CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2023-50466

    Last Modified: 21 Nov 2024

    An authenticated command injection vulnerability in Weintek cMT2078X easyweb Web Version v2.1.3, OS v20220215 allows attackers to execute arbitrary code or access sensitive information via injecting a crafted payload into the HMI Name parameter.

    Published: 19 Dec 2023
    4.9
    Medium

    CVE-2023-31347

    Last Modified: 17 Mar 2025

    Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC when Secure TSC is enabled potentially resulting in a loss of guest integrity.  

    Published: 19 Dec 2023
    9.8
    Critical

    CVE-2023-49004

    Last Modified: 21 Nov 2024

    An issue in D-Link DIR-850L v.B1_FW223WWb01 allows a remote attacker to execute arbitrary code via a crafted script to the en parameter.

    Published: 19 Dec 2023
    6.5
    Medium

    CVE-2023-49006

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) vulnerability in Phpsysinfo version 3.4.3 allows a remote attacker to obtain sensitive information via a crafted page in the XML.php file.

    Published: 19 Dec 2023
    6.3
    Medium

    CVE-2023-50725

    Last Modified: 21 Nov 2024

    Resque is a Redis-backed Ruby library for creating background jobs, placing them on multiple queues, and processing them later. The following paths in resque-web have been found to be vulnerable to reflected XSS: "/failed/?class=<script>alert(document.cookie)</script>" and "/queues/><img src=a onerror=alert(document.cookie)>". This issue has been patched in version 2.2.1.

    Published: 19 Dec 2023
    6.3
    Medium

    CVE-2023-50727

    Last Modified: 23 Apr 2025

    Resque is a Redis-backed Ruby library for creating background jobs, placing them on multiple queues, and processing them later. Reflected XSS issue occurs when /queues is appended with /"><svg%20onload=alert(domain)>. This issue has been patched in version 2.6.0.

    Published: 19 Dec 2023
    4.3
    Medium

    CVE-2023-50761

    Last Modified: 13 Feb 2025

    The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If present, Thunderbird did not compare the signature creation date with the message date and time, and displayed a valid signature despite a date or time mismatch. This could be used to give recipients the impression that a message was sent at a different date or time. This vulnerability affects Thunderbird < 115.6.

    Published: 19 Dec 2023
    4.3
    Medium

    CVE-2023-50762

    Last Modified: 13 Feb 2025

    When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This is because the text was interpreted as a MIME message and the first paragraph was always treated as an email header section. A digitally signed text from a different context, such as a signed GIT commit, could be used to spoof an email message. This vulnerability affects Thunderbird < 115.6.

    Published: 19 Dec 2023
    4.3
    Medium

    CVE-2023-6135

    Last Modified: 13 Feb 2025

    Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.

    Published: 19 Dec 2023
    8.8
    High

    CVE-2023-6856

    Last Modified: 13 Feb 2025

    The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

    Published: 19 Dec 2023
    5.3
    Medium

    CVE-2023-6857

    Last Modified: 13 Feb 2025

    When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Firefox on Unix-based operating systems (Android, Linux, MacOS). Windows is unaffected.* This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

    Published: 19 Dec 2023
    8.8
    High

    CVE-2023-6858

    Last Modified: 7 May 2025

    Firefox was susceptible to a heap buffer overflow in `nsTextFragment` due to insufficient OOM handling. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

    Published: 19 Dec 2023
    8.8
    High

    CVE-2023-6859

    Last Modified: 13 Feb 2025

    A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

    Published: 19 Dec 2023
    6.5
    Medium

    CVE-2023-6860

    Last Modified: 13 Feb 2025

    The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

    Published: 19 Dec 2023
    8.8
    High

    CVE-2023-6862

    Last Modified: 13 Feb 2025

    A use-after-free was identified in the `nsDNSService::Init`. This issue appears to manifest rarely during start-up. This vulnerability affects Firefox ESR < 115.6 and Thunderbird < 115.6.

