CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2022-38141

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Zorem Sales Report Email for WooCommerce.This issue affects Sales Report Email for WooCommerce: from n/a through 2.8.

    Published: 17 Jan 2024
    6.5
    Medium

    CVE-2022-36418

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Vagary Digital HREFLANG Tags Lite.This issue affects HREFLANG Tags Lite: from n/a through 2.0.0.

    Published: 17 Jan 2024
    6.5
    Medium

    CVE-2023-5006

    Last Modified: 11 Jun 2025

    The WP Discord Invite WordPress plugin before 2.5.1 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to perform actions on their behalf by tricking a logged in administrator to submit a crafted request.

    Published: 17 Jan 2024
    4.3
    Medium

    CVE-2024-0647

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, was found in Sparksuite SimpleMDE up to 1.11.2. This affects an unknown part of the component iFrame Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-251373 was assigned to this vulnerability.

    Published: 17 Jan 2024
    8.8
    High

    CVE-2023-5041

    Last Modified: 17 Jun 2025

    The Track The Click WordPress plugin before 0.3.12 does not properly sanitize query parameters to the stats REST endpoint before using them in a database query, allowing a logged in user with an author role or higher to perform time based blind SQLi attacks on the database.

    Published: 17 Jan 2024
    —
    Unknown

    CVE-2024-0663

    Last Modified: 19 Jan 2024

    REJECT: This is a false positive report.

    Published: 17 Jan 2024
    7.1
    High

    CVE-2024-0396

    Last Modified: 21 Nov 2024

    In Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), an input validation issue was discovered. An authenticated user can manipulate a parameter in an HTTPS transaction. The modified transaction could lead to computational errors within MOVEit Transfer and potentially result in a denial of service.

    Published: 17 Jan 2024
    7.3
    High

    CVE-2024-0645

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in Explorer++ affecting version 1.3.5.531. A local attacker could execute arbitrary code via a long filename argument by monitoring Structured Exception Handler (SEH) records.

    Published: 17 Jan 2024
    10
    Critical

    CVE-2024-0643

    Last Modified: 2 Jun 2025

    Unrestricted upload of dangerous file types in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to upload different file extensions without any restrictions, resulting in a full system compromise.

    Published: 17 Jan 2024
    9.8
    Critical

    CVE-2024-0642

    Last Modified: 2 Jun 2025

    Inadequate access control in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to access the application as an administrator user through the application endpoint, due to lack of proper credential management.

    Published: 17 Jan 2024
    10
    Critical

    CVE-2021-4434

    Last Modified: 8 Apr 2026

    The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. This allows attackers to execute code on the server.

    Published: 17 Jan 2024
    6.5
    Medium

    CVE-2023-51743

    Last Modified: 17 Jun 2025

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Set Upstream Channel ID (UCID) parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform a Denial of Service (DoS) attack on the targeted system.

    Published: 17 Jan 2024
    6.5
    Medium

    CVE-2023-51742

    Last Modified: 17 Jun 2025

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Add Downstream Frequency parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform a Denial of Service (DoS) attack on the targeted system.

    Published: 17 Jan 2024
    —
    Unknown

    CVE-2024-0644

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 17 Jan 2024
    7.5
    High

    CVE-2023-51741

    Last Modified: 17 Jun 2025

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could exploit this vulnerability by eavesdropping on the victim’s network traffic to extract username and password from the web interface (Password Reset Page) of the vulnerable targeted system.

    Published: 17 Jan 2024
    7.5
    High

    CVE-2023-51740

    Last Modified: 21 Nov 2024

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could exploit this vulnerability by eavesdropping on the victim’s network traffic to extract username and password from the web interface (Login Page) of the vulnerable targeted system.

    Published: 17 Jan 2024
    6.9
    Medium

    CVE-2023-51739

    Last Modified: 2 Jun 2025

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Device Name parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

    Published: 17 Jan 2024
    6.9
    Medium

    CVE-2023-51738

    Last Modified: 17 Jun 2025

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Network Name (SSID) parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

    Published: 17 Jan 2024
    6.9
    Medium

    CVE-2023-51737

    Last Modified: 21 May 2025

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Preshared Phrase parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

    Published: 17 Jan 2024
    6.9
    Medium

    CVE-2023-51736

    Last Modified: 2 Jun 2025

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the L2TP/PPTP Username parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

    Published: 17 Jan 2024
    6.9
    Medium

    CVE-2023-51735

    Last Modified: 9 Jun 2025

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Pre-shared key parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

    Published: 17 Jan 2024
    6.9
    Medium

    CVE-2023-51734

    Last Modified: 21 Nov 2024

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Identity parameter under Remote endpoint settings at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

    Published: 17 Jan 2024
    6.9
    Medium

    CVE-2023-51733

    Last Modified: 21 Nov 2024

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Identity parameter under Local endpoint settings at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

    Published: 17 Jan 2024
    6.9
    Medium

    CVE-2023-51732

    Last Modified: 2 Jun 2025

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the IPsec Tunnel Name parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

    Published: 17 Jan 2024
    6.9
    Medium

    CVE-2023-51731

    Last Modified: 17 Jun 2025

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Hostname parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

    Published: 17 Jan 2024
    6.9
    Medium

    CVE-2023-51730

    Last Modified: 17 Jun 2025

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the DDNS Password parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

