CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2023-6830

    Last Modified: 8 Apr 2026

    The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vulnerability allows unauthenticated users to inject arbitrary HTML code into form fields. When the form data is viewed by an administrator in the Entries View Page, the injected HTML code is rendered, potentially leading to admin area defacement or redirection to malicious websites. CVE-2024-23522 appears to be a duplicate of this issue.

    Published: 9 Jan 2024
    4.4
    Medium

    CVE-2023-6842

    Last Modified: 8 Apr 2026

    The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name field label and description field label parameter in all versions up to 6.7 (inclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this only affects multi-site installations and installations where unfiltered_html has been disabled. However, in the formidable settings admins can extend form creation, deletion and other management permissions to other user types, which makes it possible for this vulnerability to be exploited by lower level user types as long as they have been granted the proper permissions.

    Published: 9 Jan 2024
    7.2
    High

    CVE-2023-7219

    Last Modified: 3 Jun 2025

    A vulnerability has been found in Totolink N350RT 9.3.5u.6139_B202012 and classified as critical. Affected by this vulnerability is the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument http_host leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249853 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 9 Jan 2024
    5.4
    Medium

    CVE-2023-6788

    Last Modified: 8 Apr 2026

    The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.1. This is due to missing or incorrect nonce validation on the contents function. This makes it possible for unauthenticated attackers to update the options "mf_hubsopt_token", "mf_hubsopt_refresh_token", "mf_hubsopt_token_type", and "mf_hubsopt_expires_in" via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This would allow an attacker to connect their own Hubspot account to a victim site's metform to obtain leads and contacts.

    Published: 9 Jan 2024
    4.4
    Medium

    CVE-2023-6594

    Last Modified: 8 Apr 2026

    The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 9.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. Administrators can give button creation privileges to users with lower levels (contributor+) which would allow those lower-privileged users to carry out attacks.

    Published: 9 Jan 2024
    8.8
    High

    CVE-2023-39336

    Last Modified: 3 Jun 2025

    An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal network to execute arbitrary SQL queries and retrieve output without the need for authentication. Under specific circumstances, this may also lead to RCE on the core server.

    Published: 9 Jan 2024
    7.4
    High

    CVE-2024-22125

    Last Modified: 17 Jun 2025

    Under certain conditions the Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge) - version 1.0, allows an attacker to access highly sensitive information which would otherwise be restricted causing high impact on confidentiality.

    Published: 9 Jan 2024
    4.1
    Medium

    CVE-2024-22124

    Last Modified: 21 Nov 2024

    Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22_EXT, WEBDISP 7.22_EXT, WEBDISP 7.53, WEBDISP 7.54, could allow an attacker to access information which would otherwise be restricted causing high impact on confidentiality.

    Published: 9 Jan 2024
    4.1
    Medium

    CVE-2024-21738

    Last Modified: 3 Jun 2025

    SAP NetWeaver ABAP Application Server and ABAP Platform do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker with low privileges can cause limited impact to confidentiality of the application data after successful exploitation.

    Published: 9 Jan 2024
    8.4
    High

    CVE-2024-21737

    Last Modified: 3 Jun 2025

    In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to traverse through various layers and execute OS commands directly. By this, such user can control the behaviour of the application. This leads to considerable impact on confidentiality, integrity and availability.

    Published: 9 Jan 2024
    6.4
    Medium

    CVE-2024-21736

    Last Modified: 17 Apr 2025

    SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary authorization checks. A function import could be triggered allowing the attacker to create in-house bank accounts leading to low impact on the confidentiality of the application.

    Published: 9 Jan 2024
    7.3
    High

    CVE-2024-21735

    Last Modified: 17 Jun 2025

    SAP LT Replication Server - version S4CORE 103, S4CORE 104, S4CORE 105, S4CORE 106, S4CORE 107, S4CORE 108, does not perform necessary authorization checks. This could allow an attacker with high privileges to perform unintended actions, resulting in escalation of privileges, which has High impact on confidentiality, integrity and availability of the system.

    Published: 9 Jan 2024
    3.7
    Low

    CVE-2024-21734

    Last Modified: 21 Nov 2024

    SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious page which could lead to a very convincing phishing attack with low impact on confidentiality and integrity of the application.

    Published: 9 Jan 2024
    9.8
    Critical

    CVE-2024-21646

    Last Modified: 16 Jun 2025

    Azure uAMQP is a general purpose C library for AMQP 1.0. The UAMQP library is used by several clients to implement AMQP protocol communication. When clients using this library receive a crafted binary type data, an integer overflow or wraparound or memory safety issue can occur and may cause remote code execution. This vulnerability has been patched in release 2024-01-01.

    Published: 9 Jan 2024
    5.4
    Medium

    CVE-2023-26998

    Last Modified: 5 Jul 2026

    Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the creator parameter of the Alert Configuration page.

