| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-32845 | Hig | 0.49 | 7.5 | 0.01 | Dec 4, 2023 | In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:… | ||
| CVE-2023-32844 | Hig | 0.49 | 7.5 | 0.01 | Dec 4, 2023 | In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:… | ||
| CVE-2023-32843 | Hig | 0.49 | 7.5 | 0.01 | Dec 4, 2023 | In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:… | ||
| CVE-2023-32842 | Hig | 0.49 | 7.5 | 0.01 | Dec 4, 2023 | In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:… | ||
| CVE-2023-32841 | Hig | 0.49 | 7.5 | 0.01 | Dec 4, 2023 | In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:… | ||
| CVE-2023-42748 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42747 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In camera service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42746 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In power manager, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42745 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42743 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42740 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42739 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In engineermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42738 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In telocom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42736 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42717 | Hig | 0.49 | 7.5 | 0.00 | Dec 4, 2023 | In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed | ||
| CVE-2023-42716 | Hig | 0.49 | 7.5 | 0.00 | Dec 4, 2023 | In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed | ||
| CVE-2023-42696 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42695 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42694 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42693 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42692 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42691 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42690 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42689 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42688 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42687 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42686 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42685 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42681 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In ion service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-38003 | Hig | 0.47 | 7.2 | 0.01 | Dec 4, 2023 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a user with DATAACCESS privileges to execute routines that they should not have access to. IBM X-Force ID: 260214. | ||
| CVE-2023-49947 | Hig | 0.49 | 7.5 | 0.01 | Dec 3, 2023 | Forgejo before 1.20.5-1 allows 2FA bypass when docker login uses Basic Authentication. | ||
| CVE-2020-36768 | Hig | 0.41 | 7.3 | 0.01 | Dec 3, 2023 | A vulnerability was found in rl-institut NESP2 Initial Release/1.0. It has been classified as critical. Affected is an unknown function of the file app/database.py. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | ||
| CVE-2023-39257 | Hig | 0.47 | 7.3 | 0.00 | Dec 2, 2023 | Dell Rugged Control Center, version prior to 4.7, contains an Improper Access Control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder when product installation repair is performed, leading… | ||
| CVE-2023-39256 | Hig | 0.47 | 7.3 | 0.00 | Dec 2, 2023 | Dell Rugged Control Center, version prior to 4.7, contains an improper access control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder during product installation and upgrade, leading to… | ||
| CVE-2023-48314 | Hig | 0.46 | 7.1 | 0.00 | Dec 1, 2023 | Collabora Online is a collaborative online office suite based on LibreOffice technology. Users of Nextcloud with Collabora Online Built-in CODE Server app can be vulnerable to attack via proxy.php. This vulnerability has been fixed in Collabora Online - Built-in CODE Server… | ||
| CVE-2023-49277 | Hig | 0.47 | 8.3 | 0.01 | Dec 1, 2023 | dpaste is an open source pastebin application written in Python using the Django framework. A security vulnerability has been identified in the expires parameter of the dpaste API, allowing for a POST Reflected XSS attack. This vulnerability can be exploited by an attacker to… | ||
| CVE-2023-40699 | Hig | 0.49 | 7.5 | 0.01 | Dec 1, 2023 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper input validation. IBM X-Force ID: 265161. | ||
| CVE-2023-42006 | Hig | 0.55 | 8.4 | 0.00 | Dec 1, 2023 | IBM Administration Runtime Expert for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information caused by improper authority checks. IBM X-Force ID: 265266. | ||
| CVE-2023-48893 | Hig | 0.57 | 8.8 | 0.01 | Dec 1, 2023 | SLiMS (aka SENAYAN Library Management System) through 9.6.1 allows admin/modules/reporting/customs/staff_act.php SQL Injection via startDate or untilDate. | ||
| CVE-2023-48813 | Hig | 0.57 | 8.8 | 0.01 | Dec 1, 2023 | Senayan Library Management Systems (Slims) 9 Bulian v9.6.1 is vulnerable to SQL Injection via admin/modules/reporting/customs/fines_report.php. | ||
| CVE-2023-45168 | Hig | 0.55 | 8.4 | 0.00 | Dec 1, 2023 | IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 267966. | ||
| CVE-2023-5637 | Hig | 0.49 | 7.5 | 0.01 | Dec 1, 2023 | Unrestricted Upload of File with Dangerous Type vulnerability in ArslanSoft Education Portal allows Read Sensitive Strings Within an Executable. This issue affects Education Portal: before v1.1. | ||
| CVE-2023-5635 | Hig | 0.49 | 7.5 | 0.01 | Dec 1, 2023 | Improper Protection for Outbound Error Messages and Alert Signals vulnerability in ArslanSoft Education Portal allows Account Footprinting. This issue affects Education Portal: before v1.1. | ||
| CVE-2023-5427 | Hig | 0.51 | 7.8 | 0.00 | Dec 1, 2023 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU processing operations to gain access to already freed memory.This… | ||
| CVE-2023-6033 | Hig | 0.57 | 8.7 | 0.01 | Dec 1, 2023 | Improper neutralization of input in Jira integration configuration in GitLab CE/EE, affecting all versions from 15.10 prior to 16.6.1, 16.5 prior to 16.5.3, and 16.4 prior to 16.4.3 allows attacker to execute javascript in victim's browser. | ||