    Published: 17 Jan 2024
    6.9
    Medium

    CVE-2023-51729

    Last Modified: 17 Jun 2025

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the DDNS Username parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

    Published: 17 Jan 2024
    6.9
    Medium

    CVE-2023-51728

    Last Modified: 21 Nov 2024

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the SMTP Password parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

    Published: 17 Jan 2024
    6.9
    Medium

    CVE-2023-51727

    Last Modified: 2 Jun 2025

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the SMTP Username parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

    Published: 17 Jan 2024
    6.9
    Medium

    CVE-2023-51726

    Last Modified: 21 May 2025

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the SMTP Server Name parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

    Published: 17 Jan 2024
    6.9
    Medium

    CVE-2023-51725

    Last Modified: 2 Jun 2025

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Contact Email Address parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

    Published: 17 Jan 2024
    6.9
    Medium

    CVE-2023-51724

    Last Modified: 17 Jun 2025

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the URL parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

    Published: 17 Jan 2024
    6.9
    Medium

    CVE-2023-51723

    Last Modified: 21 Nov 2024

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Description parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

    Published: 17 Jan 2024
    6.9
    Medium

    CVE-2023-51722

    Last Modified: 21 Nov 2024

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Time Server 3 parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

    Published: 17 Jan 2024
    6.9
    Medium

    CVE-2023-51721

    Last Modified: 17 Jun 2025

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Time Server 2 parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

    Published: 17 Jan 2024
    6.9
    Medium

    CVE-2023-51720

    Last Modified: 2 Jun 2025

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Time Server 1 parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

    Published: 17 Jan 2024
    6.9
    Medium

    CVE-2023-51719

    Last Modified: 17 Jun 2025

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Traceroute parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

    Published: 17 Jan 2024
    7.2
    High

    CVE-2024-0405

    Last Modified: 8 Apr 2026

    The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin, version 1.5.3, is vulnerable to Post-Authenticated SQL Injection via multiple JSON parameters in the /wp-json/burst/v1/data/compare endpoint. Affected parameters include 'browser', 'device', 'page_id', 'page_url', 'platform', and 'referrer'. This vulnerability arises due to insufficient escaping of user-supplied parameters and the lack of adequate preparation in SQL queries. As a result, authenticated attackers with editor access or higher can append additional SQL queries into existing ones, potentially leading to unauthorized access to sensitive information from the database.

    Published: 17 Jan 2024
    5.5
    Medium

    CVE-2024-1141

    Last Modified: 20 Nov 2025

    A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-store when the DEBUG log level is enabled.

    Published: 17 Jan 2024
    5.4
    Medium

    CVE-2023-52069

    Last Modified: 2 Jun 2025

    kodbox v1.49.04 was discovered to contain a cross-site scripting (XSS) vulnerability via the URL parameter.

    Published: 17 Jan 2024
    7.5
    High

    CVE-2023-52285

    Last Modified: 17 Jun 2025

    ExamSys 9150244 allows SQL Injection via the /Support/action/Pages.php s_score2 parameter.

    Published: 17 Jan 2024
    6.1
    Medium

    CVE-2023-25295

    Last Modified: 17 Jun 2025

    A Cross Site Scripting (XSS) vulnerability in evewa3ajax.php in GRUEN eVEWA3 Community 31 through 53 allows attackers to obtain escalated privileges via a crafted request to the login panel.

    Published: 17 Jan 2024
    9.8
    Critical

    CVE-2023-44077

    Last Modified: 17 Jun 2025

    Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636.

    Published: 17 Jan 2024
    6.1
    Medium

    CVE-2023-46952

    Last Modified: 2 Jun 2025

    Cross Site Scripting vulnerability in ABO.CMS v.5.9.3 allows an attacker to execute arbitrary code via a crafted payload to the Referer header.

    Published: 17 Jan 2024
    6.1
    Medium

    CVE-2023-48858

    Last Modified: 2 Jun 2025

    A Cross-site scripting (XSS) vulnerability in login page php code in Armex ABO.CMS 5.9 allows remote attackers to inject arbitrary web script or HTML via the login.php? URL part.

    Published: 17 Jan 2024
    4.6
    Medium

    CVE-2023-49515

    Last Modified: 21 Nov 2024

    Insecure Permissiosn vulnerability in TP Link TC70 and C200 WIFI Camera v.3 firmware v.1.3.4 and fixed in v.1.3.11 allows a physically proximate attacker to obtain sensitive information via a connection to the UART pin components.

    Published: 17 Jan 2024
    6.1
    Medium

    CVE-2024-22714

    Last Modified: 20 Jun 2025

    Stupid Simple CMS <=1.2.4 is vulnerable to Cross Site Scripting (XSS) in the editing section of the article content.

    Published: 17 Jan 2024
    8.8
    High

    CVE-2024-22715

    Last Modified: 20 Jun 2025

    Stupid Simple CMS <=1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin-edit.php.

    Published: 17 Jan 2024
    6.5
    Medium

    CVE-2024-23525

    Last Modified: 2 Jun 2025

    The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.

    Published: 17 Jan 2024
    6.5
    Medium

    CVE-2023-36235

    Last Modified: 10 Jun 2025

    An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.

    Published: 17 Jan 2024