.1.5 does not have CSRF check in an AJAX action, and does not validate user input before using it in the wp_remote_get() function, leading to a Blind SSRF issue | 8.8 |
2023-05-30 | CVE-2023-2288 | Themeisle | Deserialization of Untrusted Data vulnerability in Themeisle Otter The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operations on them. | 8.8 |
2023-05-30 | CVE-2023-33191 | Nirmata | Unspecified vulnerability in Nirmata Kyverno 1.9.2/1.9.3 Kyverno is a policy engine designed for Kubernetes. | 8.8 |
2023-05-30 | CVE-2023-26130 | CPP Httplib Project | Injection vulnerability in Cpp-Httplib Project Cpp-Httplib Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type header in the HTTP .Patch, .Post, .Put and .Delete requests. | 8.8 |
2023-05-30 | CVE-2023-33245 | Minecraft | Link Following vulnerability in Minecraft Minecraft through 1.19 and 1.20 pre-releases before 7 (Java) allow arbitrary file overwrite, and possibly code execution, via crafted world data that contains a symlink. | 8.8 |
2023-05-29 | CVE-2023-30253 | Dolibarr | OS Command Injection vulnerability in Dolibarr Erp/Crm Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data. | 8.8 |
2023-05-29 | CVE-2022-33974 | Smashballoon | Unspecified vulnerability in Smashballoon Custom Twitter Feeds Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds (Tweets Widget) plugin <= 1.8.4 versions. | 8.8 |
2023-05-29 | CVE-2022-45372 | Codeixer | Unspecified vulnerability in Codeixer Product Gallery Slider for Woocommerce Cross-Site Request Forgery (CSRF) vulnerability in Codeixer Product Gallery Slider for WooCommerce plugin <= 2.2.8 versions. | 8.8 |
2023-05-29 | CVE-2023-30350 | FS | Unspecified vulnerability in FS S3900 24T4S Firmware FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin password. | 8.8 |
2023-05-29 | CVE-2023-31874 | Yank Note | Incorrect Permission Assignment for Critical Resource vulnerability in Yank-Note Yank Note 3.52.1 Yank Note (YN) 3.52.1 allows execution of arbitrary code when a crafted file is opened, e.g., via nodeRequire('child_process'). | 8.8 |
2023-06-03 | CVE-2023-3083 | Teampass | Unspecified vulnerability in Teampass Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | 8.7 |
2023-06-01 | CVE-2022-43760 | Suse | Unspecified vulnerability in Suse Rancher An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SUSE Rancher allows users in some higher-privileged groups to to inject code that is executed within another user's browser, allowing the attacker to steal sensitive information, manipulate web content, or perform other malicious activities on behalf of the victims. | 8.4 |
2023-06-03 | CVE-2023-3084 | Teampass | Unspecified vulnerability in Teampass Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | 8.1 |
2023-06-02 | CVE-2023-25734 | Mozilla | Unspecified vulnerability in Mozilla Firefox After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. | 8.1 |
2023-06-01 | CVE-2023-32714 | Splunk | Path Traversal vulnerability in Splunk and Splunk APP for Lookup File Editing In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path traversal exploit that can then be used to read and write to restricted areas of the Splunk installation directory. | 8.1 |
2023-06-01 | CVE-2023-32310 | Dataease | Authorization Bypass Through User-Controlled Key vulnerability in Dataease DataEase is an open source data visualization and analysis tool. | 8.1 |
2023-06-01 | CVE-2023-28713 | Contec | Cleartext Storage of Sensitive Information vulnerability in Contec Conprosys HMI System Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. | 8.1 |
2023-06-01 | CVE-2023-23955 | Broadcom | Server-Side Request Forgery (SSRF) vulnerability in Broadcom Advanced Secure Gateway and Content Analysis Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Server-Side Request Forgery vulnerability. | 8.1 |
2023-06-01 | CVE-2023-22647 | Suse | Unspecified vulnerability in Suse Rancher An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing permissions to manipulate Kubernetes secrets in the local cluster, resulting in the secret being deleted, but their read-level permissions to the secret being preserved. | 8.0 |
2023-06-04 | CVE-2023-3091 | Captura Project | Unspecified vulnerability in Captura Project Captura ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Captura up to 8.0.0. | 7.8 |
2023-06-02 | CVE-2023-27744 | Southrivertech | Unspecified vulnerability in Southrivertech Titan FTP Server Nextgen 1.2.1050 An issue was discovered in South River Technologies TitanFTP NextGen server that allows for a vertical privilege escalation leading to remote code execution. | 7.8 |
2023-06-02 | CVE-2023-29724 | Bt21 X BTS Wallpaper Project | Unspecified vulnerability in Bt21 X BTS Wallpaper Project Bt21 X BTS Wallpaper 12 The BT21 x BTS Wallpaper app 12 for Android allows unauthorized apps to actively request permission to modify data in the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the app is opened. | 7.8 |
2023-06-01 | CVE-2023-28066 | Dell | Unspecified vulnerability in Dell OS Recovery Tool 2.2.4013/2.3.7012.0 Dell OS Recovery Tool, versions 2.2.4013 and 2.3.7012.0, contain an Improper Access Control Vulnerability. | 7.8 |
2023-06-01 | CVE-2023-33551 | Erofs Utils Project | Out-of-bounds Write vulnerability in Erofs-Utils Project Erofs-Utils 1.6 Heap Buffer Overflow in the erofsfsck_dirent_iter function in fsck/main.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code via a crafted erofs filesystem image. | 7.8 |
2023-06-01 | CVE-2023-33552 | Erofs Utils Project | Out-of-bounds Write vulnerability in Erofs-Utils Project Erofs-Utils 1.6 Heap Buffer Overflow in the erofs_read_one_data function at data.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code via a crafted erofs filesystem image. | 7.8 |
2023-06-01 | CVE-2023-34312 | Tencent | Release of Invalid Pointer or Reference vulnerability in Tencent QQ and TIM In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from inter-process communication, which leads to a write-what-where condition. | 7.8 |
2023-06-01 | CVE-2023-28399 | Contec | Incorrect Permission Assignment for Critical Resource vulnerability in Contec Conprosys HMI System Incorrect permission assignment for critical resource exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. | 7.8 |
2023-06-01 | CVE-2023-23953 | Broadcom | Unspecified vulnerability in Broadcom Advanced Secure Gateway and Content Analysis Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to an Elevation of Privilege vulnerability. | 7.8 |
2023-06-01 | CVE-2023-2598 | Linux Netapp | Out-of-bounds Write vulnerability in multiple products A flaw was found in the fixed buffer registration code for io_uring (io_sqe_buffer_register in io_uring/rsrc.c) in the Linux kernel that allows out-of-bounds access to physical memory beyond the end of the buffer. | 7.8 |
2023-05-31 | CVE-2023-26278 | IBM | Unspecified vulnerability in IBM Qradar Wincollect 10.0/10.0.1 IBM QRadar WinCollect Agent 10.0 through 10.1.3 could allow a local authenticated attacker to gain elevated privileges on the system. | 7.8 |
2023-05-31 | CVE-2023-26277 | IBM | Unspecified vulnerability in IBM Qradar Wincollect 10.0/10.0.1 IBM QRadar WinCollect Agent 10.0 though 10.1.3 could allow a local user to execute commands on the system due to execution with unnecessary privileges. | 7.8 |
2023-05-31 | CVE-2023-3012 | Gpac | Unspecified vulnerability in Gpac NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2. | 7.8 |
2023-05-31 | CVE-2023-29742 | Bestweather Project | Unspecified vulnerability in Bestweather Project Bestweather 7.3.1 An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a code execution attack by manipulating the database. | 7.8 |
2023-05-30 | CVE-2023-29738 | Wavekeyboard | Unspecified vulnerability in Wavekeyboard Wave Animated Keyboard Emoji 1.70.7 An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause code execution and escalation of Privileges via the database files. | 7.8 |
2023-05-30 | CVE-2023-2939 | Link Following vulnerability in Google Chrome Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to perform privilege escalation via crafted symbolic link. | 7.8 | |
2023-05-30 | CVE-2023-34153 | Imagemagick Fedoraproject Redhat | Command Injection vulnerability in multiple products A vulnerability was found in ImageMagick. | 7.8 |
2023-05-30 | CVE-2022-47029 | Actionlauncher | Unspecified vulnerability in Actionlauncher Action Launcher 50.5 An issue was found in Action Launcher v50.5 allows an attacker to escalate privilege via modification of the intent string to function update. | 7.8 |
2023-05-30 | CVE-2023-29733 | Dualspace | Unspecified vulnerability in Dualspace Lock Master 2.2.4 The Lock Master app 2.2.4 for Android allows unauthorized apps to modify the values in its SharedPreference files. | 7.8 |
2023-05-30 | CVE-2023-31184 | Rozcom | Use of Hard-coded Credentials vulnerability in Rozcom Client ROZCOM client CWE-798: Use of Hard-coded Credentials | 7.8 |
2023-05-30 | CVE-2023-28079 | Dell | Unspecified vulnerability in Dell Powerpath 7.0/7.1/7.2 PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains Insecure File and Folder Permissions vulnerability. | 7.8 |
2023-05-30 | CVE-2023-30601 | Apache | Unspecified vulnerability in Apache Cassandra Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra This issue affects Apache Cassandra: from 4.0.0 through 4.0.9, from 4.1.0 through 4.1.1. WORKAROUND The vulnerability requires nodetool/JMX access to be exploitable, disable access for any non-trusted users. MITIGATION Upgrade to 4.0.10 or 4.1.2 and leave the new FQL/Auditlog configuration property allow_nodetool_archive_command as false. | 7.8 |
2023-05-30 | CVE-2023-0779 | Zephyrproject | NULL Pointer Dereference vulnerability in Zephyrproject Zephyr At the most basic level, an invalid pointer can be input that crashes the device, but with more knowledge of the device’s memory layout, further exploitation is possible. | 7.7 |
2023-06-03 | CVE-2023-33143 | Microsoft | Unspecified vulnerability in Microsoft Edge Chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 7.5 |
2023-06-02 | CVE-2023-1297 | Hashicorp | Unspecified vulnerability in Hashicorp Consul Consul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local service could corrupt Consul state, resulting in denial of service. | 7.5 |
