CVE Notify
19.5K subscribers
4 photos
236K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2023-29457
Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script can be activated through Action form fields, which can be sent as request to a website with a vulnerability that enables execution of malicious scripts.

πŸŽ–@cveNotify
🚨 CVE-2023-29456
URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards.


πŸŽ–@cveNotify
🚨 CVE-2023-29454
Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the payload for every victim visiting its web pages.

πŸŽ–@cveNotify
🚨 CVE-2023-3657
A vulnerability, which was classified as critical, has been found in SourceCodester AC Repair and Services System 1.0. This issue affects some unknown processing of the file Master.php?f=save_book of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-234011.

πŸŽ–@cveNotify
🚨 CVE-2023-25078
Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.

πŸŽ–@cveNotify
🚨 CVE-2023-23585
Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.

πŸŽ–@cveNotify
🚨 CVE-2023-22435
Experion server may experience a DoS due to a stack overflow when handling a specially crafted message.

πŸŽ–@cveNotify
🚨 CVE-2023-29452

Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field β€œAttribution text” when selected β€œOther” Tile provider.



πŸŽ–@cveNotify
🚨 CVE-2023-3659
A vulnerability has been found in SourceCodester AC Repair and Services System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file admin/?page=user/manage_user. The manipulation of the argument firstname/middlename leads to cross site scripting. The attack can be launched remotely. The identifier VDB-234013 was assigned to this vulnerability.

πŸŽ–@cveNotify
🚨 CVE-2023-3658
A vulnerability, which was classified as critical, was found in SourceCodester AC Repair and Services System 1.0. Affected is an unknown function of the file Master.php?f=delete_book of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-234012.

πŸŽ–@cveNotify
🚨 CVE-2023-25770
Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message.

πŸŽ–@cveNotify
🚨 CVE-2023-25178
Controller may be loaded with malicious firmware which could enable remote code execution



πŸŽ–@cveNotify
🚨 CVE-2023-24480
Controller DoS due to stack overflow when decoding a message from the server

πŸŽ–@cveNotify
🚨 CVE-2023-24474
Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message

πŸŽ–@cveNotify
🚨 CVE-2023-3657
A vulnerability, which was classified as critical, has been found in SourceCodester AC Repair and Services System 1.0. This issue affects some unknown processing of the file Master.php?f=save_book of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-234011.

πŸŽ–@cveNotify
🚨 CVE-2023-3661
A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been classified as critical. This affects an unknown part of the file /classes/Master.php?f=save_inquiry. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-234015.

πŸŽ–@cveNotify
🚨 CVE-2023-3660
A vulnerability was found in Campcodes Retro Cellphone Online Store 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/add_user_modal.php. The manipulation of the argument un leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-234014 is the identifier assigned to this vulnerability.

πŸŽ–@cveNotify
🚨 CVE-2023-2003
Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a remote attacker to store base64-encoded malicious code in the device's data tables via the PCOM protocol, which can then be retrieved by a client and executed on the device.



πŸŽ–@cveNotify
🚨 CVE-2023-26597
Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller.

πŸŽ–@cveNotify
🚨 CVE-2023-25948
Server information leak of configuration data when an error is generated in response to a specially crafted message.

πŸŽ–@cveNotify
🚨 CVE-2023-26980
** DISPUTED ** PAX Technology PAX A920 Pro PayDroid 8.1suffers from a Race Condition vulnerability, which allows attackers to bypass the payment software and force the OS to boot directly to Android during the boot process. NOTE: the vendor disputes this because the attack is not feasible: the home launcher will be loaded before any user applications.

πŸŽ–@cveNotify