CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2023-52129

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Michael Winkler teachPress.This issue affects teachPress: from n/a through 9.0.4.

    Published: 5 Jan 2024
    4.3
    Medium

    CVE-2023-52130

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliates Manager: from n/a through 2.9.31.

    Published: 5 Jan 2024
    4.3
    Medium

    CVE-2023-52136

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds – A Tweets Widget or X Feed Widget.This issue affects Custom Twitter Feeds – A Tweets Widget or X Feed Widget: from n/a through 2.1.2.

    Published: 5 Jan 2024
    4.3
    Medium

    CVE-2023-52145

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Marios Alexandrou Republish Old Posts.This issue affects Republish Old Posts: from n/a through 1.21.

    Published: 5 Jan 2024
    5.4
    Medium

    CVE-2023-52149

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Floating Button.This issue affects Floating Button: from n/a through 6.0.

    Published: 5 Jan 2024
    8.8
    High

    CVE-2023-52150

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Ovation S.R.L. Dynamic Content for Elementor.This issue affects Dynamic Content for Elementor: from n/a before 2.12.5.

    Published: 5 Jan 2024
    4.3
    Medium

    CVE-2023-52184

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: from n/a through 2.0.6.

    Published: 5 Jan 2024
    7.5
    High

    CVE-2023-51502

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.6.1.

    Published: 5 Jan 2024
    6.5
    Medium

    CVE-2023-52178

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MojofyWP WP Affiliate Disclosure allows Stored XSS.This issue affects WP Affiliate Disclosure: from n/a through 1.2.7.

    Published: 5 Jan 2024
    4.3
    Medium

    CVE-2023-6493

    Last Modified: 8 Apr 2026

    The Depicter Slider – Responsive Image Slider, Video Slider & Post Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.6. This is due to missing or incorrect nonce validation on the 'save' function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE-2023-51491 appears to be a duplicate of this issue.

    Published: 5 Jan 2024
    3.9
    Low

    CVE-2023-41782

    Last Modified: 28 Jan 2025

    There is a DLL hijacking vulnerability in ZTE ZXCLOUD iRAI, an attacker could place a fake DLL file in a specific directory and successfully exploit this vulnerability to execute malicious code.

    Published: 5 Jan 2024
    3.5
    Low

    CVE-2024-1979

    Last Modified: 15 Apr 2026

    A vulnerability was found in Quarkus. In certain conditions related to the CI process, git credentials could be inadvertently published, which could put the git repository at risk.

    Published: 5 Jan 2024
    5.9
    Medium

    CVE-2023-52323

    Last Modified: 3 Jun 2025

    PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.

    Published: 5 Jan 2024
    9.8
    Critical

    CVE-2020-13880

    Last Modified: 18 Jun 2025

    IrfanView B3D PlugIns before version 4.56 has a B3d.dll!+1cbf heap-based out-of-bounds write.

    Published: 5 Jan 2024
    9.8
    Critical

    CVE-2020-13878

    Last Modified: 17 Jun 2025

    IrfanView B3D PlugIns before version 4.56 has a B3d.dll!+27ef heap-based out-of-bounds write.

    Published: 5 Jan 2024
    9.8
    Critical

    CVE-2020-13879

    Last Modified: 17 Apr 2025

    IrfanView B3D PlugIns before version 4.56 has a B3d.dll!+214f heap-based out-of-bounds write.

    Published: 5 Jan 2024
    6.1
    Medium

    CVE-2022-36677

    Last Modified: 8 May 2025

    Obsidian Mind Map v1.1.0 allows attackers to execute arbitrary code via a crafted payload injected into an uploaded document.

    Published: 5 Jan 2024
    9.8
    Critical

    CVE-2024-22087

    Last Modified: 23 Jan 2026

    route in main.c in Pico HTTP Server in C through f3b69a6 has an sprintf stack-based buffer overflow via a long URI, leading to remote code execution.

    Published: 5 Jan 2024
    9.8
    Critical

    CVE-2023-50027

    Last Modified: 3 Jun 2025

    SQL Injection vulnerability in Buy Addons baproductzoommagnifier module for PrestaShop versions 1.0.16 and before, allows remote attackers to escalate privileges and gain sensitive information via BaproductzoommagnifierZoomModuleFrontController::run() method.

    Published: 5 Jan 2024
    7.5
    High

    CVE-2023-50991

    Last Modified: 13 Jun 2025

    Buffer Overflow vulnerability in Tenda i29 versions 1.0 V1.0.0.5 and 1.0 V1.0.0.2, allows remote attackers to cause a denial of service (DoS) via the pingIp parameter in the pingSet function.

    Published: 5 Jan 2024
    9.8
    Critical

    CVE-2023-51277

    Last Modified: 3 Jun 2025

    nbviewer-app (aka Jupyter Notebook Viewer) before 0.1.6 has the get-task-allow entitlement for release builds.

    Published: 5 Jan 2024
    6.1
    Medium

    CVE-2024-22075

    Last Modified: 5 Jun 2025

    Firefly III (aka firefly-iii) before 6.1.1 allows webhooks HTML Injection.

    Published: 5 Jan 2024
    9.8
    Critical

    CVE-2024-22086

    Last Modified: 18 Jun 2025

    handle_request in http.c in cherry through 4b877df has an sscanf stack-based buffer overflow via a long URI, leading to remote code execution.

    Published: 5 Jan 2024
    9.8
    Critical

    CVE-2024-22088

    Last Modified: 21 Nov 2024

    Lotos WebServer through 0.1.1 (commit 3eb36cc) has a use-after-free in buffer_avail() at buffer.h via a long URI, because realloc is mishandled.