2023-06-02 | CVE-2023-33672 | Tenda | Out-of-bounds Write vulnerability in Tenda AC8 Firmware 16.03.34.06 Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function. | 7.5 |
2023-06-02 | CVE-2023-25743 | Mozilla | Authentication Bypass by Spoofing vulnerability in Mozilla Firefox Focus A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.<br>*This bug only affects Firefox Focus. | 7.5 |
2023-06-02 | CVE-2023-29537 | Mozilla | Race Condition vulnerability in Mozilla Firefox and Focus Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. | 7.5 |
2023-06-02 | CVE-2023-2060 | Mitsubishielectric | Weak Password Requirements vulnerability in Mitsubishielectric products Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to access to the module via FTP by dictionary attack or password sniffing. | 7.5 |
2023-06-02 | CVE-2023-2061 | Mitsubishielectric | Use of Hard-coded Credentials vulnerability in Mitsubishielectric products Use of Hard-coded Password vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to obtain a hard-coded password and access to the module via FTP. | 7.5 |
2023-06-01 | CVE-2023-27639 | Tshirtecommerce | Path Traversal vulnerability in Tshirtecommerce Custom Product Designer An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. | 7.5 |
2023-06-01 | CVE-2023-27640 | Tshirtecommerce | Path Traversal vulnerability in Tshirtecommerce Custom Product Designer An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. | 7.5 |
2023-06-01 | CVE-2023-29723 | Glitter Unicorn Wallpaper Project | Unspecified vulnerability in Glitter Unicorn Wallpaper Project Glitter Unicorn Wallpaper 7.0/8.0 The Glitter Unicorn Wallpaper app for Android 7.0 thru 8.0 allows unauthorized applications to actively request permission to insert data into the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the application is opened. | 7.5 |
2023-06-01 | CVE-2023-32690 | Dmtf | Unspecified vulnerability in Dmtf Libspdm libspdm is a sample implementation that follows the DMTF SPDM specifications. | 7.5 |
2023-06-01 | CVE-2023-33960 | Openproject | Cleartext Transmission of Sensitive Information vulnerability in Openproject OpenProject is web-based project management software. | 7.5 |
2023-06-01 | CVE-2023-34092 | Vitejs | Use of Incorrectly-Resolved Name or Reference vulnerability in Vitejs Vite Vite provides frontend tooling. | 7.5 |
2023-06-01 | CVE-2023-29748 | Story Saver FOR Instagram Video Downloader Project | Unspecified vulnerability in Story Saver for Instagram - Video Downloader Project Story Saver for Instagram - Video Downloader 1.0.6 Story Saver for Instragram - Video Downloader 1.0.6 for Android has an exposed component that provides a method to modify the SharedPreference file. | 7.5 |
2023-06-01 | CVE-2023-29159 | Encode | Path Traversal vulnerability in Encode Starlette Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files in a web service which was built using Starlette. | 7.5 |
2023-05-31 | CVE-2023-34258 | BMC | Missing Encryption of Sensitive Data vulnerability in BMC Patrol 9.13.10.01 An issue was discovered in BMC Patrol before 22.1.00. | 7.5 |
2023-05-31 | CVE-2023-33964 | Multiversx | Unspecified vulnerability in Multiversx Mx-Chain-Go mx-chain-go is an implementation of the MultiversX blockchain protocol written in the Go language. | 7.5 |
2023-05-31 | CVE-2023-34227 | Jetbrains | Unspecified vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacks | 7.5 |
2023-05-31 | CVE-2023-33507 | Kramerav | Unspecified vulnerability in Kramerav VIA GO2 Firmware KramerAV VIA GO² < 4.0.1.1326 is vulnerable to Unauthenticated arbitrary file read. | 7.5 |
2023-05-31 | CVE-2023-30285 | Deviniti | Unspecified vulnerability in Deviniti Issue Sync An issue in Deviniti Issue Sync Synchronization v3.5.2 for Jira allows attackers to obtain the login credentials of a user via a crafted request sent to /rest/synchronizer/1.0/technicalUser. | 7.5 |
2023-05-31 | CVE-2023-2749 | Asustor | Incorrect Default Permissions vulnerability in Asustor Download Center Download Center fails to properly validate the file path submitted by a user, An attacker can exploit this vulnerability to gain unauthorized access to sensitive files or directories without appropriate permission restrictions. | 7.5 |
2023-05-31 | CVE-2021-31233 | Fighting Cock Information System Project | SQL Injection vulnerability in Fighting Cock Information System Project Fighting Cock Information System 1.0 SQL Injection vulnerability found in Fighting Cock Information System v.1.0 allows a remote attacker to obtain sensitive information via the edit_breed.php parameter. | 7.5 |
2023-05-31 | CVE-2023-30197 | Webbax | Path Traversal vulnerability in Webbax Myinventory 1.6.6 Incorrect Access Control in the module "My inventory" (myinventory) <= 1.6.6 from Webbax for PrestaShop, allows a guest to download personal information without restriction by performing a path traversal attack. | 7.5 |
2023-05-31 | CVE-2022-47525 | FOX IT | Divide By Zero vulnerability in Fox-It FOX Datadiode Firmware 3.4.3 Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a Divide-by-Zero vulnerability in the packet parser. | 7.5 |
2023-05-30 | CVE-2023-29726 | Applika | Improper Resource Shutdown or Release vulnerability in Applika Call Blocker 6.6.3 The Call Blocker application 6.6.3 for Android incorrectly opens a key component that an attacker can use to inject large amounts of dirty data into the application's database. | 7.5 |
2023-05-30 | CVE-2023-29740 | Amdroidapp | Unspecified vulnerability in Amdroidapp Alarm Clock for Heavy Sleepers 5.3.2 An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause a denial of service attack by manipulating the database. | 7.5 |
2023-05-30 | CVE-2023-29743 | Bestweather Project | Unspecified vulnerability in Bestweather Project Bestweather 7.3.1 An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database. | 7.5 |
2023-05-30 | CVE-2023-2953 | Openldap Redhat Apple Netapp | NULL Pointer Dereference vulnerability in multiple products A vulnerability was found in openldap. | 7.5 |
2023-05-30 | CVE-2023-32342 | IBM | Information Exposure Through Discrepancy vulnerability in IBM Http Server IBM GSKit could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. | 7.5 |
2023-05-30 | CVE-2023-33740 | Luowice | Unspecified vulnerability in Luowice 3.5.18 Incorrect access control in luowice v3.5.18 allows attackers to access cloud source code information via modification fo the Verify parameter in a warning message. | 7.5 |
2023-05-30 | CVE-2023-33741 | Macro Video | Unspecified vulnerability in Macro-Video V380 PRO 1.4.97 Macrovideo v380pro v1.4.97 shares the device id and password when sharing the device. | 7.5 |
2023-05-30 | CVE-2023-29731 | Loka | Incorrect Default Permissions vulnerability in Loka Solive 1.6.14/1.6.16/1.6.20 SoLive 1.6.14 thru 1.6.20 for Android has an exposed component that provides a method to modify the SharedPreference file. | 7.5 |
2023-05-30 | CVE-2023-31185 | Rozcom | Unspecified vulnerability in Rozcom Client ROZCOM server framework - Misconfiguration may allow information disclosure via an unspecified request. | 7.5 |
2023-05-30 | CVE-2023-2968 | Proxy Project | Unspecified vulnerability in Proxy Project Proxy 2.0.0/2.1.1 A remote attacker can trigger a denial of service in the socket.remoteAddress variable, by sending a crafted HTTP request. | 7.5 |
2023-05-30 | CVE-2022-4240 | Honeywell | Missing Authentication for Critical Function vulnerability in Honeywell Onewireless Network Wireless Device Manager Firmware R322.1 Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This issue affects OneWireless version 322.1 | 7.5 |
2023-05-30 | CVE-2023-23755 | Joomla | Improper Restriction of Excessive Authentication Attempts vulnerability in Joomla Joomla! An issue was discovered in Joomla! 4.2.0 through 4.3.1. | 7.5 |
2023-05-30 | CVE-2023-24826 | Riot OS | Access of Uninitialized Pointer vulnerability in Riot-Os Riot RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. | 7.5 |
2023-05-30 | CVE-2023-33973 | Riot OS | NULL Pointer Dereference vulnerability in Riot-Os Riot RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. | 7.5 |
2023-05-30 | CVE-2023-24817 | Riot OS | Integer Underflow (Wrap or Wraparound) vulnerability in Riot-Os Riot RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. | 7.5 |
2023-05-30 | CVE-2023-24825 | Riot OS | Unchecked Return Value vulnerability in Riot-Os Riot RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. | 7.5 |
2023-05-30 | CVE-2023-30196 | Webbax | Path Traversal vulnerability in Webbax Salesbooster 1.10.4 Prestashop salesbooster <= 1.10.4 is vulnerable to Incorrect Access Control via modules/salesbooster/downloads/download.php. | 7.5 |
2023-05-30 | CVE-2023-33175 | Toui Project | Improper Control of Dynamically-Managed Code Resources vulnerability in Toui Project Toui ToUI is a Python package for creating user interfaces (websites and desktop apps) from HTML. | 7.5 |
2023-05-30 | CVE-2023-33198 | Tgstation13 | Unspecified vulnerability in Tgstation13 Tgstation-Server tgstation-server is a production scale tool for BYOND server management. | 7.5 |
2023-05-29 | CVE-2014-125102 | Bestwebsoft | Unspecified vulnerability in Bestwebsoft Relevant A vulnerability classified as problematic was found in Bestwebsoft Relevant Plugin up to 1.0.7 on WordPress. | 7.5 |
2023-05-29 | CVE-2021-27825 | Mercurycom | Path Traversal vulnerability in Mercurycom Mac1200R Firmware A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL. | 7.5 |
2023-05-29 | CVE-2023-29380 | Linuxmint | Path Traversal vulnerability in Linuxmint Warpinator Warpinator before 1.6.0 allows remote file deletion via directory traversal in top_dir_basenames. | 7.5 |
2023-05-29 | CVE-2023-30570 | Libreswan | Resource Exhaustion vulnerability in Libreswan pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets. | 7.5 |
2023-05-31 | CVE-2023-28348 | Faronics | Cleartext Transmission of Sensitive Information vulnerability in Faronics Insight 10.0.19045 An issue was discovered in Faronics Insight 10.0.19045 on Windows. | 7.4 |
2023-05-31 | CVE-2023-28352 | Faronics | Incorrect Authorization vulnerability in Faronics Insight 10.0.19045 An issue was discovered in Faronics Insight 10.0.19045 on Windows. | 7.4 |
