CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2024-36801

    Last Modified: 3 Apr 2025

    A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid parameter in Download.php.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2023-52176

    Last Modified: 15 Apr 2026

    Authentication Bypass by Spoofing vulnerability in miniorange Malware Scanner allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Malware Scanner: from n/a through 4.7.1.

    Published: 4 Jun 2024
    3.7
    Low

    CVE-2023-52147

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in All In One WP Security & Firewall Team All In One WP Security & Firewall allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects All In One WP Security & Firewall: from n/a through 5.2.4.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2023-51667

    Last Modified: 29 May 2025

    Authentication Bypass by Spoofing vulnerability in FeedbackWP Rate my Post – WP Rating System allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Rate my Post – WP Rating System: from n/a through 3.4.2.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2023-51544

    Last Modified: 4 Feb 2025

    Improper Control of Interaction Frequency vulnerability in Metagauss RegistrationMagic allows Functionality Misuse.This issue affects RegistrationMagic: from n/a through 5.2.5.0.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2023-51543

    Last Modified: 4 Feb 2025

    Authentication Bypass by Spoofing vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects RegistrationMagic: from n/a through 5.2.5.0.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2023-51542

    Last Modified: 15 Apr 2026

    Authentication Bypass by Spoofing vulnerability in WPMU DEV Branda allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Branda: from n/a through 3.4.14.

    Published: 4 Jun 2024
    6.5
    Medium

    CVE-2023-51511

    Last Modified: 21 Nov 2024

    Improper Authentication vulnerability in Pluggabl LLC Booster Elite for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booster Elite for WooCommerce: from n/a before 7.1.3.

    Published: 4 Jun 2024
    8.1
    High

    CVE-2024-29170

    Last Modified: 8 Jan 2025

    Dell PowerScale OneFS versions 8.2.x through 9.8.0.x contain a use of hard coded credentials vulnerability. An adjacent network unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure of network traffic and denial of service.

    Published: 4 Jun 2024
    7.8
    High

    CVE-2024-37065

    Last Modified: 15 Apr 2026

    Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously crafted model to run arbitrary code on an end user's system when loaded.

    Published: 4 Jun 2024
    7.8
    High

    CVE-2024-37064

    Last Modified: 15 Apr 2026

    Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded.

    Published: 4 Jun 2024
    7.8
    High

    CVE-2024-37063

    Last Modified: 15 Apr 2026

    A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser.

    Published: 4 Jun 2024
    7.8
    High

    CVE-2024-37062

    Last Modified: 15 Apr 2026

    Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded.

    Published: 4 Jun 2024
    8.8
    High

    CVE-2024-37061

    Last Modified: 3 Feb 2025

    Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitrary code on an end user’s system when run.

    Published: 4 Jun 2024
    8.8
    High

    CVE-2024-37060

    Last Modified: 3 Feb 2025

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe to execute arbitrary code on an end user’s system when run.

    Published: 4 Jun 2024
    8.8
    High

    CVE-2024-37059

    Last Modified: 3 Feb 2025

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorch model to run arbitrary code on an end user’s system when interacted with.

    Published: 4 Jun 2024
    8.8
    High

    CVE-2024-37058

    Last Modified: 3 Feb 2025

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langchain AgentExecutor model to run arbitrary code on an end user’s system when interacted with.

    Published: 4 Jun 2024
    7.1
    High

    CVE-2024-4254

    Last Modified: 21 Oct 2025

    The 'deploy-website.yml' workflow in the gradio-app/gradio repository, specifically in the 'main' branch, is vulnerable to secrets exfiltration due to improper authorization. The vulnerability arises from the workflow's explicit checkout and execution of code from a fork, which is unsafe as it allows the running of untrusted code in an environment with access to push to the base repository and access secrets. This flaw could lead to the exfiltration of sensitive secrets such as GITHUB_TOKEN, HF_TOKEN, VERCEL_ORG_ID, VERCEL_PROJECT_ID, COMMENT_TOKEN, AWSACCESSKEYID, AWSSECRETKEY, and VERCEL_TOKEN. The vulnerability is present in the workflow file located at https://github.com/gradio-app/gradio/blob/72f4ca88ab569aae47941b3fb0609e57f2e13a27/.github/workflows/deploy-website.yml.

    Published: 4 Jun 2024
    8.8
    High

    CVE-2024-37057

    Last Modified: 3 Feb 2025

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Tensorflow model to run arbitrary code on an end user’s system when interacted with.

    Published: 4 Jun 2024
    8.8
    High

    CVE-2024-37056

    Last Modified: 3 Feb 2025

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded LightGBM scikit-learn model to run arbitrary code on an end user’s system when interacted with.

    Published: 4 Jun 2024
    8.8
    High

    CVE-2024-37055

    Last Modified: 3 Feb 2025

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdarima model to run arbitrary code on an end user’s system when interacted with.

    Published: 4 Jun 2024
    8.8
    High

    CVE-2024-37054

    Last Modified: 3 Feb 2025

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to run arbitrary code on an end user’s system when interacted with.

    Published: 4 Jun 2024
    8.8
    High

    CVE-2024-37053

    Last Modified: 3 Feb 2025

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.

    Published: 4 Jun 2024
    8.8
    High

    CVE-2024-37052

    Last Modified: 3 Feb 2025

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.

    Published: 4 Jun 2024
    6.5
    Medium

    CVE-2023-49852

    Last Modified: 28 Apr 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Vsourz Digital Responsive Slick Slider WordPress allows Code Injection.This issue affects Responsive Slick Slider WordPress: from n/a through 1.4.