| CVE-2023-45253 | Hig | 0.51 | 7.8 | 0.00 | Dec 1, 2023 | An issue was discovered in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, allows attackers to manipulate files and escalate privileges via RollingFileAppender.DeleteFile method performed by the log4net library. | ||
| CVE-2023-45252 | Hig | 0.51 | 7.8 | 0.00 | Dec 1, 2023 | DLL Hijacking vulnerability in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, due to the installation of the service in a directory that grants write privileges to standard users, allows attackers to manipulate files, execute arbitrary code, and… | ||
| CVE-2023-48016 | Hig | 0.49 | 7.5 | 0.01 | Dec 1, 2023 | Restaurant Table Booking System V1.0 is vulnerable to SQL Injection in rtbs/admin/index.php via the username parameter. | ||
| CVE-2023-47307 | Hig | 0.49 | 7.5 | 0.01 | Nov 30, 2023 | Buffer Overflow vulnerability in /apply.cgi in Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 allows attackers to cause a denial of service via the ApCliAuthMode parameter. | ||
| CVE-2023-47279 | Hig | 0.49 | 7.5 | 0.01 | Nov 30, 2023 | In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an unauthenticated attacker to disclose user information through a single UDP packet, obtain plaintext credentials, or perform NTLM relaying. |
- risk 0.49cvss 7.5epss 0.01
In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
- risk 0.49cvss 7.5epss 0.01
In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
- risk 0.49cvss 7.5epss 0.01
In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
- risk 0.49cvss 7.5epss 0.01
In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
- risk 0.49cvss 7.5epss 0.01
In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
- risk 0.51cvss 7.8epss 0.00
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In camera service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In power manager, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In engineermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In telocom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.49cvss 7.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed
- risk 0.49cvss 7.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In ion service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.47cvss 7.2epss 0.01
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a user with DATAACCESS privileges to execute routines that they should not have access to. IBM X-Force ID: 260214.
- risk 0.49cvss 7.5epss 0.01
Forgejo before 1.20.5-1 allows 2FA bypass when docker login uses Basic Authentication.
- risk 0.41cvss 7.3epss 0.01
A vulnerability was found in rl-institut NESP2 Initial Release/1.0. It has been classified as critical. Affected is an unknown function of the file app/database.py. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
- risk 0.47cvss 7.3epss 0.00
Dell Rugged Control Center, version prior to 4.7, contains an Improper Access Control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder when product installation repair is performed, leading…
- risk 0.47cvss 7.3epss 0.00
Dell Rugged Control Center, version prior to 4.7, contains an improper access control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder during product installation and upgrade, leading to…
- risk 0.46cvss 7.1epss 0.00
Collabora Online is a collaborative online office suite based on LibreOffice technology. Users of Nextcloud with Collabora Online Built-in CODE Server app can be vulnerable to attack via proxy.php. This vulnerability has been fixed in Collabora Online - Built-in CODE Server…
- risk 0.47cvss 8.3epss 0.01
dpaste is an open source pastebin application written in Python using the Django framework. A security vulnerability has been identified in the expires parameter of the dpaste API, allowing for a POST Reflected XSS attack. This vulnerability can be exploited by an attacker to…
- risk 0.49cvss 7.5epss 0.01
IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper input validation. IBM X-Force ID: 265161.
- risk 0.55cvss 8.4epss 0.00
IBM Administration Runtime Expert for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information caused by improper authority checks. IBM X-Force ID: 265266.
- risk 0.57cvss 8.8epss 0.01
SLiMS (aka SENAYAN Library Management System) through 9.6.1 allows admin/modules/reporting/customs/staff_act.php SQL Injection via startDate or untilDate.
- risk 0.57cvss 8.8epss 0.01
Senayan Library Management Systems (Slims) 9 Bulian v9.6.1 is vulnerable to SQL Injection via admin/modules/reporting/customs/fines_report.php.
- risk 0.55cvss 8.4epss 0.00
IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 267966.
- risk 0.49cvss 7.5epss 0.01
Unrestricted Upload of File with Dangerous Type vulnerability in ArslanSoft Education Portal allows Read Sensitive Strings Within an Executable. This issue affects Education Portal: before v1.1.
- risk 0.49cvss 7.5epss 0.01
Improper Protection for Outbound Error Messages and Alert Signals vulnerability in ArslanSoft Education Portal allows Account Footprinting. This issue affects Education Portal: before v1.1.
- risk 0.51cvss 7.8epss 0.00
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU processing operations to gain access to already freed memory.This…
- risk 0.57cvss 8.7epss 0.01
Improper neutralization of input in Jira integration configuration in GitLab CE/EE, affecting all versions from 15.10 prior to 16.6.1, 16.5 prior to 16.5.3, and 16.4 prior to 16.4.3 allows attacker to execute javascript in victim's browser.
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, allows attackers to manipulate files and escalate privileges via RollingFileAppender.DeleteFile method performed by the log4net library.
- risk 0.51cvss 7.8epss 0.00
DLL Hijacking vulnerability in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, due to the installation of the service in a directory that grants write privileges to standard users, allows attackers to manipulate files, execute arbitrary code, and…
- risk 0.49cvss 7.5epss 0.01
Restaurant Table Booking System V1.0 is vulnerable to SQL Injection in rtbs/admin/index.php via the username parameter.
- risk 0.49cvss 7.5epss 0.01
Buffer Overflow vulnerability in /apply.cgi in Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 allows attackers to cause a denial of service via the ApCliAuthMode parameter.
- risk 0.49cvss 7.5epss 0.01
In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an unauthenticated attacker to disclose user information through a single UDP packet, obtain plaintext credentials, or perform NTLM relaying.