2023-06-02 | CVE-2023-2063 | Mitsubishielectric | Unrestricted Upload of File with Dangerous Type vulnerability in Mitsubishielectric products Unrestricted Upload of File with Dangerous Type vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to cause information disclosure, tampering, deletion or destruction via file upload/download. | 7.3 |
2023-05-31 | CVE-2023-28346 | Faronics | Incorrect Permission Assignment for Critical Resource vulnerability in Faronics Insight 10.0.19045 An issue was discovered in Faronics Insight 10.0.19045 on Windows. | 7.3 |
2023-05-30 | CVE-2023-28080 | Dell | Unspecified vulnerability in Dell Powerpath 7.0/7.1/7.2 PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains DLL Hijacking Vulnerabilities. | 7.3 |
2023-06-02 | CVE-2022-47616 | Hitrontech | OS Command Injection vulnerability in Hitrontech Coda-5310 Firmware Hitron CODA-5310 has insufficient filtering for specific parameters in the connection test function. | 7.2 |
2023-06-01 | CVE-2023-29154 | Contec | SQL Injection vulnerability in Contec Conprosys HMI System SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3. | 7.2 |
2023-05-31 | CVE-2023-33627 | H3C | Out-of-bounds Write vulnerability in H3C Magic R300-2100M Firmware R3002100Mv100R004 H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the UpdateSnat interface at /goform/aspForm. | 7.2 |
2023-05-31 | CVE-2023-33628 | H3C | Out-of-bounds Write vulnerability in H3C Magic R300-2100M Firmware R3002100Mv100R004 H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the DelvsList interface at /goform/aspForm. | 7.2 |
2023-05-31 | CVE-2023-33629 | H3C | Out-of-bounds Write vulnerability in H3C Magic R300-2100M Firmware R3002100Mv100R004 H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the DeltriggerList interface at /goform/aspForm. | 7.2 |
2023-05-31 | CVE-2023-33630 | H3C | Out-of-bounds Write vulnerability in H3C Magic R300-2100M Firmware R3002100Mv100R004 H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the EditvsList interface at /goform/aspForm. | 7.2 |
2023-05-31 | CVE-2023-33631 | H3C | Out-of-bounds Write vulnerability in H3C Magic R300-2100M Firmware R3002100Mv100R004 H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the DelSTList interface at /goform/aspForm. | 7.2 |
2023-05-31 | CVE-2023-33632 | H3C | Out-of-bounds Write vulnerability in H3C Magic R300-2100M Firmware R3002100Mv100R004 H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the ipqos_lanip_dellist interface at /goform/aspForm. | 7.2 |
2023-05-31 | CVE-2023-33633 | H3C | Out-of-bounds Write vulnerability in H3C Magic R300-2100M Firmware R3002100Mv100R004 H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the UpdateWanParams interface at /goform/aspForm. | 7.2 |
2023-05-31 | CVE-2023-33634 | H3C | Out-of-bounds Write vulnerability in H3C Magic R300-2100M Firmware R3002100Mv100R004 H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the EdittriggerList interface at /goform/aspForm. | 7.2 |
2023-05-31 | CVE-2023-33635 | H3C | Out-of-bounds Write vulnerability in H3C Magic R300-2100M Firmware R3002100Mv100R004 H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the UpdateMacClone interface at /goform/aspForm. | 7.2 |
2023-05-31 | CVE-2023-33636 | H3C | Out-of-bounds Write vulnerability in H3C Magic R300-2100M Firmware R3002100Mv100R004 H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the ipqos_lanip_editlist interface at /goform/aspForm. | 7.2 |
2023-05-31 | CVE-2023-33637 | H3C | Out-of-bounds Write vulnerability in H3C Magic R300-2100M Firmware R3002100Mv100R004 H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the DelDNSHnList interface at /goform/aspForm. | 7.2 |
2023-05-31 | CVE-2023-33638 | H3C | Out-of-bounds Write vulnerability in H3C Magic R300-2100M Firmware R3002100Mv100R004 H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the Edit_BasicSSID_5G interface at /goform/aspForm. | 7.2 |
2023-05-31 | CVE-2023-33639 | H3C | Out-of-bounds Write vulnerability in H3C Magic R300-2100M Firmware R3002100Mv100R004 H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the SetMobileAPInfoById interface at /goform/aspForm. | 7.2 |
2023-05-31 | CVE-2023-33640 | H3C | Out-of-bounds Write vulnerability in H3C Magic R300-2100M Firmware R3002100Mv100R004 H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the SetAPWifiorLedInfoById interface at /goform/aspForm. | 7.2 |
2023-05-31 | CVE-2023-33641 | H3C | Out-of-bounds Write vulnerability in H3C Magic R300-2100M Firmware R3002100Mv100R004 H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the AddMacList interface at /goform/aspForm. | 7.2 |
2023-05-31 | CVE-2023-33642 | H3C | Out-of-bounds Write vulnerability in H3C Magic R300-2100M Firmware R3002100Mv100R004 H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the Edit_BasicSSID interface at /goform/aspForm. | 7.2 |
2023-05-31 | CVE-2023-33643 | H3C | Out-of-bounds Write vulnerability in H3C Magic R300-2100M Firmware R3002100Mv100R004 H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the AddWlanMacList interface at /goform/aspForm. | 7.2 |
2023-05-31 | CVE-2023-2435 | Blog IN Blog Project | Path Traversal vulnerability in Blog-In-Blog Project Blog-In-Blog 1.1.1 The Blog-in-Blog plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.1 via a shortcode attribute. | 7.2 |
2023-05-30 | CVE-2023-33234 | Apache | Unspecified vulnerability in Apache Airflow Cncf Kubernetes Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection. In order to exploit this weakness, a user would already need elevated permissions (Op or Admin) to change the connection object in this manner. Operators should upgrade to provider version 7.0.0 which has removed the vulnerability. | 7.2 |
2023-05-30 | CVE-2023-0329 | Elementor | Unspecified vulnerability in Elementor Website Builder The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role. | 7.2 |
2023-05-30 | CVE-2023-27988 | Zyxel | OS Command Injection vulnerability in Zyxel Nas326 Firmware, Nas540 Firmware and Nas542 Firmware The post-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.13)C0 could allow an authenticated attacker with administrator privileges to execute some operating system (OS) commands on an affected device remotely. | 7.2 |
2023-05-29 | CVE-2022-24628 | Audiocodes | SQL Injection vulnerability in Audiocodes Device Manager Express An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. | 7.2 |
2023-05-29 | CVE-2022-24630 | Audiocodes | Command Injection vulnerability in Audiocodes Device Manager Express An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. | 7.2 |
2023-06-01 | CVE-2023-2977 | Opensc Project Redhat | Out-of-bounds Read vulnerability in multiple products A vulnerbility was found in OpenSC. | 7.1 |
2023-05-31 | CVE-2022-48502 | Linux Netapp | Out-of-bounds Read vulnerability in multiple products An issue was discovered in the Linux kernel before 6.2. | 7.1 |
2023-05-31 | CVE-2023-3013 | Gpac | Unspecified vulnerability in Gpac Unchecked Return Value in GitHub repository gpac/gpac prior to 2.2.2. | 7.1 |
2023-05-31 | CVE-2023-28344 | Faronics | Exposure of Resource to Wrong Sphere vulnerability in Faronics Insight 10.0.19045 An issue was discovered in Faronics Insight 10.0.19045 on Windows. | 7.1 |
2023-05-31 | CVE-2023-29745 | Bestweather Project | Unspecified vulnerability in Bestweather Project Bestweather 7.3.1 An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database. | 7.1 |
2023-05-30 | CVE-2022-39071 | ZTE | Unspecified vulnerability in ZTE products There is an unauthorized access vulnerability in some ZTE mobile phones. | 7.1 |
2023-05-30 | CVE-2022-39075 | ZTE | Unspecified vulnerability in ZTE products There is an unauthorized access vulnerability in some ZTE mobile phones. | 7.1 |
2023-05-30 | CVE-2023-32698 | Goreleaser | Incorrect Default Permissions vulnerability in Goreleaser Nfpm nFPM is an alternative to fpm. | 7.1 |
235 Medium Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2023-05-30 | CVE-2022-46361 | Honeywell | OS Command Injection vulnerability in Honeywell Onewireless Network Wireless Device Manager Firmware R322.1 An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. | 6.8 |
2023-05-30 | CVE-2022-45853 | Zyxel | Unspecified vulnerability in Zyxel products The privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmware version V2.70(AAHI.3) could allow an authenticated, local attacker with administrator privileges to execute some system commands as 'root' on a vulnerable device via SSH. | 6.7 |
2023-06-04 | CVE-2023-3095 | Teampass | Unspecified vulnerability in Teampass Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | 6.5 |
2023-06-03 | CVE-2023-2405 | Vcita | Cross-Site Request Forgery (CSRF) vulnerability in Vcita CRM and Lead Management BY Vcita The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.2. | 6.5 |
2023-06-03 | CVE-2023-2407 | Vcita | Cross-Site Request Forgery (CSRF) vulnerability in Vcita products The Event Registration Calendar By vcita plugin, versions up to and including 3.9.1, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Cross-Site Request Forgery. | 6.5 |
2023-06-03 | CVE-2023-2416 | Vcita | Cross-Site Request Forgery (CSRF) vulnerability in Vcita Online Booking & Scheduling Calendar for Wordpress BY Vcita The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the vcita_logout_callback function in versions up to, and including, 4.2.10. | 6.5 |
2023-06-02 | CVE-2023-2816 | Hashicorp | Unspecified vulnerability in Hashicorp Consul 1.15.0 Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies. | 6.5 |
2023-06-02 | CVE-2023-3075 | Corebos | Unspecified vulnerability in Corebos 5.4/5.5/7.0 Cross-Site Request Forgery (CSRF) in GitHub repository tsolucio/corebos prior to 8. | 6.5 |
2023-06-02 | CVE-2023-0430 | Mozilla | Improper Certificate Validation vulnerability in Mozilla Thunderbird Certificate OCSP revocation status was not checked when verifying S/Mime signatures. | 6.5 |
2023-06-02 | CVE-2023-0547 | Mozilla | Improper Certificate Validation vulnerability in Mozilla Thunderbird OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. | 6.5 |
2023-06-02 | CVE-2023-0616 | Mozilla | Resource Exhaustion vulnerability in Mozilla Thunderbird If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which could cause Thunderbird's user interface to lock up and no longer respond to the user's actions. | 6.5 |
