Latest CVE Feed
-
9.8
CRITICALCVE-2023-50643
An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.... Read more
Affected Products : evernote- Published: Jan. 09, 2024
- Modified: Jun. 03, 2025
-
7.8
HIGHCVE-2023-50612
Insecure Permissions vulnerability in fit2cloud Cloud Explorer Lite version 1.4.1, allow local attackers to escalate privileges and obtain sensitive information via the cloud accounts parameter.... Read more
Affected Products : cloudexplorer_lite- Published: Jan. 06, 2024
- Modified: Jun. 03, 2025
-
6.1
MEDIUMCVE-2023-50609
Cross Site Scripting (XSS) vulnerability in AVA teaching video application service platform version 3.1, allows remote attackers to execute arbitrary code via a crafted script to ajax.aspx.... Read more
Affected Products : teaching_video_application_service_platform- Published: Jan. 06, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2023-50585
Tenda A18 v15.13.07.09 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.... Read more
- Published: Jan. 09, 2024
- Modified: Jun. 03, 2025
-
6.1
MEDIUMCVE-2023-50345
HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to malicious sites, potentially leading to phishing attacks or other security threats. ... Read more
Affected Products : dryice_myxalytics- Published: Jan. 03, 2024
- Modified: Jun. 03, 2025
-
7.2
HIGHCVE-2023-50162
SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function.... Read more
Affected Products : empirecms- Published: Jan. 09, 2024
- Modified: Jun. 03, 2025
-
5.4
MEDIUMCVE-2023-50136
Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the name field when creating a new custom table.... Read more
Affected Products : jfinalcms- Published: Jan. 09, 2024
- Modified: Jun. 03, 2025
-
6.5
MEDIUMCVE-2023-50126
Missing encryption in the RFID tags of the Hozard alarm system (Alarmsysteem) v1.0 allow attackers to create a cloned tag via brief physical proximity to one of the original tags, which results in an attacker being able to bring the alarm system to a disa... Read more
Affected Products : alarm_system- Published: Jan. 11, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2023-50090
Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write arbitrary files and run arbitrary commands via crafted POST request.... Read more
Affected Products : ureport2- Published: Jan. 03, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2023-50027
SQL Injection vulnerability in Buy Addons baproductzoommagnifier module for PrestaShop versions 1.0.16 and before, allows remote attackers to escalate privileges and gain sensitive information via BaproductzoommagnifierZoomModuleFrontController::run() met... Read more
Affected Products : bazoom_magnifier- Published: Jan. 05, 2024
- Modified: Jun. 03, 2025
-
5.5
MEDIUMCVE-2023-49558
An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the modules/preprocs/nasm/nasm-pp.c component.... Read more
Affected Products : yasm- Published: Jan. 03, 2024
- Modified: Jun. 03, 2025
-
5.5
MEDIUMCVE-2023-49556
Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_delete_term function in the libyasm/expr.c component.... Read more
Affected Products : yasm- Published: Jan. 03, 2024
- Modified: Jun. 03, 2025
-
7.5
HIGHCVE-2023-49553
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_destroy function in the msj.c file.... Read more
Affected Products : mjs- Published: Jan. 02, 2024
- Modified: Jun. 03, 2025
-
8.8
HIGHCVE-2023-49471
Blind Server-Side Request Forgery (SSRF) vulnerability in karlomikus Bar Assistant before version 3.2.0 does not validate a parameter before making a request through Image::make(), which could allow authenticated remote attackers to execute arbitrary code... Read more
Affected Products : bar_assistant- Published: Jan. 10, 2024
- Modified: Jun. 03, 2025
-
6.1
MEDIUMCVE-2023-49394
Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.... Read more
Affected Products : zentao- Published: Jan. 10, 2024
- Modified: Jun. 03, 2025
-
7.5
HIGHCVE-2023-48261
The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.... Read more
Affected Products : nexo-os nexo_cordless_nutrunner_nxa011s-36v-b_\(0608842012\) nexo_cordless_nutrunner_nxa011s-36v_\(0608842011\) nexo_cordless_nutrunner_nxa015s-36v-b_\(0608842006\) nexo_cordless_nutrunner_nxa015s-36v_\(0608842001\) nexo_cordless_nutrunner_nxa030s-36v-b_\(0608842007\) nexo_cordless_nutrunner_nxa030s-36v_\(0608842002\) nexo_cordless_nutrunner_nxa050s-36v-b_\(0608842008\) nexo_cordless_nutrunner_nxa050s-36v_\(0608842003\) nexo_cordless_nutrunner_nxa065s-36v-b_\(0608842014\) +11 more products- Published: Jan. 10, 2024
- Modified: Jun. 03, 2025
-
6.5
MEDIUMCVE-2023-47997
An issue discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 leads to an infinite loop and allows attackers to cause a denial of service.... Read more
Affected Products : freeimage- Published: Jan. 10, 2024
- Modified: Jun. 03, 2025
-
8.8
HIGHCVE-2023-47994
An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows attackers to obtain sensitive information, cause a denial of service and/or run arbitrary code.... Read more
Affected Products : freeimage- Published: Jan. 09, 2024
- Modified: Jun. 03, 2025
-
8.8
HIGHCVE-2023-47890
pyLoad 0.5.0 is vulnerable to Unrestricted File Upload.... Read more
Affected Products : pyload- Published: Jan. 08, 2024
- Modified: Jun. 03, 2025
-
4.7
MEDIUMCVE-2023-46836
The fixes for XSA-422 (Branch Type Confusion) and XSA-434 (Speculative Return Stack Overflow) are not IRQ-safe. It was believed that the mitigations always operated in contexts with IRQs disabled. However, the original XSA-254 fix for Meltdown (XPTI) de... Read more
Affected Products : xen- Published: Jan. 05, 2024
- Modified: Jun. 03, 2025