NA - CVE-2023-46238 - ZITADEL is an identity infrastructure...
ZITADEL is an identity infrastructure management system. ZITADEL users can upload their own avatar image using various image types including SVG. SVG can include scripts, such as javascript, which...
NA - CVE-2023-46449 - Sourcecodester Free and Open Source inventory...
Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account...
NA - CVE-2023-5784 - A vulnerability was found in Netentsec NS-ASG...
A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by this issue is some unknown functionality of the file...
NA - CVE-2023-5785 - A vulnerability was found in Netentsec NS-ASG...
A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This affects an unknown part of the file...
NA - CVE-2023-5786 - A vulnerability was found in GeoServer...
A vulnerability was found in GeoServer GeoWebCache up to 1.15.1. It has been declared as problematic. This vulnerability affects unknown code of the file /geoserver/gwc/rest.html. The manipulation...
NA - CVE-2023-5787 - A vulnerability was found in Shaanxi Chanming...
A vulnerability was found in Shaanxi Chanming Education Technology Score Query System 5.0. It has been rated as critical. This issue affects some unknown processing. The manipulation of the...
NA - CVE-2023-41966 -
The application suffers from a privilege...
The application suffers from a privilege escalation vulnerability. A user with read permissions can elevate privileges by sending a HTTP POST to set a parameter.
NA - CVE-2023-42769 - The cookie session ID is of insufficient length...
The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the...
NA - CVE-2023-43208 - NextGen Healthcare Mirth Connect before version...
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. This is a bypass of the patch put in for CVE-2023-37679.