CVE Severity Distribution (Last 30 Days)
Found 9 CVEs in the last 30 days.
CVE-2023-30799
CRITICAL
CVSS: 9.1
EPSS: 1.4%
VulnCheck KEV
PoC Available
CWE-269
T1068
MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or HTTP interface. The attacker can abuse this vulnerability to execute arbitrary code on the system.
Published: 2023-07-19
CVE-2023-3079
HIGH
CVSS: 8.8
EPSS: 32.1%
VulnCheck KEV
PoC Available
CWE-843
CWE-843
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published: 2023-06-05
CVE-2023-30795
HIGH
CVSS: 7.8
EPSS: 0.2%
CWE-125
CWE-125
T1005
A vulnerability has been identified in JT Open (All versions < V11.4), JT Utilities (All versions < V13.4), Parasolid V34.0 (All versions < V34.0.253), Parasolid V34.1 (All versions < V34.1.243), Parasolid V35.0 (All versions < V35.0.177), Parasolid V35.1 (All versions < V35.1.073). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current process.
Published: 2023-08-08
CVE-2023-30796
HIGH
CVSS: 7.8
EPSS: 0.2%
CWE-125
CWE-125
T1005
A vulnerability has been identified in JT Open (All versions < V11.4), JT Utilities (All versions < V13.4). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current process.
Published: 2023-08-08
CVE-2023-30797
HIGH
CVSS: 7.5
EPSS: 0.8%
CWE-330
CWE-330
CWE-330
Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow an attacker to guess the credentials and gain access to resources managed by Lemur.
Published: 2023-04-19
CVE-2023-30798
HIGH
CVSS: 7.5
EPSS: 1.3%
CWE-400
CWE-400
T1499
There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or files which can cause excessive memory usage resulting in denial of service of the HTTP service.
Published: 2023-04-21
CVE-2023-30791
HIGH
CVSS: 7.1
EPSS: 0.5%
CWE-434
CWE-434
T1105
Plane version 0.7.1-dev allows an attacker to change the avatar of his profile, which allows uploading files with HTML extension that interprets both HTML and JavaScript.
Published: 2023-07-15
CVE-2023-30792
MEDIUM
CVSS: 6.1
EPSS: 0.4%
CWE-79
CWE-79
T1189
Anchor tag hrefs in Lexical prior to v0.10.0 would render javascript: URLs, allowing for cross-site scripting on link clicks in cases where input was being parsed from untrusted sources.
Published: 2023-04-29
CVE-2023-30790
MEDIUM
CVSS: 5.4
EPSS: 0.6%
CWE-79
CWE-79
T1189
MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/relationships` endpoint and first_name and last_name parameter.
Published: 2023-05-08