Latest CVE Feed
-
9.8
CRITICALCVE-2023-51963
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-51953
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-51952
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2023-51252
PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is provided, pdf files and html files containing malicious code are uploaded, an XSS popup window is realized through online viewing.... Read more
Affected Products : publiccms- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-51126
Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value parameter.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-51123
An issue discovered in D-Link dir815 v.1.01SSb08.bin allows a remote attacker to execute arbitrary code via a crafted POST request to the service parameter in the soapcgi_main function of the cgibin binary component.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-49237
An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.... Read more
- Published: Jan. 09, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-49236
A stack-based buffer overflow was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices, leading to arbitrary command execution. This occurs because of lack of length validation during an sscanf of a user-entered scale field in the RTSP playback functio... Read more
- Published: Jan. 09, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-49235
An issue was discovered in libremote_dbg.so on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Filtering of debug information is mishandled during use of popen. Consequently, an attacker can bypass validation and execute a shell command.... Read more
- Published: Jan. 09, 2024
- Modified: Jun. 20, 2025
-
7.5
HIGHCVE-2023-48864
SEMCMS v4.8 was discovered to contain a SQL injection vulnerability via the languageID parameter in /web_inc.php.... Read more
Affected Products : semcms- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
6.5
MEDIUMCVE-2023-47995
Memory Allocation with Excessive Size Value discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 allows attackers to cause a denial of service.... Read more
Affected Products : freeimage- Published: Jan. 09, 2024
- Modified: Jun. 20, 2025
-
6.5
MEDIUMCVE-2023-47993
A Buffer out-of-bound read vulnerability in Exif.cpp::ReadInt32 in FreeImage 3.18.0 allows attackers to cause a denial-of-service.... Read more
Affected Products : freeimage- Published: Jan. 09, 2024
- Modified: Jun. 20, 2025
-
4.2
MEDIUMCVE-2023-42934
An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app with root privileges may be able to access private information.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
7.5
HIGHCVE-2023-42869
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Ventura 13.4, iOS 16.5 and iPadOS 16.5. Multiple issues in libxml2.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
6.5
MEDIUMCVE-2023-42862
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, tvOS 16.4, iOS 16.4 and iPadOS 16.4, watchOS 9.4. Processing an image may result in disclosure of process memory.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
7.0
HIGHCVE-2023-42832
A race condition was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.7.9, macOS Monterey 12.6.8, macOS Ventura 13.5. An app may be able to gain root privileges.... Read more
Affected Products : macos- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
7.8
HIGHCVE-2023-42826
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing a file may lead to arbitrary code execution.... Read more
Affected Products : macos- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
5.5
MEDIUMCVE-2023-41994
A logic issue was addressed with improved checks This issue is fixed in macOS Sonoma 14. A camera extension may be able to access the camera view from apps other than the app for which it was granted permission.... Read more
Affected Products : macos- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
7.8
HIGHCVE-2023-41974
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17. An app may be able to execute arbitrary code with kernel privileges.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
8.8
HIGHCVE-2023-41060
A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. A remote user may be able to cause kernel code execution.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025