Latest CVE Feed
-
9.8
CRITICALCVE-2023-51887
Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL.... Read more
Affected Products : mathtex- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
9.1
CRITICALCVE-2023-51839
DeviceFarmer stf v3.6.6 suffers from Use of a Broken or Risky Cryptographic Algorithm.... Read more
Affected Products : smartphone_test_farm- Published: Jan. 29, 2024
- Modified: Jun. 20, 2025
-
6.8
MEDIUMCVE-2023-51820
An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitrary code.... Read more
- Published: Feb. 02, 2024
- Modified: Jun. 20, 2025
-
6.5
MEDIUMCVE-2023-51813
Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary code via the staff_list parameter in the index.php component.... Read more
Affected Products : free_and_open_source_inventory_management_system- Published: Jan. 30, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2023-48132
An issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- Published: Jan. 26, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2023-48129
An issue in kimono-oldnew mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- Published: Jan. 26, 2024
- Modified: Jun. 20, 2025
-
7.5
HIGHCVE-2023-47355
The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers for PowerOff, Reboot, and Recovery (e.g., com.eypcnnapps.quickreboot.widget.PowerOff) that are susceptible to unauthori... Read more
Affected Products : root_quick_reboot- Published: Feb. 05, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2023-43997
An issue in Yoruichi hobby base mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2023-43996
An issue in Q co ltd mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2023-43995
An issue in picot.golf mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2023-43992
An issue in STOCKMAN GROUP mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
8.8
HIGHCVE-2023-43317
An issue in Coign CRM Portal v.06.06 allows a remote attacker to escalate privileges via the userPermissionsList parameter in Session Storage component.... Read more
Affected Products : coign- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-38319
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the FAS key entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.... Read more
Affected Products : opennds- Published: Jan. 26, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-38318
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the gateway FQDN entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.... Read more
Affected Products : opennds- Published: Jan. 26, 2024
- Modified: Jun. 20, 2025
-
6.1
MEDIUM- Published: Jan. 30, 2024
- Modified: Jun. 20, 2025
-
6.1
MEDIUMCVE-2023-33758
Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the CLIENT_NAME and DEVICE_GUID fields in the login component.... Read more
Affected Products : maximiser_soft_pbx- Published: Jan. 25, 2024
- Modified: Jun. 20, 2025
-
5.9
MEDIUMCVE-2023-33757
A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Android App) v1.8.5 and before allows attackers to eavesdrop on communications via a man-in-the-middle attack.... Read more
- Published: Jan. 25, 2024
- Modified: Jun. 20, 2025
-
7.2
HIGHCVE-2023-31505
An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrary code and obtain sensitive information via a crafted .phtml file.... Read more
Affected Products : cms- Published: Jan. 31, 2024
- Modified: Jun. 20, 2025
-
7.5
HIGHCVE-2023-29055
In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.properties', that may contain serverside credentials. When the kylin service runs over HTTP (or other plain text protocol), it is possi... Read more
Affected Products : kylin- Published: Jan. 29, 2024
- Modified: Jun. 20, 2025
-
5.5
MEDIUMCVE-2022-4964
Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.... Read more
Affected Products : ubuntu_pipewire-pulse- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025