Total
402547 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-52325 | 1 Trendmicro | 1 Apex Central | 2026-06-17 | N/A | 7.5 HIGH |
| A local file inclusion vulnerability in one of Trend Micro Apex Central's widgets could allow a remote attacker to execute arbitrary code on affected installations. Please note: this vulnerability must be used in conjunction with another one to exploit an affected system. In addition, an attacker must first obtain a valid set of credentials on target system in order to exploit this vulnerability. | |||||
| CVE-2023-52324 | 1 Trendmicro | 1 Apex Central | 2026-06-17 | N/A | 8.8 HIGH |
| An unrestricted file upload vulnerability in Trend Micro Apex Central could allow a remote attacker to create arbitrary files on affected installations. Please note: although authentication is required to exploit this vulnerability, this vulnerability could be exploited when the attacker has any valid set of credentials. Also, this vulnerability could be potentially used in combination with another vulnerability to execute arbitrary code. | |||||
| CVE-2023-52323 | 1 Pycryptodome | 2 Pycryptodome, Pycryptodomex | 2026-06-17 | N/A | 5.9 MEDIUM |
| PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack. | |||||
| CVE-2023-52322 | 1 Spip | 1 Spip | 2026-06-17 | N/A | 6.1 MEDIUM |
| ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as alphanumerics. | |||||
| CVE-2023-52314 | 1 Paddlepaddle | 1 Paddlepaddle | 2026-06-17 | N/A | 9.6 CRITICAL |
| PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. This resulted in the ability to execute arbitrary commands on the operating system. | |||||
| CVE-2023-52313 | 1 Paddlepaddle | 1 Paddlepaddle | 2026-06-17 | N/A | 4.7 MEDIUM |
| FPE in paddle.argmin and paddle.argmax in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service. | |||||
| CVE-2023-52312 | 1 Paddlepaddle | 1 Paddlepaddle | 2026-06-17 | N/A | 4.7 MEDIUM |
| Nullptr dereference in paddle.crop in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service. | |||||
| CVE-2023-52311 | 1 Paddlepaddle | 1 Paddlepaddle | 2026-06-17 | N/A | 9.6 CRITICAL |
| PaddlePaddle before 2.6.0 has a command injection in _wget_download. This resulted in the ability to execute arbitrary commands on the operating system. | |||||
| CVE-2023-52310 | 1 Paddlepaddle | 1 Paddlepaddle | 2026-06-17 | N/A | 9.6 CRITICAL |
| PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute arbitrary commands on the operating system. | |||||
| CVE-2023-52309 | 1 Paddlepaddle | 1 Paddlepaddle | 2026-06-17 | N/A | 8.2 HIGH |
| Heap buffer overflow in paddle.repeat_interleave in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, information disclosure, or more damage is possible. | |||||
| CVE-2023-52308 | 1 Paddlepaddle | 1 Paddlepaddle | 2026-06-17 | N/A | 4.7 MEDIUM |
| FPE in paddle.amin in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service. | |||||
| CVE-2023-52307 | 1 Paddlepaddle | 1 Paddlepaddle | 2026-06-17 | N/A | 8.2 HIGH |
| Stack overflow in paddle.linalg.lu_unpack in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage. | |||||
| CVE-2023-52306 | 1 Paddlepaddle | 1 Paddlepaddle | 2026-06-17 | N/A | 4.7 MEDIUM |
| FPE in paddle.lerp in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service. | |||||
| CVE-2023-52305 | 1 Paddlepaddle | 1 Paddlepaddle | 2026-06-17 | N/A | 4.7 MEDIUM |
| FPE in paddle.topk in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service. | |||||
| CVE-2023-52304 | 1 Paddlepaddle | 1 Paddlepaddle | 2026-06-17 | N/A | 8.2 HIGH |
| Stack overflow in paddle.searchsorted in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage. | |||||
| CVE-2023-52303 | 1 Paddlepaddle | 1 Paddlepaddle | 2026-06-17 | N/A | 4.7 MEDIUM |
| Nullptr in paddle.put_along_axis in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service. | |||||
| CVE-2023-52302 | 1 Paddlepaddle | 1 Paddlepaddle | 2026-06-17 | N/A | 4.7 MEDIUM |
| Nullptr in paddle.nextafter in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service. | |||||
| CVE-2023-52296 | 1 Ibm | 1 Db2 | 2026-06-17 | N/A | 5.3 MEDIUM |
| IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service when querying a specific UDF built-in function concurrently. IBM X-Force ID: 278547. | |||||
| CVE-2023-52292 | 1 Ibm | 1 Sterling File Gateway | 2026-06-17 | N/A | 6.4 MEDIUM |
| IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |||||
| CVE-2023-52291 | 1 Apache | 1 Streampark | 2026-06-17 | N/A | 4.7 MEDIUM |
| In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark system and have system-level permissions. Generally, only users of that system have the authorization to log in, and users would not manually input a dangerous operation command. Therefore, the risk level of this vulnerability is very low. Background: In the "Project" module, the maven build args “<” operator causes command injection. e.g : “< (curl http://xxx.com )” will be executed as a command injection, Mitigation: all users should upgrade to 2.1.4, The "<" operator will blocked。 | |||||