    Published: 9 Jan 2024
    6.5
    Medium

    CVE-2023-6129

    Last Modified: 12 May 2026

    Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications running on PowerPC CPU based platforms if the CPU provides vector instructions. Impact summary: If an attacker can influence whether the POLY1305 MAC algorithm is used, the application state might be corrupted with various application dependent consequences. The POLY1305 MAC (message authentication code) implementation in OpenSSL for PowerPC CPUs restores the contents of vector registers in a different order than they are saved. Thus the contents of some of these vector registers are corrupted when returning to the caller. The vulnerable code is used only on newer PowerPC processors supporting the PowerISA 2.07 instructions. The consequences of this kind of internal application state corruption can be various - from no consequences, if the calling application does not depend on the contents of non-volatile XMM registers at all, to the worst consequences, where the attacker could get complete control of the application process. However unless the compiler uses the vector registers for storing pointers, the most likely consequence, if any, would be an incorrect result of some application dependent calculations or a crash leading to a denial of service. The POLY1305 MAC algorithm is most frequently used as part of the CHACHA20-POLY1305 AEAD (authenticated encryption with associated data) algorithm. The most common usage of this AEAD cipher is with TLS protocol versions 1.2 and 1.3. If this cipher is enabled on the server a malicious client can influence whether this AEAD cipher is used. This implies that TLS server applications using OpenSSL can be potentially impacted. However we are currently not aware of any concrete application that would be affected by this issue therefore we consider this a Low severity security issue.

    Published: 9 Jan 2024
    7
    High

    CVE-2022-36765

    Last Modified: 3 Nov 2025

    EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.

    Published: 9 Jan 2024
    9.8
    Critical

    CVE-2023-26999

    Last Modified: 16 Jun 2025

    An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file.

    Published: 9 Jan 2024
    6.1
    Medium

    CVE-2023-27000

    Last Modified: 18 Jun 2025

    Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the name parameter of the Profile and Exclusion List page(s).

    Published: 9 Jan 2024
    7
    High

    CVE-2022-36764

    Last Modified: 3 Nov 2025

    EDK2 is susceptible to a vulnerability in the Tcg2MeasurePeImage() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.

    Published: 9 Jan 2024
    9.8
    Critical

    CVE-2024-23897

    Last Modified: 24 Oct 2025

    Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.

    Published: 9 Jan 2024
    3.2
    Low

    CVE-2023-20573

    Last Modified: 20 Jun 2025

    A privileged attacker can prevent delivery of debug exceptions to SEV-SNP guests potentially resulting in guests not receiving expected debug information.

    Published: 9 Jan 2024
    7.3
    High

    CVE-2024-20697

    Last Modified: 5 Jun 2025

    Windows libarchive Remote Code Execution Vulnerability

    Published: 9 Jan 2024
    9.8
    Critical

    CVE-2023-50585

    Last Modified: 3 Jun 2025

    Tenda A18 v15.13.07.09 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.

    Published: 9 Jan 2024
    5.5
    Medium

    CVE-2023-50974

    Last Modified: 17 Jun 2025

    In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as UNIX permissions. Any user of the local system can access those credentials.

    Published: 9 Jan 2024
    5.5
    Medium

    CVE-2023-36629

    Last Modified: 20 Jun 2025

    The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.

    Published: 9 Jan 2024
    7.5
    High

    CVE-2023-27098

    Last Modified: 18 Jun 2025

    TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.

    Published: 9 Jan 2024
    8.1
    High

    CVE-2023-41056

    Last Modified: 17 Jun 2025

    Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.

    Published: 9 Jan 2024
    4.9
    Medium

    CVE-2023-46906

    Last Modified: 17 Apr 2025

    juzaweb <= 3.4 is vulnerable to Incorrect Access Control, resulting in an application outage after a 500 HTTP status code. The payload in the timezone field was not correctly validated.

    Published: 9 Jan 2024
    6.5
    Medium

    CVE-2023-47997

    Last Modified: 4 Nov 2025

    An issue discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 leads to an infinite loop and allows attackers to cause a denial of service.

    Published: 9 Jan 2024
    8.8
    High

    CVE-2023-47992

    Last Modified: 17 Jun 2025

    An integer overflow vulnerability in FreeImageIO.cpp::_MemoryReadProc in FreeImage 3.18.0 allows attackers to obtain sensitive information, cause a denial-of-service attacks and/or run arbitrary code.

    Published: 9 Jan 2024
    6.5
    Medium

    CVE-2023-47993

    Last Modified: 20 Jun 2025

    A Buffer out-of-bound read vulnerability in Exif.cpp::ReadInt32 in FreeImage 3.18.0 allows attackers to cause a denial-of-service.

