| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-48123 | Hig | 0.05 | 8.8 | 0.68 | Dec 6, 2023 | An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file. | ||
| CVE-2023-46751 | Hig | 0.49 | 7.5 | 0.02 | Dec 6, 2023 | An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows remote attackers to crash the application via a dangling pointer. | ||
| CVE-2023-45285 | Hig | 0.49 | 7.5 | 0.01 | Dec 6, 2023 | Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the module is unavailable via the secure "https://" and "git+ssh://" protocols, even if GOINSECURE is not set for said module. This only affects users who are not… | ||
| CVE-2023-39539 | Hig | 0.49 | 7.5 | 0.01 | Dec 6, 2023 | AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability. | ||
| CVE-2023-39538 | Hig | 0.49 | 7.5 | 0.00 | Dec 6, 2023 | AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a BMP Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability. | ||
| CVE-2023-48859 | Hig | 0.57 | 8.8 | 0.01 | Dec 6, 2023 | TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows attackers to bypass front-end security restrictions and execute arbitrary code. | ||
| CVE-2023-6288 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2023 | Code injection in Remote Desktop Manager 2023.3.9.3 and earlier on macOS allows an attacker to execute code via the DYLIB_INSERT_LIBRARIES environment variable. | ||
| CVE-2023-32268 | Hig | 0.47 | 7.2 | 0.01 | Dec 6, 2023 | Exposure of Proxy Administrator Credentials An authenticated administrator equivalent Filr user can access the credentials of proxy administrators. | ||
| CVE-2023-6514 | Hig | 0.57 | 8.8 | 0.00 | Dec 6, 2023 | The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability. Successful exploitation of this vulnerability may allow attackers to access restricted functions. Successful exploitation of this vulnerability may allow attackers… | ||
| CVE-2023-6458 | Hig | 0.46 | 7.1 | 0.01 | Dec 6, 2023 | Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traversal. | ||
| CVE-2023-49247 | Hig | 0.49 | 7.5 | 0.00 | Dec 6, 2023 | Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-49246 | Hig | 0.49 | 7.5 | 0.00 | Dec 6, 2023 | Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-49245 | Hig | 0.49 | 7.5 | 0.00 | Dec 6, 2023 | Unauthorized access vulnerability in the Huawei Share module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-49244 | Hig | 0.49 | 7.5 | 0.00 | Dec 6, 2023 | Permission management vulnerability in the multi-user module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-49243 | Hig | 0.49 | 7.5 | 0.00 | Dec 6, 2023 | Vulnerability of unauthorized access to email attachments in the email module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-49242 | Hig | 0.49 | 7.5 | 0.00 | Dec 6, 2023 | Free broadcast vulnerability in the running management module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-49241 | Hig | 0.49 | 7.5 | 0.00 | Dec 6, 2023 | API permission control vulnerability in the network management module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-49240 | Hig | 0.49 | 7.5 | 0.00 | Dec 6, 2023 | Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-49239 | Hig | 0.49 | 7.5 | 0.00 | Dec 6, 2023 | Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-44113 | Hig | 0.49 | 7.5 | 0.00 | Dec 6, 2023 | Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-44099 | Hig | 0.49 | 7.5 | 0.01 | Dec 6, 2023 | Vulnerability of data verification errors in the kernel module. Successful exploitation of this vulnerability may cause WLAN interruption. | ||
| CVE-2023-49897 | Hig | 0.73 | 8.8 | 0.51 | KEV | Dec 6, 2023 | An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| CVE-2023-22523 | Hig | 0.58 | 8.8 | 0.11 | Dec 6, 2023 | This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets… | ||
| CVE-2023-22522 | Hig | 0.58 | 8.8 | 0.13 | Dec 6, 2023 | This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page. Using this approach, an attacker is able to achieve Remote Code Execution (RCE) on an affected instance. Publicly… | ||
| CVE-2023-6510 | Hig | 0.57 | 8.8 | 0.01 | Dec 6, 2023 | Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium) | ||
| CVE-2023-6509 | Hig | 0.57 | 8.8 | 0.01 | Dec 6, 2023 | Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: High) | ||
| CVE-2023-6508 | Hig | 0.57 | 8.8 | 0.01 | Dec 6, 2023 | Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2023-5970 | Hig | 0.57 | 8.8 | 0.01 | Dec 5, 2023 | Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resulting in an MFA bypass. | ||
| CVE-2023-44221 | Hig | 0.65 | 7.2 | 0.75 | KEV | Dec 5, 2023 | Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability. | |
| CVE-2023-45287 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2023 | Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may… | ||
| CVE-2023-45084 | Hig | 0.46 | 7.0 | 0.00 | Dec 5, 2023 | An issue exists in SoftIron HyperCloud where drive caddy removal and reinsertion without a reboot may erroneously cause the system to recognize the caddy as new media and wipe all data on the drives due to a missing synchronization flaw, which impacts data availability and… | ||
| CVE-2023-44297 | Hig | 0.46 | 7.1 | 0.00 | Dec 5, 2023 | Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information disclosure, information tampering, code… | ||
| CVE-2023-6357 | Hig | 0.57 | 8.8 | 0.01 | Dec 5, 2023 | A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device. | ||
| CVE-2023-49448 | Hig | 0.57 | 8.8 | 0.00 | Dec 5, 2023 | JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/nav/delete. | ||
| CVE-2023-49447 | Hig | 0.57 | 8.8 | 0.00 | Dec 5, 2023 | JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/update. | ||
| CVE-2023-49446 | Hig | 0.57 | 8.8 | 0.00 | Dec 5, 2023 | JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/save. | ||
| CVE-2023-49398 | Hig | 0.57 | 8.8 | 0.00 | Dec 5, 2023 | JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/delete. | ||
| CVE-2023-49397 | Hig | 0.57 | 8.8 | 0.00 | Dec 5, 2023 | JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/updateStatus. | ||
| CVE-2023-49396 | Hig | 0.57 | 8.8 | 0.00 | Dec 5, 2023 | JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/save. | ||
| CVE-2023-49395 | Hig | 0.57 | 8.8 | 0.00 | Dec 5, 2023 | JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/update. | ||
| CVE-2023-49383 | Hig | 0.57 | 8.8 | 0.00 | Dec 5, 2023 | JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/save. | ||
