Vulnerabilities (CVE)

Total 402547 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-52325 1 Trendmicro 1 Apex Central 2026-06-17 N/A 7.5 HIGH
A local file inclusion vulnerability in one of Trend Micro Apex Central's widgets could allow a remote attacker to execute arbitrary code on affected installations. Please note: this vulnerability must be used in conjunction with another one to exploit an affected system. In addition, an attacker must first obtain a valid set of credentials on target system in order to exploit this vulnerability.
CVE-2023-52324 1 Trendmicro 1 Apex Central 2026-06-17 N/A 8.8 HIGH
An unrestricted file upload vulnerability in Trend Micro Apex Central could allow a remote attacker to create arbitrary files on affected installations. Please note: although authentication is required to exploit this vulnerability, this vulnerability could be exploited when the attacker has any valid set of credentials. Also, this vulnerability could be potentially used in combination with another vulnerability to execute arbitrary code.
CVE-2023-52323 1 Pycryptodome 2 Pycryptodome, Pycryptodomex 2026-06-17 N/A 5.9 MEDIUM
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
CVE-2023-52322 1 Spip 1 Spip 2026-06-17 N/A 6.1 MEDIUM
ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as alphanumerics.
CVE-2023-52314 1 Paddlepaddle 1 Paddlepaddle 2026-06-17 N/A 9.6 CRITICAL
PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. This resulted in the ability to execute arbitrary commands on the operating system.
CVE-2023-52313 1 Paddlepaddle 1 Paddlepaddle 2026-06-17 N/A 4.7 MEDIUM
FPE in paddle.argmin and paddle.argmax in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.
CVE-2023-52312 1 Paddlepaddle 1 Paddlepaddle 2026-06-17 N/A 4.7 MEDIUM
Nullptr dereference in paddle.crop in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.
CVE-2023-52311 1 Paddlepaddle 1 Paddlepaddle 2026-06-17 N/A 9.6 CRITICAL
PaddlePaddle before 2.6.0 has a command injection in _wget_download. This resulted in the ability to execute arbitrary commands on the operating system.
CVE-2023-52310 1 Paddlepaddle 1 Paddlepaddle 2026-06-17 N/A 9.6 CRITICAL
PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute arbitrary commands on the operating system.
CVE-2023-52309 1 Paddlepaddle 1 Paddlepaddle 2026-06-17 N/A 8.2 HIGH
Heap buffer overflow in paddle.repeat_interleave in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, information disclosure, or more damage is possible.
CVE-2023-52308 1 Paddlepaddle 1 Paddlepaddle 2026-06-17 N/A 4.7 MEDIUM
FPE in paddle.amin in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.
CVE-2023-52307 1 Paddlepaddle 1 Paddlepaddle 2026-06-17 N/A 8.2 HIGH
Stack overflow in paddle.linalg.lu_unpack in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage.
CVE-2023-52306 1 Paddlepaddle 1 Paddlepaddle 2026-06-17 N/A 4.7 MEDIUM
FPE in paddle.lerp in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.
CVE-2023-52305 1 Paddlepaddle 1 Paddlepaddle 2026-06-17 N/A 4.7 MEDIUM
FPE in paddle.topk in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.
CVE-2023-52304 1 Paddlepaddle 1 Paddlepaddle 2026-06-17 N/A 8.2 HIGH
Stack overflow in paddle.searchsorted in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage.
CVE-2023-52303 1 Paddlepaddle 1 Paddlepaddle 2026-06-17 N/A 4.7 MEDIUM
Nullptr in paddle.put_along_axis in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.
CVE-2023-52302 1 Paddlepaddle 1 Paddlepaddle 2026-06-17 N/A 4.7 MEDIUM
Nullptr in paddle.nextafter in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.
CVE-2023-52296 1 Ibm 1 Db2 2026-06-17 N/A 5.3 MEDIUM
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service when querying a specific UDF built-in function concurrently. IBM X-Force ID: 278547.
CVE-2023-52292 1 Ibm 1 Sterling File Gateway 2026-06-17 N/A 6.4 MEDIUM
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2023-52291 1 Apache 1 Streampark 2026-06-17 N/A 4.7 MEDIUM
In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark system and have system-level permissions. Generally, only users of that system have the authorization to log in, and users would not manually input a dangerous operation command. Therefore, the risk level of this vulnerability is very low. Background: In the "Project" module, the maven build args  “<” operator causes command injection. e.g : “< (curl  http://xxx.com )” will be executed as a command injection, Mitigation: all users should upgrade to 2.1.4,  The "<" operator will blocked。