CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2023-51080

    Last Modified: 12 Sept 2025

    The NumberUtil.toBigDecimal method in hutool-core v5.8.23 was discovered to contain a stack overflow.

    Published: 27 Dec 2023
    9.8
    Critical

    CVE-2023-51084

    Last Modified: 26 Aug 2025

    hyavijava v6.0.07.1 was discovered to contain a stack overflow via the ResultConverter.convert2Xml method.

    Published: 27 Dec 2023
    9.8
    Critical

    CVE-2023-43955

    Last Modified: 21 Nov 2024

    The com.phlox.tvwebbrowser TV Bro application through 2.0.0 for Android mishandles external intents through WebView. This allows attackers to execute arbitrary code, create arbitrary files. and perform arbitrary downloads via JavaScript that uses takeBlobDownloadData.

    Published: 27 Dec 2023
    9.8
    Critical

    CVE-2023-5991

    Last Modified: 21 Nov 2024

    The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server

    Published: 26 Dec 2023
    4.8
    Medium

    CVE-2023-5980

    Last Modified: 17 Apr 2025

    The BSK Forms Blacklist WordPress plugin before 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 26 Dec 2023
    7.5
    High

    CVE-2023-6114

    Last Modified: 21 Nov 2024

    The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup-pro/tmp` directory in the Pro version), which temporarily stores files containing sensitive data. When directory listing is enabled in the web server, this allows unauthenticated attackers to discover and access these sensitive files, which include a full database dump and a zip archive of the site.

    Published: 26 Dec 2023
    5.3
    Medium

    CVE-2023-6155

    Last Modified: 21 Nov 2024

    The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticated attacker to perform a search for users of the system, ultimately leaking user email addresses.

    Published: 26 Dec 2023
    7.5
    High

    CVE-2023-6250

    Last Modified: 21 Nov 2024

    The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthenticated users via a meta tag

    Published: 26 Dec 2023
    7.2
    High

    CVE-2023-5939

    Last Modified: 21 Nov 2024

    The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 loads the contents of the import file in an unsafe manner, leading to remote code execution by privileged users.

    Published: 26 Dec 2023
    6.5
    Medium

    CVE-2023-5672

    Last Modified: 21 Nov 2024

    The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file path parameters when attaching files to emails, leading to local file inclusion, and allowing an attacker to leak the contents of arbitrary files.

    Published: 26 Dec 2023
    7.6
    High

    CVE-2023-5644

    Last Modified: 21 Nov 2024

    The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view and delete data that should only be accessible to Admin users.

    Published: 26 Dec 2023
    7.5
    High

    CVE-2023-5203

    Last Modified: 21 Nov 2024

    The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query parameters before using them in an SQL query, allowing unauthenticated attackers to extract sensitive data from the database via blind time based SQL injection techniques, or in some cases an error/union based technique.

    Published: 26 Dec 2023
    8.8
    High

    CVE-2023-5645

    Last Modified: 21 Nov 2024

    The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Contributor.

    Published: 26 Dec 2023
    6.1
    Medium

    CVE-2023-6268

    Last Modified: 21 Nov 2024

    The JSON Content Importer WordPress plugin before 1.5.4 does not sanitise and escape the tab parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 26 Dec 2023
    8.8
    High

    CVE-2023-5673

    Last Modified: 21 Nov 2024

    The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file extensions uploading files to attach to emails, allowing attackers to upload PHP files, leading to remote code execution.

    Published: 26 Dec 2023
    8.8
    High

    CVE-2023-5674

    Last Modified: 21 Nov 2024

    The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Contributor.

    Published: 26 Dec 2023
    6.1
    Medium

    CVE-2023-6166

    Last Modified: 21 Nov 2024

    The Quiz Maker WordPress plugin before 6.4.9.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

    Published: 26 Dec 2023
    8.8
    High

    CVE-2023-5931

    Last Modified: 21 Nov 2024

    The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 does not validate files to be uploaded, which could allow attackers with a low-privilege account (e.g. subscribers) to upload arbitrary files such as PHP on the server

    Published: 26 Dec 2023
    3.5
    Low

    CVE-2015-10127

    Last Modified: 21 Nov 2024

    A vulnerability was found in PlusCaptcha Plugin up to 2.0.6 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 2.0.14 is able to address this issue. The patch is identified as 1274afc635170daafd38306487b6bb8a01f78ecd. It is recommended to upgrade the affected component. VDB-248954 is the identifier assigned to this vulnerability.