    Published: 9 Jan 2024
    8.8
    High

    CVE-2023-47994

    Last Modified: 3 Jun 2025

    An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows attackers to obtain sensitive information, cause a denial of service and/or run arbitrary code.

    Published: 9 Jan 2024
    6.5
    Medium

    CVE-2023-47996

    Last Modified: 14 May 2025

    An integer overflow vulnerability in Exif.cpp::jpeg_read_exif_dir in FreeImage 3.18.0 allows attackers to obtain information and cause a denial of service.

    Published: 9 Jan 2024
    9.8
    Critical

    CVE-2023-49235

    Last Modified: 20 Jun 2025

    An issue was discovered in libremote_dbg.so on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Filtering of debug information is mishandled during use of popen. Consequently, an attacker can bypass validation and execute a shell command.

    Published: 9 Jan 2024
    9.8
    Critical

    CVE-2023-49236

    Last Modified: 20 Jun 2025

    A stack-based buffer overflow was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices, leading to arbitrary command execution. This occurs because of lack of length validation during an sscanf of a user-entered scale field in the RTSP playback function of davinci.

    Published: 9 Jan 2024
    9.8
    Critical

    CVE-2023-49237

    Last Modified: 20 Jun 2025

    An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.

    Published: 9 Jan 2024
    9.8
    Critical

    CVE-2023-49238

    Last Modified: 17 Jun 2025

    In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password. Although this password must be changed upon the first login, it is possible that an attacker logs in before the legitimate administrator logs in.

    Published: 9 Jan 2024
    9.8
    Critical

    CVE-2023-49569

    Last Modified: 21 Nov 2024

    A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse case scenario, remote code execution could be achieved. Applications are only affected if they are using the ChrootOS https://pkg.go.dev/github.com/go-git/go-billy/v5/osfs#ChrootOS , which is the default when using "Plain" versions of Open and Clone funcs (e.g. PlainClone). Applications using BoundOS https://pkg.go.dev/github.com/go-git/go-billy/v5/osfs#BoundOS  or in-memory filesystems are not affected by this issue. This is a go-git implementation issue and does not affect the upstream git cli.

    Published: 9 Jan 2024
    5.4
    Medium

    CVE-2023-50136

    Last Modified: 3 Jun 2025

    Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the name field when creating a new custom table.

    Published: 9 Jan 2024
    9.8
    Critical

    CVE-2023-50643

    Last Modified: 3 Jun 2025

    An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.

    Published: 9 Jan 2024
    8.3
    High

    CVE-2023-50932

    Last Modified: 6 Jan 2026

    An issue was discovered in savignano S/Notify before 4.0.2 for Confluence. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator clicking a malicious link in an email or by visiting a malicious website. If executed while an administrator is logged on to Confluence, an attacker could exploit this to modify the configuration of the S/Notify app on that host. This can, in particular, lead to email notifications being no longer encrypted when they should be.

    Published: 9 Jan 2024
    9.8
    Critical

    CVE-2023-51717

    Last Modified: 16 Jun 2025

    Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.

    Published: 9 Jan 2024
    5.4
    Medium

    CVE-2022-28975

    Last Modified: 27 Jan 2026

    A stored cross-site scripting (XSS) vulnerability in Infoblox NIOS v8.5.2-409296 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the VLAN View Name field.

    Published: 9 Jan 2024
    7
    High

    CVE-2022-36763

    Last Modified: 3 Nov 2025

    EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.

    Published: 9 Jan 2024
    7.5
    High

    CVE-2024-20672

    Last Modified: 3 Jun 2025

    .NET Denial of Service Vulnerability

    Published: 9 Jan 2024
    4.3
    Medium

    CVE-2024-21664

    Last Modified: 17 Jun 2025

    jwx is a Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. Calling `jws.Parse` with a JSON serialized payload where the `signature` field is present while `protected` is absent can lead to a nil pointer dereference. The vulnerability can be used to crash/DOS a system doing JWS verification. This vulnerability has been patched in versions 2.0.19 and 1.2.28.

    Published: 9 Jan 2024
    8.8
    High

    CVE-2024-23898

    Last Modified: 20 Jun 2025

    Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute CLI commands on the Jenkins controller.

    Published: 9 Jan 2024
    6.5
    Medium

    CVE-2023-47995

    Last Modified: 4 Nov 2025

    Memory Allocation with Excessive Size Value discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 allows attackers to cause a denial of service.

    Published: 9 Jan 2024
    5.5
    Medium

    CVE-2024-22368

    Last Modified: 4 Nov 2025

    The Spreadsheet::ParseXLSX package before 0.28 for Perl can encounter an out-of-memory condition during parsing of a crafted XLSX document. This occurs because the memoize implementation does not have appropriate constraints on merged cells.

    Published: 9 Jan 2024