| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-45761 | Hig | 0.46 | 7.1 | 0.00 | Oct 25, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Joovii Sendle Shipping Plugin plugin <= 5.13 versions. | ||
| CVE-2023-45759 | Hig | 0.46 | 7.1 | 0.00 | Oct 25, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Peter Keung Peter’s Custom Anti-Spam plugin <= 3.2.2 versions. | ||
| CVE-2023-45756 | Hig | 0.46 | 7.1 | 0.00 | Oct 25, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Spider Teams ApplyOnline – Application Form Builder and Manager plugin <= 2.5.2 versions. | ||
| CVE-2023-45750 | Hig | 0.46 | 7.1 | 0.00 | Oct 25, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in POSIMYTH Nexter Extension plugin <= 2.0.3 versions. | ||
| CVE-2023-45637 | Hig | 0.46 | 7.1 | 0.00 | Oct 25, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime EventPrime – Events Calendar, Bookings and Tickets plugin <= 3.1.5 versions. | ||
| CVE-2023-45555 | Hig | 0.51 | 7.8 | 0.01 | Oct 25, 2023 | File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the down_url function in zzz.php file. | ||
| CVE-2023-45321 | Hig | 0.54 | 8.3 | 0.00 | Oct 25, 2023 | The Android Client application, when enrolled with the define method 1 (the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip address and credentials to connect to a remote MQTT broker entity) instead of HTTPS and this feature… | ||
| CVE-2023-45220 | Hig | 0.57 | 8.8 | 0.00 | Oct 25, 2023 | The Android Client application, when enrolled with the define method 1(the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip address and credentials to connect to a remote MQTT broker entity) instead of HTTPS and this feature… | ||
| CVE-2023-43961 | Hig | 0.57 | 8.8 | 0.01 | Oct 25, 2023 | An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted request may cause an authentication bypass. | ||
| CVE-2023-43795 | Hig | 0.61 | 8.6 | 0.68 | Oct 25, 2023 | GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC Web Processing Service (WPS) specification is designed to process information from any server using GET and POST requests. This presents the opportunity for… | ||
| CVE-2023-43507 | Hig | 0.47 | 7.2 | 0.01 | Oct 25, 2023 | A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit this vulnerability to obtain and modify… | ||
| CVE-2023-43506 | Hig | 0.51 | 7.8 | 0.00 | Oct 25, 2023 | A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges to those of a higher role. A successful exploit allows malicious users to execute arbitrary code with root level privileges on the Linux… | ||
| CVE-2023-43488 | Hig | 0.51 | 7.9 | 0.00 | Oct 25, 2023 | The vulnerability allows a low privileged (untrusted) application to modify a critical system property that should be denied, in order to enable the ADB (Android Debug Bridge) protocol to be exposed on the network, exploiting it to gain a privileged shell on the device without… | ||
| CVE-2023-42494 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2023 | EisBaer Scada - CWE-749: Exposed Dangerous Method or Function | ||
| CVE-2023-42493 | Hig | 0.46 | 7.1 | 0.00 | Oct 25, 2023 | EisBaer Scada - CWE-256: Plaintext Storage of a Password | ||
| CVE-2023-42492 | Hig | 0.46 | 7.1 | 0.00 | Oct 25, 2023 | EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key | ||
| CVE-2023-42491 | Hig | 0.57 | 8.8 | 0.01 | Oct 25, 2023 | EisBaer Scada - CWE-285: Improper Authorization | ||
| CVE-2023-42490 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2023 | EisBaer Scada - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | ||
| CVE-2023-42489 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2023 | EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource | ||
| CVE-2023-42488 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2023 | EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | ||
| CVE-2023-41960 | Hig | 0.46 | 7.1 | 0.00 | Oct 25, 2023 | The vulnerability allows an unprivileged(untrusted) third-party application to interact with a content-provider unsafely exposed by the Android Agent application, potentially modifying sensitive settings of the Android Client application itself. | ||
| CVE-2023-41372 | Hig | 0.51 | 7.8 | 0.00 | Oct 25, 2023 | The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client application, inducing it to connect to an attacker - controlled malicious server.This is possible by forging a valid broadcast intent… | ||
| CVE-2023-41339 | Hig | 0.49 | 8.6 | 0.01 | Oct 25, 2023 | GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The WMS specification defines an ``sld=`` parameter for GetMap, GetLegendGraphic and GetFeatureInfo operations for user supplied "dynamic styling". Enabling the… | ||
| CVE-2023-41255 | Hig | 0.57 | 8.8 | 0.00 | Oct 25, 2023 | The vulnerability allows an unprivileged user with access to the subnet of the TPC-110W device to gain a root shell on the device itself abusing the lack of authentication of the ‘su’ binary file installed on the device that can be accessed through the ADB (Android Debug… | ||
