CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2023-38827

    Last Modified: 3 Jun 2025

    Cross Site Scripting vulnerability in Follet School Solutions Destiny v.20_0_1_AU4 and later allows a remote attacker to run arbitrary code via presentonesearchresultsform.do.

    Published: 9 Jan 2024
    8.3
    High

    CVE-2023-50930

    Last Modified: 14 May 2025

    An issue was discovered in savignano S/Notify before 4.0.2 for Jira. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator clicking a malicious link in an email or by visiting a malicious website. If executed while an administrator is logged on to Jira, an attacker could exploit this to modify the configuration of the S/Notify app on that host. This can, in particular, lead to email notifications being no longer encrypted when they should be.

    Published: 9 Jan 2024
    6.8
    Medium

    CVE-2023-4001

    Last Modified: 20 Nov 2025

    An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a duplicate UUID (the same as in the "/boot/" file system) can bypass the GRUB password protection feature on UEFI systems, which enumerate removable drives before non-removable ones. This issue was introduced in a downstream patch in Red Hat's version of grub2 and does not affect the upstream package.

    Published: 9 Jan 2024
    7.3
    High

    CVE-2024-20696

    Last Modified: 3 Nov 2025

    Windows libarchive Remote Code Execution Vulnerability

    Published: 9 Jan 2024
    7.5
    High

    CVE-2024-21312

    Last Modified: 3 May 2025

    .NET Framework Denial of Service Vulnerability

    Published: 9 Jan 2024
    6.5
    Medium

    CVE-2024-23899

    Last Modified: 4 Jun 2025

    Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing attackers with Overall/Read permission to read content from arbitrary files on the Jenkins controller file system.

    Published: 9 Jan 2024
    4.3
    Medium

    CVE-2024-23900

    Last Modified: 16 Jun 2025

    Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace any config.xml files on the Jenkins controller file system with content not controllable by the attackers.

    Published: 9 Jan 2024
    8.3
    High

    CVE-2023-50931

    Last Modified: 6 Jan 2026

    An issue was discovered in savignano S/Notify before 2.0.1 for Bitbucket. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator clicking a malicious link in an email or by visiting a malicious website. If executed while an administrator is logged on to Bitbucket, an attacker could exploit this to modify the configuration of the S/Notify app on that host. This can, in particular, lead to email notifications being no longer encrypted when they should be.

    Published: 9 Jan 2024
    9.9
    Critical

    CVE-2024-21663

    Last Modified: 21 Nov 2024

    Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is vulnerable to remote code execution. An attacker is able to execute shell commands in the server without having an admin role. This vulnerability has been fixed in version 0.0.8.

    Published: 8 Jan 2024
    8
    High

    CVE-2024-21648

    Last Modified: 17 Jun 2025

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The rollback action is missing a right protection, a user can rollback to a previous version of the page to gain rights they don't have anymore. The problem has been patched in XWiki 14.10.17, 15.5.3 and 15.8-rc-1 by ensuring that the rights are checked before performing the rollback.

    Published: 8 Jan 2024
    7.5
    High

    CVE-2024-21651

    Last Modified: 3 Jun 2025

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to attach a file to a page can post a malformed TAR file by manipulating file modification times headers, which when parsed by Tika, could cause a denial of service issue via CPU consumption. This vulnerability has been patched in XWiki 14.10.18, 15.5.3 and 15.8 RC1.

    Published: 8 Jan 2024
    3.7
    Low

    CVE-2022-40696

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This issue affects Advanced Custom Fields (ACF): from 3.1.1 through 6.0.2.

    Published: 8 Jan 2024
    6.3
    Medium

    CVE-2022-36352

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Memberships, Groups and Communities: from n/a through 5.0.3.

    Published: 8 Jan 2024
    —
    Unknown

    CVE-2022-29409

    Last Modified: 8 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 8 Jan 2024
    5.4
    Medium

    CVE-2022-34344

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Rymera Web Co Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More.This issue affects Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More: from n/a through 2.1.5.

    Published: 8 Jan 2024
    7.2
    High

    CVE-2023-7218

    Last Modified: 17 Jun 2025

    A vulnerability, which was classified as critical, was found in Totolink N350RT 9.3.5u.6139_B202012. Affected is the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password leads to stack-based buffer overflow. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-249852. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Jan 2024
    7.6
    High

    CVE-2023-52142

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cool Plugins Events Shortcodes For The Events Calendar.This issue affects Events Shortcodes For The Events Calendar: from n/a through 2.3.1.

    Published: 8 Jan 2024
    9.1
    Critical

    CVE-2023-52202

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Folder Feedburner Playlist Free.This issue affects HTML5 MP3 Player with Folder Feedburner Playlist Free: from n/a through 2.8.0.

    Published: 8 Jan 2024
    5.3
    Medium

    CVE-2022-45354

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.

    Published: 8 Jan 2024
    5.3
    Medium

    CVE-2023-51406

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FastDup – Fastest WordPress Migration & Duplicator.This issue affects FastDup – Fastest WordPress Migration & Duplicator: from n/a through 2.1.7.

    Published: 8 Jan 2024
    5.3
    Medium

    CVE-2023-51408

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StudioWombat WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce.This issue affects WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce: from n/a through 1.4.3.

    Published: 8 Jan 2024
    7.1
    High

    CVE-2023-52196

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phil Ewels CPT Bootstrap Carousel allows Reflected XSS.This issue affects CPT Bootstrap Carousel: from n/a through 1.12.

    Published: 8 Jan 2024
    5.9
    Medium

    CVE-2023-52197

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Impactpixel Ads Invalid Click Protection allows Stored XSS.This issue affects Ads Invalid Click Protection: from n/a through 1.0.

