CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2023-35895

    Last Modified: 21 Nov 2024

    IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 259116.

    Published: 20 Dec 2023
    5.4
    Medium

    CVE-2023-36520

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in MarketingFire Editorial Calendar.This issue affects Editorial Calendar: from n/a through 3.7.12.

    Published: 20 Dec 2023
    5.4
    Medium

    CVE-2023-51458

    Last Modified: 6 May 2025

    Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 20 Dec 2023
    5.4
    Medium

    CVE-2023-51462

    Last Modified: 21 Nov 2024

    Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

    Published: 20 Dec 2023
    5.4
    Medium

    CVE-2023-51460

    Last Modified: 21 Nov 2024

    Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 20 Dec 2023
    5.4
    Medium

    CVE-2023-51461

    Last Modified: 21 Nov 2024

    Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 20 Dec 2023
    5.4
    Medium

    CVE-2023-51457

    Last Modified: 21 Nov 2024

    Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 20 Dec 2023
    5.4
    Medium

    CVE-2023-51459

    Last Modified: 21 Nov 2024

    Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

    Published: 20 Dec 2023
    4.7
    Medium

    CVE-2023-6784

    Last Modified: 27 Nov 2024

    A malicious user could potentially use the Sitefinity system for the distribution of phishing emails.

    Published: 20 Dec 2023
    8.2
    High

    CVE-2023-37871

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: from n/a through 2.5.6.

    Published: 20 Dec 2023
    7.5
    High

    CVE-2023-50249

    Last Modified: 21 Nov 2024

    Sentry-Javascript is official Sentry SDKs for JavaScript. A ReDoS (Regular expression Denial of Service) vulnerability has been identified in Sentry's Astro SDK 7.78.0-7.86.0. Under certain conditions, this vulnerability allows an attacker to cause excessive computation times on the server, leading to denial of service (DoS). This vulnerability has been patched in sentry/astro version 7.87.0.

    Published: 20 Dec 2023
    5.4
    Medium

    CVE-2023-38513

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Jordy Meow Photo Engine (Media Organizer & Lightroom).This issue affects Photo Engine (Media Organizer & Lightroom): from n/a through 6.2.5.

    Published: 20 Dec 2023
    7.6
    High

    CVE-2023-38519

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MainWP MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance.This issue affects MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance: from n/a through 4.4.3.3.

    Published: 20 Dec 2023
    8.3
    High

    CVE-2023-40555

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in UX-themes Flatsome | Multi-Purpose Responsive WooCommerce Theme.This issue affects Flatsome | Multi-Purpose Responsive WooCommerce Theme: from n/a through 3.17.5.

    Published: 20 Dec 2023
    5.3
    Medium

    CVE-2023-41796

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in WP Sunshine Sunshine Photo Cart: Free Client Galleries for Photographers.This issue affects Sunshine Photo Cart: Free Client Galleries for Photographers: from n/a before 3.0.0.

    Published: 20 Dec 2023
    7.4
    High

    CVE-2023-46147

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.

    Published: 20 Dec 2023
    2.7
    Low

    CVE-2023-46311

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team Comments – wpDiscuz.This issue affects Comments – wpDiscuz: from n/a through 7.6.3.

    Published: 20 Dec 2023
    7.6
    High

    CVE-2023-47236

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum iPages Flipbook For WordPress.This issue affects iPages Flipbook For WordPress: from n/a through 1.4.8.

    Published: 20 Dec 2023
    7.1
    High

    CVE-2023-47507

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in Master Slider Master Slider Pro.This issue affects Master Slider Pro: from n/a through 3.6.5.

    Published: 20 Dec 2023
    —
    Unknown

    CVE-2023-6997

    Last Modified: 7 Jun 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 20 Dec 2023
    7.5
    High

    CVE-2023-6562

    Last Modified: 21 Nov 2024

    JPX Fragment List (flst) box vulnerability in Kakadu 7.9 allows an attacker to exfiltrate local and remote files reachable by a server if the server allows the attacker to upload a specially-crafted the image that is displayed back to the attacker.

