CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2023-5210

    Last Modified: 21 Nov 2024

    The AMP+ Plus WordPress plugin through 3.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 4 Dec 2023
    5.4
    Medium

    CVE-2023-4460

    Last Modified: 21 Nov 2024

    The Uploading SVG, WEBP and ICO files WordPress plugin through 1.2.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

    Published: 4 Dec 2023
    6.1
    Medium

    CVE-2023-5951

    Last Modified: 20 Feb 2025

    The Welcart e-Commerce WordPress plugin before 2.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 4 Dec 2023
    4.8
    Medium

    CVE-2023-5137

    Last Modified: 29 May 2025

    The Simply Excerpts WordPress plugin through 1.4 does not sanitize and escape some fields in the plugin settings, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed (for example in a multisite setup).

    Published: 4 Dec 2023
    8.8
    High

    CVE-2023-5762

    Last Modified: 21 Nov 2024

    The Filr WordPress plugin before 1.2.3.6 is vulnerable from an RCE (Remote Code Execution) vulnerability, which allows the operating system to execute commands and fully compromise the server on behalf of a user with Author-level privileges.

    Published: 4 Dec 2023
    4.8
    Medium

    CVE-2023-5874

    Last Modified: 21 Nov 2024

    The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 4 Dec 2023
    8.8
    High

    CVE-2023-5953

    Last Modified: 29 May 2025

    The Welcart e-Commerce WordPress plugin before 2.9.5 does not validate files to be uploaded, as well as does not have authorisation and CSRF in an AJAX action handling such upload. As a result, any authenticated users, such as subscriber could upload arbitrary files, such as PHP on the server

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-5952

    Last Modified: 20 Feb 2025

    The Welcart e-Commerce WordPress plugin before 2.9.5 unserializes user input from cookies, which could allow unautehtniacted users to perform PHP Object Injection when a suitable gadget is present on the blog

    Published: 4 Dec 2023
    6.5
    Medium

    CVE-2023-5105

    Last Modified: 21 Nov 2024

    The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass the file download logic and download files such as `wp-config.php`

    Published: 4 Dec 2023
    6.5
    Medium

    CVE-2023-5979

    Last Modified: 21 Nov 2024

    The eCommerce Product Catalog Plugin for WordPress plugin before 3.3.26 does not have CSRF checks in some of its admin pages, which could allow attackers to make logged-in users perform unwanted actions via CSRF attacks, such as delete all products

    Published: 4 Dec 2023
    3.5
    Low

    CVE-2023-49080

    Last Modified: 13 Feb 2025

    The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. Unhandled errors in API requests coming from an authenticated user include traceback information, which can include path information. There is no known mechanism by which to trigger these errors without authentication, so the paths revealed are not considered particularly sensitive, given that the requesting user has arbitrary execution permissions already in the same environment. A fix has been introduced in commit `0056c3aa52` which no longer includes traceback information in JSON error responses. For compatibility, the traceback field is present, but always empty. This commit has been included in version 2.11.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 4 Dec 2023
    7.5
    High

    CVE-2023-47633

    Last Modified: 27 Nov 2024

    Traefik is an open source HTTP reverse proxy and load balancer. The traefik docker container uses 100% CPU when it serves as its own backend, which is an automatically generated route resulting from the Docker integration in the default configuration. This issue has been addressed in versions 2.10.6 and 3.0.0-beta5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 4 Dec 2023
    4.8
    Medium

    CVE-2023-47106

    Last Modified: 21 Nov 2024

    Traefik is an open source HTTP reverse proxy and load balancer. When a request is sent to Traefik with a URL fragment, Traefik automatically URL encodes and forwards the fragment to the backend server. This violates RFC 7230 because in the origin-form the URL should only contain the absolute path and the query. When this is combined with another frontend proxy like Nginx, it can be used to bypass frontend proxy URI-based access control restrictions. This vulnerability has been addressed in versions 2.10.6 and 3.0.0-beta5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 4 Dec 2023
    5.9
    Medium

    CVE-2023-47124

    Last Modified: 18 Dec 2024

    Traefik is an open source HTTP reverse proxy and load balancer. When Traefik is configured to use the `HTTPChallenge` to generate and renew the Let's Encrypt TLS certificates, the delay authorized to solve the challenge (50 seconds) can be exploited by attackers to achieve a `slowloris attack`. This vulnerability has been patch in version 2.10.6 and 3.0.0-beta5. Users are advised to upgrade. Users unable to upgrade should replace the `HTTPChallenge` with the `TLSChallenge` or the `DNSChallenge`.

