CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2023-52252

    Last Modified: 21 Nov 2024

    Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload endpoint.

    Published: 30 Dec 2023
    6.1
    Medium

    CVE-2023-52257

    Last Modified: 21 Nov 2024

    LogoBee 0.2 allows updates.php?id= XSS.

    Published: 30 Dec 2023
    9.8
    Critical

    CVE-2023-52262

    Last Modified: 21 Nov 2024

    outdoorbits little-backup-box (aka Little Backup Box) before f39f91c allows remote attackers to execute arbitrary code because the PHP extract function is used for untrusted input.

    Published: 30 Dec 2023
    6.1
    Medium

    CVE-2023-52263

    Last Modified: 21 Nov 2024

    Brave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect. This is related to browser/brave_content_browser_client.cc and browser/ui/webui/brave_web_ui_controller_factory.cc.

    Published: 30 Dec 2023
    6.1
    Medium

    CVE-2023-52264

    Last Modified: 21 Nov 2024

    The beesblog (aka Bees Blog) component before 1.6.2 for thirty bees allows Reflected XSS because controllers/front/post.php sharing_url is mishandled.

    Published: 30 Dec 2023
    5.4
    Medium

    CVE-2023-52265

    Last Modified: 17 Apr 2025

    IDURAR (aka idurar-erp-crm) through 2.0.1 allows stored XSS via a PATCH request with a crafted JSON email template in the /api/email/update data.

    Published: 30 Dec 2023
    7.5
    High

    CVE-2023-52267

    Last Modified: 21 Nov 2024

    ehttp 1.0.6 before 17405b9 has a simple_log.cpp _log out-of-bounds-read during error logging for long strings.

    Published: 30 Dec 2023
    —
    Unknown

    CVE-2023-7182

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 29 Dec 2023
    2.4
    Low

    CVE-2023-7171

    Last Modified: 21 Nov 2024

    A vulnerability was found in Novel-Plus up to 4.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file novel-admin/src/main/java/com/java2nb/novel/controller/FriendLinkController.java of the component Friendly Link Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The patch is named d6093d8182362422370d7eaf6c53afde9ee45215. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-249307.

    Published: 29 Dec 2023
    9
    Critical

    CVE-2023-52139

    Last Modified: 21 Nov 2024

    Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endpoints or Websocket APIs that are incorrectly specified as [kind](https://github.com/misskey-dev/misskey/blob/406b4bdbe79b5b0b68fcdcb3c4b6e419460a0258/packages/backend/src/server/api/endpoints.ts#L811) or [secure](https://github.com/misskey-dev/misskey/blob/406b4bdbe79b5b0b68fcdcb3c4b6e419460a0258/packages/backend/src/server/api/endpoints.ts#L805) without the user's permission and perform operations such as reading or adding non-public content. As a result, if the user who authenticated the application is an administrator, confidential information such as object storage secret keys and SMTP server passwords will be leaked, and general users can also create invitation codes without permission and leak non-public user information. This is patched in version [2023.12.1](https://github.com/misskey-dev/misskey/commit/c96bc36fedc804dc840ea791a9355d7df0748e64).

    Published: 29 Dec 2023
    7.7
    High

    CVE-2023-52137

    Last Modified: 21 Nov 2024

    The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets. The [`verify-changed-files`](https://github.com/tj-actions/verify-changed-files) workflow returns the list of files changed within a workflow execution. This could potentially allow filenames that contain special characters such as `;` which can be used by an attacker to take over the [GitHub Runner](https://docs.github.com/en/actions/using-github-hosted-runners/about-github-hosted-runners) if the output value is used in a raw fashion (thus being directly replaced before execution) inside a `run` block. By running custom commands, an attacker may be able to steal secrets such as `GITHUB_TOKEN` if triggered on other events than `pull_request`. This has been patched in versions [17](https://github.com/tj-actions/verify-changed-files/releases/tag/v17) and [17.0.0](https://github.com/tj-actions/verify-changed-files/releases/tag/v17.0.0) by enabling `safe_output` by default and returning filename paths escaping special characters for bash environments.

    Published: 29 Dec 2023
    5.3
    Medium

    CVE-2023-51663

    Last Modified: 17 Apr 2025

    Hail is an open-source, general-purpose, Python-based data analysis tool with additional data types and methods for working with genomic data. Hail relies on OpenID Connect (OIDC) email addresses from ID tokens to verify the validity of a user's domain, but because users have the ability to change their email address, they could create accounts and use resources in clusters that they should not have access to. For example, a user could create a Microsoft or Google account and then change their email to `[email protected]`. This account can then be used to create a Hail Batch account in Hail Batch clusters whose organization domain is `example.org`. The attacker is not able to access private data or impersonate another user, but they would have the ability to run jobs if Hail Batch billing projects are enabled and create Azure Tenants if they have Azure Active Directory Administrator access.