    Published: 20 Dec 2023
    6.5
    Medium

    CVE-2023-6769

    Last Modified: 21 Nov 2024

    Stored XSS vulnerability in Amazing Little Poll, affecting versions 1.3 and 1.4. This vulnerability allows a remote attacker to store a malicious JavaScript payload in the "lp_admin.php" file in the "question" and "item" parameters. This vulnerability could lead to malicious JavaScript execution while the page is loading.

    Published: 20 Dec 2023
    9.4
    Critical

    CVE-2023-6768

    Last Modified: 21 Nov 2024

    Authentication bypass vulnerability in Amazing Little Poll affecting versions 1.3 and 1.4. This vulnerability could allow an unauthenticated user to access the admin panel without providing any credentials by simply accessing the "lp_admin.php?adminstep=" parameter.

    Published: 20 Dec 2023
    6.5
    Medium

    CVE-2023-6910

    Last Modified: 23 Feb 2026

    A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource consumption. Authenticated attacker can exhaust server storage space to a point where the server can no longer serve requests.

    Published: 20 Dec 2023
    7.5
    High

    CVE-2023-6912

    Last Modified: 23 Feb 2026

    Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication attempts, potentially compromising targeted M-Files user accounts by guessing passwords.

    Published: 20 Dec 2023
    7.5
    High

    CVE-2023-37544

    Last Modified: 13 Feb 2025

    Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication. This issue affects Apache Pulsar WebSocket Proxy: from 2.8.0 through 2.8.*, from 2.9.0 through 2.9.*, from 2.10.0 through 2.10.4, from 2.11.0 through 2.11.1, 3.0.0. The known risks include a denial of service due to the WebSocket Proxy accepting any connections, and excessive data transfer due to misuse of the WebSocket ping/pong feature. 2.10 Pulsar WebSocket Proxy users should upgrade to at least 2.10.5. 2.11 Pulsar WebSocket Proxy users should upgrade to at least 2.11.2. 3.0 Pulsar WebSocket Proxy users should upgrade to at least 3.0.1. 3.1 Pulsar WebSocket Proxy users are unaffected. Any users running the Pulsar WebSocket Proxy for 2.8, 2.9, and earlier should upgrade to one of the above patched versions.

    Published: 20 Dec 2023
    7.6
    High

    CVE-2023-0011

    Last Modified: 24 Apr 2025

    A flaw in the input validation in TOBY-L2 allows a user to execute arbitrary operating system commands using specifically crafted AT commands. This vulnerability requires physical access to the serial interface of the module or the ability to modify the system or software which uses its serial interface to send malicious AT commands. Exploitation of the vulnerability gives full administrative (root) privileges to the attacker to execute any operating system command on TOBY-L2 which can lead to modification of the behavior of the module itself as well as the components connected with it (depending on its rights on other connected systems). It can further provide the ability to read system level files and hamper the availability of the module as well.. This issue affects TOBY-L2 series: TOBY-L200, TOBY-L201, TOBY-L210, TOBY-L220, TOBY-L280.

    Published: 20 Dec 2023
    7.5
    High

    CVE-2023-6977

    Last Modified: 21 Nov 2024

    This vulnerability enables malicious users to read sensitive files on the server.

    Published: 20 Dec 2023
    8.8
    High

    CVE-2023-6976

    Last Modified: 21 Nov 2024

    This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the context of the server process.

    Published: 20 Dec 2023
    9.8
    Critical

    CVE-2023-6975

    Last Modified: 21 Nov 2024

    A malicious user could use this issue to get command execution on the vulnerable machine and get access to data & models information.

