NVD disclosure day

Published threat advisories for October 31, 2023

CVE advisoryCRITICAL

CVE-2023-42425

Turing Edge+ EVC5FD Cloud Connection Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in Turing Edge+ devices that could allow a remote attacker to execute arbitrary code and obtain sensitive information via cloud connection components. This could lead to compromise of the device and its data when connected to the internet, necessitating a review of deployed instances for relevanc

CVE advisoryKnown Exploit

CVE-2023-22518

Confluence Improper Authorization Risk

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Confluence Data Center and Server allows attackers to gain administrator access, potentially causing a complete loss of data confidentiality, integrity, and availability. Affected organizations should take immediate action to mitigate this risk.

• CISA KEV

CVE advisoryCRITICAL

CVE-2023-36263

Prestashop Opart Limit Quantity SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in the opartlimitquantity module for PrestaShop, allowing unauthenticated attackers to execute arbitrary SQL commands via simple HTTP requests. This could lead to unauthorized access or modification of sensitive shop data, impacting data integrity and service operations. Confirmatio