CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2023-47811

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Suresh KUMAR Mukhiya Anywhere Flash Embed plugin <= 1.0.5 versions.

    Published: 22 Nov 2023
    6.5
    Medium

    CVE-2023-47810

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Asdqwe Dev Ajax Domain Checker plugin <= 1.3.0 versions.

    Published: 22 Nov 2023
    5.9
    Medium

    CVE-2023-47809

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Accordion plugin <= 2.6 versions.

    Published: 22 Nov 2023
    6.5
    Medium

    CVE-2023-47808

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Christina Uechi Add Widgets to Page plugin <= 1.3.2 versions.

    Published: 22 Nov 2023
    6.5
    Medium

    CVE-2023-47786

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LayerSlider plugin <= 7.7.9 versions.

    Published: 22 Nov 2023
    7.1
    High

    CVE-2023-47773

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YAS Global Team Permalinks Customizer plugin <= 2.8.2 versions.

    Published: 22 Nov 2023
    7.1
    High

    CVE-2023-47768

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson Footer Putter plugin <= 1.17 versions.

    Published: 22 Nov 2023
    7.1
    High

    CVE-2023-47767

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fla-shop.Com Interactive World Map plugin <= 3.2.0 versions.

    Published: 22 Nov 2023
    7.1
    High

    CVE-2023-47766

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timo Reith Post Status Notifier Lite plugin <= 1.11.0 versions.

    Published: 22 Nov 2023
    0
    Low

    CVE-2024-0584

    Last Modified: 14 Feb 2024

    Do not use this CVE as it is duplicate of CVE-2023-6932

    Published: 22 Nov 2023
    5.9
    Medium

    CVE-2023-47759

    Last Modified: 29 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premio Chaty chaty allows DOM-Based XSS.This issue affects Chaty: from n/a through <= 3.1.2.

    Published: 22 Nov 2023
    6.5
    Medium

    CVE-2023-6265

    Last Modified: 21 Nov 2024

    ** UNSUPPORTED WHEN ASSIGNED ** Draytek Vigor2960 v1.5.1.4 and v1.5.1.5 are vulnerable to directory traversal via the mainfunction.cgi dumpSyslog 'option' parameter allowing an authenticated attacker with access to the web management interface to delete arbitrary files. Vigor2960 is no longer supported.

    Published: 22 Nov 2023
    7.1
    High

    CVE-2023-30496

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MagePeople Team WpBusTicketly plugin <= 5.2.5 versions.

    Published: 22 Nov 2023
    4.3
    Medium

    CVE-2023-47825

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in TienCOP WP EXtra plugin <= 6.4 versions.

    Published: 22 Nov 2023
    5.4
    Medium

    CVE-2023-47824

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in wpWax Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator plugin <= 1.3.8 versions.

    Published: 22 Nov 2023
    4.3
    Medium

    CVE-2023-47819

    Last Modified: 5 Jun 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Dang Ngoc Binh Easy Call Now by ThikShare plugin <= 1.1.0 versions.

    Published: 22 Nov 2023
    6.2
    Medium

    CVE-2023-25682

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 247034.

    Published: 22 Nov 2023
    5.4
    Medium

    CVE-2023-39925

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Download Community by PeepSo plugin <= 6.1.6.0 versions.

    Published: 22 Nov 2023
    4.3
    Medium

    CVE-2023-47792

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Infinite Uploads Big File Uploads – Increase Maximum File Upload Size plugin <= 2.1.1 versions.

    Published: 22 Nov 2023
    5.3
    Medium

    CVE-2023-6264

    Last Modified: 21 Nov 2024

    Information leak in Content-Security-Policy header in Devolutions Server 2023.3.7.0 allows an unauthenticated attacker to list the configured Devolutions Gateways endpoints.

    Published: 22 Nov 2023
    4.3
    Medium

    CVE-2023-47791

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Leadster plugin <= 1.1.2 versions.

    Published: 22 Nov 2023
    7.1
    High

    CVE-2023-47785

    Last Modified: 5 Jun 2025

    Cross-Site Request Forgery (CSRF) vulnerability in LayerSlider plugin <= 7.7.9 versions.

    Published: 22 Nov 2023
    4.3
    Medium

    CVE-2022-36777

    Last Modified: 21 Nov 2024

    IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.16.0could allow an authenticated user to obtain sensitive version information that could aid in further attacks against the system. IBM X-Force ID: 233665.

    Published: 22 Nov 2023
    8.8
    High

    CVE-2023-47781

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Thrive Themes Thrive Theme Builder < 3.24.2 versions.

    Published: 22 Nov 2023
    4.3
    Medium

    CVE-2023-47775

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions.

    Published: 22 Nov 2023
    4.3
    Medium

    CVE-2023-47765

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in CodeBard CodeBard's Patron Button and Widgets for Patreon plugin <= 2.1.9 versions.

    Published: 22 Nov 2023
    5.4
    Medium

    CVE-2023-47758

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form plugin <= 1.7.11 versions.