    Published: 29 Dec 2023
    7.8
    High

    CVE-2020-17163

    Last Modified: 5 Sept 2025

    Visual Studio Code Python Extension Remote Code Execution Vulnerability

    Published: 29 Dec 2023
    5.3
    Medium

    CVE-2023-51527

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Senol Sahin AI Power: Complete AI Pack – Powered by GPT-4.This issue affects AI Power: Complete AI Pack – Powered by GPT-4: from n/a through 1.8.2.

    Published: 29 Dec 2023
    5.3
    Medium

    CVE-2023-51688

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress.This issue affects eCommerce Product Catalog Plugin for WordPress: from n/a through 3.3.26.

    Published: 29 Dec 2023
    5.3
    Medium

    CVE-2023-51687

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode Product Catalog Simple.This issue affects Product Catalog Simple: from n/a through 1.7.6.

    Published: 29 Dec 2023
    4.1
    Medium

    CVE-2023-51517

    Last Modified: 28 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affects Calculated Fields Form: from n/a through 1.2.28.

    Published: 29 Dec 2023
    9.8
    Critical

    CVE-2023-4675

    Last Modified: 21 May 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GM Information Technologies MDO allows SQL Injection. This issue affects MDO: through 20231229.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Dec 2023
    —
    Unknown

    CVE-2023-4674

    Last Modified: 21 May 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yaztek Software Technologies and Computer Systems E-Commerce Software allows SQL Injection. This issue affects E-Commerce Software: through 20231229.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Dec 2023
    9.8
    Critical

    CVE-2023-4541

    Last Modified: 21 May 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ween Software Admin Panel allows SQL Injection. This issue affects Admin Panel: through 20231229.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Dec 2023
    8.8
    High

    CVE-2023-47804

    Last Modified: 13 Feb 2025

    Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. Links can be activated by clicks, or by automatic document events. The execution of such links must be subject to user approval. In the affected versions of OpenOffice, approval for certain links is not requested; when activated, such links could therefore result in arbitrary script execution. This is a corner case of CVE-2022-47502.

    Published: 29 Dec 2023
    4.7
    Medium

    CVE-2023-51675

    Last Modified: 28 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More.This issue affects Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More: from n/a through 6.9.18.

    Published: 29 Dec 2023
    9.9
    Critical

    CVE-2023-51410

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in WPVibes WP Mail Log.This issue affects WP Mail Log: from n/a through 1.1.2.

    Published: 29 Dec 2023
    10
    Critical

    CVE-2023-51411

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Shabti Kaplan Frontend Admin by DynamiApps.This issue affects Frontend Admin by DynamiApps: from n/a through 3.18.3.

    Published: 29 Dec 2023
    9
    Critical

    CVE-2023-51412

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Piotnet Piotnet Forms.This issue affects Piotnet Forms: from n/a through 1.0.25.

    Published: 29 Dec 2023
    9.9
    Critical

    CVE-2023-51417

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Joris van Montfort JVM Gutenberg Rich Text Icons.This issue affects JVM Gutenberg Rich Text Icons: from n/a through 1.2.3.

    Published: 29 Dec 2023
    10
    Critical

    CVE-2023-51419

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Bertha.Ai BERTHA AI. Your AI co-pilot for WordPress and Chrome.This issue affects BERTHA AI. Your AI co-pilot for WordPress and Chrome: from n/a through 1.11.10.7.

    Published: 29 Dec 2023
    9.9
    Critical

    CVE-2023-51421

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Soft8Soft LLC Verge3D Publishing and E-Commerce.This issue affects Verge3D Publishing and E-Commerce: from n/a through 4.5.2.

    Published: 29 Dec 2023
    10
    Critical

    CVE-2023-51468

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Jacques Malgrange Rencontre – Dating Site.This issue affects Rencontre – Dating Site: from n/a through 3.10.1.

    Published: 29 Dec 2023
    10
    Critical

    CVE-2023-51473

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Pixelemu TerraClassifieds – Simple Classifieds Plugin.This issue affects TerraClassifieds – Simple Classifieds Plugin: from n/a through 2.0.3.

    Published: 29 Dec 2023
    10
    Critical

    CVE-2023-51475

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in IOSS WP MLM SOFTWARE PLUGIN.This issue affects WP MLM SOFTWARE PLUGIN: from n/a through 4.0.

    Published: 29 Dec 2023
    9.6
    Critical

    CVE-2023-51414

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in EnvialoSimple EnvíaloSimple: Email Marketing y Newsletters.This issue affects EnvíaloSimple: Email Marketing y Newsletters: from n/a through 2.1.

