CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2024-0228

    Last Modified: 9 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is a duplicate of CVE-2024-0193.

    Published: 3 Jan 2024
    6.1
    Medium

    CVE-2024-21910

    Last Modified: 28 Nov 2025

    TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing user's browser.

    Published: 3 Jan 2024
    7.5
    High

    CVE-2024-21909

    Last Modified: 28 Nov 2025

    PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of service vulnerability. An attacker may trigger the denial of service condition by providing crafted data to the DecodeFromBytes or other decoding mechanisms in PeterO.Cbor. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition.

    Published: 3 Jan 2024
    6.1
    Medium

    CVE-2024-21908

    Last Modified: 28 Nov 2025

    TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser.

    Published: 3 Jan 2024
    6.5
    Medium

    CVE-2023-46738

    Last Modified: 21 Nov 2024

    CubeFS is an open-source cloud-native file storage system. A security vulnerability was found in CubeFS HandlerNode in versions prior to 3.3.1 that could allow authenticated users to send maliciously-crafted requests that would crash the ObjectNode and deny other users from using it. The root cause was improper handling of incoming HTTP requests that could allow an attacker to control the ammount of memory that the ObjectNode would allocate. A malicious request could make the ObjectNode allocate more memory that the machine had available, and the attacker could exhaust memory by way of a single malicious request. An attacker would need to be authenticated in order to invoke the vulnerable code with their malicious request and have permissions to delete objects. In addition, the attacker would need to know the names of existing buckets of the CubeFS deployment - otherwise the request would be rejected before it reached the vulnerable code. As such, the most likely attacker is an inside user or an attacker that has breached the account of an existing user in the cluster. The issue has been patched in v3.3.1. There is no other mitigation besides upgrading.

    Published: 3 Jan 2024
    6.5
    Medium

    CVE-2023-30617

    Last Modified: 16 Jun 2025

    Kruise provides automated management of large-scale applications on Kubernetes. Starting in version 0.8.0 and prior to versions 1.3.1, 1.4.1, and 1.5.2, an attacker who has gained root privilege of the node that kruise-daemon run can leverage the kruise-daemon pod to list all secrets in the entire cluster. After that, the attacker can leverage the "captured" secrets (e.g. the kruise-manager service account token) to gain extra privileges such as pod modification. Versions 1.3.1, 1.4.1, and 1.5.2 fix this issue. A workaround is available. For users that do not require imagepulljob functions, they can modify kruise-daemon-role to drop the cluster level secret get/list privilege.

    Published: 3 Jan 2024
    7.5
    High

    CVE-2024-21907

    Last Modified: 28 Nov 2025

    Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition.

    Published: 3 Jan 2024
    9.8
    Critical

    CVE-2023-51784

    Last Modified: 16 May 2025

    Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.10.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/9329

    Published: 3 Jan 2024
    7.5
    High

    CVE-2023-51785

    Last Modified: 13 Feb 2025

    Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a arbitrary file read attack using mysql driver. Users are advised to upgrade to Apache InLong's 1.10.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/9331

    Published: 3 Jan 2024
    5.4
    Medium

    CVE-2024-0201

    Last Modified: 8 Apr 2026

    The Product Expiry for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_settings' function in versions up to, and including, 2.5. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update plugin settings. CVE-2023-52179 appears to be a duplicate of this issue.

    Published: 3 Jan 2024
    6.1
    Medium

    CVE-2023-6621

    Last Modified: 18 Jun 2025

    The POST SMTP WordPress plugin before 2.8.7 does not sanitise and escape the msg parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 3 Jan 2024
    5.3
    Medium

    CVE-2023-6984

    Last Modified: 8 Apr 2026

    The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.13. This is due to missing or incorrect nonce validation in the powerpack-lite-for-elementor/classes/class-pp-admin-settings.php file. This makes it possible for unauthenticated attackers to modify and reset plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 3 Jan 2024
    6.4
    Medium

    CVE-2023-6747

    Last Modified: 8 Apr 2026

    The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attributes in all versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping. This makes it possible for contributors and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 3 Jan 2024
    4.3
    Medium

    CVE-2023-7068

    Last Modified: 8 Apr 2026

    The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on theprint_packinglist action in all versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to export orders which can contain sensitive information.

