CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2023-5710

    Last Modified: 8 Apr 2026

    The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_constants() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve sensitive information such as database credentials.

    Published: 7 Dec 2023
    4.3
    Medium

    CVE-2023-5713

    Last Modified: 8 Apr 2026

    The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve potentially sensitive option values, and deserialize the content of those values.

    Published: 7 Dec 2023
    4.3
    Medium

    CVE-2023-5712

    Last Modified: 8 Apr 2026

    The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_global_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve sensitive global value information.

    Published: 7 Dec 2023
    4.3
    Medium

    CVE-2023-5714

    Last Modified: 8 Apr 2026

    The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_db_specs() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve data key specs.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-5761

    Last Modified: 21 Nov 2024

    The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'url' parameter in versions 1.4.0 to 1.4.6.1 (free) and versions 1.4.0 to 1.5.0 (pro) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 7 Dec 2023
    4.3
    Medium

    CVE-2023-5711

    Last Modified: 8 Apr 2026

    The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_php_info() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve sensitive information provided by PHP info.

    Published: 7 Dec 2023
    6.5
    Medium

    CVE-2023-6566

    Last Modified: 21 Nov 2024

    Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.

    Published: 7 Dec 2023
    8.2
    High

    CVE-2023-43303

    Last Modified: 5 Jul 2026

    An issue in craftbeer bar canvas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token (via captured network traffic).

    Published: 7 Dec 2023
    5.5
    Medium

    CVE-2023-40238

    Last Modified: 25 Feb 2026

    A LogoFAIL issue was discovered in BmpDecoderDxe in Insyde InsydeH2O with kernel 5.2 before 05.28.47, 5.3 before 05.37.47, 5.4 before 05.45.47, 5.5 before 05.53.47, and 5.6 before 05.60.47 for certain Lenovo devices. Image parsing of crafted BMP logo files can copy data to a specific address during the DXE phase of UEFI execution. This occurs because of an integer signedness error involving PixelHeight and PixelWidth during RLE4/RLE8 compression.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-41913

    Last Modified: 18 Dec 2025

    strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKE_SA_INIT message.

    Published: 7 Dec 2023
    8.8
    High

    CVE-2023-33413

    Last Modified: 21 Nov 2024

    The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02, allows remote authenticated users to execute arbitrary commands.

    Published: 7 Dec 2023
    8.8
    High

    CVE-2023-33412

    Last Modified: 21 Nov 2024

    The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions before 3.17.02, allows remote authenticated users to execute arbitrary commands via a crafted request targeting vulnerable cgi endpoints.

    Published: 7 Dec 2023
    5.3
    Medium

    CVE-2023-46871

    Last Modified: 21 Nov 2024

    GPAC version 2.3-DEV-rev602-ged8424300-master in MP4Box contains a memory leak in NewSFDouble scenegraph/vrml_tools.c:300. This vulnerability may lead to a denial of service.

    Published: 7 Dec 2023
    5.4
    Medium

    CVE-2023-48828

    Last Modified: 21 Nov 2024

    Time Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.

    Published: 7 Dec 2023
    5.4
    Medium

    CVE-2023-48839

    Last Modified: 21 Nov 2024

    Appointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.

    Published: 7 Dec 2023
    8.2
    High

    CVE-2023-43304

    Last Modified: 28 May 2025

    An issue in PARK DANDAN mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49429

    Last Modified: 21 Nov 2024

    Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature through the 'mac' parameter at /goform/setModules.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49432

    Last Modified: 26 Nov 2024

    Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform/setMacFilterCfg.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49437

    Last Modified: 28 May 2025

    Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.

    Published: 7 Dec 2023
    8.8
    High

    CVE-2023-49460

    Last Modified: 21 Nov 2024

    libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::decode_uncompressed_image.

    Published: 7 Dec 2023
    6.1
    Medium

    CVE-2023-48208

    Last Modified: 26 Nov 2024

    A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php.

    Published: 7 Dec 2023
    7.5
    High

    CVE-2023-49958

    Last Modified: 21 Nov 2024

    An issue was discovered in Dalmann OCPP.Core through 1.2.0 for OCPP (Open Charge Point Protocol) for electric vehicles. The server processes mishandle StartTransaction messages containing additional, arbitrary properties, or duplicate properties. The last occurrence of a duplicate property is accepted. This could be exploited to alter transaction records or impact system integrity.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49999

    Last Modified: 26 Nov 2024

    Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setUmountUSBPartition.

    Published: 7 Dec 2023
    5.4
    Medium

    CVE-2023-41169

    Last Modified: 21 Nov 2024

    NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 2 of 4).

