<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – VMware Photon (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/photon.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/photon-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – VMware Photon (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:08 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2023-34060 – VMware Cloud Director Appliance contains an authentication bypass vulnerability ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34060</guid>
    <pubDate>Tue, 14 Nov 2023 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-34060</strong></p>
  <p>VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance was upgraded to 10.5 from an older version. On an upgraded version of VMware Cloud Director Appliance 10.5, a malicious actor with network access to the appliance can bypass login restrictions when authenticating on port 22 (ssh) or port 5480 (appliance management console) . Thi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46055 – An issue in ThingNario Photon v.1.0 allows a remote attacker to execute arbitrar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46055</guid>
    <pubDate>Sat, 21 Oct 2023 07:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46055</strong></p>
  <p>An issue in ThingNario Photon v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the ping function to the "thingnario Logger Maintenance Webpage" endpoint.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-1681 – Multiple buffer overflows in (1) phrelay-cfg, (2) phlocale, (3) pkg-installer, o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-1681</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-1681</guid>
    <pubDate>Thu, 26 Aug 2004 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-1681</strong></p>
  <p>Multiple buffer overflows in (1) phrelay-cfg, (2) phlocale, (3) pkg-installer, or (4) input-cfg in QNX Photon microGUI for QNX RTP 6.1 allow local users to gain privileges via a long -s (server) command line parameter.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-1681">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
