CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2023-49827

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme allows Reflected XSS.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4.1.

    Published: 14 Dec 2023
    —
    Unknown

    CVE-2023-6818

    Last Modified: 5 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 14 Dec 2023
    6.5
    Medium

    CVE-2023-49828

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo allows Stored XSS.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 6.4.2.

    Published: 14 Dec 2023
    6.5
    Medium

    CVE-2023-49833

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Spectra – WordPress Gutenberg Blocks allows Stored XSS.This issue affects Spectra – WordPress Gutenberg Blocks: from n/a through 2.7.9.

    Published: 14 Dec 2023
    5.9
    Medium

    CVE-2023-49836

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brontobytes Cookie Bar allows Stored XSS.This issue affects Cookie Bar: from n/a through 2.0.

    Published: 14 Dec 2023
    4.7
    Medium

    CVE-2023-6545

    Last Modified: 21 Nov 2024

    The package authelia-bhf included in Beckhoffs TwinCAT/BSD is prone to an open redirect that allows a remote unprivileged attacker to redirect a user to another site. This may have limited impact to integrity and does solely affect anthelia-bhf the Beckhoff fork of authelia.

    Published: 14 Dec 2023
    6.5
    Medium

    CVE-2023-46144

    Last Modified: 21 Nov 2024

    A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.

    Published: 14 Dec 2023
    6.5
    Medium

    CVE-2023-49846

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through 2.1.17.

    Published: 14 Dec 2023
    7.5
    High

    CVE-2023-46143

    Last Modified: 22 May 2025

    Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.

    Published: 14 Dec 2023
    8.8
    High

    CVE-2023-46142

    Last Modified: 21 Nov 2024

    A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full access on the affected devices.

    Published: 14 Dec 2023
    9.8
    Critical

    CVE-2023-46141

    Last Modified: 21 Nov 2024

    Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.

    Published: 14 Dec 2023
    7.5
    High

    CVE-2023-5592

    Last Modified: 21 Nov 2024

    Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to download and execute applications without integrity checks on the device which may result in a complete loss of integrity.

    Published: 14 Dec 2023
    7.4
    High

    CVE-2023-45185

    Last Modified: 21 Nov 2024

    IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code. Due to improper authority checks the attacker could perform operations on the PC under the user's authority. IBM X-Force ID: 268273.

    Published: 14 Dec 2023
    9.8
    Critical

    CVE-2023-0757

    Last Modified: 21 Nov 2024

    Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device.

    Published: 14 Dec 2023
    7.4
    High

    CVE-2023-45182

    Last Modified: 21 Nov 2024

    IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is vulnerable to having its key for an encrypted password decoded. By somehow gaining access to the encrypted password, a local attacker could exploit this vulnerability to obtain the password to other systems. IBM X-Force ID: 268265.

    Published: 14 Dec 2023
    6.5
    Medium

    CVE-2023-49847

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twinpictures Annual Archive allows Stored XSS.This issue affects Annual Archive: from n/a through 1.6.0.

    Published: 14 Dec 2023
    6.5
    Medium

    CVE-2023-50368

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Shortcodes and extra features for Phlox theme allows Stored XSS.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.15.2.

    Published: 14 Dec 2023
    6.5
    Medium

    CVE-2023-50369

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alma Alma – Pay in installments or later for WooCommerce allows Stored XSS.This issue affects Alma – Pay in installments or later for WooCommerce: from n/a through 5.1.3.

    Published: 14 Dec 2023
    6.5
    Medium

    CVE-2023-50370

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Livemesh WPBakery Page Builder Addons by Livemesh allows Stored XSS.This issue affects WPBakery Page Builder Addons by Livemesh: from n/a through 3.5.

    Published: 14 Dec 2023
    7.1
    High

    CVE-2023-48676

    Last Modified: 1 May 2025

    Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 36943.

    Published: 14 Dec 2023
    8.1
    High

    CVE-2023-6572

    Last Modified: 22 May 2025

    Command Injection in GitHub repository gradio-app/gradio prior to main.

    Published: 14 Dec 2023
    8.2
    High

    CVE-2023-6569

    Last Modified: 22 May 2025

    External Control of File Name or Path in h2oai/h2o-3

    Published: 14 Dec 2023
    6.5
    Medium

    CVE-2023-50371

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Page Visit Counter Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress allows Stored XSS.This issue affects Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress: from n/a through 8.0.6.

    Published: 14 Dec 2023
    6.1
    Medium

    CVE-2023-40627

    Last Modified: 21 Nov 2024

    A reflected XSS vulnerability was discovered in the LivingWord component for Joomla.

    Published: 14 Dec 2023
    6.1
    Medium

    CVE-2023-40659

    Last Modified: 21 Nov 2024

    A reflected XSS vulnerability was discovered in the Easy Quick Contact module for Joomla.

    Published: 14 Dec 2023
    6.1
    Medium

    CVE-2023-40658

    Last Modified: 21 Nov 2024

    A reflected XSS vulnerability was discovered in the Clicky Analytics Dashboard module for Joomla.

