NA - CVE-2023-42458 - Zope is an open-source web application server....
Zope is an open-source web application server. Prior to versions 4.8.10 and 5.8.5, there is a stored cross site scripting vulnerability for SVG images. Note that an image tag with an SVG image as...
NA - CVE-2023-42805 - quinn-proto is a state machine for the QUIC...
quinn-proto is a state machine for the QUIC transport protocol. Prior to versions 0.9.5 and 0.10.5, receiving unknown QUIC frames in a QUIC packet could result in a panic. The problem has been...
NA - CVE-2023-42806 - Hydra is the layer-two scalability solution for...
Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, not signing and verifying `$\mathsf{cid}$` allows an attacker (which must be a participant of this head) to use a...
NA - CVE-2023-42807 - Frappe LMS is an open source learning...
Frappe LMS is an open source learning management system. In versions 1.0.0 and prior, on the People Page of LMS, there was an SQL Injection vulnerability. The issue has been fixed in the `main`...
NA - CVE-2023-34575 - SQL injection vulnerability in PrestaShop...
SQL injection vulnerability in PrestaShop opartsavecart through 2.0.7 allows remote attackers to run arbitrary SQL commands via OpartSaveCartDefaultModuleFrontController::initContent() and...
NA - CVE-2023-36109 - Buffer Overflow vulnerability in JerryScript...
Buffer Overflow vulnerability in JerryScript version 3.0, allows remote attackers to execute arbitrary code via ecma_stringbuilder_append_raw component at /jerry-core/ecma/base/ecma-helpers-string.c.
NA - CVE-2023-37279 - Faktory is a language-agnostic persistent...
Faktory is a language-agnostic persistent background job server. Prior to version 1.8.0, the Faktory web dashboard can suffer from denial of service by a crafted malicious url query param `days`....
NA - CVE-2023-43135 - There is an unauthorized access vulnerability...
There is an unauthorized access vulnerability in TP-LINK ER5120G 4.0 2.0.0 Build 210817 Rel.80868n, which allows attackers to obtain sensitive information of the device without authentication,...