CVE-2023-49062

Katran could disclose non-initialized kernel memory as part of an IP header. The issue was present for IPv4 encapsulation and ICMP (v4) Too Big packet generation. After a bpf_xdp_adjust_head call, Katran code didn’t initialize the Identification field for the IPv4 header, resulting in writing content of kernel memory in that field of IP header. The issue affected all Katran versions prior to commit 6a03106ac1eab39d0303662963589ecb2374c97f
Max CVSS
7.5
Published
2023-11-28
Updated
2023-12-04
EPSS
0.09%

CVE-2023-49061

An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120.
Max CVSS
6.1
Published
2023-11-21
Updated
2023-11-28
EPSS
0.05%

CVE-2023-49060

An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulnerability affects Firefox for iOS < 120.
Max CVSS
9.8
Published
2023-11-21
Updated
2023-11-30
EPSS
0.09%

CVE-2023-49058

SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing ‘traverse to parent directory’ are passed through to the file APIs. As a result, it has a low impact to the confidentiality.
Max CVSS
5.3
Published
2023-12-12
Updated
2023-12-14
EPSS
0.05%

CVE-2023-49052

File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function in the created forms component.
Max CVSS
8.8
Published
2023-11-30
Updated
2023-12-05
EPSS
0.73%

CVE-2023-49047

Tenda AX1803 v1.0.0.1 contains a stack overflow via the devName parameter in the function formSetDeviceName.
Max CVSS
7.5
Published
2023-11-27
Updated
2023-12-01
EPSS
0.05%

CVE-2023-49046

Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the devName parameter in the function formAddMacfilterRule.
Max CVSS
9.8
Published
2023-11-27
Updated
2023-12-01
EPSS
0.20%

CVE-2023-49044

Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the ssid parameter in the function form_fast_setting_wifi_set.
Max CVSS
9.8
Published
2023-11-27
Updated
2023-12-01
EPSS
0.20%

CVE-2023-49043

Buffer Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the wpapsk_crypto parameter in the function fromSetWirelessRepeat.
Max CVSS
9.8
Published
2023-11-27
Updated
2023-12-01
EPSS
0.20%

CVE-2023-49042

Heap Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the schedStartTime parameter or the schedEndTime parameter in the function setSchedWifi.
Max CVSS
9.8
Published
2023-11-27
Updated
2023-12-01
EPSS
0.20%

CVE-2023-49040

An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the adslPwd parameter in the form_fast_setting_internet_set function.
Max CVSS
9.8
Published
2023-11-27
Updated
2023-12-01
EPSS
0.32%

CVE-2023-49032

An issue in LTB Self Service Password before v.1.5.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via hijack of the SMS verification code function to arbitrary phone.
Max CVSS
9.8
Published
2023-12-21
Updated
2024-01-02
EPSS
0.05%

CVE-2023-49030

SQL Injection vulnerability in32ns KLive v.2019-1-19 and before allows a remote attacker to obtain sensitive information via a crafted script to the web/user.php component.
Max CVSS
7.5
Published
2023-11-27
Updated
2023-12-13
EPSS
0.07%

CVE-2023-49029

Cross Site Scripting vulnerability in smpn1smg absis v.2017-10-19 and before allows a remote attacker to execute arbitrary code via the nama parameter in the lock/lock.php file.
Max CVSS
6.1
Published
2023-11-27
Updated
2023-12-01
EPSS
0.16%

CVE-2023-49028

Cross Site Scripting vulnerability in smpn1smg absis v.2017-10-19 and before allows a remote attacker to execute arbitrary code via the user parameter in the lock/lock.php file.
Max CVSS
5.4
Published
2023-11-27
Updated
2023-12-13
EPSS
0.11%

CVE-2023-49007

In Netgear Orbi RBR750 firmware before V7.2.6.21, there is a stack-based buffer overflow in /usr/sbin/httpd.
Max CVSS
9.8
Published
2023-12-08
Updated
2023-12-12
EPSS
0.09%

CVE-2023-49006

Cross Site Request Forgery (CSRF) vulnerability in Phpsysinfo version 3.4.3 allows a remote attacker to obtain sensitive information via a crafted page in the XML.php file.
Max CVSS
6.5
Published
2023-12-19
Updated
2024-01-02
EPSS
0.05%

CVE-2023-49004

An issue in D-Link DIR-850L v.B1_FW223WWb01 allows a remote attacker to execute arbitrary code via a crafted script to the en parameter.
Max CVSS
9.8
Published
2023-12-19
Updated
2023-12-22
EPSS
0.24%

CVE-2023-49003

An issue in simplemobiletools Simple Dialer 5.18.1 allows an attacker to bypass intended access restrictions via interaction with com.simplemobiletools.dialer.activities.DialerActivity.
Max CVSS
0.0
Published
2023-12-27
Updated
2023-12-28
EPSS
0.04%

CVE-2023-49002

An issue in Xenom Technologies (sinous) Phone Dialer-voice Call Dialer v.1.2.5 allows an attacker to bypass intended access restrictions via interaction with com.funprime.calldialer.ui.activities.OutgoingActivity.
Max CVSS
0.0
Published
2023-12-27
Updated
2023-12-28
EPSS
0.04%

CVE-2023-49001

An issue in Indi Browser (aka kvbrowser) v.12.11.23 allows an attacker to bypass intended access restrictions via interaction with the com.example.gurry.kvbrowswer.webview component.
Max CVSS
0.0
Published
2023-12-27
Updated
2023-12-28
EPSS
0.04%

CVE-2023-49000

An issue in ArtistScope ArtisBrowser v.34.1.5 and before allows an attacker to bypass intended access restrictions via interaction with the com.artis.browser.IntentReceiverActivity component.
Max CVSS
0.0
Published
2023-12-27
Updated
2023-12-28
EPSS
0.04%

CVE-2023-48967

Ssolon <= 2.6.0 and <=2.5.12 is vulnerable to Deserialization of Untrusted Data.
Max CVSS
9.8
Published
2023-12-04
Updated
2023-12-07
EPSS
0.07%

CVE-2023-48966

An arbitrary file upload vulnerability in the component /admin/api.upload/file of ThinkAdmin v6.1.53 allows attackers to execute arbitrary code via a crafted Zip file.
Max CVSS
8.8
Published
2023-12-04
Updated
2023-12-07
EPSS
0.06%

CVE-2023-48965

An issue in the component /admin/api.plugs/script of ThinkAdmin v6.1.53 allows attackers to getshell via providing a crafted URL to download a malicious PHP file.
Max CVSS
8.8
Published
2023-12-04
Updated
2023-12-07
EPSS
0.05%
50 vulnerabilities found
1 2 3 4 5 6 ...... 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 ...... 39 40 41 42 43 44 45 46 47 48 49 50