CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2023-40674

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lasso Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management allows Stored XSS.This issue affects Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management: from n/a through 118.

    Published: 30 Nov 2023
    5.9
    Medium

    CVE-2023-40680

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Yoast Yoast SEO allows Stored XSS.This issue affects Yoast SEO: from n/a through 21.0.

    Published: 30 Nov 2023
    5.9
    Medium

    CVE-2023-41127

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Evergreen Content Poster Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media allows Stored XSS.This issue affects Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media: from n/a through 1.3.6.1.

    Published: 30 Nov 2023
    5.9
    Medium

    CVE-2023-41128

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Iqonic Design WP Roadmap – Product Feedback Board allows Stored XSS.This issue affects WP Roadmap – Product Feedback Board: from n/a through 1.0.8.

    Published: 30 Nov 2023
    5.9
    Medium

    CVE-2023-41136

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Laurence/OhMyBox.Info Simple Long Form allows Stored XSS.This issue affects Simple Long Form: from n/a through 2.2.2.

    Published: 30 Nov 2023
    6.5
    Medium

    CVE-2023-45050

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Jetpack – WP Security, Backup, Speed, & Growth allows Stored XSS.This issue affects Jetpack – WP Security, Backup, Speed, & Growth: from n/a through 12.8-a.1.

    Published: 30 Nov 2023
    6.5
    Medium

    CVE-2023-47505

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elementor allows Cross-Site Scripting (XSS).This issue affects Elementor: from n/a through 3.16.4.

    Published: 30 Nov 2023
    6.5
    Medium

    CVE-2023-47777

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce Blocks allows Stored XSS.This issue affects WooCommerce: from n/a through 8.1.1; WooCommerce Blocks: from n/a through 11.1.1.

    Published: 30 Nov 2023
    6.5
    Medium

    CVE-2023-47850

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PeepSo Community by PeepSo – Social Network, Membership, Registration, User Profiles allows Stored XSS.This issue affects Community by PeepSo – Social Network, Membership, Registration, User Profiles: from n/a through 6.2.2.0.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-49733

    Last Modified: 13 Feb 2025

    Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.

    Published: 30 Nov 2023
    6.5
    Medium

    CVE-2023-47851

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Akhtarujjaman Shuvo Bootstrap Shortcodes Ultimate allows Stored XSS.This issue affects Bootstrap Shortcodes Ultimate: from n/a through 4.3.1.

    Published: 30 Nov 2023
    6.5
    Medium

    CVE-2023-47854

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Howard Ehrenberg Parallax Image allows Stored XSS.This issue affects Parallax Image: from n/a through 1.7.1.

    Published: 30 Nov 2023
    6.5
    Medium

    CVE-2023-48289

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SpreadsheetConverter Import Spreadsheets from Microsoft Excel allows Stored XSS.This issue affects Import Spreadsheets from Microsoft Excel: from n/a through 10.1.3.

    Published: 30 Nov 2023
    7.1
    High

    CVE-2023-48322

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eDoc Intelligence eDoc Employee Job Application – Best WordPress Job Manager for Employees allows Reflected XSS.This issue affects eDoc Employee Job Application – Best WordPress Job Manager for Employees: from n/a through 1.13.

    Published: 30 Nov 2023
    7.1
    High

    CVE-2023-48326

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager allows Reflected XSS.This issue affects Events Manager: from n/a through 6.4.5.

    Published: 30 Nov 2023
    5.9
    Medium

    CVE-2023-48329

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard Fast Custom Social Share by CodeBard allows Stored XSS.This issue affects Fast Custom Social Share by CodeBard: from n/a through 1.1.1.

    Published: 30 Nov 2023
    6.5
    Medium

    CVE-2023-48336

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cybernetikz Easy Social Icons allows Stored XSS.This issue affects Easy Social Icons: from n/a through 3.2.4.

    Published: 30 Nov 2023
    5.9
    Medium

    CVE-2023-48737

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PT Trijaya Digital Grup TriPay Payment Gateway allows Stored XSS.This issue affects TriPay Payment Gateway: from n/a through 3.2.7.

    Published: 30 Nov 2023
    5.8
    Medium

    CVE-2023-48743

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Menard Simply Exclude allows Reflected XSS.This issue affects Simply Exclude: from n/a through 2.0.6.6.

    Published: 30 Nov 2023
    4.7
    Medium

    CVE-2021-36806

    Last Modified: 2 Dec 2024

    A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on Sophos Email Appliance older than version 4.5.3.4.

    Published: 30 Nov 2023
    6.5
    Medium

    CVE-2023-49620

    Last Modified: 13 Feb 2025

    Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), with unauthorized access vulnerability (IDOR), but after version 3.1.0 we fixed this issue. We mark this cve as moderate level because it still requires user login to operate, please upgrade to version 3.1.0 to avoid this vulnerability

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2022-45135

    Last Modified: 13 Feb 2025

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.

    Published: 30 Nov 2023
    7.2
    High

    CVE-2023-49701

    Last Modified: 21 Nov 2024

    Memory Corruption in SIM management while USIMPhase2init

    Published: 30 Nov 2023
    8.3
    High

    CVE-2023-49077

    Last Modified: 21 Nov 2024

    Mailcow: dockerized is an open source groupware/email suite based on docker. A Cross-Site Scripting (XSS) vulnerability has been identified within the Quarantine UI of the system. This vulnerability poses a significant threat to administrators who utilize the Quarantine feature. An attacker can send a carefully crafted email containing malicious JavaScript code. This issue has been patched in version 2023-11.