    Published: 4 Dec 2023
    5.9
    Medium

    CVE-2023-5768

    Last Modified: 21 Nov 2024

    A vulnerability exists in the HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Incomplete or wrong received APDU frame layout may cause blocking on link layer. Error reason was an endless blocking when reading incoming frames on link layer with wrong length information of APDU or delayed reception of data octets. Only communication link of affected HCI IEC 60870-5-104 is blocked. If attack sequence stops the communication to the previously attacked link gets normal again.

    Published: 4 Dec 2023
    6
    Medium

    CVE-2023-5767

    Last Modified: 21 Nov 2024

    A vulnerability exists in the webserver that affects the RTU500 series product versions listed below. A malicious actor could perform cross-site scripting on the webserver due to an RDT language file being improperly sanitized.

    Published: 4 Dec 2023
    4
    Medium

    CVE-2023-6460

    Last Modified: 7 May 2026

    A potential logging of the firestore key via logging within nodejs-firestore exists - Developers who were logging objects through this._settings would be logging the firestore key as well potentially exposing it to anyone with logs read access. We recommend upgrading to version 6.1.0 to avoid this issue

    Published: 4 Dec 2023
    7.8
    High

    CVE-2023-32804

    Last Modified: 21 Nov 2024

    Out-of-bounds Write vulnerability in Arm Ltd Midgard GPU Userspace Driver, Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a local non-privileged user to write a constant pattern to a limited amount of memory not allocated by the user space driver.This issue affects Midgard GPU Userspace Driver: from r0p0 through r32p0; Bifrost GPU Userspace Driver: from r0p0 through r44p0; Valhall GPU Userspace Driver: from r19p0 through r44p0; Arm 5th Gen GPU Architecture Userspace Driver: from r41p0 through r44p0.

    Published: 4 Dec 2023
    8.1
    High

    CVE-2023-44302

    Last Modified: 21 Nov 2024

    Dell DM5500 5.14.0.0 and prior contain an improper authentication vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access of resources or functionality that could possibly lead to execute arbitrary code.

    Published: 4 Dec 2023
    5.4
    Medium

    CVE-2023-44301

    Last Modified: 21 Nov 2024

    Dell DM5500 5.14.0.0 and prior contain a Reflected Cross-Site Scripting Vulnerability. A network attacker with low privileges could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript code in a victim user's web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery.

    Published: 4 Dec 2023
    5.5
    Medium

    CVE-2023-44300

    Last Modified: 21 Nov 2024

    Dell DM5500 5.14.0.0, contain a Plain-text Password Storage Vulnerability in the appliance. A local attacker with privileges could potentially exploit this vulnerability, leading to the disclosure of certain service credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

    Published: 4 Dec 2023
    6.5
    Medium

    CVE-2023-44306

    Last Modified: 21 Nov 2024

    Dell DM5500 contains a path traversal vulnerability in the appliance. A remote attacker with high privileges could potentially exploit this vulnerability to overwrite configuration files stored on the server filesystem.

    Published: 4 Dec 2023
    8.1
    High

    CVE-2023-44305

    Last Modified: 21 Nov 2024

    Dell DM5500 5.14.0.0, contains a Stack-based Buffer Overflow Vulnerability in the appliance. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by sending specially crafted input data.

    Published: 4 Dec 2023
    8.8
    High

    CVE-2023-44304

    Last Modified: 21 Nov 2024

    Dell DM5500 contains a privilege escalation vulnerability in the appliance. A remote attacker with low privileges could potentially exploit this vulnerability to escape the restricted shell and gain root access to the appliance.

    Published: 4 Dec 2023
    7.2
    High

    CVE-2023-44291

    Last Modified: 21 Nov 2024

    Dell DM5500 5.14.0.0 contains an OS command injection vulnerability in the appliance. A remote attacker with high privileges could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker.

    Published: 4 Dec 2023
    7.7
    High

    CVE-2023-49287

    Last Modified: 29 May 2025

    TinyDir is a lightweight C directory and file reader. Buffer overflows in the `tinydir_file_open()` function. This vulnerability has been patched in version 1.2.6.

    Published: 4 Dec 2023
    8.8
    High

    CVE-2023-49108

    Last Modified: 21 Nov 2024

    Path traversal vulnerability exists in RakRak Document Plus Ver.3.2.0.0 to Ver.6.4.0.7 (excluding Ver.6.1.1.3a). If this vulnerability is exploited, arbitrary files on the server may be obtained or deleted by a user of the product with specific privileges.

    Published: 4 Dec 2023
    6.7
    Medium

    CVE-2023-32870

    Last Modified: 21 Nov 2024

    In display drm, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363740; Issue ID: ALPS07363740.

