Latest CVE Feed
-
9.8
CRITICALCVE-2023-51892
An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to the FrameworkShellController component.... Read more
Affected Products : e-cology- EPSS Score: %2.87
- Published: Jan. 20, 2024
- Modified: May. 30, 2025
-
7.5
HIGHCVE-2023-51886
Buffer Overflow vulnerability in the main() function in Mathtex 1.05 and before allows a remote attacker to cause a denial of service when using \convertpath.... Read more
Affected Products : mathtex- EPSS Score: %0.67
- Published: Jan. 24, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2023-51885
Buffer Overflow vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via the length of the LaTeX string component.... Read more
Affected Products : mathtex- EPSS Score: %2.95
- Published: Jan. 24, 2024
- Modified: May. 30, 2025
-
7.5
HIGHCVE-2023-50943
Apache Airflow, versions before 2.8.1, have a vulnerability that allows a potential attacker to poison the XCom data by bypassing the protection of "enable_xcom_pickling=False" configuration setting resulting in poisoned data after XCom deserialization. T... Read more
Affected Products : airflow- EPSS Score: %0.19
- Published: Jan. 24, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2023-50693
An issue in Jester v.0.6.0 and before allows a remote attacker to send a malicious crafted request.... Read more
Affected Products : jester- EPSS Score: %1.17
- Published: Jan. 19, 2024
- Modified: May. 30, 2025
-
7.8
HIGHCVE-2023-50274
HPE OneView may allow command injection with local privilege escalation.... Read more
Affected Products : oneview- EPSS Score: %0.28
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2023-47352
Technicolor TC8715D devices have predictable default WPA2 security passwords. An attacker who scans for SSID and BSSID values may be able to predict these passwords.... Read more
- EPSS Score: %0.05
- Published: Jan. 22, 2024
- Modified: May. 30, 2025
-
7.8
HIGHCVE-2023-47200
A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged... Read more
Affected Products : apex_one- EPSS Score: %0.03
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
7.8
HIGHCVE-2023-47199
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the ta... Read more
Affected Products : apex_one- EPSS Score: %0.03
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
7.8
HIGHCVE-2023-47194
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the ta... Read more
Affected Products : apex_one- EPSS Score: %0.03
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
7.5
HIGHCVE-2023-47035
RPTC 0x3b08c was discovered to not conduct status checks on the parameter tradingOpen. This vulnerability can allow attackers to conduct unauthorized transfer operations.... Read more
Affected Products : reptilian_coin- EPSS Score: %0.07
- Published: Jan. 19, 2024
- Modified: May. 30, 2025
-
7.5
HIGHCVE-2023-47033
MultiSigWallet 0xF0C99 was discovered to contain a reentrancy vulnerability via the function executeTransaction.... Read more
Affected Products : multisigwallet- EPSS Score: %0.15
- Published: Jan. 19, 2024
- Modified: May. 30, 2025
-
6.1
MEDIUMCVE-2023-45889
A Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.8 allows remote attackers to inject JavaScript into any webpage. NOTE: this issue exists because of an incomplete fix for CVE-2022-48612.... Read more
Affected Products : oneclick- EPSS Score: %0.15
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
5.4
MEDIUMCVE-2023-44001
An issue in Ailand clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- EPSS Score: %0.08
- Published: Jan. 24, 2024
- Modified: May. 30, 2025
-
5.4
MEDIUMCVE-2023-43991
An issue in PRIMA CLINIC mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- EPSS Score: %0.08
- Published: Jan. 24, 2024
- Modified: May. 30, 2025
-
5.4
MEDIUMCVE-2023-43990
An issue in cherub-hair mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- EPSS Score: %0.08
- Published: Jan. 24, 2024
- Modified: May. 30, 2025
-
5.4
MEDIUMCVE-2023-42143
Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5afc928c allows malicious users to create a backdoor by redirecting the device to an attacker-controlled machine which serves the manipulated firmware file. The device is updated with the manipu... Read more
- EPSS Score: %0.14
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
6.1
MEDIUMCVE-2023-41178
Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided by an attacker. Please note, this vulnerability is similar to,... Read more
Affected Products : mobile_security- EPSS Score: %0.41
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
6.1
MEDIUMCVE-2023-41177
Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided by an attacker. Please note, this vulnerability is similar to,... Read more
Affected Products : mobile_security- EPSS Score: %0.29
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2023-35835
An issue was discovered in SolaX Pocket WiFi 3 through 3.001.02. The device provides a WiFi access point for initial configuration. The WiFi network provided has no network authentication (such as an encryption key) and persists permanently, including aft... Read more
- EPSS Score: %0.20
- Published: Jan. 23, 2024
- Modified: May. 30, 2025