U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, misconfigurations, product names, and impact metrics.

For information on how to the cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2023-42336 - An issue in NETIS SYSTEMS WF2409Ev4 v.1.0.1.705 allows a remote attacker to execute arbitrary code and obtain sensitive information via the password parameter in the /etc/shadow.sample component.
    Published: September 15, 2023; 9:15:08 PM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2023-42454 - SQLpage is a SQL-only webapp builder. Someone using SQLpage versions prior to 0.11.1, whose SQLpage instance is exposed publicly, with a database connection string specified in the `sqlpage/sqlpage.json` configuration file (not in an environment v... read CVE-2023-42454
    Published: September 18, 2023; 6:15:47 PM -0400

    V3.1: 9.1 CRITICAL

  • CVE-2023-39046 - An information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
    Published: September 18, 2023; 6:15:46 PM -0400

    V3.1: 6.5 MEDIUM

  • CVE-2023-35851 - SUNNET WMPro portal's FAQ function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to obtain sensitive information via a database.
    Published: September 17, 2023; 11:15:08 PM -0400

    V3.1: 7.5 HIGH

  • CVE-2023-35850 - SUNNET WMPro portal's file management function has a vulnerability of insufficient filtering for user input. A remote attacker with administrator privilege or a privileged account can exploit this vulnerability to inject and execute arbitrary sys... read CVE-2023-35850
    Published: September 17, 2023; 11:15:07 PM -0400

    V3.1: 7.2 HIGH

  • CVE-2023-0923 - A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making requests to the Jupyter API. This flaw can lead to file content exposure and other issues.
    Published: September 15, 2023; 5:15:09 PM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2023-41443 - SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list.
    Published: September 18, 2023; 6:15:47 PM -0400

    V3.1: 7.2 HIGH

  • CVE-2021-26837 - SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privileges, and gain sensitive information.
    Published: September 18, 2023; 8:15:33 PM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2023-0813 - A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an Open... read CVE-2023-0813
    Published: September 15, 2023; 5:15:08 PM -0400

    V3.1: 7.5 HIGH

  • CVE-2023-40167 - Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accepts the `+` character proceeding the content-length value in a HTTP/1 header field. This is more permissive than allowed by the... read CVE-2023-40167
    Published: September 15, 2023; 4:15:09 PM -0400

    V3.1: 5.3 MEDIUM

  • CVE-2023-1108 - A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
    Published: September 14, 2023; 11:15:08 AM -0400

    V3.1: 7.5 HIGH

  • CVE-2023-37756 - I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation. Attackers are able to easily guess users' passwords via a bruteforce attack.
    Published: September 14, 2023; 5:15:10 PM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2023-4974 - A vulnerability was found in Academy LMS 6.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file /academy/tutor/filter of the component GET Parameter Handler. The manipulation of the argument price_min/... read CVE-2023-4974
    Published: September 14, 2023; 11:15:09 PM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2023-38706 - Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, a malicious user can create an unlimited number of drafts with very long draft keys w... read CVE-2023-38706
    Published: September 15, 2023; 4:15:09 PM -0400

    V3.1: 6.5 MEDIUM

  • CVE-2022-47848 - An issue was discovered in Bezeq Vtech NB403-IL version BZ_2.02.07.09.13.01 and Vtech IAD604-IL versions BZ_2.02.07.09.13.01, BZ_2.02.07.09.13T, and BZ_2.02.07.09.09T, allows remote attackers to gain sensitive information via rootDesc.xml page of ... read CVE-2022-47848
    Published: September 15, 2023; 12:15:07 PM -0400

    V3.1: 7.5 HIGH

  • CVE-2023-4988 - A vulnerability, which was classified as problematic, was found in Bettershop LaikeTui. This affects an unknown part of the file index.php?module=system&action=uploadImg. The manipulation of the argument imgFile leads to unrestricted upload. It is... read CVE-2023-4988
    Published: September 15, 2023; 12:15:08 PM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2023-36727 - Microsoft Edge (Chromium-based) Spoofing Vulnerability
    Published: September 15, 2023; 6:15:13 PM -0400

    V3.1: 6.1 MEDIUM

  • CVE-2023-36735 - Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
    Published: September 15, 2023; 6:15:13 PM -0400

    V3.1: 9.6 CRITICAL

  • CVE-2023-42442 - JumpServer is an open source bastion host and a professional operation and maintenance security audit system. Starting in version 3.0.0 and prior to versions 3.5.5 and 3.6.4, session replays can download without authentication. Session replays sto... read CVE-2023-42442
    Published: September 15, 2023; 5:15:11 PM -0400

    V3.1: 5.3 MEDIUM

  • CVE-2023-41889 - SHIRASAGI is a Content Management System. Prior to version 1.18.0, SHIRASAGI is vulnerable to a Post-Unicode normalization issue. This happens when a logical validation or a security check is performed before a Unicode normalization. The Unicode c... read CVE-2023-41889
    Published: September 15, 2023; 5:15:11 PM -0400

    V3.1: 5.3 MEDIUM