    Published: 26 Dec 2023
    3.5
    Low

    CVE-2014-125109

    Last Modified: 21 Nov 2024

    A vulnerability was found in BestWebSoft Portfolio Plugin up to 2.27. It has been declared as problematic. This vulnerability affects the function bws_add_menu_render of the file bws_menu/bws_menu.php. The manipulation of the argument bwsmn_form_email leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 2.28 is able to address this issue. The name of the patch is d2ede580474665af56ff262a05783fbabe4529b8. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-248956.

    Published: 26 Dec 2023
    9.8
    Critical

    CVE-2023-51467

    Last Modified: 21 Nov 2024

    The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code

    Published: 26 Dec 2023
    7.5
    High

    CVE-2023-50968

    Last Modified: 13 Feb 2025

    Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. The same uri can be operated to realize a SSRF attack also without authorizations. Users are recommended to upgrade to version 18.12.11, which fixes this issue.

    Published: 26 Dec 2023
    4.3
    Medium

    CVE-2012-10017

    Last Modified: 21 Nov 2024

    A vulnerability was found in BestWebSoft Portfolio Plugin up to 2.04 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 2.06 is able to address this issue. The patch is named 68af950330c3202a706f0ae9bbb52ceaa17dda9d. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-248955.

    Published: 26 Dec 2023
    7.8
    High

    CVE-2023-5180

    Last Modified: 21 Nov 2024

    An issue was discovered in Open Design Alliance Drawings SDK before 2024.12. A corrupted value of number of sectors used by the Fat structure in a crafted DGN file leads to an out-of-bounds write. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 26 Dec 2023
    6.5
    Medium

    CVE-2023-51363

    Last Modified: 21 Nov 2024

    VR-S1000 firmware Ver. 2.37 and earlier allows a network-adjacent unauthenticated attacker who can access the product's web management page to obtain sensitive information.

    Published: 26 Dec 2023
    4.6
    Medium

    CVE-2023-46711

    Last Modified: 21 Nov 2024

    VR-S1000 firmware Ver. 2.37 and earlier uses a hard-coded cryptographic key which may allow an attacker to analyze the password of a specific product user.

    Published: 26 Dec 2023
    7.8
    High

    CVE-2023-46681

    Last Modified: 21 Nov 2024

    Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in VR-S1000 firmware Ver. 2.37 and earlier allows an authenticated attacker who can access to the product's command line interface to execute an arbitrary command.

    Published: 26 Dec 2023
    6.8
    Medium

    CVE-2023-45741

    Last Modified: 21 Nov 2024

    VR-S1000 firmware Ver. 2.37 and earlier allows an attacker with access to the product's web management page to execute arbitrary OS commands.

    Published: 26 Dec 2023
    5.4
    Medium

    CVE-2023-42436

    Last Modified: 21 Nov 2024

    Stored cross-site scripting vulnerability exists in the presentation feature of GROWI versions prior to v3.4.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.

    Published: 26 Dec 2023
    6.5
    Medium

    CVE-2023-50332

    Last Modified: 21 Nov 2024

    Improper authorization vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v6.0.6. If this vulnerability is exploited, a user may delete or suspend its own account without the user's intention.

    Published: 26 Dec 2023
    6.5
    Medium

    CVE-2023-50294

    Last Modified: 21 Nov 2024

    The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As a result, the Secret access key for external service may be obtained by an attacker who can access the App Settings page.

    Published: 26 Dec 2023
    5.4
    Medium

    CVE-2023-50175

    Last Modified: 23 Apr 2025

    Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page, the Markdown Settings (/admin/markdown) page, and the Customize (/admin/customize) page of GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.

    Published: 26 Dec 2023
    5.4
    Medium

    CVE-2023-49807

    Last Modified: 21 Nov 2024

    Stored cross-site scripting vulnerability when processing the MathJax exists in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.