    Published: 20 Dec 2023
    9.8
    Critical

    CVE-2023-6974

    Last Modified: 21 Nov 2024

    A malicious user could use this issue to access internal HTTP(s) servers and in the worst case (ie: aws instance) it could be abuse to get a remote code execution on the victim machine.

    Published: 20 Dec 2023
    5.4
    Medium

    CVE-2023-47707

    Last Modified: 21 Nov 2024

    IBM Security Guardium Key Lifecycle Manager 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 271522.

    Published: 20 Dec 2023
    5.3
    Medium

    CVE-2023-47703

    Last Modified: 21 Nov 2024

    IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 271197.

    Published: 20 Dec 2023
    4.3
    Medium

    CVE-2023-47702

    Last Modified: 21 Nov 2024

    IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view modify files on the system. IBM X-Force ID: 271196.

    Published: 20 Dec 2023
    6.6
    Medium

    CVE-2023-47706

    Last Modified: 21 Nov 2024

    IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file type. IBM X-Force ID: 271341.

    Published: 20 Dec 2023
    4.3
    Medium

    CVE-2023-47705

    Last Modified: 21 Nov 2024

    IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate username data due to improper input validation. IBM X-Force ID: 271228.

    Published: 20 Dec 2023
    4
    Medium

    CVE-2023-47704

    Last Modified: 21 Nov 2024

    IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source code repository. IBM X-Force ID: 271220.

    Published: 20 Dec 2023
    9.1
    Critical

    CVE-2023-27172

    Last Modified: 16 Sept 2026

    Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the secret key used to sign JWT tokens via a bruteforce attack.

    Published: 20 Dec 2023
    5.3
    Medium

    CVE-2023-41166

    Last Modified: 26 Nov 2024

    An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. It's possible to know if a specific user account exists on the SNS firewall by using remote access commands.

    Published: 20 Dec 2023
    6.5
    Medium

    CVE-2023-47093

    Last Modified: 21 Nov 2024

    An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.21, 4.4.0 through 4.6.8, and 4.7.0. Sending a crafted ICMP packet may lead to a crash of the ASQ engine.

    Published: 20 Dec 2023
    9.8
    Critical

    CVE-2023-47990

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in components/table_manager/html/edit_admin_table.php in CuppaCMS V1.0 allows attackers to run arbitrary SQL commands via the table parameter.

    Published: 20 Dec 2023
    9.8
    Critical

    CVE-2023-49032

    Last Modified: 24 Apr 2025

    An issue in LTB Self Service Password before v.1.5.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via hijack of the SMS verification code function to arbitrary phone.

    Published: 20 Dec 2023
    9.8
    Critical

    CVE-2023-50044

    Last Modified: 21 Nov 2024

    Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an input string.

    Published: 20 Dec 2023
    9.8
    Critical

    CVE-2023-50628

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in libming version 0.4.8, allows attackers to execute arbitrary code and obtain sensitive information via parser.c component.

    Published: 20 Dec 2023
    5.4
    Medium

    CVE-2023-50639

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in CuteHttpFileServer v.1.0 and v.2.0 allows attackers to obtain sensitive information via the file upload function in the home page.

    Published: 20 Dec 2023
    9.8
    Critical

    CVE-2023-50983

    Last Modified: 21 Nov 2024

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function.

    Published: 20 Dec 2023
    9.8
    Critical

    CVE-2023-50984

    Last Modified: 21 Nov 2024

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the ip parameter in the spdtstConfigAndStart function.

    Published: 20 Dec 2023
    9.8
    Critical

    CVE-2023-50985

    Last Modified: 21 Nov 2024

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanGw parameter in the lanCfgSet function.

    Published: 20 Dec 2023
    9.8
    Critical

    CVE-2023-50986

    Last Modified: 21 Nov 2024

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function.

    Published: 20 Dec 2023
    9.8
    Critical

    CVE-2023-50987

    Last Modified: 21 Nov 2024

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysTimeInfoSet function.

    Published: 20 Dec 2023