CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-25095

    Last Modified: 2 Feb 2026

    The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server.

    Published: 8 Jan 2024
    7.2
    High

    CVE-2023-5957

    Last Modified: 18 Jun 2025

    The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image files uploaded in the settings, allowing high privileged user to upload arbitrary files to the web server, triggering an RCE vulnerability by uploading a web shell.

    Published: 8 Jan 2024
    6.5
    Medium

    CVE-2023-6139

    Last Modified: 3 Jun 2025

    The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Denial of Service attacks.

    Published: 8 Jan 2024
    6.1
    Medium

    CVE-2023-6627

    Last Modified: 18 Jun 2025

    The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, which attackers can abuse to store malicious HTML/Javascript on the site.

    Published: 8 Jan 2024
    7.5
    High

    CVE-2023-6042

    Last Modified: 3 Jun 2025

    Any unauthenticated user may send e-mail from the site with any title or content to the admin

    Published: 8 Jan 2024
    6.1
    Medium

    CVE-2023-6161

    Last Modified: 17 Jun 2025

    The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 8 Jan 2024
    6.1
    Medium

    CVE-2023-6555

    Last Modified: 18 Jun 2025

    The Email Subscription Popup WordPress plugin before 1.2.20 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 8 Jan 2024
    6.1
    Medium

    CVE-2023-6529

    Last Modified: 18 Jun 2025

    The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Stored XSS, as previous versions have such vulnerabilities.

    Published: 8 Jan 2024
    5.3
    Medium

    CVE-2023-52208

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Constant Contact Constant Contact Forms.This issue affects Constant Contact Forms: from n/a through 2.4.2.

    Published: 8 Jan 2024
    4.3
    Medium

    CVE-2023-52222

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.2.2.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2022-3328

    Last Modified: 3 Jun 2025

    Race condition in snap-confine's must_mkdir_and_open_with_perms()

    Published: 8 Jan 2024
    9.3
    Critical

    CVE-2023-52215

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UkrSolution Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce.This issue affects Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce: from n/a through 1.5.1.

    Published: 8 Jan 2024
    10
    Critical

    CVE-2023-52218

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in Anton Bond Woocommerce Tranzila Payment Gateway.This issue affects Woocommerce Tranzila Payment Gateway: from n/a through 1.0.8.

    Published: 8 Jan 2024
    9.9
    Critical

    CVE-2023-52219

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in Gecka Gecka Terms Thumbnails.This issue affects Gecka Terms Thumbnails: from n/a through 1.1.

    Published: 8 Jan 2024
    10
    Critical

    CVE-2023-52225

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in Tagbox Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics.This issue affects Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics: from n/a through 3.1.

    Published: 8 Jan 2024
    6.5
    Medium

    CVE-2024-21744

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mapster Technology Inc. Mapster WP Maps allows Stored XSS.This issue affects Mapster WP Maps: from n/a through 1.2.38.

    Published: 8 Jan 2024
    6.5
    Medium

    CVE-2024-21745

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Laybuy Laybuy Payment Extension for WooCommerce allows Stored XSS.This issue affects Laybuy Payment Extension for WooCommerce: from n/a through 5.3.9.

    Published: 8 Jan 2024
    7.6
    High

    CVE-2024-21747

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting.This issue affects WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting: from n/a through 1.12.8.

    Published: 8 Jan 2024
    10
    Critical

    CVE-2024-21650

    Last Modified: 17 Jun 2025

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code execution (RCE) attack through its user registration feature. This issue allows an attacker to execute arbitrary code by crafting malicious payloads in the "first name" or "last name" fields during user registration. This impacts all installations that have user registration enabled for guests. This vulnerability has been patched in XWiki 14.10.17, 15.5.3 and 15.8 RC1.

    Published: 8 Jan 2024
    7
    High

    CVE-2023-32650

    Last Modified: 4 Nov 2025

    An integer overflow vulnerability exists in the FST_BL_GEOM parsing maxhandle functionality of GTKWave 3.3.115, when compiled as a 32-bit binary. A specially crafted .fst file can lead to memory corruption. A victim would need to open a malicious file to trigger this vulnerability.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-35704

    Last Modified: 4 Nov 2025

    Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the fstReaderVarint32WithSkip function.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-35703

    Last Modified: 4 Nov 2025

    Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the fstReaderVarint64 function.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-35702

    Last Modified: 4 Nov 2025

    Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the fstReaderVarint32 function.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-35958

    Last Modified: 4 Nov 2025

    Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A specially-crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the copy function `fstFread`.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-35957