    Published: 3 Jan 2024
    9.6
    Critical

    CVE-2023-52314

    Last Modified: 21 Nov 2024

    PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. This resulted in the ability to execute arbitrary commands on the operating system.

    Published: 3 Jan 2024
    4.7
    Medium

    CVE-2023-52313

    Last Modified: 17 Jun 2025

    FPE in paddle.argmin and paddle.argmax in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

    Published: 3 Jan 2024
    4.7
    Medium

    CVE-2023-52312

    Last Modified: 3 Jun 2025

    Nullptr dereference in paddle.crop in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

    Published: 3 Jan 2024
    9.6
    Critical

    CVE-2023-52311

    Last Modified: 17 Jun 2025

    PaddlePaddle before 2.6.0 has a command injection in _wget_download. This resulted in the ability to execute arbitrary commands on the operating system.

    Published: 3 Jan 2024
    9.6
    Critical

    CVE-2023-52310

    Last Modified: 17 Apr 2025

    PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute arbitrary commands on the operating system.

    Published: 3 Jan 2024
    8.2
    High

    CVE-2023-52309

    Last Modified: 21 Nov 2024

    Heap buffer overflow in paddle.repeat_interleave in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, information disclosure, or more damage is possible.

    Published: 3 Jan 2024
    4.7
    Medium

    CVE-2023-52308

    Last Modified: 9 May 2025

    FPE in paddle.amin in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

    Published: 3 Jan 2024
    8.2
    High

    CVE-2023-52307

    Last Modified: 16 Jun 2025

    Stack overflow in paddle.linalg.lu_unpack in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage.

    Published: 3 Jan 2024
    4.7
    Medium

    CVE-2023-52306

    Last Modified: 3 Jun 2025

    FPE in paddle.lerp in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

    Published: 3 Jan 2024
    4.7
    Medium

    CVE-2023-52305

    Last Modified: 3 Jun 2025

    FPE in paddle.topk in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

    Published: 3 Jan 2024
    8.2
    High

    CVE-2023-52304

    Last Modified: 17 Jun 2025

    Stack overflow in paddle.searchsorted in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage.

    Published: 3 Jan 2024
    4.7
    Medium

    CVE-2023-52303

    Last Modified: 17 Jun 2025

    Nullptr in paddle.put_along_axis in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

    Published: 3 Jan 2024
    4.7
    Medium

    CVE-2023-52302

    Last Modified: 21 Nov 2024

    Nullptr in paddle.nextafter in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

    Published: 3 Jan 2024
    4.7
    Medium

    CVE-2023-38678

    Last Modified: 3 Jun 2025

    OOB access in paddle.mode in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

    Published: 3 Jan 2024
    4.7
    Medium

    CVE-2023-38677

    Last Modified: 17 Apr 2025

    FPE in paddle.linalg.eig in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

    Published: 3 Jan 2024
    4.7
    Medium

    CVE-2023-38676

    Last Modified: 21 Nov 2024

    Nullptr in paddle.dot in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

    Published: 3 Jan 2024
    4.7
    Medium

    CVE-2023-38675

    Last Modified: 21 May 2025

    FPE in paddle.linalg.matrix_rank in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

    Published: 3 Jan 2024
    4.7
    Medium

    CVE-2023-38674

    Last Modified: 6 Jun 2025

    FPE in paddle.nanmedian in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

    Published: 3 Jan 2024
    6.4
    Medium

    CVE-2023-6986

    Last Modified: 8 Apr 2026

    The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's embed_oembed_html shortcode in all versions up to 3.9.5 (exclusive) due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 3 Jan 2024
    6.1
    Medium

    CVE-2023-6981

    Last Modified: 8 Apr 2026

    The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to SQL Injection via the 'group_id' parameter in all versions up to, and including, 6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This can leveraged to achieve Reflected Cross-site Scripting.

