Latest CVE Feed
-
9.8
CRITICALCVE-2023-50027
SQL Injection vulnerability in Buy Addons baproductzoommagnifier module for PrestaShop versions 1.0.16 and before, allows remote attackers to escalate privileges and gain sensitive information via BaproductzoommagnifierZoomModuleFrontController::run() met... Read more
Affected Products : bazoom_magnifier- Published: Jan. 05, 2024
- Modified: Jun. 03, 2025
-
5.5
MEDIUMCVE-2023-49558
An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the modules/preprocs/nasm/nasm-pp.c component.... Read more
Affected Products : yasm- Published: Jan. 03, 2024
- Modified: Jun. 03, 2025
-
5.5
MEDIUMCVE-2023-49556
Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_delete_term function in the libyasm/expr.c component.... Read more
Affected Products : yasm- Published: Jan. 03, 2024
- Modified: Jun. 03, 2025
-
7.5
HIGHCVE-2023-49553
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_destroy function in the msj.c file.... Read more
Affected Products : mjs- Published: Jan. 02, 2024
- Modified: Jun. 03, 2025
-
8.8
HIGHCVE-2023-49471
Blind Server-Side Request Forgery (SSRF) vulnerability in karlomikus Bar Assistant before version 3.2.0 does not validate a parameter before making a request through Image::make(), which could allow authenticated remote attackers to execute arbitrary code... Read more
Affected Products : bar_assistant- Published: Jan. 10, 2024
- Modified: Jun. 03, 2025
-
6.1
MEDIUMCVE-2023-49394
Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.... Read more
Affected Products : zentao- Published: Jan. 10, 2024
- Modified: Jun. 03, 2025
-
7.5
HIGHCVE-2023-48261
The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.... Read more
Affected Products : nexo-os nexo_cordless_nutrunner_nxa011s-36v-b_\(0608842012\) nexo_cordless_nutrunner_nxa011s-36v_\(0608842011\) nexo_cordless_nutrunner_nxa015s-36v-b_\(0608842006\) nexo_cordless_nutrunner_nxa015s-36v_\(0608842001\) nexo_cordless_nutrunner_nxa030s-36v-b_\(0608842007\) nexo_cordless_nutrunner_nxa030s-36v_\(0608842002\) nexo_cordless_nutrunner_nxa050s-36v-b_\(0608842008\) nexo_cordless_nutrunner_nxa050s-36v_\(0608842003\) nexo_cordless_nutrunner_nxa065s-36v-b_\(0608842014\) +11 more products- Published: Jan. 10, 2024
- Modified: Jun. 03, 2025
-
6.5
MEDIUMCVE-2023-47997
An issue discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 leads to an infinite loop and allows attackers to cause a denial of service.... Read more
Affected Products : freeimage- Published: Jan. 10, 2024
- Modified: Jun. 03, 2025
-
8.8
HIGHCVE-2023-47994
An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows attackers to obtain sensitive information, cause a denial of service and/or run arbitrary code.... Read more
Affected Products : freeimage- Published: Jan. 09, 2024
- Modified: Jun. 03, 2025
-
8.8
HIGHCVE-2023-47890
pyLoad 0.5.0 is vulnerable to Unrestricted File Upload.... Read more
Affected Products : pyload- Published: Jan. 08, 2024
- Modified: Jun. 03, 2025
-
4.7
MEDIUMCVE-2023-46836
The fixes for XSA-422 (Branch Type Confusion) and XSA-434 (Speculative Return Stack Overflow) are not IRQ-safe. It was believed that the mitigations always operated in contexts with IRQs disabled. However, the original XSA-254 fix for Meltdown (XPTI) de... Read more
Affected Products : xen- Published: Jan. 05, 2024
- Modified: Jun. 03, 2025
-
7.2
HIGHCVE-2023-46474
File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted PHP file uploaded to the start_import.php file.... Read more
Affected Products : pmb- Published: Jan. 11, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2023-46308
In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty.... Read more
Affected Products : plotly.js- Published: Jan. 03, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2023-45722
HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory. The pr... Read more
Affected Products : dryice_myxalytics- Published: Jan. 03, 2024
- Modified: Jun. 03, 2025
-
8.2
HIGHCVE-2023-45559
An issue in Tamaki_hamanoki Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.... Read more
Affected Products : line- Published: Jan. 03, 2024
- Modified: Jun. 03, 2025
-
7.8
HIGHCVE-2023-42933
This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to gain elevated privileges.... Read more
Affected Products : macos- Published: Jan. 10, 2024
- Modified: Jun. 03, 2025
-
5.5
MEDIUMCVE-2023-42872
The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app may be able to access sensitive user data.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 03, 2025
-
8.8
HIGHCVE-2023-42866
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, tvOS 16.6, Safari 16.6, watchOS 9.6. Processing web content may lead to arbitrary code execution.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 03, 2025
-
5.5
MEDIUMCVE-2023-42831
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Monterey 12.6.8, macOS Ventura 13.5. An app may be able to fingerprint the user.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 03, 2025
-
7.8
HIGHCVE-2023-42828
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.5. An app may be able to gain root privileges.... Read more
Affected Products : macos- Published: Jan. 10, 2024
- Modified: Jun. 03, 2025