CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2023-45126

    Last Modified: 13 Feb 2025

    It is a duplicate.

    Published: 21 Dec 2023
    —
    Unknown

    CVE-2023-45125

    Last Modified: 13 Feb 2025

    It is a duplicate.

    Published: 21 Dec 2023
    —
    Unknown

    CVE-2023-45124

    Last Modified: 13 Feb 2025

    It is a duplicate.

    Published: 21 Dec 2023
    6.3
    Medium

    CVE-2023-7039

    Last Modified: 24 Apr 2025

    A vulnerability classified as critical has been found in Byzoro S210 up to 20231210. Affected is an unknown function of the file /importexport.php. The manipulation of the argument sql leads to injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-248688.

    Published: 21 Dec 2023
    4.3
    Medium

    CVE-2023-49765

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Blaz K. Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rating System: from n/a through 3.4.1.

    Published: 21 Dec 2023
    6.5
    Medium

    CVE-2023-47191

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in KaineLabs Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress.This issue affects Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress: from n/a through 1.2.2.

    Published: 21 Dec 2023
    6.5
    Medium

    CVE-2023-32799

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Shipping Multiple Addresses.This issue affects Shipping Multiple Addresses: from n/a through 3.8.3.

    Published: 21 Dec 2023
    5.4
    Medium

    CVE-2023-32747

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 1.15.78.

    Published: 21 Dec 2023
    6.5
    Medium

    CVE-2023-50834

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in August Infotech WooCommerce Menu Extension allows Stored XSS.This issue affects WooCommerce Menu Extension: from n/a through 1.6.2.

    Published: 21 Dec 2023
    6.5
    Medium

    CVE-2023-50833

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExtendThemes Colibri Page Builder allows Stored XSS.This issue affects Colibri Page Builder: from n/a through 1.0.239.

    Published: 21 Dec 2023
    4.3
    Medium

    CVE-2023-7038

    Last Modified: 21 Nov 2024

    A vulnerability was found in automad up to 1.10.9. It has been rated as problematic. This issue affects some unknown processing of the file /dashboard?controller=UserCollection::createUser of the component User Creation Handler. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248687. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 21 Dec 2023
    5.9
    Medium

    CVE-2023-50832

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mondula GmbH Multi Step Form allows Stored XSS.This issue affects Multi Step Form: from n/a through 1.7.13.

    Published: 21 Dec 2023
    6.5
    Medium

    CVE-2023-50831

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme CURCY – Multi Currency for WooCommerce allows Stored XSS.This issue affects CURCY – Multi Currency for WooCommerce: from n/a through 2.2.0.

    Published: 21 Dec 2023
    5.9
    Medium

    CVE-2023-50830

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Seosbg Seos Contact Form allows Stored XSS.This issue affects Seos Contact Form: from n/a through 1.8.0.

    Published: 21 Dec 2023
    5.9
    Medium

    CVE-2023-50829

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aerin Loan Repayment Calculator and Application Form allows Stored XSS.This issue affects Loan Repayment Calculator and Application Form: from n/a through 2.9.3.

    Published: 21 Dec 2023
    6.3
    Medium

    CVE-2023-7037

    Last Modified: 21 Nov 2024

    A vulnerability was found in automad up to 1.10.9. It has been declared as critical. This vulnerability affects the function import of the file FileController.php. The manipulation of the argument importUrl leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-248686 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 21 Dec 2023
    —
    Unknown

    CVE-2023-45123

    Last Modified: 13 Feb 2025

    It is a duplicate.

    Published: 21 Dec 2023
    —
    Unknown

    CVE-2023-45122

    Last Modified: 13 Feb 2025

    It is a duplicate.

    Published: 21 Dec 2023
    8.8
    High

    CVE-2023-45121

    Last Modified: 19 May 2025

    Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'desc' parameter of the /update.php?q=addquiz resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 21 Dec 2023
    8.8
    High

    CVE-2023-45120

    Last Modified: 19 May 2025

    Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'qid' parameter of the /update.php?q=quiz&step=2 resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 21 Dec 2023
    6.5
    Medium

    CVE-2023-40058

    Last Modified: 21 Nov 2024

    Sensitive data was added to our public-facing knowledgebase that, if exploited, could be used to access components of Access Rights Manager (ARM) if the threat actor is in the same environment.