2023-06-02 | CVE-2023-1945 | Mozilla | Out-of-bounds Write vulnerability in Mozilla Thunderbird Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash. | 6.5 |
2023-06-02 | CVE-2023-23597 | Mozilla | Inadequate Encryption Strength vulnerability in Mozilla Firefox A compromised web child process could disable web security opening restrictions, leading to a new child process being spawned within the <code>file://</code> context. | 6.5 |
2023-06-02 | CVE-2023-23598 | Mozilla | Unspecified vulnerability in Mozilla Firefox Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website could arbitrarily read a file via a call to <code>DataTransfer.setData</code>. | 6.5 |
2023-06-02 | CVE-2023-23599 | Mozilla | Improper Encoding or Escaping of Output vulnerability in Mozilla Firefox When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. | 6.5 |
2023-06-02 | CVE-2023-23600 | Mozilla | Unspecified vulnerability in Mozilla Firefox Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. | 6.5 |
2023-06-02 | CVE-2023-23601 | Mozilla | Origin Validation Error vulnerability in Mozilla Firefox Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks. | 6.5 |
2023-06-02 | CVE-2023-23602 | Mozilla | Improper Check for Unusual or Exceptional Conditions vulnerability in Mozilla Firefox A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. | 6.5 |
2023-06-02 | CVE-2023-23603 | Mozilla | Unspecified vulnerability in Mozilla Firefox Regular expressions used to filter out forbidden properties and values from style directives in calls to <code>console.log</code> weren't accounting for external URLs. | 6.5 |
2023-06-02 | CVE-2023-23604 | Mozilla | Unspecified vulnerability in Mozilla Firefox A duplicate <code>SystemPrincipal</code> object could be created when parsing a non-system html document via <code>DOMParser::ParseFromSafeString</code>. | 6.5 |
2023-06-02 | CVE-2023-25728 | Mozilla | Unspecified vulnerability in Mozilla Firefox ESR The <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child iframe's unredacted URI when interaction with that iframe triggers a redirect. | 6.5 |
2023-06-02 | CVE-2023-25738 | Mozilla | Out-of-bounds Read vulnerability in Mozilla Firefox Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to related variables.<br>*This bug only affects Firefox on Windows. | 6.5 |
2023-06-02 | CVE-2023-25741 | Mozilla | Unspecified vulnerability in Mozilla Firefox When dragging and dropping an image cross-origin, the image's size could potentially be leaked. | 6.5 |
2023-06-02 | CVE-2023-25742 | Mozilla | Unspecified vulnerability in Mozilla Firefox ESR When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing the tab to crash. | 6.5 |
2023-06-02 | CVE-2023-25751 | Mozilla | Unspecified vulnerability in Mozilla Firefox Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorrectly. | 6.5 |
2023-06-02 | CVE-2023-25752 | Mozilla | Unspecified vulnerability in Mozilla Firefox When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. | 6.5 |
2023-06-02 | CVE-2023-28160 | Mozilla | Unspecified vulnerability in Mozilla Firefox When following a redirect to a publicly accessible web extension file, the URL may have been translated to the actual local path, leaking potentially sensitive information. | 6.5 |
2023-06-02 | CVE-2023-28163 | Mozilla | Unspecified vulnerability in Mozilla Firefox When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would have resolved those in the context of the current user. | 6.5 |
2023-06-02 | CVE-2023-28164 | Mozilla | Unspecified vulnerability in Mozilla Firefox Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. | 6.5 |
2023-06-02 | CVE-2023-29535 | Mozilla | Unspecified vulnerability in Mozilla products Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. | 6.5 |
2023-06-02 | CVE-2023-29544 | Mozilla | Resource Exhaustion vulnerability in Mozilla Firefox and Focus If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentially exploitable crash. | 6.5 |
2023-06-02 | CVE-2023-29547 | Mozilla | Unspecified vulnerability in Mozilla Firefox ESR and Focus When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, when it should have silently failed. | 6.5 |
2023-06-02 | CVE-2023-29548 | Mozilla | Unspecified vulnerability in Mozilla products A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. | 6.5 |
2023-06-02 | CVE-2023-29549 | Mozilla | Inadequate Encryption Strength vulnerability in Mozilla Firefox and Focus Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm. | 6.5 |
2023-06-02 | CVE-2023-32206 | Mozilla | Out-of-bounds Read vulnerability in Mozilla Firefox An out-of-bound read could have led to a crash in the RLBox Expat driver. | 6.5 |
2023-06-02 | CVE-2023-32211 | Mozilla | Unspecified vulnerability in Mozilla Firefox A type checking bug would have led to invalid code being compiled. | 6.5 |
2023-06-01 | CVE-2023-33754 | Inpiazza | Improper Restriction of Excessive Authentication Attempts vulnerability in Inpiazza Cloud Wifi The captive portal in Inpiazza Cloud WiFi versions prior to v4.2.17 does not enforce limits on the number of attempts for password recovery, allowing attackers to brute force valid user accounts to gain access to login credentials. | 6.5 |
2023-06-01 | CVE-2023-32706 | Splunk | XXE vulnerability in Splunk and Splunk Cloud Platform On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an unauthenticated attacker can send specially-crafted messages to the XML parser within SAML authentication to cause a denial of service in the Splunk daemon. | 6.5 |
2023-06-01 | CVE-2023-32716 | Splunk | Improper Check for Unusual or Exceptional Conditions vulnerability in Splunk and Splunk Cloud Platform In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, an attacker can exploit a vulnerability in the {{dump}} SPL command to cause a denial of service by crashing the Splunk daemon. | 6.5 |
2023-06-01 | CVE-2023-34091 | Nirmata | Unspecified vulnerability in Nirmata Kyverno Kyverno is a policy engine designed for Kubernetes. | 6.5 |
2023-06-01 | CVE-2023-28043 | Dell | Unspecified vulnerability in Dell Secure Connect Gateway 5.14.00.16 Dell SCG 5.14 contains an information disclosure vulnerability during the SRS to SCG upgrade path. | 6.5 |
2023-06-01 | CVE-2023-22652 | Opensuse | Unspecified vulnerability in Opensuse Libeconf 0.5.1 A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf leads to DoS via malformed config files. This issue affects libeconf: before 0.5.2. | 6.5 |
2023-06-01 | CVE-2023-32181 | Opensuse | Unspecified vulnerability in Opensuse Libeconf 0.5.1 A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf allows for DoS via malformed configuration files This issue affects libeconf: before 0.5.2. | 6.5 |
2023-05-31 | CVE-2023-33979 | GPT Academic Project | Information Exposure vulnerability in GPT Academic Project GPT Academic gpt_academic provides a graphical interface for ChatGPT/GLM. | 6.5 |
2023-05-31 | CVE-2023-34228 | Jetbrains | Unspecified vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions | 6.5 |
2023-05-30 | CVE-2023-2952 | Wireshark Debian | Infinite Loop vulnerability in multiple products XRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file | 6.5 |
2023-05-30 | CVE-2023-2940 | Unspecified vulnerability in Google Chrome Inappropriate implementation in Downloads in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. | 6.5 | |
2023-05-30 | CVE-2023-33179 | Xibosignage | SQL Injection vulnerability in Xibosignage Xibo Xibo is a content management system (CMS). | 6.5 |
2023-05-30 | CVE-2023-33180 | Xibosignage | SQL Injection vulnerability in Xibosignage Xibo Xibo is a content management system (CMS). | 6.5 |
2023-05-30 | CVE-2023-31187 | Avaya | Insufficiently Protected Credentials vulnerability in Avaya IX Workforce Engagement 15.2.7.1195 Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials | 6.5 |
2023-05-30 | CVE-2023-33178 | Xibosignage | SQL Injection vulnerability in Xibosignage Xibo Xibo is a content management system (CMS). | 6.5 |
2023-05-30 | CVE-2023-32699 | Metersphere | Allocation of Resources Without Limits or Throttling vulnerability in Metersphere MeterSphere is an open source continuous testing platform. | 6.5 |
2023-05-30 | CVE-2023-32689 | Parseplatform | Unrestricted Upload of File with Dangerous Type vulnerability in Parseplatform Parse-Server Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 6.5 |
2023-05-30 | CVE-2022-43485 | Honeywell | Use of Insufficiently Random Values vulnerability in Honeywell Onewireless Network Wireless Device Manager Firmware R322.1 Use of Insufficiently Random Values in Honeywell OneWireless. | 6.5 |
2023-05-30 | CVE-2023-2650 | Openssl Debian | Allocation of Resources Without Limits or Throttling vulnerability in multiple products Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Impact summary: Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience notable to very long delays when processing those messages, which may lead to a Denial of Service. An OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers - most of which have no size limit. | 6.5 |
2023-05-30 | CVE-2023-1524 | Wpdownloadmanager | Unspecified vulnerability in Wpdownloadmanager Download Manager The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. | 6.5 |
2023-05-30 | CVE-2023-2970 | Mindspore | Unspecified vulnerability in Mindspore 2.0.0 A vulnerability classified as problematic was found in MindSpore 2.0.0-alpha/2.0.0-rc1. | 6.5 |
2023-05-30 | CVE-2023-34204 | Imapsync Project | Link Following vulnerability in Imapsync Project Imapsync imapsync through 2.229 uses predictable paths under /tmp and /var/tmp in its default mode of operation. | 6.5 |
2023-05-29 | CVE-2023-32687 | Tgstation13 | Insufficiently Protected Credentials vulnerability in Tgstation13 Tgstation-Server tgstation-server is a toolset to manage production BYOND servers. | 6.5 |
2023-05-29 | CVE-2023-24603 | Open Xchange | Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6 OX App Suite before backend 7.10.6-rev37 does not check size limits when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of data. | 6.5 |
2023-05-29 | CVE-2023-28153 | Kiddoware | Unspecified vulnerability in Kiddoware 3.8.45/3.8.49 An issue was discovered in the Kiddoware Kids Place Parental Control application before 3.8.50 for Android. | 6.4 |