    Published: 7 Dec 2023
    5.3
    Medium

    CVE-2023-43299

    Last Modified: 21 Nov 2024

    An issue in DA BUTCHERS mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 7 Dec 2023
    8.2
    High

    CVE-2023-43300

    Last Modified: 21 Nov 2024

    An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 7 Dec 2023
    8.2
    High

    CVE-2023-43301

    Last Modified: 21 Nov 2024

    An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 7 Dec 2023
    8.2
    High

    CVE-2023-43302

    Last Modified: 21 Nov 2024

    An issue in sanTas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 7 Dec 2023
    8.8
    High

    CVE-2023-39909

    Last Modified: 21 Nov 2024

    Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-40300

    Last Modified: 21 Nov 2024

    NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-40301

    Last Modified: 28 May 2025

    NETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability.

    Published: 7 Dec 2023
    9.1
    Critical

    CVE-2023-40302

    Last Modified: 21 Nov 2024

    NETSCOUT nGeniusPULSE 3.8 has Weak File Permissions Vulnerability

    Published: 7 Dec 2023
    7.5
    High

    CVE-2023-41106

    Last Modified: 21 Nov 2024

    An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.3. An attacker can gain access to a Zimbra account. This is also fixed in 9.0.0 Patch 35 and 8.8.15 Patch 42.

    Published: 7 Dec 2023
    5.4
    Medium

    CVE-2023-41168

    Last Modified: 21 Nov 2024

    NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 1 of 4).

    Published: 7 Dec 2023
    6.1
    Medium

    CVE-2023-41170

    Last Modified: 21 Nov 2024

    NetScout nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting vulnerability.

    Published: 7 Dec 2023
    5.4
    Medium

    CVE-2023-41171

    Last Modified: 26 Nov 2024

    NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 3 of 4).

    Published: 7 Dec 2023
    5.4
    Medium

    CVE-2023-41172

    Last Modified: 21 Nov 2024

    NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 4 of 4).

    Published: 7 Dec 2023
    5.4
    Medium

    CVE-2023-41905

    Last Modified: 21 Nov 2024

    NETSCOUT nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting (XSS) vulnerability by an authenticated user.

    Published: 7 Dec 2023
    6.1
    Medium

    CVE-2023-43103

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in a web endpoint in Zimbra Collaboration (ZCS) before 10.0.4 via an unsanitized parameter. This is also fixed in 8.8.15 Patch 43 and 9.0.0 Patch 36.

    Published: 7 Dec 2023
    6.1
    Medium

    CVE-2023-43102

    Last Modified: 21 Nov 2024

    An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.4. An XSS issue can be exploited to access the mailbox of an authenticated user. This is also fixed in 8.8.15 Patch 43 and 9.0.0 Patch 36.

    Published: 7 Dec 2023
    5.3
    Medium

    CVE-2023-43298

    Last Modified: 26 Nov 2024

    An issue in SCOL Members Card mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 7 Dec 2023
    6.3
    Medium

    CVE-2023-45866

    Last Modified: 4 Nov 2025

    Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.

    Published: 7 Dec 2023
    7.5
    High

    CVE-2023-46307

    Last Modified: 28 May 2025

    An issue was discovered in server.js in etcd-browser 87ae63d75260. By supplying a /../../../ Directory Traversal input to the URL's GET request while connecting to the remote server port specified during setup, an attacker can retrieve local operating system files from the remote system.

    Published: 7 Dec 2023
    6.1
    Medium

    CVE-2023-46693

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in FormaLMS before 4.0.5 allows attackers to run arbitrary code via title parameters.

    Published: 7 Dec 2023
    5.4
    Medium

    CVE-2023-46857

    Last Modified: 21 Nov 2024

    Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, allowing JavaScript in the SRC attribute of an IFRAME element. An authenticated attack with assets.create permission is required for exploitation.

    Published: 7 Dec 2023
    4.3
    Medium

    CVE-2023-46916

    Last Modified: 21 Nov 2024

    Maxima Max Pro Power 1.0 486A devices allow BLE traffic replay. An attacker can use GATT characteristic handle 0x0012 to perform potentially disruptive actions such as starting a Heart Rate monitor.

    Published: 7 Dec 2023
    5.4
    Medium

    CVE-2023-46974

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in Best Courier Management System v.1.000 allows a remote attacker to execute arbitrary code via a crafted payload to the page parameter in the URL.

    Published: 7 Dec 2023
    6.5
    Medium

    CVE-2023-47440

    Last Modified: 21 Nov 2024

    Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticated attackers to extract sensitive files in the host machine.

    Published: 7 Dec 2023
    5.4
    Medium

    CVE-2023-48172

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability in Shuttle Booking Software 2.0 allows a remote attacker to inject JavaScript via the name, description, title, or address parameter to index.php.

    Published: 7 Dec 2023
    5.3
    Medium

    CVE-2023-48205

    Last Modified: 21 Nov 2024

    Jorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emails.

    Published: 7 Dec 2023