| CVE-2023-3112 | Hig | 0.51 | 7.8 | 0.00 | Oct 25, 2023 | A vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker with local access to execute code with elevated privileges. | ||
| CVE-2023-3010 | Hig | 0.47 | 7.3 | 0.00 | Oct 25, 2023 | Grafana is an open-source platform for monitoring and observability. The WorldMap panel plugin, versions before 1.0.4 contains a DOM XSS vulnerability. | ||
| CVE-2023-39930 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2023 | A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS client request. | ||
| CVE-2023-39740 | Hig | 0.53 | 8.2 | 0.01 | Oct 25, 2023 | The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | ||
| CVE-2023-39739 | Hig | 0.53 | 8.2 | 0.01 | Oct 25, 2023 | The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | ||
| CVE-2023-39737 | Hig | 0.53 | 8.2 | 0.01 | Oct 25, 2023 | The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | ||
| CVE-2023-39736 | Hig | 0.53 | 8.2 | 0.01 | Oct 25, 2023 | The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | ||
| CVE-2023-39735 | Hig | 0.53 | 8.2 | 0.01 | Oct 25, 2023 | The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | ||
| CVE-2023-39734 | Hig | 0.53 | 8.2 | 0.01 | Oct 25, 2023 | The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | ||
| CVE-2023-39733 | Hig | 0.53 | 8.2 | 0.01 | Oct 25, 2023 | The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | ||
| CVE-2023-39732 | Hig | 0.53 | 8.2 | 0.01 | Oct 25, 2023 | The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | ||
| CVE-2023-39619 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2023 | ReDos in NPMJS Node Email Check v.1.0.4 allows an attacker to cause a denial of service via a crafted string to the scpSyntax component. | ||
| CVE-2023-39231 | Hig | 0.47 | 7.3 | 0.01 | Oct 25, 2023 | PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing registered device. A threat actor may be able to exploit this vulnerability to register their own MFA device if they have knowledge of… | ||
| CVE-2023-39219 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2023 | PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests | ||
| CVE-2023-38041 | Hig | 0.46 | 7.0 | 0.01 | Oct 25, 2023 | A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system. | ||
| CVE-2023-37910 | Hig | 0.46 | 8.1 | 0.01 | Oct 25, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with the introduction of attachment move support in version 14.0-rc-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, an attacker with edit access on any… | ||
| CVE-2023-37283 | Hig | 0.53 | 8.1 | 0.01 | Oct 25, 2023 | Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter | ||
| CVE-2023-34447 | Hig | 0.00 | 8.8 | 0.01 | Oct 25, 2023 | iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, on `pages/UI.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0. | ||
| CVE-2023-34446 | Hig | 0.00 | 8.8 | 0.01 | Oct 25, 2023 | iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, when displaying `pages/preferences.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0. | ||
| CVE-2023-31582 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2023 | jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less. | ||
| CVE-2023-30912 | Hig | 0.47 | 7.2 | 0.01 | Oct 25, 2023 | A remote code execution issue exists in HPE OneView. | ||
| CVE-2023-27377 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2023 | Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers. | ||
| CVE-2023-27376 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2023 | Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers. | ||
| CVE-2023-27375 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2023 | Missing authentication in the StudentPopupDetails_ContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers. | ||
| CVE-2023-27259 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2023 | Missing authentication in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student and teacher data by unauthenticated attackers. | ||
| CVE-2023-27258 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2023 | Missing authentication in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student and teacher data by unauthenticated attackers. |
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Joovii Sendle Shipping Plugin plugin <= 5.13 versions.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Peter Keung Peter’s Custom Anti-Spam plugin <= 3.2.2 versions.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Spider Teams ApplyOnline – Application Form Builder and Manager plugin <= 2.5.2 versions.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in POSIMYTH Nexter Extension plugin <= 2.0.3 versions.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime EventPrime – Events Calendar, Bookings and Tickets plugin <= 3.1.5 versions.
- risk 0.51cvss 7.8epss 0.01
File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the down_url function in zzz.php file.