2023-06-02 | CVE-2023-2062 | Mitsubishielectric | Exposure of Resource to Wrong Sphere vulnerability in Mitsubishielectric products Missing Password Field Masking vulnerability in Mitsubishi Electric Corporation EtherNet/IP configuration tools SW1DNN-EIPCT-BD and SW1DNN-EIPCTFX5-BD allows a remote unauthenticated attacker to know the password for MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP. | 6.2 |
2023-06-04 | CVE-2013-10028 | Eelv Newsletter Project | Unspecified vulnerability in Eelv Newsletter Project Eelv Newsletter A vulnerability was found in EELV Newsletter Plugin 2.x on WordPress. | 6.1 |
2023-06-03 | CVE-2023-3085 | X WRT | Cross-site Scripting vulnerability in X-Wrt Luci A vulnerability, which was classified as problematic, has been found in X-WRT luci up to 22.10_b202303061504. | 6.1 |
2023-06-03 | CVE-2023-2298 | Vcita | Cross-site Scripting vulnerability in Vcita Online Booking & Scheduling Calendar for Wordpress 4.2.10 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in versions up to, and including, 4.2.10 due to insufficient input sanitization and output escaping. | 6.1 |
2023-06-03 | CVE-2023-2301 | Vcita | Cross-Site Request Forgery (CSRF) vulnerability in Vcita Contact Form Builder BY Vcita The Contact Form Builder by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.9.1. | 6.1 |
2023-06-03 | CVE-2023-2303 | Vcita | Cross-Site Request Forgery (CSRF) vulnerability in Vcita Contact Form and Calls to Action BY Vcita The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.4. | 6.1 |
2023-06-02 | CVE-2023-33761 | Simpleredak | Cross-site Scripting vulnerability in Simpleredak 2.47.23.05 eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /view/cb/format_642.php. | 6.1 |
2023-06-02 | CVE-2023-33763 | Simpleredak | Cross-site Scripting vulnerability in Simpleredak 2.47.23.05 eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /scheduler/index.php. | 6.1 |
2023-06-02 | CVE-2023-29540 | Mozilla | Open Redirect vulnerability in Mozilla Firefox and Focus Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <code>allow-top-navigation-to-custom-protocols</code>. | 6.1 |
2023-06-02 | CVE-2023-33731 | Escanav | Cross-site Scripting vulnerability in Escanav Escan Management Console 14.0.1400.2281 Reflected Cross Site Scripting (XSS) in the view dashboard detail feature in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the URL directly. | 6.1 |
2023-06-02 | CVE-2023-28705 | Openfind | Cross-site Scripting vulnerability in Openfind Mail2000 6.0/7.0 Openfind Mail2000 has insufficient filtering special characters of email content of its content filtering function. | 6.1 |
2023-06-02 | CVE-2023-2835 | Wpdirectorykit | Cross-site Scripting vulnerability in Wpdirectorykit WP Directory KIT The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. | 6.1 |
2023-06-02 | CVE-2015-10110 | Tinychat | Unspecified vulnerability in Tinychat Room SPY A vulnerability classified as problematic was found in ruddernation TinyChat Room Spy Plugin up to 1.2.8 on WordPress. | 6.1 |
2023-06-02 | CVE-2016-15032 | MH Httpbl Project | Unspecified vulnerability in MH Httpbl Project MH Httpbl ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in mback2k mh_httpbl Extension up to 1.1.7 on TYPO3. | 6.1 |
2023-06-01 | CVE-2023-32715 | Splunk | Cross-site Scripting vulnerability in Splunk APP for Lookup File Editing In the Splunk App for Lookup File Editing versions below 4.0.1, a user can insert potentially malicious JavaScript code into the app, which causes that code to run on the user’s machine. | 6.1 |
2023-06-01 | CVE-2018-25086 | Fanpress CM Project | Cross-site Scripting vulnerability in Fanpress CM Project Fanpress CM A vulnerability was found in sea75300 FanPress CM up to 3.6.3. | 6.1 |
2023-06-01 | CVE-2010-10010 | Psychostats | Unspecified vulnerability in Psychostats A vulnerability classified as problematic has been found in Stars Alliance PsychoStats up to 3.2.2a. | 6.1 |
2023-06-01 | CVE-2023-3026 | Diagrams | Unspecified vulnerability in Diagrams Drawio Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 21.2.8. | 6.1 |
2023-05-31 | CVE-2023-33732 | Escanav | Cross-site Scripting vulnerability in Escanav Escan Management Console 14.0.1400.2281 Cross Site Scripting (XSS) in the New Policy form in Microworld Technologies eScan management console 14.0.1400.2281 allows a remote attacker to inject arbitrary code via the vulnerable parameters type, txtPolicyType, and Deletefileval. | 6.1 |
2023-05-31 | CVE-2023-3020 | Scilicot | Unspecified vulnerability in Scilicot I, Librarian Cross-site Scripting (XSS) - Reflected in GitHub repository mkucej/i-librarian-free prior to 5.10.4. | 6.1 |
2023-05-31 | CVE-2023-34222 | Jetbrains | Unspecified vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible | 6.1 |
2023-05-31 | CVE-2023-34226 | Jetbrains | Unspecified vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05 reflected XSS in the Subscriptions page was possible | 6.1 |
2023-05-31 | CVE-2023-3014 | Beipyvideoresolution Project | Unspecified vulnerability in Beipyvideoresolution Project Beipyvideoresolution A vulnerability, which was classified as problematic, was found in BeipyVideoResolution up to 2.6. | 6.1 |
2023-05-31 | CVE-2023-3016 | VIP Video Analysis Project | Unspecified vulnerability in VIP Video Analysis Project VIP Video Analysis 1.0 A vulnerability was found in yiwent Vip Video Analysis 1.0 and classified as problematic. | 6.1 |
2023-05-31 | CVE-2023-3005 | Local Service Search Engine Management System Project | Unspecified vulnerability in Local Service Search Engine Management System Project Local Service Search Engine Management System 1.0 A vulnerability, which was classified as problematic, was found in SourceCodester Local Service Search Engine Management System 1.0. | 6.1 |
2023-05-31 | CVE-2023-26131 | Algernon Project | Cross-site Scripting vulnerability in Algernon Project Algernon All versions of the package github.com/xyproto/algernon/engine; all versions of the package github.com/xyproto/algernon/themes are vulnerable to Cross-site Scripting (XSS) via the themes.NoPage(filename, theme) function due to improper user input sanitization. | 6.1 |
2023-05-31 | CVE-2014-125103 | Bestwebsoft | Unspecified vulnerability in Bestwebsoft Twitter A vulnerability was found in BestWebSoft Twitter Plugin up to 1.3.2 on WordPress. | 6.1 |
2023-05-31 | CVE-2015-10107 | Simplr Registration Form Plus Project | Unspecified vulnerability in Simplr Registration Form Plus+ Project Simplr Registration Form Plus+ A vulnerability was found in Simplr Registration Form Plus+ Plugin up to 2.3.4 on WordPress and classified as problematic. | 6.1 |
2023-05-31 | CVE-2023-2998 | Phpmyfaq | Unspecified vulnerability in PHPmyfaq Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14. | 6.1 |
2023-05-31 | CVE-2023-2999 | Phpmyfaq | Unspecified vulnerability in PHPmyfaq Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14. | 6.1 |
2023-05-31 | CVE-2023-28350 | Faronics | Cross-site Scripting vulnerability in Faronics Insight 10.0.19045 An issue was discovered in Faronics Insight 10.0.19045 on Windows. | 6.1 |
2023-05-30 | CVE-2023-33962 | Jstachio Project | Cross-site Scripting vulnerability in Jstachio Project Jstachio JStachio is a type-safe Java Mustache templating engine. | 6.1 |
2023-05-30 | CVE-2023-32218 | Avaya | Open Redirect vulnerability in Avaya IX Workforce Engagement 15.2.7.1195 Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect') | 6.1 |
2023-05-30 | CVE-2023-23754 | Joomla | Open Redirect vulnerability in Joomla Joomla! An issue was discovered in Joomla! 4.2.0 through 4.3.1. | 6.1 |
2023-05-30 | CVE-2023-20884 | Vmware | Open Redirect vulnerability in VMWare products VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure. | 6.1 |
2023-05-30 | CVE-2023-2973 | Students Online Internship Timesheet System Project | Unspecified vulnerability in Students Online Internship Timesheet System Project Students Online Internship Timesheet System 1.0 A vulnerability, which was classified as problematic, has been found in SourceCodester Students Online Internship Timesheet Syste 1.0. | 6.1 |
2023-05-30 | CVE-2023-0733 | Newsletter Popup Project | Unspecified vulnerability in Newsletter Popup Project Newsletter Popup The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks | 6.1 |
2023-05-30 | CVE-2023-2023 | Kunalnagar | Cross-site Scripting vulnerability in Kunalnagar Custom 404 PRO The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting. | 6.1 |
2023-05-30 | CVE-2023-2256 | Themeisle | Unspecified vulnerability in Themeisle Product Addons & Fields for Woocommerce The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting. | 6.1 |
2023-05-30 | CVE-2023-2296 | Loginizer | Unspecified vulnerability in Loginizer The Loginizer WordPress plugin before 1.7.9 does not escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | 6.1 |
2023-05-30 | CVE-2023-2518 | Yikesinc | Unspecified vulnerability in Yikesinc Easy Forms for Mailchimp The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape a parameter before outputting it back in the page when the debug option is enabled, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | 6.1 |
2023-05-30 | CVE-2023-33186 | Zulip | Unspecified vulnerability in Zulip Server 7.0 Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and chat to make remote work productive and delightful. | 6.1 |
2023-05-29 | CVE-2023-27613 | Monitorclick | Unspecified vulnerability in Monitorclick Forms ADA 1.0 Unauth. | 6.1 |
2023-05-29 | CVE-2023-24601 | Open Xchange | Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6 OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree. | 6.1 |
2023-05-29 | CVE-2023-24602 | Open Xchange | Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6 OX App Suite before frontend 7.10.6-rev24 allows XSS via data to the Tumblr portal widget, such as a post title. | 6.1 |
2023-05-30 | CVE-2023-33974 | Riot OS | Race Condition vulnerability in Riot-Os Riot RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. | 5.9 |
2023-05-30 | CVE-2023-32691 | GO Simple Tunnel Project | Information Exposure Through Discrepancy vulnerability in GO Simple Tunnel Project GO Simple Tunnel gost (GO Simple Tunnel) is a simple tunnel written in golang. | 5.9 |