    Published: 21 Dec 2023
    5.5
    Medium

    CVE-2023-4255

    Last Modified: 13 Feb 2025

    An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to the w3m binary. Exploitation of this flaw could lead to application crashes, resulting in a denial of service condition.

    Published: 21 Dec 2023
    8.8
    High

    CVE-2023-45119

    Last Modified: 19 May 2025

    Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'n' parameter of the /update.php?q=quiz resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 21 Dec 2023
    5.5
    Medium

    CVE-2023-4256

    Last Modified: 13 Feb 2025

    Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. This vulnerability can be exploited by supplying a specifically crafted file to the tcprewrite binary. This flaw enables a local attacker to initiate a Denial of Service (DoS) attack.

    Published: 21 Dec 2023
    4.7
    Medium

    CVE-2023-7036

    Last Modified: 21 Nov 2024

    A vulnerability was found in automad up to 1.10.9. It has been classified as problematic. This affects the function upload of the file FileCollectionController.php of the component Content Type Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248685 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 21 Dec 2023
    8.8
    High

    CVE-2023-45118

    Last Modified: 19 May 2025

    Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'fdid' parameter of the /update.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 21 Dec 2023
    8.8
    High

    CVE-2023-45117

    Last Modified: 19 May 2025

    Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'eid' parameter of the /update.php?q=rmquiz resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 21 Dec 2023
    8.8
    High

    CVE-2023-45116

    Last Modified: 19 May 2025

    Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'demail' parameter of the /update.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 21 Dec 2023
    8.8
    High

    CVE-2023-45115

    Last Modified: 21 May 2025

    Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'ch' parameter of the /update.php?q=addqns resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 21 Dec 2023
    8.6
    High

    CVE-2023-51442

    Last Modified: 21 Nov 2024

    Navidrome is an open source web-based music collection server and streamer. A security vulnerability has been identified in navidrome's subsonic endpoint, allowing for authentication bypass. This exploit enables unauthorized access to any known account by utilizing a JSON Web Token (JWT) signed with the key "not so secret". The vulnerability can only be exploited on instances that have never been restarted. Navidrome supports an extension to the subsonic authentication scheme, where a JWT can be provided using a `jwt` query parameter instead of the traditional password or token and salt (corresponding to resp. the `p` or `t` and `s` query parameters). This authentication bypass vulnerability potentially affects all instances that don't protect the subsonic endpoint `/rest/`, which is expected to be most instances in a standard deployment, and most instances in the reverse proxy setup too (as the documentation mentions to leave that endpoint unprotected). This issue has been patched in version 0.50.2.

    Published: 21 Dec 2023
    6.3
    Medium

    CVE-2023-50724

    Last Modified: 21 Nov 2024

    Resque (pronounced like "rescue") is a Redis-backed library for creating background jobs, placing those jobs on multiple queues, and processing them later. resque-web in resque versions before 2.1.0 are vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. This issue has been patched in version 2.1.0.

    Published: 21 Dec 2023
    5.9
    Medium

    CVE-2023-50828

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Vongries Ultimate Dashboard – Custom WordPress Dashboard allows Stored XSS.This issue affects Ultimate Dashboard – Custom WordPress Dashboard: from n/a through 3.7.11.

    Published: 21 Dec 2023
    5.9
    Medium

    CVE-2023-50827

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Accredible Accredible Certificates & Open Badges allows Stored XSS.This issue affects Accredible Certificates & Open Badges: from n/a through 1.4.8.

    Published: 21 Dec 2023
    5.9
    Medium

    CVE-2023-50826

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Freshlight Lab Menu Image, Icons made easy allows Stored XSS.This issue affects Menu Image, Icons made easy: from n/a through 3.10.

    Published: 21 Dec 2023
    6.5
    Medium

    CVE-2023-50825

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terrier Tenacity iframe Shortcode allows Stored XSS.This issue affects iframe Shortcode: from n/a through 2.0.

