CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2023-50988

    Last Modified: 21 Nov 2024

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the bandwidth parameter in the wifiRadioSetIndoor function.

    Published: 20 Dec 2023
    9.8
    Critical

    CVE-2023-50989

    Last Modified: 26 Nov 2024

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function.

    Published: 20 Dec 2023
    9.8
    Critical

    CVE-2023-50990

    Last Modified: 21 Nov 2024

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebootTime parameter in the sysScheduleRebootSet function.

    Published: 20 Dec 2023
    9.8
    Critical

    CVE-2023-50992

    Last Modified: 21 Nov 2024

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a stack overflow via the ip parameter in the setPing function.

    Published: 20 Dec 2023
    9.8
    Critical

    CVE-2023-50993

    Last Modified: 21 Nov 2024

    Ruijie WS6008 v1.x v2.x AC_RGOS11.9(6)W3B2_G2C6-01_10221911 and WS6108 v1.x AC_RGOS11.9(6)W3B2_G2C6-01_10221911 was discovered to contain a command injection vulnerability via the function downFiles.

    Published: 20 Dec 2023
    5.3
    Medium

    CVE-2023-47161

    Last Modified: 21 Nov 2024

    IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 may mishandle input validation of an uploaded archive file leading to a denial of service due to resource exhaustion. IBM X-Force ID: 270799.

    Published: 19 Dec 2023
    6.2
    Medium

    CVE-2023-42012

    Last Modified: 21 Nov 2024

    An IBM UrbanCode Deploy Agent 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts. IBM X-Force ID: 265509.

    Published: 19 Dec 2023
    4.1
    Medium

    CVE-2023-50706

    Last Modified: 25 Feb 2026

    A user without administrator permissions with access to the UC500 windows system could perform a memory dump of the running processes and extract clear credentials or valid session tokens.

    Published: 19 Dec 2023
    5.3
    Medium

    CVE-2023-42013

    Last Modified: 21 Nov 2024

    IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 265510.

    Published: 19 Dec 2023
    5.3
    Medium

    CVE-2023-50705

    Last Modified: 21 Nov 2024

    An attacker could create malicious requests to obtain sensitive information about the web server.

    Published: 19 Dec 2023
    4.3
    Medium

    CVE-2023-50704

    Last Modified: 21 Nov 2024

    An attacker could construct a URL within the application that causes a redirection to an arbitrary external domain and could be leveraged to facilitate phishing attacks against application users.

    Published: 19 Dec 2023
    6.3
    Medium

    CVE-2023-50703

    Last Modified: 25 Feb 2026

    An attacker with network access could perform a man-in-the-middle (MitM) attack and capture sensitive information to gain unauthorized access to the application.

    Published: 19 Dec 2023
    8.2
    High

    CVE-2023-6689

    Last Modified: 25 Feb 2026

    A successful CSRF attack could force the user to perform state changing requests on the application. If the victim is an administrative account, a CSRF attack could compromise the entire web application.

    Published: 19 Dec 2023
    9.6
    Critical

    CVE-2023-50707

    Last Modified: 21 Nov 2024

    Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service condition on the device.

    Published: 19 Dec 2023
    9.4
    Critical

    CVE-2023-6930

    Last Modified: 21 Nov 2024

    EuroTel ETL3100 versions v01c01 and v01x37 suffer from an unauthenticated configuration and log download vulnerability. This enables the attacker to disclose sensitive information and assist in authentication bypass, privilege escalation, and full system access.

    Published: 19 Dec 2023
    7.5
    High

    CVE-2023-6929

    Last Modified: 6 May 2025

    EuroTel ETL3100 versions v01c01 and v01x37 are vulnerable to insecure direct object references that occur when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability, attackers can bypass authorization, access the hidden resources on the system, and execute privileged functionalities.

    Published: 19 Dec 2023
    9.8
    Critical

    CVE-2023-6928

    Last Modified: 21 Nov 2024

    EuroTel ETL3100 versions v01c01 and v01x37 does not limit the number of attempts to guess administrative credentials in remote password attacks to gain full control of the system.

    Published: 19 Dec 2023
    6.2
    Medium

    CVE-2023-45172

    Last Modified: 21 Nov 2024

    IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in AIX windows to cause a denial of service. IBM X-Force ID: 267970.

    Published: 19 Dec 2023
    4.9
    Medium

    CVE-2023-47146

    Last Modified: 21 Nov 2024

    IBM Qradar SIEM 7.5 could allow a privileged user to obtain sensitive domain information due to data being misidentified. IBM X-Force ID: 270372.

    Published: 19 Dec 2023
    7.2
    High

    CVE-2023-38126

    Last Modified: 21 Nov 2024

    Softing edgeAggregator Restore Configuration Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of backup zip files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this to execute code in the context of root. Was ZDI-CAN-20543.

    Published: 19 Dec 2023
    5.4
    Medium

    CVE-2023-50835

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Praveen Goswami Advanced Category Template.This issue affects Advanced Category Template: from n/a through 0.1.

    Published: 19 Dec 2023
    5.4
    Medium

    CVE-2023-49164

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in OceanWP Ocean Extra.This issue affects Ocean Extra: from n/a through 2.2.2.

    Published: 19 Dec 2023
    4.7
    Medium

    CVE-2023-46624

    Last Modified: 28 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Parcel Pro.This issue affects Parcel Pro: from n/a through 1.6.11.

    Published: 19 Dec 2023
    4.3
    Medium

    CVE-2022-43450

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in XWP Stream.This issue affects Stream: from n/a through 3.9.2.