2023-05-29 | CVE-2020-29547 | Citadel | Command Injection vulnerability in Citadel Webcit An issue was discovered in Citadel through webcit-926. | 5.9 |
2023-06-02 | CVE-2023-28469 | ARM | Unspecified vulnerability in ARM products An issue was discovered in the Arm Mali GPU Kernel Driver. | 5.5 |
2023-06-02 | CVE-2023-33717 | Mp4V2 Project | Memory Leak vulnerability in Mp4V2 Project Mp4V2 2.1.3 mp4v2 v2.1.3 was discovered to contain a memory leak when a method calling MP4File::ReadBytes() had allocated memory but did not catch exceptions thrown by ReadBytes() | 5.5 |
2023-06-02 | CVE-2023-29725 | Bt21 X BTS Wallpaper Project | Unspecified vulnerability in Bt21 X BTS Wallpaper Project Bt21 X BTS Wallpaper 12 The BT21 x BTS Wallpaper app 12 for Android allows unauthorized applications to actively request permission to insert data into the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the application is opened. | 5.5 |
2023-06-02 | CVE-2023-28147 | ARM | Unspecified vulnerability in ARM products An issue was discovered in the Arm Mali GPU Kernel Driver. | 5.5 |
2023-06-01 | CVE-2023-32324 | Openprinting Debian | Out-of-bounds Write vulnerability in multiple products OpenPrinting CUPS is an open source printing system. | 5.5 |
2023-06-01 | CVE-2023-33544 | Hawt | Path Traversal vulnerability in Hawt Hawtio 2.17.2 hawtio 2.17.2 is vulnerable to Path Traversal. | 5.5 |
2023-06-01 | CVE-2023-33546 | Janino Project | Out-of-bounds Write vulnerability in Janino Project Janino Janino 3.1.9 and earlier are subject to denial of service (DOS) attacks when using the expression evaluator.guess parameter name method. | 5.5 |
2023-06-01 | CVE-2023-33461 | Ndevilla | NULL Pointer Dereference vulnerability in Ndevilla Iniparser 4.1 iniparser v4.1 is vulnerable to NULL Pointer Dereference in function iniparser_getlongint which misses check NULL for function iniparser_getstring's return. | 5.5 |
2023-06-01 | CVE-2023-33716 | Mp4V2 | Memory Leak vulnerability in Mp4V2 2.1.3 mp4v2 v2.1.3 was discovered to contain a memory leak via the class MP4StringProperty at mp4property.cpp. | 5.5 |
2023-06-01 | CVE-2023-33719 | Mp4V2 | Memory Leak vulnerability in Mp4V2 2.1.3 mp4v2 v2.1.3 was discovered to contain a memory leak via MP4SdpAtom::Read() at atom_sdp.cpp | 5.5 |
2023-06-01 | CVE-2023-2985 | Linux | Use After Free vulnerability in Linux Kernel A use after free flaw was found in hfsplus_put_super in fs/hfsplus/super.c in the Linux Kernel. | 5.5 |
2023-05-31 | CVE-2023-34256 | Linux Suse Debian | Out-of-bounds Read vulnerability in multiple products An issue was discovered in the Linux kernel before 6.3.3. | 5.5 |
2023-05-31 | CVE-2023-3006 | Linux | Improper Cross-boundary Removal of Sensitive Data vulnerability in Linux Kernel 6.1 A known cache speculation vulnerability, known as Branch History Injection (BHI) or Spectre-BHB, becomes actual again for the new hw AmpereOne. | 5.5 |
2023-05-30 | CVE-2023-34151 | Imagemagick Fedoraproject Redhat Debian | Integer Overflow or Wraparound vulnerability in multiple products A vulnerability was found in ImageMagick. | 5.5 |
2023-05-30 | CVE-2022-47028 | Actionlauncher | Injection vulnerability in Actionlauncher Action Launcher 50.5 An issue discovered in Action Launcher for Android v50.5 allows an attacker to cause a denial of service via arbitary data injection to function insert. | 5.5 |
2023-05-30 | CVE-2023-23561 | Stormshield | Unspecified vulnerability in Stormshield Endpoint Security 2.3.0/2.3.2 Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control: authenticated users can read sensitive information. | 5.5 |
2023-05-30 | CVE-2023-29735 | MWM | Resource Exhaustion vulnerability in MWM Edjing MIX 7.09.01 An issue found in edjing Mix v.7.09.01 for Android allows a local attacker to cause a denial of service via the database files. | 5.5 |
2023-05-30 | CVE-2023-33656 | Emqx | Allocation of Resources Without Limits or Throttling vulnerability in Emqx Nanomq 0.17.2 A memory leak vulnerability exists in NanoMQ 0.17.2. | 5.5 |
2023-05-30 | CVE-2023-29737 | Wavekeyboard | Unspecified vulnerability in Wavekeyboard Wave Animated Keyboard Emoji 1.70.7 An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause a denial of service via the database files. | 5.5 |
2023-05-30 | CVE-2023-32448 | Dell | Unspecified vulnerability in Dell Powerpath 7.0/7.1/7.2 PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains License Key Stored in Cleartext vulnerability. | 5.5 |
2023-06-03 | CVE-2023-2300 | Vcita | Cross-site Scripting vulnerability in Vcita Contact Form Builder BY Vcita The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 4.9.1 due to insufficient input sanitization and output escaping. | 5.4 |
2023-06-03 | CVE-2023-2302 | Vcita | Cross-site Scripting vulnerability in Vcita Contact Form and Calls to Action BY Vcita The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping. | 5.4 |
2023-06-03 | CVE-2023-2404 | Vcita | Cross-site Scripting vulnerability in Vcita CRM and Lead Management BY Vcita The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 2.6.2 due to insufficient input sanitization and output escaping. | 5.4 |
2023-06-03 | CVE-2023-2406 | Vcita | Cross-site Scripting vulnerability in Vcita products The Event Registration Calendar By vcita plugin, versions up to and including 3.9.1, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. | 5.4 |
2023-06-03 | CVE-2023-2415 | Vcita | Missing Authorization vulnerability in Vcita Online Booking & Scheduling Calendar for Wordpress BY Vcita The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_logout_callback function in versions up to, and including, 4.2.10. | 5.4 |
2023-06-03 | CVE-2023-3051 | Azexo | Cross-site Scripting vulnerability in Azexo Page Builder With Image MAP BY Azexo 1.27.133 The Page Builder by AZEXO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'azh_post' shortcode in versions up to, and including, 1.27.133 due to insufficient input sanitization and output escaping. | 5.4 |
2023-06-02 | CVE-2023-3073 | Corebos | Unspecified vulnerability in Corebos 5.4/5.5/7.0 Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8 via evvtgendoc. | 5.4 |
2023-06-02 | CVE-2023-3074 | Corebos | Unspecified vulnerability in Corebos 5.4/5.5/7.0 Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8. | 5.4 |
2023-06-02 | CVE-2023-25730 | Mozilla | Unspecified vulnerability in Mozilla Firefox ESR A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode indefinitely, resulting in potential user confusion or spoofing attacks. | 5.4 |
2023-06-02 | CVE-2023-3070 | Corebos | Unspecified vulnerability in Corebos 5.4/5.5/7.0 Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8. | 5.4 |
2023-06-02 | CVE-2023-3071 | Tsolucio | Cross-site Scripting vulnerability in Tsolucio Corebos Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8. | 5.4 |
2023-06-02 | CVE-2023-3067 | Trilium Project | Unspecified vulnerability in Trilium Project Trilium Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.59.4. | 5.4 |
2023-06-02 | CVE-2023-3060 | Agro School Management System Project | Unspecified vulnerability in Agro-School Management System Project Agro-School Management System 1.0 A vulnerability has been found in code-projects Agro-School Management System 1.0 and classified as problematic. | 5.4 |
2023-06-02 | CVE-2023-3058 | 07Fly | Cross-site Scripting vulnerability in 07Fly Customer Relationship Management 1.2.0 A vulnerability was found in 07FLY CRM up to 1.2.0. | 5.4 |
2023-06-01 | CVE-2023-33764 | Simpleredak | Cross-site Scripting vulnerability in Simpleredak 2.47.23.05 eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component #/de/casting/show/detail/<ID>. | 5.4 |
2023-06-01 | CVE-2023-32711 | Splunk | Cross-site Scripting vulnerability in Splunk In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, a Splunk dashboard view lets a low-privileged user exploit a vulnerability in the Bootstrap web framework (CVE-2019-8331) and build a stored cross-site scripting (XSS) payload. | 5.4 |
2023-06-01 | CVE-2023-3035 | Gougucms | Unspecified vulnerability in Gougucms Pythagorean OA Office System A vulnerability has been found in Guangdong Pythagorean OA Office System up to 4.50.31 and classified as problematic. | 5.4 |
2023-06-01 | CVE-2023-30758 | Pleasanter | Cross-site Scripting vulnerability in Pleasanter Cross-site scripting vulnerability in Pleasanter 1.3.38.1 and earlier allows a remote authenticated attacker to inject an arbitrary script. | 5.4 |
2023-06-01 | CVE-2023-23954 | Broadcom | Cross-site Scripting vulnerability in Broadcom Advanced Secure Gateway and Content Analysis Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Stored Cross-Site Scripting vulnerability. | 5.4 |
2023-05-31 | CVE-2023-33287 | Actonic | Cross-site Scripting vulnerability in Actonic Inline Table Editing A stored cross-site scripting (XSS) vulnerability in the Inline Table Editing application before 3.8.0 for Confluence allows attackers to store and execute arbitrary JavaScript via a crafted payload injected into the tables. | 5.4 |
2023-05-31 | CVE-2023-34088 | Collaboraoffice | Cross-site Scripting vulnerability in Collaboraoffice Collabora Online Collabora Online is a collaborative online office suite. | 5.4 |
2023-05-31 | CVE-2023-33971 | Teclib Edition | Cross-site Scripting vulnerability in Teclib-Edition Form Creator 2.13.5 Formcreator is a GLPI plugin which allow creation of custom forms and the creation of one or more tickets when the form is filled. | 5.4 |
2023-05-31 | CVE-2023-3021 | Scilico | Unspecified vulnerability in Scilico I, Librarian Cross-site Scripting (XSS) - Stored in GitHub repository mkucej/i-librarian-free prior to 5.10.4. | 5.4 |
2023-05-31 | CVE-2023-3017 | Oretnom23 | Unspecified vulnerability in Oretnom23 Lost and Found Information System 1.0 A vulnerability was found in SourceCodester Lost and Found Information System 1.0. | 5.4 |
2023-05-31 | CVE-2023-26842 | Churchcrm | Cross-site Scripting vulnerability in Churchcrm 4.5.3 A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the OptionManager.php. | 5.4 |
2023-05-31 | CVE-2023-31548 | Churchcrm | Cross-site Scripting vulnerability in Churchcrm 4.5.3 A stored Cross-site scripting (XSS) vulnerability in the FundRaiserEditor.php component of ChurchCRM v4.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | 5.4 |
