Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.1

    MEDIUM
    CVE-2023-52328

    Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not ... Read more

    Affected Products : apex_central
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 8.8

    HIGH
    CVE-2023-52324

    An unrestricted file upload vulnerability in Trend Micro Apex Central could allow a remote attacker to create arbitrary files on affected installations. Please note: although authentication is required to exploit this vulnerability, this vulnerability ... Read more

    Affected Products : apex_central
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 4.8

    MEDIUM
    CVE-2023-52046

    Cross Site Scripting vulnerability (XSS) in webmin v.2.105 and earlier allows a remote attacker to execute arbitrary code via a crafted payload to the "Execute cron job as" tab Input field.... Read more

    Affected Products : webmin webmin
    • Published: Jan. 25, 2024
    • Modified: May. 30, 2025
  • 9.8

    CRITICAL
    CVE-2023-52039

    An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.... Read more

    Affected Products : x6000r_firmware x6000r
    • Published: Jan. 24, 2024
    • Modified: May. 30, 2025
  • 9.8

    CRITICAL
    CVE-2023-52038

    An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.... Read more

    Affected Products : x6000r_firmware x6000r
    • Published: Jan. 24, 2024
    • Modified: May. 30, 2025
  • 7.5

    HIGH
    CVE-2023-51926

    YonBIP v3_23.05 was discovered to contain an arbitrary file read vulnerability via the nc.bs.framework.comn.serv.CommonServletDispatcher component.... Read more

    Affected Products : yonbip
    • Published: Jan. 20, 2024
    • Modified: May. 30, 2025
  • 9.8

    CRITICAL
    CVE-2023-51892

    An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to the FrameworkShellController component.... Read more

    Affected Products : e-cology
    • Published: Jan. 20, 2024
    • Modified: May. 30, 2025
  • 7.5

    HIGH
    CVE-2023-51886

    Buffer Overflow vulnerability in the main() function in Mathtex 1.05 and before allows a remote attacker to cause a denial of service when using \convertpath.... Read more

    Affected Products : mathtex
    • Published: Jan. 24, 2024
    • Modified: May. 30, 2025
  • 9.8

    CRITICAL
    CVE-2023-51885

    Buffer Overflow vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via the length of the LaTeX string component.... Read more

    Affected Products : mathtex
    • Published: Jan. 24, 2024
    • Modified: May. 30, 2025
  • 7.5

    HIGH
    CVE-2023-50943

    Apache Airflow, versions before 2.8.1, have a vulnerability that allows a potential attacker to poison the XCom data by bypassing the protection of "enable_xcom_pickling=False" configuration setting resulting in poisoned data after XCom deserialization. T... Read more

    Affected Products : airflow
    • Published: Jan. 24, 2024
    • Modified: May. 30, 2025
  • 9.8

    CRITICAL
    CVE-2023-50693

    An issue in Jester v.0.6.0 and before allows a remote attacker to send a malicious crafted request.... Read more

    Affected Products : jester
    • Published: Jan. 19, 2024
    • Modified: May. 30, 2025
  • 7.8

    HIGH
    CVE-2023-50274

    HPE OneView may allow command injection with local privilege escalation.... Read more

    Affected Products : oneview
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 8.8

    HIGH
    CVE-2023-47352

    Technicolor TC8715D devices have predictable default WPA2 security passwords. An attacker who scans for SSID and BSSID values may be able to predict these passwords.... Read more

    Affected Products : tc8715d_firmware tc8715d
    • Published: Jan. 22, 2024
    • Modified: May. 30, 2025
  • 7.8

    HIGH
    CVE-2023-47200

    A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged... Read more

    Affected Products : apex_one
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 7.8

    HIGH
    CVE-2023-47199

    An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the ta... Read more

    Affected Products : apex_one
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 7.8

    HIGH
    CVE-2023-47194

    An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the ta... Read more

    Affected Products : apex_one
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 7.5

    HIGH
    CVE-2023-47035

    RPTC 0x3b08c was discovered to not conduct status checks on the parameter tradingOpen. This vulnerability can allow attackers to conduct unauthorized transfer operations.... Read more

    Affected Products : reptilian_coin
    • Published: Jan. 19, 2024
    • Modified: May. 30, 2025
  • 7.5

    HIGH
    CVE-2023-47033

    MultiSigWallet 0xF0C99 was discovered to contain a reentrancy vulnerability via the function executeTransaction.... Read more

    Affected Products : multisigwallet
    • Published: Jan. 19, 2024
    • Modified: May. 30, 2025
  • 6.1

    MEDIUM
    CVE-2023-45889

    A Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.8 allows remote attackers to inject JavaScript into any webpage. NOTE: this issue exists because of an incomplete fix for CVE-2022-48612.... Read more

    Affected Products : oneclick
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 5.4

    MEDIUM
    CVE-2023-44001

    An issue in Ailand clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more

    Affected Products : line
    • Published: Jan. 24, 2024
    • Modified: May. 30, 2025
Showing 20 of 292795 Results