    Published: 29 Dec 2023
    9.9
    Critical

    CVE-2023-51422

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition: from n/a through 3.05.0.

    Published: 29 Dec 2023
    9.9
    Critical

    CVE-2023-51470

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in Jacques Malgrange Rencontre – Dating Site.This issue affects Rencontre – Dating Site: from n/a through 3.11.1.

    Published: 29 Dec 2023
    10
    Critical

    CVE-2023-51505

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in realmag777 Active Products Tables for WooCommerce. Professional products tables for WooCommerce store.This issue affects Active Products Tables for WooCommerce. Professional products tables for WooCommerce store : from n/a through 1.0.6.

    Published: 29 Dec 2023
    9.6
    Critical

    CVE-2023-51545

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in ThemeHigh Job Manager & Career – Manage job board listings, and recruitments.This issue affects Job Manager & Career – Manage job board listings, and recruitments: from n/a through 1.4.4.

    Published: 29 Dec 2023
    7.1
    High

    CVE-2023-7114

    Last Modified: 21 Nov 2024

    Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.

    Published: 29 Dec 2023
    3.7
    Low

    CVE-2023-7113

    Last Modified: 21 Nov 2024

    Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web client.

    Published: 29 Dec 2023
    4.9
    Medium

    CVE-2023-51676

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Leevio Happy Addons for Elementor.This issue affects Happy Addons for Elementor: from n/a through 3.9.1.1.

    Published: 29 Dec 2023
    5.4
    Medium

    CVE-2023-50878

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in InspireUI MStore API.This issue affects MStore API: from n/a through 4.10.1.

    Published: 29 Dec 2023
    4.3
    Medium

    CVE-2023-50902

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WPExpertsio New User Approve.This issue affects New User Approve: from n/a through 2.5.1.

    Published: 29 Dec 2023
    4.3
    Medium

    CVE-2023-51354

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WebbaPlugins Appointment & Event Booking Calendar Plugin – Webba Booking.This issue affects Appointment & Event Booking Calendar Plugin – Webba Booking: from n/a through 4.5.33.

    Published: 29 Dec 2023
    5.4
    Medium

    CVE-2023-51358

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Bright Plugins Block IPs for Gravity Forms.This issue affects Block IPs for Gravity Forms: from n/a through 1.0.1.

    Published: 29 Dec 2023
    5.4
    Medium

    CVE-2023-51378

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Rise Themes Rise Blocks – A Complete Gutenberg Page Builder.This issue affects Rise Blocks – A Complete Gutenberg Page Builder: from n/a through 3.1.

    Published: 29 Dec 2023
    4.3
    Medium

    CVE-2023-51402

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Brain Storm Force Ultimate Addons for WPBakery Page Builder.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through 3.19.17.

    Published: 29 Dec 2023
    8.5
    High

    CVE-2023-7080

    Last Modified: 21 Nov 2024

    The V8 inspector intentionally allows arbitrary code execution within the Workers sandbox for debugging. wrangler dev would previously start an inspector server listening on all network interfaces. This would allow an attacker on the local network to connect to the inspector and run arbitrary code. Additionally, the inspector server did not validate Origin/Host headers, granting an attacker that can trick any user on the local network into opening a malicious website the ability to run code. If wrangler dev --remote was being used, an attacker could access production resources if they were bound to the worker. This issue was fixed in [email protected] and [email protected]. Whilst wrangler dev's inspector server listens on local interfaces by default as of [email protected], an SSRF vulnerability in miniflare https://github.com/cloudflare/workers-sdk/security/advisories/GHSA-fwvg-2739-22v7  (CVE-2023-7078) allowed access from the local network until [email protected]. [email protected] and [email protected] introduced validation for the Origin/Host headers.

    Published: 29 Dec 2023
    6.4
    Medium

    CVE-2023-7079

    Last Modified: 21 Nov 2024

    Sending specially crafted HTTP requests and inspector messages to Wrangler's dev server could result in any file on the user's computer being accessible over the local network. An attacker that could trick any user on the local network into opening a malicious website could also read any file.

    Published: 29 Dec 2023
    7.5
    High

    CVE-2023-7078

    Last Modified: 21 Nov 2024

    Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Miniflare was configured to listen on external network interfaces (as was the default in wrangler until 3.19.0), an attacker on the local network could access other local servers.

    Published: 29 Dec 2023
    6.1
    Medium

    CVE-2023-44089

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). It was possible to execute malicious JS code on Visual Consoles. This issue affects Pandora FMS: from 700 through 774.

    Published: 29 Dec 2023
    5.9
    Medium

    CVE-2023-44088

    Last Modified: 17 Apr 2025

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to be executed using any account with low privileges. This issue affects Pandora FMS: from 700 through 774.

    Published: 29 Dec 2023