    Last Modified: 4 Nov 2025

    Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A specially-crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the decompression function `uncompress`.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-35956

    Last Modified: 4 Nov 2025

    Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A specially-crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the decompression function `fastlz_decompress`.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-35955

    Last Modified: 4 Nov 2025

    Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A specially-crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the decompression function `LZ4_decompress_safe_partial`.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-35964

    Last Modified: 4 Nov 2025

    Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns decompression in the `vcd2lxt` utility.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-35963

    Last Modified: 4 Nov 2025

    Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns decompression in the `vcd2lxt2` utility.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-35962

    Last Modified: 4 Nov 2025

    Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns decompression in the `vcd2vzt` utility.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-35961

    Last Modified: 4 Nov 2025

    Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns decompression in `vcd_recorder_main`.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-35960

    Last Modified: 4 Nov 2025

    Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns legacy decompression in `vcd_main`.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-35959

    Last Modified: 4 Nov 2025

    Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns `.ghw` decompression.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-35970

    Last Modified: 4 Nov 2025

    Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 chain_table parsing functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the chain_table of the `FST_BL_VCDATA_DYN_ALIAS2` section type.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-35969

    Last Modified: 4 Nov 2025

    Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 chain_table parsing functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the chain_table of `FST_BL_VCDATA` and `FST_BL_VCDATA_DYN_ALIAS` section types.

    Published: 8 Jan 2024
    7
    High

    CVE-2023-35992

    Last Modified: 4 Nov 2025

    An integer overflow vulnerability exists in the FST fstReaderIterBlocks2 vesc allocation functionality of GTKWave 3.3.115, when compiled as a 32-bit binary. A specially crafted .fst file can lead to memory corruption. A victim would need to open a malicious file to trigger this vulnerability.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-35997

    Last Modified: 4 Nov 2025

    Multiple improper array index validation vulnerabilities exist in the fstReaderIterBlocks2 tdelta functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the tdelta indexing when signal_lens is 2 or more.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-35996

    Last Modified: 4 Nov 2025

    Multiple improper array index validation vulnerabilities exist in the fstReaderIterBlocks2 tdelta functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the tdelta indexing when signal_lens is 0.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-35995

    Last Modified: 4 Nov 2025

    Multiple improper array index validation vulnerabilities exist in the fstReaderIterBlocks2 tdelta functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the tdelta indexing when signal_lens is 1.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-35994

    Last Modified: 4 Nov 2025

    Multiple improper array index validation vulnerabilities exist in the fstReaderIterBlocks2 tdelta functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the tdelta initialization part.

    Published: 8 Jan 2024
    7
    High

    CVE-2023-35128

    Last Modified: 4 Nov 2025

    An integer overflow vulnerability exists in the fstReaderIterBlocks2 time_table tsec_nitems functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to memory corruption. A victim would need to open a malicious file to trigger this vulnerability.

    Published: 8 Jan 2024
    7
    High

    CVE-2023-36747

    Last Modified: 4 Nov 2025

    Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 fstWritex len functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to memory corruption. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the handling of `len` in `fstWritex` when `beg_time` does not match the start of the time table.

    Published: 8 Jan 2024
    7
    High

    CVE-2023-36746

    Last Modified: 4 Nov 2025

    Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 fstWritex len functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to memory corruption. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the handling of `len` in `fstWritex` when parsing the time table.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-36864

    Last Modified: 4 Nov 2025

    An integer overflow vulnerability exists in the fstReaderIterBlocks2 temp_signal_value_buf allocation functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-36916

    Last Modified: 4 Nov 2025

    Multiple integer overflow vulnerabilities exist in the FST fstReaderIterBlocks2 chain_table allocation functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the allocation of the `chain_table_lengths` array.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-36915

    Last Modified: 4 Nov 2025

    Multiple integer overflow vulnerabilities exist in the FST fstReaderIterBlocks2 chain_table allocation functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the allocation of the `chain_table` array.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-34087

    Last Modified: 4 Nov 2025

    An improper array index validation vulnerability exists in the EVCD var len parsing functionality of GTKWave 3.3.115. A specially crafted .evcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-37420

    Last Modified: 4 Nov 2025

    Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the vcd2lxt conversion utility.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-37419

    Last Modified: 4 Nov 2025

    Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the vcd2lxt2 conversion utility.

    Published: 8 Jan 2024
    7.8
    High

    CVE-2023-37418

    Last Modified: 4 Nov 2025

    Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the vcd2vzt conversion utility.

    Published: 8 Jan 2024