    Published: 5 Jan 2024
    7.5
    High

    CVE-2024-0241

    Last Modified: 14 May 2026

    encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacker might cause a denial of service condition by sending an HTTP request with an extremely long "id" parameter.

    Published: 4 Jan 2024
    6.1
    Medium

    CVE-2024-22048

    Last Modified: 29 Nov 2025

    govuk_tech_docs versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability. Malicious JavaScript may be executed in the user's browser if a malicious search result is displayed on the search page.

    Published: 4 Jan 2024
    7.5
    High

    CVE-2024-22050

    Last Modified: 29 Nov 2025

    Path traversal in the static file service in Iodine less than 0.7.33 allows an unauthenticated, remote attacker to read files outside the public folder via malicious URLs.

    Published: 4 Jan 2024
    5.3
    Medium

    CVE-2024-22049

    Last Modified: 7 Jan 2026

    httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.

    Published: 4 Jan 2024
    6.1
    Medium

    CVE-2024-21636

    Last Modified: 17 Jun 2025

    view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. Versions prior to 3.9.0 and 2.83.0 have a cross-site scripting vulnerability that has the potential to impact anyone rendering a component directly from a controller with the view_component gem. Note that only components that define a `#call` method (i.e. instead of using a sidecar template) are affected. The return value of the `#call` method is not sanitized and can include user-defined content. In addition, the return value of the `#output_postamble` methodis not sanitized, which can also lead to cross-site scripting issues. Versions 3.9.0 and 2.83.0 have been released and fully mitigate both the `#call` and the `#output_postamble` vulnerabilities. As a workaround, sanitize the return value of `#call`.

    Published: 4 Jan 2024
    5.4
    Medium

    CVE-2023-6551

    Last Modified: 3 Jun 2025

    As a simple library, class.upload.php does not perform an in-depth check on uploaded files, allowing a stored XSS vulnerability when the default configuration is used. Developers must be aware of that fact and use extension whitelisting accompanied by forcing the server to always provide content-type based on the file extension. The README has been updated to include these guidelines.

    Published: 4 Jan 2024
    8.8
    High

    CVE-2024-21625

    Last Modified: 21 Nov 2024

    SideQuest is a place to get virtual reality applications for Oculus Quest. The SideQuest desktop application uses deep links with a custom protocol (`sidequest://`) to trigger actions in the application from its web contents. Because, prior to version 0.10.35, the deep link URLs were not sanitized properly in all cases, a one-click remote code execution can be achieved in cases when a device is connected, the user is presented with a malicious link and clicks it from within the application. As of version 0.10.35, the custom protocol links within the electron application are now being parsed and sanitized properly.

    Published: 4 Jan 2024
    6.9
    Medium

    CVE-2023-3726

    Last Modified: 24 Sept 2025

    OCSInventory allow stored email template with special characters that lead to a Stored cross-site Scripting.

    Published: 4 Jan 2024
    9.8
    Critical

    CVE-2023-50867

    Last Modified: 17 Jun 2025

    Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the signupAction.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 4 Jan 2024
    9.8
    Critical

    CVE-2023-50866

    Last Modified: 3 Jun 2025

    Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginAction.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 4 Jan 2024
    9.8
    Critical

    CVE-2023-50865

    Last Modified: 17 Jun 2025

    Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'city' parameter of the hotelSearch.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 4 Jan 2024
    9.8
    Critical

    CVE-2023-50864

    Last Modified: 17 Jun 2025

    Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelId' parameter of the hotelDetails.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 4 Jan 2024
    9.8
    Critical

    CVE-2023-50863

    Last Modified: 17 Jun 2025

    Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the generateReceipt.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 4 Jan 2024
    9.8
    Critical

    CVE-2023-50862

    Last Modified: 17 Jun 2025

    Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the booking.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 4 Jan 2024
    8.8
    High

    CVE-2023-50760

    Last Modified: 21 Nov 2024

    Online Notice Board System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'f' parameter of user/update_profile_pic.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

    Published: 4 Jan 2024
    9.8
    Critical

    CVE-2023-50753

    Last Modified: 3 Jun 2025

    Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parameter of the user/update_profile.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 4 Jan 2024
    9.8
    Critical

    CVE-2023-50752

    Last Modified: 21 Nov 2024

    Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'e' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 4 Jan 2024
    9.8
    Critical

    CVE-2023-50743

    Last Modified: 3 Jun 2025

    Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parameter of the registration.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 4 Jan 2024
    9.8
    Critical

    CVE-2023-49666

    Last Modified: 5 Dec 2025

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'custmer_details' parameter of the submit_material_list.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 4 Jan 2024
    9.8
    Critical

    CVE-2023-49665

    Last Modified: 17 Jun 2025

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'quantity[]' parameter of the submit_delivery_list.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 4 Jan 2024
    9.8
    Critical

    CVE-2023-49658

    Last Modified: 17 Jun 2025

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'bank_details' parameter of the party_submit.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 4 Jan 2024
    9.8
    Critical

    CVE-2023-49639

    Last Modified: 17 Jun 2025

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'customer_details' parameter of the buyer_invoice_submit.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 4 Jan 2024
    9.8
    Critical

    CVE-2023-49633

    Last Modified: 17 Jun 2025

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'buyer_address' parameter of the buyer_detail_submit.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 4 Jan 2024
    9.8
    Critical

    CVE-2023-49625

    Last Modified: 17 Jun 2025

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the partylist_edit_submit.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 4 Jan 2024
    9.8
    Critical

    CVE-2023-49624

    Last Modified: 17 Jun 2025

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cancelid' parameter of the material_bill.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 4 Jan 2024
    9.8
    Critical

    CVE-2023-49622

    Last Modified: 17 Jun 2025

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'itemnameid' parameter of the material_bill.php?action=itemRelation resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 4 Jan 2024