    Published: 4 Jun 2024
    3.7
    Low

    CVE-2023-49822

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in David Vongries Ultimate Dashboard allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Ultimate Dashboard: from n/a through 3.7.10.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2023-49774

    Last Modified: 15 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005.

    Published: 4 Jun 2024
    3.7
    Low

    CVE-2023-49748

    Last Modified: 15 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPServeur, NicolasKulka, wpformation WPS Hide Login allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPS Hide Login: from n/a through 1.9.11.

    Published: 4 Jun 2024
    3.7
    Low

    CVE-2023-49741

    Last Modified: 15 Apr 2026

    Authentication Bypass by Spoofing vulnerability in wpdevart Coming soon and Maintenance mode allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coming soon and Maintenance mode: from n/a through 3.7.3.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2023-48753

    Last Modified: 15 Apr 2026

    Authentication Bypass by Spoofing vulnerability in 10up Restricted Site Access allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Restricted Site Access: from n/a through 7.4.1.

    Published: 4 Jun 2024
    6.5
    Medium

    CVE-2023-48747

    Last Modified: 5 Feb 2025

    Improper Authentication vulnerability in Pluggabl LLC Booster for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booster for WooCommerce: from n/a through 7.1.2.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2023-48745

    Last Modified: 15 Apr 2026

    Improper Restriction of Excessive Authentication Attempts vulnerability in WebFactory Ltd Captcha Code allows Functionality Bypass.This issue affects Captcha Code: from n/a through 2.9.

    Published: 4 Jun 2024
    3.7
    Low

    CVE-2023-48335

    Last Modified: 15 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Webcraftic Hide login page allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Hide login page: from n/a through 1.1.9.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2023-48318

    Last Modified: 12 Jul 2025

    Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Contact Form Email allows Functionality Bypass.This issue affects Contact Form Email: from n/a through 1.3.41.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2023-48290

    Last Modified: 21 Nov 2024

    Improper Restriction of Excessive Authentication Attempts vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Functionality Bypass.This issue affects Form Maker by 10Web: from n/a through 1.15.20.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2023-48285

    Last Modified: 15 Apr 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Tips and Tricks HQ Stripe Payments allows Code Injection.This issue affects Stripe Payments: from n/a through 2.0.79.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2023-48276

    Last Modified: 28 Apr 2026

    Improper Restriction of Excessive Authentication Attempts vulnerability in Nitin Rathod WP Forms Puzzle Captcha allows Functionality Bypass.This issue affects WP Forms Puzzle Captcha: from n/a through 4.1.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2023-48271

    Last Modified: 28 Apr 2026

    Authentication Bypass by Spoofing vulnerability in yonifre Maspik – Spam blacklist allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Maspik – Spam blacklist: from n/a through 0.10.3.

    Published: 4 Jun 2024
    8.3
    High

    CVE-2023-47837

    Last Modified: 29 May 2025

    Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.

    Published: 4 Jun 2024
    3.7
    Low

    CVE-2023-47818

    Last Modified: 15 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in LWS LWS Hide Login allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects LWS Hide Login: from n/a through 2.1.8.

    Published: 4 Jun 2024
    3.7
    Low

    CVE-2023-47769

    Last Modified: 28 Apr 2026

    Authentication Bypass by Spoofing vulnerability in WP Maintenance allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Maintenance: from n/a through 6.1.3.

    Published: 4 Jun 2024
    —
    Unknown

    CVE-2023-47663

    Last Modified: 18 Mar 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 4 Jun 2024
    5.4
    Medium

    CVE-2023-47513

    Last Modified: 15 Apr 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in ARI Soft ARI Stream Quiz allows Code Injection.This issue affects ARI Stream Quiz: from n/a through 1.3.2.

    Published: 4 Jun 2024
    6.5
    Medium

    CVE-2024-5463

    Last Modified: 4 Aug 2025

    A vulnerability regarding buffer copy without checking the size of input ('Classic Buffer Overflow') has been found in the login component. This allows remote attackers to write specific files containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. This attack only affects the login service which will automatically restart. The following models with Synology Camera Firmware versions before 1.1.1-0383 may be affected: BC500 and TC500.

    Published: 4 Jun 2024
    6.4
    Medium

    CVE-2024-4637

    Last Modified: 8 Apr 2026

    The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.7.10 due to insufficient input sanitization and output escaping on the user supplied Elementor 'wrapperid' and 'zindex' display attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2023-47189

    Last Modified: 28 Apr 2026

    Improper Authentication vulnerability in WPMU DEV Defender Security allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Defender Security: from n/a through 4.2.0.

    Published: 4 Jun 2024
    7.5
    High

    CVE-2023-46630

    Last Modified: 28 Apr 2026

    Improper Authentication vulnerability in wpase Admin and Site Enhancements (ASE) allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Admin and Site Enhancements (ASE): from n/a through 5.7.1.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2023-46310

    Last Modified: 28 Apr 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpDiscuz allows Code Injection.This issue affects wpDiscuz: from n/a through 7.6.10.

    Published: 4 Jun 2024
    5.4
    Medium

    CVE-2023-45635

    Last Modified: 28 Apr 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Darko Responsive Tabs allows Code Injection.This issue affects Responsive Tabs: from n/a before 4.0.6.

    Published: 4 Jun 2024
    4.3
    Medium

    CVE-2023-45053

    Last Modified: 28 Apr 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in pluginever WP Content Pilot – Autoblogging & Affiliate Marketing Plugin allows Code Injection.This issue affects WP Content Pilot – Autoblogging & Affiliate Marketing Plugin: from n/a through 1.3.3.

    Published: 4 Jun 2024