    Published: 19 Dec 2023
    8.8
    High

    CVE-2023-6863

    Last Modified: 13 Feb 2025

    The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

    Published: 19 Dec 2023
    8.8
    High

    CVE-2023-6864

    Last Modified: 21 Nov 2024

    Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

    Published: 19 Dec 2023
    6.5
    Medium

    CVE-2023-6865

    Last Modified: 13 Feb 2025

    `EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be abused in order to write data to a local disk which may have implications for private browsing mode. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.

    Published: 19 Dec 2023
    6
    Medium

    CVE-2023-31346

    Last Modified: 20 Mar 2025

    Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.

    Published: 19 Dec 2023
    9.8
    Critical

    CVE-2023-45887

    Last Modified: 21 Nov 2024

    DS Wireless Communication (DWC) with DWC_VERSION_3 and DWC_VERSION_11 allows remote attackers to execute arbitrary code on a game-playing client's machine via a modified GPCM message.

    Published: 19 Dec 2023
    7.8
    High

    CVE-2023-49147

    Last Modified: 21 Nov 2024

    An issue was discovered in PDF24 Creator 11.14.0. The configuration of the msi installer file was found to produce a visible cmd.exe window when using the repair function of msiexec.exe. This allows an unprivileged local attacker to use a chain of actions (e.g., an oplock on faxPrnInst.log) to open a SYSTEM cmd.exe.

    Published: 19 Dec 2023
    6.8
    Medium

    CVE-2023-49706

    Last Modified: 26 Nov 2024

    Defective request context handling in Self Service in LinOTP 3.x before 3.2.5 allows remote unauthenticated attackers to escalate privileges, thereby allowing them to act as and with the permissions of another user. Attackers must generate repeated API requests to trigger a race condition with concurrent user activity in the self-service portal.

    Published: 19 Dec 2023
    8.8
    High

    CVE-2023-6861

    Last Modified: 13 Feb 2025

    The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

    Published: 19 Dec 2023
    6.1
    Medium

    CVE-2023-6867

    Last Modified: 13 Feb 2025

    The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.

    Published: 19 Dec 2023
    5.7
    Medium

    CVE-2023-6944

    Last Modified: 20 Nov 2025

    A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error can display on the frontend, including the raw access token. Upon gaining access to this token and depending on permissions, an attacker could push malicious code to repositories, delete resources in Git, revoke or generate new keys, and sign code illegitimately.

    Published: 19 Dec 2023
    9.8
    Critical

    CVE-2023-47267

    Last Modified: 17 Dec 2025

    An issue discovered in TheGreenBow Windows Enterprise Certified VPN Client 6.52, Windows Standard VPN Client 6.87, and Windows Enterprise VPN Client 6.87 allows attackers to gain escalated privileges via crafted changes to memory mapped file.

    Published: 19 Dec 2023
    6.3
    Medium

    CVE-2023-46212

    Last Modified: 28 Apr 2026

    Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in TienCOP WP EXtra allows Accessing Functionality Not Properly Constrained by ACLs, Cross Site Request Forgery.This issue affects WP EXtra: from n/a through 6.2.

    Published: 18 Dec 2023
    6.6
    Medium

    CVE-2023-46154

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in E2Pdf.Com E2Pdf – Export To Pdf Tool for WordPress.This issue affects E2Pdf – Export To Pdf Tool for WordPress: from n/a through 1.20.18.

    Published: 18 Dec 2023
    4.3
    Medium

    CVE-2023-47754

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Clever plugins Delete Duplicate Posts allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Delete Duplicate Posts: from n/a through 4.8.9.

    Published: 18 Dec 2023
    4.3
    Medium

    CVE-2023-48751

    Last Modified: 28 Apr 2026

    Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database allows Accessing Functionality Not Properly Constrained by ACLs, Cross Site Request Forgery.This issue affects Participants Database: from n/a through 2.5.5.

    Published: 18 Dec 2023
    7.5
    High

    CVE-2023-49819

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in Gordon Böhme, Antonio Leutsch Structured Content (JSON-LD) #wpsc.This issue affects Structured Content (JSON-LD) #wpsc: from n/a through 1.5.3.

    Published: 18 Dec 2023
    5.3
    Medium

    CVE-2022-45809

    Last Modified: 28 Apr 2026

    Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs Rating: from n/a through 5.0.0.