| CVE-2023-49382 | Hig | 0.57 | 8.8 | 0.00 | Dec 5, 2023 | JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/delete. | ||
| CVE-2023-49381 | Hig | 0.57 | 8.8 | 0.00 | Dec 5, 2023 | JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/update. | ||
| CVE-2023-49380 | Hig | 0.57 | 8.8 | 0.00 | Dec 5, 2023 | JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/delete. | ||
| CVE-2023-49379 | Hig | 0.57 | 8.8 | 0.00 | Dec 5, 2023 | JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /admin/friend_link/save. | ||
| CVE-2023-49378 | Hig | 0.57 | 8.8 | 0.00 | Dec 5, 2023 | JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/form/save. | ||
| CVE-2023-49377 | Hig | 0.57 | 8.8 | 0.00 | Dec 5, 2023 | JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/update. | ||
| CVE-2023-49376 | Hig | 0.57 | 8.8 | 0.00 | Dec 5, 2023 | JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/delete. | ||
| CVE-2023-49375 | Hig | 0.57 | 8.8 | 0.00 | Dec 5, 2023 | JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/update. | ||
| CVE-2023-49374 | Hig | 0.57 | 8.8 | 0.00 | Dec 5, 2023 | JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/slide/update. |
- risk 0.05cvss 8.8epss 0.68
An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows remote attackers to crash the application via a dangling pointer.
- risk 0.49cvss 7.5epss 0.01
Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the module is unavailable via the secure "https://" and "git+ssh://" protocols, even if GOINSECURE is not set for said module. This only affects users who are not…
- risk 0.49cvss 7.5epss 0.01
AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability.
- risk 0.49cvss 7.5epss 0.00
AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a BMP Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability.
- risk 0.57cvss 8.8epss 0.01
TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows attackers to bypass front-end security restrictions and execute arbitrary code.
- risk 0.51cvss 7.8epss 0.00
Code injection in Remote Desktop Manager 2023.3.9.3 and earlier on macOS allows an attacker to execute code via the DYLIB_INSERT_LIBRARIES environment variable.
- risk 0.47cvss 7.2epss 0.01
Exposure of Proxy Administrator Credentials An authenticated administrator equivalent Filr user can access the credentials of proxy administrators.
- risk 0.57cvss 8.8epss 0.00
The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability. Successful exploitation of this vulnerability may allow attackers to access restricted functions. Successful exploitation of this vulnerability may allow attackers…
- risk 0.46cvss 7.1epss 0.01
Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traversal.
- risk 0.49cvss 7.5epss 0.00
Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
Unauthorized access vulnerability in the Huawei Share module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
Permission management vulnerability in the multi-user module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of unauthorized access to email attachments in the email module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
Free broadcast vulnerability in the running management module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
API permission control vulnerability in the network management module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.01
Vulnerability of data verification errors in the kernel module. Successful exploitation of this vulnerability may cause WLAN interruption.
- risk 0.73cvss 8.8epss 0.51
An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
- risk 0.58cvss 8.8epss 0.11
This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets…
- risk 0.58cvss 8.8epss 0.13
This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page. Using this approach, an attacker is able to achieve Remote Code Execution (RCE) on an affected instance. Publicly…
- risk 0.57cvss 8.8epss 0.01
Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)
- risk 0.57cvss 8.8epss 0.01
Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: High)
- risk 0.57cvss 8.8epss 0.01
Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.57cvss 8.8epss 0.01
Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resulting in an MFA bypass.
- risk 0.65cvss 7.2epss 0.75
Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
- risk 0.49cvss 7.5epss 0.01
Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may…
- risk 0.46cvss 7.0epss 0.00
An issue exists in SoftIron HyperCloud where drive caddy removal and reinsertion without a reboot may erroneously cause the system to recognize the caddy as new media and wipe all data on the drives due to a missing synchronization flaw, which impacts data availability and…
- risk 0.46cvss 7.1epss 0.00
Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information disclosure, information tampering, code…
- risk 0.57cvss 8.8epss 0.01
A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.
- risk 0.57cvss 8.8epss 0.00
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/nav/delete.
- risk 0.57cvss 8.8epss 0.00
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/update.
- risk 0.57cvss 8.8epss 0.00
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/save.
- risk 0.57cvss 8.8epss 0.00
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/delete.
- risk 0.57cvss 8.8epss 0.00
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/updateStatus.
- risk 0.57cvss 8.8epss 0.00
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/save.
- risk 0.57cvss 8.8epss 0.00
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/update.
- risk 0.57cvss 8.8epss 0.00
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/save.
- risk 0.57cvss 8.8epss 0.00
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/delete.
- risk 0.57cvss 8.8epss 0.00
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/update.
- risk 0.57cvss 8.8epss 0.00
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/delete.
- risk 0.57cvss 8.8epss 0.00
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /admin/friend_link/save.
- risk 0.57cvss 8.8epss 0.00
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/form/save.
- risk 0.57cvss 8.8epss 0.00
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/update.
- risk 0.57cvss 8.8epss 0.00
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/delete.
- risk 0.57cvss 8.8epss 0.00
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/update.
- risk 0.57cvss 8.8epss 0.00
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/slide/update.