    Published: 21 Dec 2023
    4.4
    Medium

    CVE-2023-7047

    Last Modified: 21 Nov 2024

    Inadequate validation of permissions when employing remote tools and macros via the context menu within Devolutions Remote Desktop Manager versions 2023.3.31 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature. This affects only SQL data sources.

    Published: 21 Dec 2023
    6.5
    Medium

    CVE-2023-50824

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Batt Insert or Embed Articulate Content into WordPress allows Stored XSS.This issue affects Insert or Embed Articulate Content into WordPress: from n/a through 4.3000000021.

    Published: 21 Dec 2023
    6.5
    Medium

    CVE-2023-50823

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wipeout Media CSS & JavaScript Toolbox allows Stored XSS.This issue affects CSS & JavaScript Toolbox: from n/a through 11.7.

    Published: 21 Dec 2023
    6.5
    Medium

    CVE-2023-50822

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Currency.Wiki Currency Converter Widget – Exchange Rates allows Stored XSS.This issue affects Currency Converter Widget – Exchange Rates: from n/a through 3.0.2.

    Published: 21 Dec 2023
    1.9
    Low

    CVE-2023-7035

    Last Modified: 15 Jun 2025

    A vulnerability was found in automad up to 1.10.9 and classified as problematic. Affected by this issue is some unknown functionality of the file packages\standard\templates\post.php of the component Setting Handler. The manipulation of the argument sitename leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 21 Dec 2023
    5.9
    Medium

    CVE-2023-50377

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AB-WP Simple Counter allows Stored XSS.This issue affects Simple Counter: from n/a through 1.0.2.

    Published: 21 Dec 2023
    5.9
    Medium

    CVE-2023-47527

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sajjad Hossain Sagor WP Edit Username allows Stored XSS.This issue affects WP Edit Username: from n/a through 1.0.5.

    Published: 21 Dec 2023
    5.9
    Medium

    CVE-2023-47525

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Event Monster – Event Management, Tickets Booking, Upcoming Event allows Stored XSS.This issue affects Event Monster – Event Management, Tickets Booking, Upcoming Event: from n/a through 1.3.2.

    Published: 21 Dec 2023
    5.4
    Medium

    CVE-2023-22674

    Last Modified: 28 Apr 2026

    Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Hal Gatewood Dashicons + Custom Post Types.This issue affects Dashicons + Custom Post Types: from n/a through 1.0.2.

    Published: 21 Dec 2023
    5.3
    Medium

    CVE-2023-28421

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Winwar Media WordPress Email Marketing Plugin – WP Email Capture.This issue affects WordPress Email Marketing Plugin – WP Email Capture: from n/a through 3.10.

    Published: 21 Dec 2023
    5.9
    Medium

    CVE-2023-2487

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orders, Refunds & Users.This issue affects Export All Posts, Products, Orders, Refunds & Users: from n/a through 2.4.1.

    Published: 21 Dec 2023
    7.5
    High

    CVE-2023-48288

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HM Plugin WordPress Job Board and Recruitment Plugin – JobWP.This issue affects WordPress Job Board and Recruitment Plugin – JobWP: from n/a through 2.1.

    Published: 21 Dec 2023
    9.8
    Critical

    CVE-2023-6145

    Last Modified: 20 May 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in İstanbul Soft Informatics and Consultancy Limited Company Softomi Advanced C2C Marketplace Software allows SQL Injection. This issue affects Softomi Advanced C2C Marketplace Software: before 12122023.

    Published: 21 Dec 2023
    5.3
    Medium

    CVE-2023-49162

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BigCommerce BigCommerce For WordPress.This issue affects BigCommerce For WordPress: from n/a through 5.0.6.

    Published: 21 Dec 2023
    6.1
    Medium

    CVE-2023-6122

    Last Modified: 20 May 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in İstanbul Soft Informatics and Consultancy Limited Company Softomi Gelişmiş C2C Pazaryeri Yazılımı allows Reflected XSS. This issue affects Softomi Gelişmiş C2C Pazaryeri Yazılımı: before 12122023.

    Published: 21 Dec 2023