2023-05-31 | CVE-2023-34220 | Jetbrains | Unspecified vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible | 5.4 |
2023-05-31 | CVE-2023-34221 | Jetbrains | Unspecified vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible | 5.4 |
2023-05-31 | CVE-2023-34225 | Jetbrains | Cross-site Scripting vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible | 5.4 |
2023-05-31 | CVE-2023-34229 | Jetbrains | Unspecified vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05 stored XSS in GitLab Connection page was possible | 5.4 |
2023-05-31 | CVE-2023-33736 | Dcatadmin | Cross-site Scripting vulnerability in Dcatadmin Dcat Admin 2.1.3 A stored cross-site scripting (XSS) vulnerability in Dcat-Admin v2.1.3-beta allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL parameter. | 5.4 |
2023-05-31 | CVE-2023-3009 | Teampass | Unspecified vulnerability in Teampass Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | 5.4 |
2023-05-31 | CVE-2023-2304 | Favorites Project | Cross-site Scripting vulnerability in Favorites Project Favorites The Favorites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_favorites' shortcode in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2023-05-31 | CVE-2023-1661 | Display Post Meta Term Meta Comment Meta AND User Meta Project | Cross-site Scripting vulnerability in Display Post Meta, Term Meta, Comment Meta, and User Meta Project Display Post Meta, Term Meta, Comment Meta, and User Meta 0.4.1 The Display post meta, term meta, comment meta, and user meta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post metadata in versions up to, and including, 0.4.1 due to insufficient input sanitization and output escaping. | 5.4 |
2023-05-31 | CVE-2023-2547 | Featherplugins | Missing Authorization vulnerability in Featherplugins Feather Login Page 1.0.7/1.1.1 The Feather Login Page plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'deleteUser' function in versions starting from 1.0.7 up to, and including, 1.1.1. | 5.4 |
2023-05-30 | CVE-2023-33961 | Leantime | Cross-site Scripting vulnerability in Leantime Leantime is a lean open source project management system. | 5.4 |
2023-05-30 | CVE-2022-36244 | Shopbeat | Cross-site Scripting vulnerability in Shopbeat Shop Beat Media Player 2.5.95 Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 suffers from Multiple Stored Cross-Site Scripting (XSS) vulnerabilities via Shop Beat Control Panel found at www.shopbeat.co.za controlpanel.shopbeat.co.za. | 5.4 |
2023-05-30 | CVE-2022-36249 | Shopbeat | Missing Authentication for Critical Function vulnerability in Shopbeat Shop Beat Media Player 2.5.95 Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. | 5.4 |
2023-05-30 | CVE-2023-23956 | Broadcom | Cross-site Scripting vulnerability in Broadcom Symantec Siteminder Webagent 12.52 A user can supply malicious HTML and JavaScript code that will be executed in the client browser | 5.4 |
2023-05-30 | CVE-2023-2981 | Abstrium | Unspecified vulnerability in Abstrium Pydio Cells 4.2.0 A vulnerability, which was classified as problematic, has been found in Abstrium Pydio Cells 4.2.0. | 5.4 |
2023-05-30 | CVE-2022-4676 | Openstreetmap | Unspecified vulnerability in Openstreetmap The OSM WordPress plugin through 6.01 does not validate and escape some of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. | 5.4 |
2023-05-30 | CVE-2023-32685 | Kanboard | Cross-site Scripting vulnerability in Kanboard Kanboard is project management software that focuses on the Kanban methodology. | 5.4 |
2023-05-29 | CVE-2022-24631 | Audiocodes | Cross-site Scripting vulnerability in Audiocodes Device Manager Express An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. | 5.4 |
2023-05-29 | CVE-2023-23699 | Progress BAR Project | Unspecified vulnerability in Progress BAR Project Progress BAR 2.2.1 Auth. | 5.4 |
2023-05-29 | CVE-2023-2954 | Djangoblog Project | Unspecified vulnerability in Djangoblog Project Djangoblog Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master. | 5.4 |
2023-06-03 | CVE-2023-2299 | Vcita | Missing Authorization vulnerability in Vcita Online Booking & Scheduling Calendar for Wordpress 4.2.10 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized medication of data via the /wp-json/vcita-wordpress/v1/actions/auth REST-API endpoint in versions up to, and including, 4.2.10 due to a missing capability check on the processAction function. | 5.3 |
2023-06-02 | CVE-2023-34094 | Chuanhuchatgpt Project | Missing Authentication for Critical Function vulnerability in Chuanhuchatgpt Project Chuanhuchatgpt ChuanhuChatGPT is a graphical user interface for ChatGPT and many large language models. | 5.3 |
2023-06-01 | CVE-2023-32710 | Splunk | Unspecified vulnerability in Splunk and Splunk Cloud Platform In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and in Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can perform an unauthorized transfer of data from a search using the ‘copyresults’ command if they know the search ID (SID) of a search job that has recently run. | 5.3 |
2023-05-31 | CVE-2023-2758 | Contec | Unspecified vulnerability in Contec Conprosys HMI System A denial of service vulnerability exists in Contec CONPROSYS HMI System versions 3.5.2 and prior. | 5.3 |
2023-05-31 | CVE-2023-34223 | Jetbrains | Unspecified vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases | 5.3 |
2023-05-30 | CVE-2023-33181 | Xibosignage | Information Exposure Through an Error Message vulnerability in Xibosignage Xibo Xibo is a content management system (CMS). | 5.3 |
2023-05-30 | CVE-2022-36243 | Shopbeat | Path Traversal vulnerability in Shopbeat Shop Beat Media Player 2.5.95 Shop Beat Solutions (pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Directory Traversal via server.shopbeat.co.za. | 5.3 |
2023-05-30 | CVE-2023-31186 | Avaya | Information Exposure Through Discrepancy vulnerability in Avaya IX Workforce Engagement 15.2.7.1195 Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy | 5.3 |
2023-05-30 | CVE-2023-0443 | Wpvibes | Unspecified vulnerability in Wpvibes Anywhere Elementor The AnyWhere Elementor WordPress plugin before 1.2.8 discloses a Freemius Secret Key which could be used by an attacker to purchase the pro subscription using test credit card numbers without actually paying the amount. | 5.3 |
2023-05-30 | CVE-2023-33955 | Minio | Unspecified vulnerability in Minio Console Minio Console is the UI for MinIO Object Storage. | 5.3 |
2023-05-29 | CVE-2022-24632 | Audiocodes | Path Traversal vulnerability in Audiocodes Device Manager Express An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. | 5.3 |
2023-05-29 | CVE-2023-30571 | Libarchive | Race Condition vulnerability in Libarchive Libarchive through 3.6.2 can cause directories to have world-writable permissions. | 5.3 |
2023-05-29 | CVE-2023-2808 | Mattermost | Unspecified vulnerability in Mattermost Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink, allowing an attacker to trigger link preview on a disallowed domain using a specially crafted link. | 5.3 |
2023-05-29 | CVE-2023-24597 | Open Xchange | Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6 OX App Suite before frontend 7.10.6-rev24 allows the loading (without user consent) of an e-mail message's remote resources during printing. | 5.3 |
2023-06-02 | CVE-2023-3031 | Webbax | Path Traversal vulnerability in Webbax King-Avis Improper Limitation of a Pathname leads to a Path Traversal vulnerability in the module King-Avis for Prestashop, allowing a user knowing the download token to read arbitrary local files.This issue affects King-Avis: before 17.3.15. | 4.9 |
2023-06-01 | CVE-2023-28824 | Contec | Server-Side Request Forgery (SSRF) vulnerability in Contec Conprosys HMI System Server-side request forgery vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. | 4.9 |
2023-05-30 | CVE-2023-2111 | Groundhogg | Unspecified vulnerability in Groundhogg Hollerbox The Fast & Effective Popups & Lead-Generation for WordPress plugin before 2.1.4 concatenates user input into an SQL query without escaping it first in the plugin's report API endpoint, which could allow administrators in multi-site configuration to leak sensitive information from the site's database. | 4.9 |
2023-06-03 | CVE-2023-32582 | Don8 Project | Cross-site Scripting vulnerability in Don8 Project Don8 Auth. | 4.8 |
2023-06-02 | CVE-2023-1159 | Booking WP Plugin | Cross-site Scripting vulnerability in Booking-Wp-Plugin Bookly The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via service titles in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. | 4.8 |
2023-06-01 | CVE-2023-28651 | Contec | Cross-site Scripting vulnerability in Contec Conprosys HMI System Cross-site scripting vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. | 4.8 |
2023-05-31 | CVE-2023-34224 | Jetbrains | Unspecified vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible | 4.8 |
2023-05-31 | CVE-2023-2836 | Crmperks | Cross-site Scripting vulnerability in Crmperks CRM Perks Forms 1.1.1 The CRM Perks Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. | 4.8 |
2023-05-31 | CVE-2023-2436 | Blog IN Blog Project | Cross-site Scripting vulnerability in Blog-In-Blog Project Blog-In-Blog 1.1.1 The Blog-in-Blog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blog_in_blog' shortcode in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 4.8 |
2023-05-30 | CVE-2023-2113 | Autoptimize | Unspecified vulnerability in Autoptimize The Autoptimize WordPress plugin before 3.1.7 does not sanitise and escape the settings imported from a previous export, allowing high privileged users (such as an administrator) to inject arbitrary javascript into the admin panel, even when the unfiltered_html capability is disabled, such as in a multisite setup. | 4.8 |
2023-05-30 | CVE-2023-2223 | 12Net | Unspecified vulnerability in 12Net Login Rebuilder The Login rebuilder WordPress plugin before 2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | 4.8 |
2023-05-30 | CVE-2023-2470 | ADD TO Feedly Project | Unspecified vulnerability in ADD to Feedly Project ADD to Feedly The Add to Feedly WordPress plugin through 1.2.11 does not sanitize and escape its settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | 4.8 |
