CVE-2023-50495

NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().
Max CVSS
6.5
Published
2023-12-12
Updated
2023-12-18
EPSS
0.05%

CVE-2023-50481

An issue was discovered in blinksocks version 3.3.8, allows remote attackers to obtain sensitive information via weak encryption algorithms in the component /presets/ssr-auth-chain.js.
Max CVSS
7.5
Published
2023-12-21
Updated
2023-12-29
EPSS
0.08%

CVE-2023-50477

An issue was discovered in nos client version 0.6.6, allows remote attackers to escalate privileges via getRPCEndpoint.js.
Max CVSS
9.8
Published
2023-12-21
Updated
2023-12-29
EPSS
0.15%

CVE-2023-50475

An issue was discovered in bcoin-org bcoin version 2.2.0, allows remote attackers to obtain sensitive information via weak hashing algorithms in the component \vendor\faye-websocket.js.
Max CVSS
9.1
Published
2023-12-21
Updated
2023-12-29
EPSS
0.12%

CVE-2023-50473

Cross-Site Scripting (XSS) vulnerability in bill-ahmed qbit-matUI version 1.16.4, allows remote attackers to obtain sensitive information via fixed session identifiers (SID) in index.js file.
Max CVSS
5.4
Published
2023-12-21
Updated
2023-12-29
EPSS
0.05%

CVE-2023-50472

cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.
Max CVSS
7.5
Published
2023-12-14
Updated
2023-12-19
EPSS
0.05%

CVE-2023-50471

cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.
Max CVSS
7.5
Published
2023-12-14
Updated
2023-12-30
EPSS
0.05%

CVE-2023-50470

A cross-site scripting (XSS) vulnerability in the component admin_ Video.php of SeaCMS v12.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Max CVSS
0.0
Published
2023-12-28
Updated
2023-12-28
EPSS
0.05%

CVE-2023-50469

Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 was discovered to contain a buffer overflow via the ApCliEncrypType parameter at /apply.cgi.
Max CVSS
9.8
Published
2023-12-15
Updated
2023-12-19
EPSS
0.09%

CVE-2023-50466

An authenticated command injection vulnerability in Weintek cMT2078X easyweb Web Version v2.1.3, OS v20220215 allows attackers to execute arbitrary code or access sensitive information via injecting a crafted payload into the HMI Name parameter.
Max CVSS
8.8
Published
2023-12-19
Updated
2023-12-29
EPSS
0.06%

CVE-2023-50465

A stored cross-site scripting (XSS) vulnerability exists in Monica (aka MonicaHQ) 4.0.0 via an SVG document uploaded by an authenticated user.
Max CVSS
5.4
Published
2023-12-11
Updated
2023-12-13
EPSS
0.05%

CVE-2023-50463

The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows attackers to spoof their source IP address via an X-Forwarded-For header, which may bypass a protection mechanism (trusted_proxy directive in reverse_proxy or IP address range restrictions).
Max CVSS
6.5
Published
2023-12-10
Updated
2023-12-13
EPSS
0.08%

CVE-2023-50457

An issue was discovered in Zammad before 6.2.0. When listing tickets linked to a knowledge base answer, or knowledge base answers of a ticket, a user could see entries for which they lack permissions.
Max CVSS
0.0
Published
2023-12-10
Updated
2023-12-11
EPSS
0.05%

CVE-2023-50456

An issue was discovered in Zammad before 6.2.0. An attacker can trigger phishing links in generated notification emails via a crafted first or last name.
Max CVSS
0.0
Published
2023-12-10
Updated
2023-12-11
EPSS
0.05%

CVE-2023-50455

An issue was discovered in Zammad before 6.2.0. Due to lack of rate limiting in the "email address verification" feature, an attacker could send many requests for a known address to cause Denial Of Service (generation of many emails, which would also spam the victim).
Max CVSS
0.0
Published
2023-12-10
Updated
2023-12-11
EPSS
0.05%

CVE-2023-50454

An issue was discovered in Zammad before 6.2.0. In several subsystems, SSL/TLS was used to establish connections to external services without proper validation of hostname and certificate authority. This is exploitable by man-in-the-middle attackers.
Max CVSS
0.0
Published
2023-12-10
Updated
2023-12-11
EPSS
0.06%

CVE-2023-50453

An issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This endpoint returns internal configuration data of user object attributes, such as selectable values, which should not be visible to the public.
Max CVSS
0.0
Published
2023-12-10
Updated
2023-12-11
EPSS
0.05%

CVE-2023-50449

JFinalCMS 5.0.0 could allow a remote attacker to read files via ../ Directory Traversal in the /common/down/file fileKey parameter.
Max CVSS
0.0
Published
2023-12-10
Updated
2023-12-11
EPSS
0.13%

CVE-2023-50448

In ActiveAdmin (aka Active Admin) before 2.12.0, a concurrency issue allows a malicious actor to access potentially private data (that belongs to another user) by making CSV export requests at certain specific times.
Max CVSS
0.0
Published
2023-12-28
Updated
2023-12-29
EPSS
0.04%

CVE-2023-50446

An issue was discovered in Mullvad VPN Windows app before 2023.6-beta1. Insufficient permissions on a directory allow any local unprivileged user to escalate privileges to SYSTEM.
Max CVSS
7.8
Published
2023-12-10
Updated
2023-12-13
EPSS
0.04%

CVE-2023-50445

Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N-V2 v4.3.7, AR750S v4.3.7, AR750 v4.3.7, AR300M v4.3.7, and B1300 v4.3.7., allows local attackers to execute arbitrary code via the get_system_log and get_crash_log functions of the logread module, as well as the upgrade_online function of the upgrade module.
Max CVSS
0.0
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%

CVE-2023-50444

By default, .ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before 2023.5; ZEDMAIL for Windows before 2023.5; and ZED! for Windows, Mac, Linux before 2023.5 include an encrypted version of sensitive user information, which could allow an unauthenticated attacker to obtain it via brute force.
Max CVSS
7.5
Published
2023-12-13
Updated
2023-12-20
EPSS
0.09%

CVE-2023-50443

Encrypted disks created by PRIMX CRYHOD for Windows before Q.2020.4 (ANSSI qualification submission) or CRYHOD for Windows before 2023.5 can be modified by an unauthenticated attacker to include a UNC reference so that it could trigger outbound network traffic from computers on which disks are opened.
Max CVSS
4.6
Published
2023-12-13
Updated
2023-12-20
EPSS
0.05%

CVE-2023-50442

Encrypted folders created by PRIMX ZONECENTRAL through 2023.5 can be modified by a local attacker (with appropriate privileges) so that specific file types are excluded from encryption temporarily. (This modification can, however, be detected, as described in the Administrator Guide.)
Max CVSS
5.5
Published
2023-12-13
Updated
2023-12-20
EPSS
0.04%

CVE-2023-50441

Encrypted folders created by PRIMX ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission) or ZONECENTRAL for Windows before 2023.5 can be modified by an unauthenticated attacker to include a UNC reference so that it could trigger outbound network traffic from computers on which folders are opened.
Max CVSS
5.5
Published
2023-12-13
Updated
2023-12-20
EPSS
0.05%
50 vulnerabilities found
1 2 3 4 5 6 ...... 7 8 9 10 11 12 13 14 15 16 17 18 19 ...... 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50