    Published: 14 Dec 2023
    6.1
    Medium

    CVE-2023-40628

    Last Modified: 21 Nov 2024

    A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.

    Published: 14 Dec 2023
    9.8
    Critical

    CVE-2023-40629

    Last Modified: 21 Nov 2024

    SQLi vulnerability in LMS Lite component for Joomla.

    Published: 14 Dec 2023
    9.8
    Critical

    CVE-2023-49708

    Last Modified: 21 Nov 2024

    SQLi vulnerability in Starshop component for Joomla.

    Published: 14 Dec 2023
    6.1
    Medium

    CVE-2023-40656

    Last Modified: 21 Nov 2024

    A reflected XSS vulnerability was discovered in the Quickform component for Joomla.

    Published: 14 Dec 2023
    9.8
    Critical

    CVE-2023-49707

    Last Modified: 21 Nov 2024

    SQLi vulnerability in S5 Register module for Joomla.

    Published: 14 Dec 2023
    6.1
    Medium

    CVE-2023-40657

    Last Modified: 21 Nov 2024

    A reflected XSS vulnerability was discovered in the Joomdoc component for Joomla.

    Published: 14 Dec 2023
    9.8
    Critical

    CVE-2023-40630

    Last Modified: 21 Nov 2024

    Unauthenticated LFI/SSRF in JCDashboards component for Joomla.

    Published: 14 Dec 2023
    6.1
    Medium

    CVE-2023-40655

    Last Modified: 4 Dec 2024

    A reflected XSS vulnerability was discovered in the Proforms Basic component for Joomla.

    Published: 14 Dec 2023
    6.5
    Medium

    CVE-2023-25644

    Last Modified: 22 May 2025

    There is a denial of service vulnerability in some ZTE mobile internet products. Due to insufficient validation of Web interface parameter, an attacker could use the vulnerability to perform a denial of service attack.

    Published: 14 Dec 2023
    4.2
    Medium

    CVE-2023-1904

    Last Modified: 21 Nov 2024

    In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server.

    Published: 14 Dec 2023
    8.4
    High

    CVE-2023-25643

    Last Modified: 21 Nov 2024

    There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters, an authenticated attacker could use the vulnerability to execute arbitrary commands.

    Published: 14 Dec 2023
    5.9
    Medium

    CVE-2023-25642

    Last Modified: 21 Nov 2024

    There is a buffer overflow vulnerability in some ZTE mobile internet producsts. Due to insufficient validation of tcp port parameter, an authenticated attacker could use the vulnerability to perform a denial of service attack. 

    Published: 14 Dec 2023
    4.3
    Medium

    CVE-2023-25651

    Last Modified: 21 Nov 2024

    There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SMS interface parameter, an authenticated attacker could use the vulnerability to execute SQL injection and cause information leak.

    Published: 14 Dec 2023
    6.5
    Medium

    CVE-2023-25650

    Last Modified: 28 Jan 2025

    There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads.

    Published: 14 Dec 2023
    6.5
    Medium

    CVE-2023-25648

    Last Modified: 28 Jan 2025

    There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attacker with ordinary user privileges could construct a fake DLL to execute command to escalate local privileges.

    Published: 14 Dec 2023
    5.3
    Medium

    CVE-2023-6407

    Last Modified: 25 Feb 2026

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file deletion upon service restart when accessed by a local and low-privileged attacker.

    Published: 14 Dec 2023
    6.5
    Medium

    CVE-2023-5630

    Last Modified: 21 Nov 2024

    A CWE-494: Download of Code Without Integrity Check vulnerability exists that could allow a privileged user to install an untrusted firmware.

    Published: 14 Dec 2023
    8.2
    High

    CVE-2023-5629

    Last Modified: 21 Nov 2024

    A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could cause disclosure of information through phishing attempts over HTTP.

    Published: 14 Dec 2023
    7.2
    High

    CVE-2023-41719

    Last Modified: 21 Nov 2024

    A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker impersonating an administrator may craft a specific web request which may lead to remote code execution.

    Published: 14 Dec 2023
    7.8
    High

    CVE-2023-41720

    Last Modified: 21 Nov 2024

    A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Ivanti Connect Secure (ICS) appliance can escalate their privileges by exploiting a vulnerable installed application. This vulnerability allows the attacker to gain elevated execution privileges on the affected system.

    Published: 14 Dec 2023
    6.2
    Medium

    CVE-2023-45184

    Last Modified: 21 Nov 2024

    IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to obtain a decryption key due to improper authority checks. IBM X-Force ID: 268270.

    Published: 14 Dec 2023
    7.5
    High

    CVE-2023-43042

    Last Modified: 22 May 2025

    IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.3 products use default passwords for a privileged user. IBM X-Force ID: 266874.

    Published: 14 Dec 2023
    5.9
    Medium

    CVE-2022-43843

    Last Modified: 21 Nov 2024

    IBM Spectrum Scale 5.1.5.0 through 5.1.5.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 239080.

    Published: 14 Dec 2023
    8.8
    High

    CVE-2023-50564

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary code via uploading a crafted ZIP file.

    Published: 14 Dec 2023