    Published: 8 Jan 2024
    6.5
    Medium

    CVE-2023-52198

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michiel van Eerd Private Google Calendars allows Stored XSS.This issue affects Private Google Calendars: from n/a through 20231125.

    Published: 8 Jan 2024
    5.3
    Medium

    CVE-2023-51490

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPMU DEV Defender Security – Malware Scanner, Login Security & Firewall.This issue affects Defender Security – Malware Scanner, Login Security & Firewall: from n/a through 4.1.0.

    Published: 8 Jan 2024
    5.3
    Medium

    CVE-2023-51508

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Database Cleaner: Clean, Optimize & Repair.This issue affects Database Cleaner: Clean, Optimize & Repair: from n/a through 0.9.8.

    Published: 8 Jan 2024
    7.6
    High

    CVE-2023-52201

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brian D. Goad pTypeConverter.This issue affects pTypeConverter: from n/a through 0.2.8.1.

    Published: 8 Jan 2024
    8.7
    High

    CVE-2024-0056

    Last Modified: 3 Jun 2025

    Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability

    Published: 8 Jan 2024
    9.1
    Critical

    CVE-2024-0057

    Last Modified: 3 Jun 2025

    NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability

    Published: 8 Jan 2024
    0
    Low

    CVE-2024-0395

    Last Modified: 10 Jan 2024

    NON Security Issue.

    Published: 8 Jan 2024
    5.9
    Medium

    CVE-2023-52203

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann cformsII allows Stored XSS.This issue affects cformsII: from n/a through 15.0.5.

    Published: 8 Jan 2024
    8.5
    High

    CVE-2023-52204

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Javik Randomize.This issue affects Randomize: from n/a through 1.4.3.

    Published: 8 Jan 2024
    7.7
    High

    CVE-2023-52206

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder.This issue affects Page Builder: Live Composer: from n/a through 1.5.25.

    Published: 8 Jan 2024
    7.1
    High

    CVE-2023-52213

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VideoWhisper Rate Star Review – AJAX Reviews for Content, with Star Ratings allows Reflected XSS.This issue affects Rate Star Review – AJAX Reviews for Content, with Star Ratings: from n/a through 1.5.1.

    Published: 8 Jan 2024
    4.3
    Medium

    CVE-2023-52216

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Yevhen Kotelnytskyi JS & CSS Script Optimizer.This issue affects JS & CSS Script Optimizer: from n/a through 0.3.3.

    Published: 8 Jan 2024
    9.6
    Critical

    CVE-2023-52200

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup.This issue affects ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup: n/a.

    Published: 8 Jan 2024
    9.1
    Critical

    CVE-2023-52205

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 SoundCloud Player with Playlist Free.This issue affects HTML5 SoundCloud Player with Playlist Free: from n/a through 2.8.0.

    Published: 8 Jan 2024
    9.1
    Critical

    CVE-2023-52207

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Playlist Free.This issue affects HTML5 MP3 Player with Playlist Free: from n/a through 3.0.0.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-6631

    Last Modified: 3 Jun 2025

    PowerSYSTEM Center versions 2020 Update 16 and prior contain a vulnerability that may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate privileges.

    Published: 8 Jan 2024
    8.8
    High

    CVE-2023-6532

    Last Modified: 18 Jun 2025

    The WP Blogs' Planetarium WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 8 Jan 2024
    7.5
    High

    CVE-2023-52190

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Swings Coupon Referral Program.This issue affects Coupon Referral Program: from n/a through 1.7.2.

    Published: 8 Jan 2024
    7.5
    High

    CVE-2023-6505

    Last Modified: 18 Jun 2025

    The Migrate WordPress Website & Backups WordPress plugin before 1.9.3 does not prevent directory listing in sensitive directories containing export files.

    Published: 8 Jan 2024
    8.8
    High

    CVE-2023-6845

    Last Modified: 9 Jan 2026

    The CommentTweets WordPress plugin through 0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

    Published: 8 Jan 2024
    7.5
    High

    CVE-2023-6750

    Last Modified: 21 Nov 2024

    The Clone WordPress plugin before 2.4.3 uses buffer files to store in-progress backup informations, which is stored at a publicly accessible, statically defined file path.

    Published: 8 Jan 2024
    4.8
    Medium

    CVE-2023-5911

    Last Modified: 18 Jun 2025

    The WP Custom Cursors | WordPress Cursor Plugin WordPress plugin through 3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 8 Jan 2024
    8.8
    High

    CVE-2023-6140

    Last Modified: 21 Nov 2024

    The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentarily uploading malicious PHP files disguised as ZIP archives, which may lead to remote code execution.

    Published: 8 Jan 2024
    8.8
    High

    CVE-2023-5235

    Last Modified: 11 Jun 2025

    The Ovic Responsive WPBakery WordPress plugin before 1.2.9 does not limit which options can be updated via some of its AJAX actions, which may allow attackers with a subscriber+ account to update blog options, such as 'users_can_register' and 'default_role'. It also unserializes user input in the process, which may lead to Object Injection attacks.

    Published: 8 Jan 2024
    5.4
    Medium

    CVE-2023-6141

    Last Modified: 18 Jun 2025

    The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Stored XSS attacks.

    Published: 8 Jan 2024
    8.8
    High

    CVE-2023-6528

    Last Modified: 3 Jun 2025

    The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.

    Published: 8 Jan 2024
    7.5
    High

    CVE-2023-6383

    Last Modified: 17 Apr 2025

    The Debug Log Manager WordPress plugin before 2.3.0 contains a Directory listing vulnerability was discovered, which allows you to download the debug log without authorization and gain access to sensitive data

    Published: 8 Jan 2024