    Published: 19 Dec 2023
    5.7
    Medium

    CVE-2023-42940

    Last Modified: 4 Nov 2025

    A session rendering issue was addressed with improved session tracking. This issue is fixed in macOS Sonoma 14.2.1. A user who shares their screen may unintentionally share the incorrect content.

    Published: 19 Dec 2023
    5.3
    Medium

    CVE-2023-49812

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005.

    Published: 19 Dec 2023
    7.6
    High

    CVE-2023-48327

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Vendors WC Vendors – WooCommerce Multi-Vendor, WooCommerce Marketplace, Product Vendors.This issue affects WC Vendors – WooCommerce Multi-Vendor, WooCommerce Marketplace, Product Vendors: from n/a through 2.4.7.

    Published: 19 Dec 2023
    9.3
    Critical

    CVE-2023-48738

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Porto Theme Porto Theme - Functionality.This issue affects Porto Theme - Functionality: from n/a before 2.12.1.

    Published: 19 Dec 2023
    7.6
    High

    CVE-2023-48741

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud AI ChatBot.This issue affects AI ChatBot: from n/a through 4.7.8.

    Published: 19 Dec 2023
    7.6
    High

    CVE-2023-48764

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GuardGiant Brute Force Protection WordPress Brute Force Protection – Stop Brute Force Attacks.This issue affects WordPress Brute Force Protection – Stop Brute Force Attacks: from n/a through 2.2.5.

    Published: 19 Dec 2023
    9.3
    Critical

    CVE-2023-49750

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spoonthemes Couponis - Affiliate & Submitting Coupons WordPress Theme.This issue affects Couponis - Affiliate & Submitting Coupons WordPress Theme: from n/a before 2.2.

    Published: 19 Dec 2023
    7.6
    High

    CVE-2023-49764

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Younes JFR. Advanced Database Cleaner.This issue affects Advanced Database Cleaner: from n/a through 3.1.2.

    Published: 19 Dec 2023
    4.7
    Medium

    CVE-2023-35883

    Last Modified: 28 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magazine3 Core Web Vitals & PageSpeed Booster.This issue affects Core Web Vitals & PageSpeed Booster: from n/a through 1.0.12.

    Published: 19 Dec 2023
    4.7
    Medium

    CVE-2023-37982

    Last Modified: 28 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for Salesforce and Contact Form 7, WPForms, Elementor, Ninja Forms.This issue affects Integration for Salesforce and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through 1.3.3.

    Published: 19 Dec 2023
    4.7
    Medium

    CVE-2023-38478

    Last Modified: 28 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for WooCommerce and QuickBooks.This issue affects Integration for WooCommerce and QuickBooks: from n/a through 1.2.3.

    Published: 19 Dec 2023
    4.7
    Medium

    CVE-2023-38481

    Last Modified: 28 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin.This issue affects Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin: from n/a before 1.3.7.

    Published: 19 Dec 2023
    4.7
    Medium

    CVE-2023-40602

    Last Modified: 28 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Doofinder Doofinder WP & WooCommerce Search.This issue affects Doofinder WP & WooCommerce Search: from n/a through 1.5.49.

    Published: 19 Dec 2023
    4.7
    Medium

    CVE-2023-41648

    Last Modified: 28 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Swapnil V. Patil Login and Logout Redirect.This issue affects Login and Logout Redirect: from n/a through 2.0.3.

    Published: 19 Dec 2023
    7.5
    High

    CVE-2023-43826

    Last Modified: 25 Feb 2026

    Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in integer overflow. If a user connects to a malicious or compromised VNC server, specially-crafted data could result in memory corruption, possibly allowing arbitrary code to be executed with the privileges of the running guacd process. Users are recommended to upgrade to version 1.5.4, which fixes this issue.

    Published: 19 Dec 2023
    4.7
    Medium

    CVE-2023-45105

    Last Modified: 28 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SERVIT Software Solutions affiliate-toolkit – WordPress Affiliate Plugin.This issue affects affiliate-toolkit – WordPress Affiliate Plugin: from n/a through 3.3.9.

    Published: 19 Dec 2023
    8.3
    High

    CVE-2023-34027

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in Rajnish Arora Recently Viewed Products.This issue affects Recently Viewed Products: from n/a through 1.0.0.

    Published: 19 Dec 2023
    4.4
    Medium

    CVE-2023-34382

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy: from n/a through 3.7.19.

    Published: 19 Dec 2023
    8.3
    High

    CVE-2023-37390

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in Themesflat Themesflat Addons For Elementor.This issue affects Themesflat Addons For Elementor: from n/a through 2.0.0.

    Published: 19 Dec 2023
    9.8
    Critical

    CVE-2023-46220

    Last Modified: 21 Nov 2024

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

    Published: 19 Dec 2023
    9.8
    Critical

    CVE-2023-46261

    Last Modified: 21 Nov 2024

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

    Published: 19 Dec 2023
    9.8
    Critical

    CVE-2023-46260

    Last Modified: 27 Nov 2024

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

    Published: 19 Dec 2023
    9.1
    Critical

    CVE-2023-46266

    Last Modified: 21 Nov 2024

    An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.

    Published: 19 Dec 2023
    9.8
    Critical

    CVE-2023-46258

    Last Modified: 21 Nov 2024

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

    Published: 19 Dec 2023
    7.5
    High

    CVE-2023-46803

    Last Modified: 21 Nov 2024

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).

    Published: 19 Dec 2023
    9.8
    Critical

    CVE-2023-46264

    Last Modified: 21 Nov 2024

    An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.

    Published: 19 Dec 2023