    Published: 30 Nov 2023
    6.7
    Medium

    CVE-2023-49700

    Last Modified: 21 Nov 2024

    Security best practices violations, a string operation in Streamingmedia will write past the end of fixed-size destination buffer if the source buffer is too large.

    Published: 30 Nov 2023
    8.6
    High

    CVE-2023-49095

    Last Modified: 27 Nov 2024

    nexkey is a microblogging platform. Insufficient validation of ActivityPub requests received in inbox could allow any user to impersonate another user in certain circumstances. This issue has been patched in version 12.122.2.

    Published: 30 Nov 2023
    6.7
    Medium

    CVE-2023-49699

    Last Modified: 21 Nov 2024

    Memory Corruption in IMS while calling VoLTE Streamingmedia Interface

    Published: 30 Nov 2023
    4.3
    Medium

    CVE-2023-49076

    Last Modified: 5 Jun 2025

    Customer-data-framework allows management of customer data within Pimcore. There are no tokens or headers to prevent CSRF attacks from occurring, therefore an attacker could abuse this vulnerability to create new customers. This issue has been patched in version 4.0.5.

    Published: 30 Nov 2023
    4.3
    Medium

    CVE-2023-49094

    Last Modified: 5 Jun 2025

    Symbolicator is a symbolication service for native stacktraces and minidumps with symbol server support. An attacker could make Symbolicator send arbitrary GET HTTP requests to internal IP addresses by using a specially crafted HTTP endpoint. The response could be reflected to the attacker if they have an account on Sentry instance. The issue has been fixed in the release 23.11.2.

    Published: 30 Nov 2023
    8.1
    High

    CVE-2023-49097

    Last Modified: 27 Nov 2024

    ZITADEL is an identity infrastructure system. ZITADEL uses the notification triggering requests Forwarded or X-Forwarded-Host header to build the button link sent in emails for confirming a password reset with the emailed code. If this header is overwritten and a user clicks the link to a malicious site in the email, the secret code can be retrieved and used to reset the users password and take over his account. Accounts with MFA or Passwordless enabled can not be taken over by this attack. This issue has been patched in versions 2.41.6, 2.40.10 and 2.39.9.

    Published: 30 Nov 2023
    —
    Unknown

    CVE-2023-47214

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 30 Nov 2023
    —
    Unknown

    CVE-2023-49605

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 30 Nov 2023
    —
    Unknown

    CVE-2023-42777

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 30 Nov 2023
    —
    Unknown

    CVE-2023-46101

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 30 Nov 2023
    —
    Unknown

    CVE-2023-46709

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 30 Nov 2023
    —
    Unknown

    CVE-2023-48337

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 30 Nov 2023
    —
    Unknown

    CVE-2023-49116

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 30 Nov 2023
    —
    Unknown

    CVE-2023-41083

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 30 Nov 2023
    —
    Unknown

    CVE-2023-49592

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 30 Nov 2023
    7.8
    High

    CVE-2023-5247

    Last Modified: 2 Dec 2024

    Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software Products allows a malicious attacker to execute a malicious code by having legitimate users open a specially crafted project file, which could result in information disclosure, tampering and deletion, or a denial-of-service (DoS) condition.

    Published: 30 Nov 2023
    4.3
    Medium

    CVE-2023-5772

    Last Modified: 8 Apr 2026

    The Debug Log Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the clear_log() function. This makes it possible for unauthenticated attackers to clear the debug log via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-4474

    Last Modified: 16 Dec 2025

    The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-4473

    Last Modified: 16 Dec 2025

    A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

    Published: 30 Nov 2023
    8.8
    High

    CVE-2023-37928

    Last Modified: 13 Feb 2025

    A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

    Published: 30 Nov 2023
    8.8
    High

    CVE-2023-37927

    Last Modified: 13 Feb 2025

    The improper neutralization of special elements in the CGI program of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-35138

    Last Modified: 21 Nov 2024

    A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2023-35137

    Last Modified: 21 Nov 2024

    An improper authentication vulnerability in the authentication module of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to obtain system information by sending a crafted URL to a vulnerable device.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-3741

    Last Modified: 2 Dec 2024

    An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execute any command on the device.

    Published: 30 Nov 2023
    7.5
    High

    CVE-2024-9779

    Last Modified: 15 Apr 2026

    A flaw was found in Open Cluster Management (OCM) when a user has access to the worker nodes which contain the cluster-manager or klusterlet deployments. The cluster-manager deployment uses a service account with the same name "cluster-manager" which is bound to a ClusterRole also named "cluster-manager", which includes the permission to create Pod resources. If this deployment runs a pod on an attacker-controlled node, the attacker can obtain the cluster-manager's token and steal any service account token by creating and mounting the target service account to control the whole cluster.

    Published: 30 Nov 2023
    9.8
    Critical

    CVE-2023-47418

    Last Modified: 21 Nov 2024

    Remote Code Execution (RCE) vulnerability in o2oa version 8.1.2 and before, allows attackers to create a new interface in the service management function to execute JavaScript.

    Published: 30 Nov 2023