- risk 0.54cvss 8.3epss 0.00
The Android Client application, when enrolled with the define method 1 (the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip address and credentials to connect to a remote MQTT broker entity) instead of HTTPS and this feature…
- risk 0.57cvss 8.8epss 0.00
The Android Client application, when enrolled with the define method 1(the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip address and credentials to connect to a remote MQTT broker entity) instead of HTTPS and this feature…
- risk 0.57cvss 8.8epss 0.01
An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
- risk 0.61cvss 8.6epss 0.68
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC Web Processing Service (WPS) specification is designed to process information from any server using GET and POST requests. This presents the opportunity for…
- risk 0.47cvss 7.2epss 0.01
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit this vulnerability to obtain and modify…
- risk 0.51cvss 7.8epss 0.00
A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges to those of a higher role. A successful exploit allows malicious users to execute arbitrary code with root level privileges on the Linux…
- risk 0.51cvss 7.9epss 0.00
The vulnerability allows a low privileged (untrusted) application to modify a critical system property that should be denied, in order to enable the ADB (Android Debug Bridge) protocol to be exposed on the network, exploiting it to gain a privileged shell on the device without…
- risk 0.49cvss 7.5epss 0.01
EisBaer Scada - CWE-749: Exposed Dangerous Method or Function
- risk 0.46cvss 7.1epss 0.00
EisBaer Scada - CWE-256: Plaintext Storage of a Password
- risk 0.46cvss 7.1epss 0.00
EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key
- risk 0.57cvss 8.8epss 0.01
EisBaer Scada - CWE-285: Improper Authorization
- risk 0.49cvss 7.5epss 0.01
EisBaer Scada - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- risk 0.49cvss 7.5epss 0.01
EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource
- risk 0.49cvss 7.5epss 0.01
EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- risk 0.46cvss 7.1epss 0.00
The vulnerability allows an unprivileged(untrusted) third-party application to interact with a content-provider unsafely exposed by the Android Agent application, potentially modifying sensitive settings of the Android Client application itself.
- risk 0.51cvss 7.8epss 0.00
The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client application, inducing it to connect to an attacker - controlled malicious server.This is possible by forging a valid broadcast intent…
- risk 0.49cvss 8.6epss 0.01
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The WMS specification defines an ``sld=`` parameter for GetMap, GetLegendGraphic and GetFeatureInfo operations for user supplied "dynamic styling". Enabling the…
- risk 0.57cvss 8.8epss 0.00
The vulnerability allows an unprivileged user with access to the subnet of the TPC-110W device to gain a root shell on the device itself abusing the lack of authentication of the ‘su’ binary file installed on the device that can be accessed through the ADB (Android Debug…
- risk 0.51cvss 7.8epss 0.00
A vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker with local access to execute code with elevated privileges.
- risk 0.47cvss 7.3epss 0.00
Grafana is an open-source platform for monitoring and observability. The WorldMap panel plugin, versions before 1.0.4 contains a DOM XSS vulnerability.
- risk 0.49cvss 7.5epss 0.01
A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS client request.
- risk 0.53cvss 8.2epss 0.01
The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- risk 0.53cvss 8.2epss 0.01
The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- risk 0.53cvss 8.2epss 0.01
The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- risk 0.53cvss 8.2epss 0.01
The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- risk 0.53cvss 8.2epss 0.01
The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- risk 0.53cvss 8.2epss 0.01
The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- risk 0.53cvss 8.2epss 0.01
The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- risk 0.53cvss 8.2epss 0.01
The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- risk 0.49cvss 7.5epss 0.01
ReDos in NPMJS Node Email Check v.1.0.4 allows an attacker to cause a denial of service via a crafted string to the scpSyntax component.
- risk 0.47cvss 7.3epss 0.01
PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing registered device. A threat actor may be able to exploit this vulnerability to register their own MFA device if they have knowledge of…
- risk 0.49cvss 7.5epss 0.01
PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests
- risk 0.46cvss 7.0epss 0.01
A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system.
- risk 0.46cvss 8.1epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with the introduction of attachment move support in version 14.0-rc-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, an attacker with edit access on any…
- risk 0.53cvss 8.1epss 0.01
Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter
- risk 0.00cvss 8.8epss 0.01
iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, on `pages/UI.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0.
- risk 0.00cvss 8.8epss 0.01
iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, when displaying `pages/preferences.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0.
- risk 0.49cvss 7.5epss 0.01
jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less.
- risk 0.47cvss 7.2epss 0.01
A remote code execution issue exists in HPE OneView.
- risk 0.49cvss 7.5epss 0.01
Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.
- risk 0.49cvss 7.5epss 0.01
Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.
- risk 0.49cvss 7.5epss 0.01
Missing authentication in the StudentPopupDetails_ContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.
- risk 0.49cvss 7.5epss 0.01
Missing authentication in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student and teacher data by unauthenticated attackers.
- risk 0.49cvss 7.5epss 0.01
Missing authentication in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student and teacher data by unauthenticated attackers.