2023-05-29 | CVE-2023-32072 | Enalean | Cross-site Scripting vulnerability in Enalean Tuleap Tuleap is an open source tool for end to end traceability of application and system developments. | 4.8 |
2023-05-31 | CVE-2023-2612 | Canonical | Improper Locking vulnerability in Canonical Ubuntu Linux 20.04/22.04/22.10 Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu Linux kernel contained a race condition when handling inode locking in some situations. | 4.7 |
2023-05-31 | CVE-2023-28345 | Faronics | Cleartext Storage of Sensitive Information vulnerability in Faronics Insight 10.0.19045 An issue was discovered in Faronics Insight 10.0.19045 on Windows. | 4.6 |
2023-05-30 | CVE-2023-1711 | Hitachienergy | Improper Encoding or Escaping of Output vulnerability in Hitachienergy Foxman-Un and Unem A vulnerability exists in a FOXMAN-UN and UNEM logging component, it only affects systems that use remote authentication to the network elements. | 4.4 |
2023-06-03 | CVE-2023-0583 | Vektor INC | Unspecified vulnerability in Vektor-Inc VK Blocks The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' function in versions up to, and including, 1.57.0.5. | 4.3 |
2023-06-03 | CVE-2023-0584 | Vektor INC | Unspecified vulnerability in Vektor-Inc VK Blocks The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_options' function in versions up to, and including, 1.57.0.5. | 4.3 |
2023-06-03 | CVE-2023-3053 | Azexo | Missing Authorization vulnerability in Azexo Page Builder With Image MAP BY Azexo 1.27.133 The Page Builder by AZEXO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'azh_add_post' function in versions up to, and including, 1.27.133. | 4.3 |
2023-06-03 | CVE-2023-3055 | Azexo | Cross-Site Request Forgery (CSRF) vulnerability in Azexo Page Builder With Image MAP BY Azexo 1.27.133 The Page Builder by AZEXO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.27.133. | 4.3 |
2023-06-02 | CVE-2023-25748 | Mozilla | Unspecified vulnerability in Mozilla Firefox By displaying a prompt with a long description, the fullscreen notification could have been hidden, resulting in potential user confusion or spoofing attacks. | 4.3 |
2023-06-02 | CVE-2023-25749 | Mozilla | Unspecified vulnerability in Mozilla Firefox Android applications with unpatched vulnerabilities can be launched from a browser using Intents, exposing users to these vulnerabilities. | 4.3 |
2023-06-02 | CVE-2023-25750 | Mozilla | Exposure of Resource to Wrong Sphere vulnerability in Mozilla Firefox Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode. | 4.3 |
2023-06-02 | CVE-2023-28159 | Mozilla | Unspecified vulnerability in Mozilla Firefox The fullscreen notification could have been hidden on Firefox for Android by using download popups, resulting in potential user confusion or spoofing attacks. | 4.3 |
2023-06-02 | CVE-2023-29533 | Mozilla | Unspecified vulnerability in Mozilla products A website could have obscured the fullscreen notification by using a combination of <code>window.open</code>, fullscreen requests, <code>window.name</code> assignments, and <code>setInterval</code> calls. | 4.3 |
2023-06-02 | CVE-2023-29538 | Mozilla | Exposure of Resource to Wrong Sphere vulnerability in Mozilla Firefox and Focus Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. | 4.3 |
2023-06-02 | CVE-2023-32205 | Mozilla | Unspecified vulnerability in Mozilla Firefox In multiple cases browser prompts could have been obscured by popups controlled by content. | 4.3 |
2023-06-02 | CVE-2023-32212 | Mozilla | Unspecified vulnerability in Mozilla Firefox An attacker could have positioned a <code>datalist</code> element to obscure the address bar. | 4.3 |
2023-06-02 | CVE-2022-24695 | Bluetooth | Unspecified vulnerability in Bluetooth Core Specification Bluetooth Classic in Bluetooth Core Specification through 5.3 does not properly conceal device information for Bluetooth transceivers in Non-Discoverable mode. | 4.3 |
2023-06-01 | CVE-2023-32709 | Splunk | Unspecified vulnerability in Splunk and Splunk Cloud Platform In Splunk Enterprise versions below 9.0.5, 8.2.11. | 4.3 |
2023-06-01 | CVE-2023-32717 | Splunk | Unspecified vulnerability in Splunk and Splunk Cloud Platform On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and in Splunk Cloud Platform versions below 9.0.2303.100, an unauthorized user can access the {{/services/indexing/preview}} REST endpoint to overwrite search results if they know the search ID (SID) of an existing search job. | 4.3 |
2023-05-31 | CVE-2023-34219 | Jetbrains | Incorrect Authorization vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API | 4.3 |
2023-05-31 | CVE-2023-23562 | Stormshield | Unspecified vulnerability in Stormshield Endpoint Security 2.3.0/2.3.2 Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control that allows an authenticated user can update global parameters. | 4.3 |
2023-05-30 | CVE-2023-2937 | Unspecified vulnerability in Google Chrome Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | 4.3 | |
2023-05-30 | CVE-2023-2938 | Unspecified vulnerability in Google Chrome Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | 4.3 | |
2023-05-30 | CVE-2023-2941 | Unspecified vulnerability in Google Chrome Inappropriate implementation in Extensions API in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to spoof the contents of the UI via a crafted Chrome Extension. | 4.3 | |
2023-05-30 | CVE-2023-24568 | Dell | Unspecified vulnerability in Dell Networker Dell NetWorker, contains an Improper Validation of Certificate with Host Mismatch vulnerability in Rabbitmq port which could disallow replacing CA signed certificates. | 4.3 |
2023-05-30 | CVE-2023-2978 | Abstrium | Authorization Bypass Through User-Controlled Key vulnerability in Abstrium Pydio Cells 4.2.0 A vulnerability was found in Abstrium Pydio Cells 4.2.0. | 4.3 |
2023-05-30 | CVE-2023-2287 | Themeisle | Unspecified vulnerability in Themeisle Orbitfox The Orbit Fox by ThemeIsle WordPress plugin before 2.10.24 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. | 4.3 |
2023-05-30 | CVE-2023-33183 | Nextcloud | Unspecified vulnerability in Nextcloud Calendar Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. | 4.3 |
2023-05-30 | CVE-2023-33182 | Nextcloud | Unspecified vulnerability in Nextcloud Contacts Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. | 4.3 |
2023-05-29 | CVE-2022-41766 | Mediawiki | Incorrect Permission Assignment for Critical Resource vulnerability in Mediawiki An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. | 4.3 |
2023-05-29 | CVE-2023-24598 | Open Xchange | Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6 OX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution lists, e.g., partial disclosure of the private contacts of another user. | 4.3 |
2023-05-29 | CVE-2023-24599 | Open Xchange | Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6 OX App Suite before backend 7.10.6-rev37 allows authenticated users to change the appointments of arbitrary users via conflicting ID numbers, aka "ID confusion." | 4.3 |
2023-05-29 | CVE-2023-24600 | Open Xchange | Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6 OX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for reading contacts) via a move to their own address book. | 4.3 |
2023-05-29 | CVE-2023-24604 | Open Xchange | Unspecified vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6 OX App Suite before backend 7.10.6-rev37 does not check HTTP header lengths when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of header data. | 4.3 |
2023-05-29 | CVE-2023-24605 | Open Xchange | Missing Authorization vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6 OX App Suite before backend 7.10.6-rev37 does not enforce 2FA for all endpoints, e.g., reading from a drive, reading contact data, and renaming tokens. | 4.2 |
10 Low Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2023-05-31 | CVE-2023-2434 | Kylephillips | Missing Authorization vulnerability in Kylephillips Nested Pages The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions up to, and including, 3.2.3. | 3.8 |
2023-05-29 | CVE-2021-37845 | Citadel | Unspecified vulnerability in Citadel Webcit An issue was discovered in Citadel through webcit-932. | 3.7 |
2023-06-02 | CVE-2023-3044 | Xpdfreader | Divide By Zero vulnerability in Xpdfreader Xpdf An excessively large PDF page size (found in fuzz testing, unlikely in normal PDF files) can result in a divide-by-zero in Xpdf's text extraction code. This is related to CVE-2022-30524, but the problem here is caused by a very large page size, rather than by a very large character coordinate. | 3.3 |
2023-06-02 | CVE-2023-2687 | Silabs | Incorrect Calculation of Buffer Size vulnerability in Silabs Gecko Software Development KIT Buffer overflow in Platform CLI component in Silicon Labs Gecko SDK v4.2.1 and earlier allows user to overwrite limited structures on the heap. | 3.3 |
2023-06-01 | CVE-2023-34339 | Jetbrains | Unspecified vulnerability in Jetbrains Ktor In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message | 3.3 |
2023-05-31 | CVE-2023-28351 | Faronics | Information Exposure Through Log Files vulnerability in Faronics Insight 10.0.19045 An issue was discovered in Faronics Insight 10.0.19045 on Windows. | 3.3 |
2023-05-30 | CVE-2022-39074 | ZTE | Unspecified vulnerability in ZTE products There is an unauthorized access vulnerability in some ZTE mobile phones. | 3.3 |
2023-06-01 | CVE-2023-32712 | Splunk | Improper Encoding or Escaping of Output vulnerability in Splunk In Splunk Enterprise versions below 9.1.0.2, 9.0.5.1, and 8.2.11.2, an attacker can inject American National Standards Institute (ANSI) escape codes into Splunk log files that, when a vulnerable terminal application reads them, can potentially, at worst, result in possible code execution in the vulnerable application. | 3.1 |
2023-05-30 | CVE-2023-2117 | 10Web | Unspecified vulnerability in 10Web Image Optimizer The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root. | 2.7 |
2023-05-30 | CVE-2023-32684 | Linuxfoundation | Files or Directories Accessible to External Parties vulnerability in Linuxfoundation Lima Lima launches Linux virtual machines, typically on macOS, for running containerd. | 2.5 |