    Published: 18 Dec 2023
    7.6
    High

    CVE-2023-47506

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Master slider Master Slider Pro allows SQL Injection.This issue affects Master Slider Pro: from n/a through 3.6.5.

    Published: 18 Dec 2023
    7.6
    High

    CVE-2023-47530

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPVibes Redirect 404 Error Page to Homepage or Custom Page with Logs allows SQL Injection.This issue affects Redirect 404 Error Page to Homepage or Custom Page with Logs: from n/a through 1.8.7.

    Published: 18 Dec 2023
    7.6
    High

    CVE-2023-47558

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mahlamusa Who Hit The Page – Hit Counter allows SQL Injection.This issue affects Who Hit The Page – Hit Counter: from n/a through 1.4.14.3.

    Published: 18 Dec 2023
    8.5
    High

    CVE-2023-33331

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce Product Vendors allows SQL Injection.This issue affects Product Vendors: from n/a through 2.1.76.

    Published: 18 Dec 2023
    7.6
    High

    CVE-2023-34168

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alex Raven WP Report Post allows SQL Injection.This issue affects WP Report Post: from n/a through 2.1.2.

    Published: 18 Dec 2023
    5.4
    Medium

    CVE-2023-49821

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in LiveChat LiveChat – WP live chat plugin for WordPress.This issue affects LiveChat – WP live chat plugin for WordPress: from n/a through 4.5.15.

    Published: 18 Dec 2023
    4.3
    Medium

    CVE-2023-49763

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Creatomatic Ltd CSprite.This issue affects CSprite: from n/a through 1.1.

    Published: 18 Dec 2023
    5.4
    Medium

    CVE-2023-49761

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Gravity Master Product Enquiry for WooCommerce.This issue affects Product Enquiry for WooCommerce: from n/a through 3.0.

    Published: 18 Dec 2023
    5.4
    Medium

    CVE-2023-49760

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Giannopoulos Kostas WPsoonOnlinePage.This issue affects WPsoonOnlinePage: from n/a through 1.9.

    Published: 18 Dec 2023
    5.4
    Medium

    CVE-2023-49759

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.3.0.

    Published: 18 Dec 2023
    5.4
    Medium

    CVE-2023-49163

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Michael Winkler teachPress.This issue affects teachPress: from n/a through 9.0.5.

    Published: 18 Dec 2023
    4.3
    Medium

    CVE-2023-49155

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder.This issue affects Button Generator – easily Button Builder: from n/a through 2.3.8.

    Published: 18 Dec 2023
    4.3
    Medium

    CVE-2023-49153

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Saiful Islam Add to Cart Text Changer and Customize Button, Add Custom Icon.This issue affects Add to Cart Text Changer and Customize Button, Add Custom Icon: from n/a through 2.0.

    Published: 18 Dec 2023
    5.4
    Medium

    CVE-2023-49148

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Kulwant Nagi Affiliate Booster – Pros & Cons, Notice, and CTA Blocks for Affiliates.This issue affects Affiliate Booster – Pros & Cons, Notice, and CTA Blocks for Affiliates: from n/a through 3.0.5.

    Published: 18 Dec 2023
    4.3
    Medium

    CVE-2023-48781

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Marketing Rapel MkRapel Regiones y Ciudades de Chile para WC.This issue affects MkRapel Regiones y Ciudades de Chile para WC: from n/a through 4.3.0.

    Published: 18 Dec 2023
    5.4
    Medium

    CVE-2023-48778

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Product Size Chart For WooCommerce.This issue affects Product Size Chart For WooCommerce: from n/a through 1.1.5.

    Published: 18 Dec 2023
    5.4
    Medium

    CVE-2023-48773

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WP Doctor WooCommerce Login Redirect.This issue affects WooCommerce Login Redirect: from n/a through 2.2.4.

    Published: 18 Dec 2023
    5.5
    Medium

    CVE-2023-46686

    Last Modified: 21 Nov 2024

    A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics Service to use less secure communication protocols. This issue affects: Gallagher Diagnostics Service prior to v1.3.0 (distributed in 9.00.1507(MR1)).

    Published: 18 Dec 2023