    Published: 4 Dec 2023
    6.7
    Medium

    CVE-2023-32869

    Last Modified: 2 Dec 2024

    In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363632; Issue ID: ALPS07363689.

    Published: 4 Dec 2023
    6.7
    Medium

    CVE-2023-32868

    Last Modified: 21 Nov 2024

    In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363632; Issue ID: ALPS07363632.

    Published: 4 Dec 2023
    6.7
    Medium

    CVE-2023-32867

    Last Modified: 21 Nov 2024

    In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560793; Issue ID: ALPS07560793.

    Published: 4 Dec 2023
    6.7
    Medium

    CVE-2023-32866

    Last Modified: 21 Nov 2024

    In mmp, there is a possible memory corruption due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07342152; Issue ID: ALPS07342152.

    Published: 4 Dec 2023
    6.7
    Medium

    CVE-2023-32865

    Last Modified: 21 Nov 2024

    In display drm, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363456; Issue ID: ALPS07363456.

    Published: 4 Dec 2023
    6.7
    Medium

    CVE-2023-32864

    Last Modified: 21 Nov 2024

    In display drm, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07292187; Issue ID: ALPS07292187.

    Published: 4 Dec 2023
    6.7
    Medium

    CVE-2023-32863

    Last Modified: 29 May 2025

    In display drm, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326314; Issue ID: ALPS07326314.

    Published: 4 Dec 2023
    6.7
    Medium

    CVE-2023-32862

    Last Modified: 21 Nov 2024

    In display, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07388762; Issue ID: ALPS07388762.

    Published: 4 Dec 2023
    6.7
    Medium

    CVE-2023-32861

    Last Modified: 2 Dec 2024

    In display, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08059081; Issue ID: ALPS08059081.

    Published: 4 Dec 2023
    6.7
    Medium

    CVE-2023-32860

    Last Modified: 21 Nov 2024

    In display, there is a possible classic buffer overflow due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929788; Issue ID: ALPS07929788.

    Published: 4 Dec 2023
    6.7
    Medium

    CVE-2023-32859

    Last Modified: 21 Nov 2024

    In meta, there is a possible classic buffer overflow due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08000473; Issue ID: ALPS08000473.

    Published: 4 Dec 2023
    7.5
    High

    CVE-2023-32846

    Last Modified: 21 Nov 2024

    In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01128524; Issue ID: MOLY01138453 (MSV-861).

    Published: 4 Dec 2023
    7.5
    High

    CVE-2023-32845

    Last Modified: 21 Nov 2024

    In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01128524; Issue ID: MOLY01139296 (MSV-860).

    Published: 4 Dec 2023
    7.5
    High

    CVE-2023-32844

    Last Modified: 21 Nov 2024

    In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01128524; Issue ID: MOLY01130183 (MSV-850).

    Published: 4 Dec 2023
    7.5
    High

    CVE-2023-32843

    Last Modified: 29 May 2025

    In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01130204; Issue ID: MOLY01130204 (MSV-849).

    Published: 4 Dec 2023
    7.5
    High

    CVE-2023-32842

    Last Modified: 21 Nov 2024

    In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01130256; Issue ID: MOLY01130256 (MSV-848).

    Published: 4 Dec 2023
    7.5
    High

    CVE-2023-32841

    Last Modified: 21 Nov 2024

    In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01128524; Issue ID: MOLY01128524 (MSV-846).

    Published: 4 Dec 2023
    4.4
    Medium

    CVE-2023-32858

    Last Modified: 21 Nov 2024

    In GZ, there is a possible information disclosure due to a missing data erasing. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07806008; Issue ID: ALPS07806008.

    Published: 4 Dec 2023
    4.4
    Medium

    CVE-2023-32857

    Last Modified: 21 Nov 2024

    In display, there is a possible out of bounds read due to an incorrect status check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07993705; Issue ID: ALPS07993710.

    Published: 4 Dec 2023
    4.4
    Medium

    CVE-2023-32856

    Last Modified: 21 Nov 2024

    In display, there is a possible out of bounds read due to an incorrect status check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07993705; Issue ID: ALPS07993705.

    Published: 4 Dec 2023
    6.7
    Medium

    CVE-2023-32855

    Last Modified: 21 Nov 2024

    In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07909204; Issue ID: ALPS07909204.

    Published: 4 Dec 2023
    6.7
    Medium

    CVE-2023-32854

    Last Modified: 29 May 2025

    In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08240132; Issue ID: ALPS08240132.

    Published: 4 Dec 2023