    Published: 26 Dec 2023
    5.4
    Medium

    CVE-2023-49779

    Last Modified: 21 Nov 2024

    Stored cross-site scripting vulnerability exists in the anchor tag of GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.

    Published: 26 Dec 2023
    5.4
    Medium

    CVE-2023-49598

    Last Modified: 21 Nov 2024

    Stored cross-site scripting vulnerability exists in the event handlers of the pre tags in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.

    Published: 26 Dec 2023
    5.4
    Medium

    CVE-2023-49119

    Last Modified: 27 Nov 2024

    Stored cross-site scripting vulnerability via the img tags exists in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.

    Published: 26 Dec 2023
    5.4
    Medium

    CVE-2023-47215

    Last Modified: 21 Nov 2024

    Stored cross-site scripting vulnerability which is exploiting a behavior of the XSS Filter exists in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.

    Published: 26 Dec 2023
    4.3
    Medium

    CVE-2023-46699

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability exists in the User settings (/me) page of GROWI versions prior to v6.0.0. If a user views a malicious page while logging in, settings may be changed without the user's intention.

    Published: 26 Dec 2023
    5.4
    Medium

    CVE-2023-45740

    Last Modified: 23 Apr 2025

    Stored cross-site scripting vulnerability when processing profile images exists in GROWI versions prior to v4.1.3. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.

    Published: 26 Dec 2023
    5.4
    Medium

    CVE-2023-45737

    Last Modified: 21 Nov 2024

    Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page and the Markdown Settings (/admin/markdown) page of GROWI versions prior to v3.5.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.

    Published: 26 Dec 2023
    5.4
    Medium

    CVE-2023-50339

    Last Modified: 21 Nov 2024

    Stored cross-site scripting vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v6.1.11. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.

    Published: 26 Dec 2023
    6.1
    Medium

    CVE-2023-50297

    Last Modified: 27 Nov 2024

    Open redirect vulnerability in PowerCMS (6 Series, 5 Series, and 4 Series) allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL. Note that all versions of PowerCMS 3 Series and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability.

    Published: 26 Dec 2023
    5.4
    Medium

    CVE-2023-49117

    Last Modified: 21 Nov 2024

    PowerCMS (6 Series, 5 Series, and 4 Series) contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. Note that all versions of PowerCMS 3 Series and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability.

    Published: 26 Dec 2023
    5.5
    Medium

    CVE-2023-51654

    Last Modified: 21 Nov 2024

    Improper link resolution before file access ('Link Following') issue exists in iPrint&Scan Desktop for Windows versions 11.0.0 and earlier. A symlink attack by a malicious user may cause a Denial-of-service (DoS) condition on the PC.

    Published: 26 Dec 2023
    6.3
    Medium

    CVE-2023-7111

    Last Modified: 23 Oct 2025

    A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. Affected is an unknown function of the file index.php. The manipulation of the argument category leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-249006 is the identifier assigned to this vulnerability.

    Published: 26 Dec 2023
    7.3
    High

    CVE-2023-7110

    Last Modified: 23 Oct 2025

    A vulnerability, which was classified as critical, has been found in code-projects Library Management System 2.0. This issue affects some unknown processing of the file login.php. The manipulation of the argument student leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249005 was assigned to this vulnerability.

    Published: 26 Dec 2023
    7.3
    High

    CVE-2023-7109

    Last Modified: 23 Oct 2025

    A vulnerability classified as critical was found in code-projects Library Management System 2.0. This vulnerability affects unknown code of the file /admin/login.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249004.

    Published: 26 Dec 2023
    4.3
    Medium

    CVE-2023-7108

    Last Modified: 23 Oct 2025

    A vulnerability classified as problematic has been found in code-projects E-Commerce Website 1.0. This affects an unknown part of the file user_signup.php. The manipulation of the argument firstname with the input <video/src=x onerror=alert(document.domain)> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249003.

    Published: 26 Dec 2023
    9.8
    Critical

    CVE-2023-51097

    Last Modified: 26 Nov 2024

    Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formSetAutoPing.

    Published: 26 Dec 2023
    9.8
    Critical

    CVE-2023-51098

    Last Modified: 21 Nov 2024

    Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formSetDiagnoseInfo .

    Published: 26 Dec 2023