    Published: 3 Jan 2024
    4.3
    Medium

    CVE-2023-6980

    Last Modified: 8 Apr 2026

    The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5. This is due to missing or incorrect nonce validation on the 'delete' action of the wp-sms-subscribers page. This makes it possible for unauthenticated attackers to delete subscribers via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 3 Jan 2024
    8.6
    High

    CVE-2023-6600

    Last Modified: 8 Apr 2026

    The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting due to a missing capability check on the update_settings() function hooked via admin_init in all versions up to, and including, 5.7.9. This makes it possible for unauthenticated attackers to update the plugin's settings which can be used to inject Cross-Site Scripting payloads and delete entire directories. PLease note there were several attempted patched, and we consider 5.7.10 to be the most sufficiently patched.

    Published: 3 Jan 2024
    6.4
    Medium

    CVE-2023-6524

    Last Modified: 8 Apr 2026

    The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the map title parameter in all versions up to and including 2.88.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 3 Jan 2024
    7.2
    High

    CVE-2023-7027

    Last Modified: 8 Apr 2026

    The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘device’ header in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 3 Jan 2024
    6.1
    Medium

    CVE-2023-6629

    Last Modified: 8 Apr 2026

    The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ parameter in all versions up to, and including, 2.8.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE-2023-6621 appears to be a duplicate of this issue. CVE-2024-29128 appears to be a duplicate of this issue.

    Published: 3 Jan 2024
    8.8
    High

    CVE-2023-45722

    Last Modified: 3 Jun 2025

    HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory.  The product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. Potential exploits can completely disrupt or take over the application.

    Published: 3 Jan 2024
    8.2
    High

    CVE-2023-45724

    Last Modified: 18 Jun 2025

    HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file without requiring user authentication.

    Published: 3 Jan 2024
    7.6
    High

    CVE-2023-45723

    Last Modified: 18 Jun 2025

    HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability.  Certain endpoints permit users to manipulate the path (including the file name) where these files are stored on the server.

    Published: 3 Jan 2024
    7.6
    High

    CVE-2023-50341

    Last Modified: 18 Jun 2025

    HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated and accessible web pages, reflects a "Missing Access Control" vulnerability, which could lead to inadvertent exposure of sensitive information and/or exposing a vulnerable endpoint.

    Published: 3 Jan 2024
    7.1
    High

    CVE-2023-50342

    Last Modified: 3 Jun 2025

    HCL DRYiCE MyXalytics is impacted by an Insecure Direct Object Reference (IDOR) vulnerability.  A user can obtain certain details about another user as a result of improper access control.

    Published: 3 Jan 2024
    8.3
    High

    CVE-2023-50343

    Last Modified: 18 Jun 2025

    HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints are accessible to Customer Admin Users that can allow access to sensitive information about other users.

    Published: 3 Jan 2024
    5.4
    Medium

    CVE-2023-50344

    Last Modified: 18 Jun 2025

    HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthenticated user can download certain files.

    Published: 3 Jan 2024
    4.3
    Medium

    CVE-2023-41783

    Last Modified: 17 Apr 2025

    There is a command injection vulnerability of ZTE's ZXCLOUD iRAI. Due to the  program  failed to adequately validate the user's input, an attacker could exploit this vulnerability  to escalate local privileges.

    Published: 3 Jan 2024
    3.7
    Low

    CVE-2023-50345

    Last Modified: 3 Jun 2025

    HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to malicious sites, potentially leading to phishing attacks or other security threats.

    Published: 3 Jan 2024
    3.1
    Low

    CVE-2023-50346

    Last Modified: 18 Jun 2025

    HCL DRYiCE MyXalytics is impacted by an information disclosure vulnerability. Certain endpoints within the application disclose detailed file information.

    Published: 3 Jan 2024
    6.7
    Medium

    CVE-2023-41776

    Last Modified: 16 Jun 2025

    There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to escalate local privileges.

    Published: 3 Jan 2024