    Published: 22 Nov 2023
    6.5
    Medium

    CVE-2023-47755

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AazzTech WooCommerce Product Carousel Slider plugin <= 3.3.5 versions.

    Published: 22 Nov 2023
    8.3
    High

    CVE-2023-6263

    Last Modified: 21 Nov 2024

    An issue was discovered by IPVM team in Network Optix NxCloud before 23.1.0.40440. It was possible to add a fake VMS server to NxCloud by using the exact identification of a legitimate VMS server. As result, it was possible to retrieve authorization headers from legitimate users when the legitimate client connects to the fake VMS server.

    Published: 22 Nov 2023
    4.3
    Medium

    CVE-2023-25986

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in WattIsIt PayGreen – Ancienne version plugin <= 4.10.2 versions.

    Published: 22 Nov 2023
    4.3
    Medium

    CVE-2023-25987

    Last Modified: 5 Jun 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Aleksandar Urošević My YouTube Channel plugin <= 3.23.3 versions.

    Published: 22 Nov 2023
    5.5
    Medium

    CVE-2023-20241

    Last Modified: 5 Jun 2025

    Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. These vulnerabilities are due to an out-of-bounds memory read from Cisco Secure Client Software. An attacker could exploit these vulnerabilities by logging in to an affected device at the same time that another user is accessing Cisco Secure Client on the same system, and then sending crafted packets to a port on that local host. A successful exploit could allow the attacker to crash the VPN Agent service, causing it to be unavailable to all users of the system. To exploit these vulnerabilities, the attacker must have valid credentials on a multi-user system.

    Published: 22 Nov 2023
    5.5
    Medium

    CVE-2023-20240

    Last Modified: 3 Jun 2025

    Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. These vulnerabilities are due to an out-of-bounds memory read from Cisco Secure Client Software. An attacker could exploit these vulnerabilities by logging in to an affected device at the same time that another user is accessing Cisco Secure Client on the same system, and then sending crafted packets to a port on that local host. A successful exploit could allow the attacker to crash the VPN Agent service, causing it to be unavailable to all users of the system. To exploit these vulnerabilities, the attacker must have valid credentials on a multi-user system.

    Published: 22 Nov 2023
    5
    Medium

    CVE-2023-20084

    Last Modified: 21 Nov 2024

    A vulnerability in the endpoint software of Cisco Secure Endpoint for Windows could allow an authenticated, local attacker to evade endpoint protection within a limited time window. This vulnerability is due to a timing issue that occurs between various software components. An attacker could exploit this vulnerability by persuading a user to put a malicious file into a specific folder and then persuading the user to execute the file within a limited time window. A successful exploit could allow the attacker to cause the endpoint software to fail to quarantine the malicious file or kill its process. Note: This vulnerability only applies to deployments that have the Windows Folder Redirection feature enabled.

    Published: 22 Nov 2023
    7.6
    High

    CVE-2023-6157

    Last Modified: 21 Nov 2024

    Improper neutralization of livestatus command delimiters in ajax_search in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for authorized users.

    Published: 22 Nov 2023
    7.6
    High

    CVE-2023-6156

    Last Modified: 21 Nov 2024

    Improper neutralization of livestatus command delimiters in the availability timeline in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for authorized users.

    Published: 22 Nov 2023
    8.6
    High

    CVE-2023-43082

    Last Modified: 21 Nov 2024

    Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a certificate signed by a third-party public Certificate Authority, the vCenter CA could be spoofed by an attacker who can obtain a CA-signed certificate.

    Published: 22 Nov 2023
    8.8
    High

    CVE-2023-2497

    Last Modified: 8 Apr 2026

    The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to missing or incorrect nonce validation on the 'import_settings' function. This makes it possible for unauthenticated attackers to exploit PHP Object Injection due to the use of unserialize() on the user supplied parameter via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 22 Nov 2023
    6.4
    Medium

    CVE-2023-5704

    Last Modified: 8 Apr 2026

    The CPO Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 22 Nov 2023
    6.3
    Medium

    CVE-2023-6008

    Last Modified: 8 Apr 2026

    The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to add, modify, or delete user meta and plugin options.

    Published: 22 Nov 2023
    8.8
    High

    CVE-2023-6009

    Last Modified: 8 Apr 2026

    The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to insufficient restriction on the 'userpro_update_user_profile' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_capabilities' parameter during a profile update.

    Published: 22 Nov 2023
    4.3
    Medium

    CVE-2023-5385

    Last Modified: 8 Apr 2026

    The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_copy_posts function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to create copies of arbitrary posts.

    Published: 22 Nov 2023
    9.8
    Critical

    CVE-2023-2449

    Last Modified: 8 Apr 2026

    The UserPro plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 5.1.1. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (userpro_process_form). The function uses the plaintext value of a password reset key instead of a hashed value which means it can easily be retrieved and subsequently used. An attacker can leverage CVE-2023-2448 and CVE-2023-2446, or another vulnerability like SQL Injection in another plugin or theme installed on the site to successfully exploit this vulnerability.

    Published: 22 Nov 2023
    4.4
    Medium

    CVE-2023-5715

    Last Modified: 8 Apr 2026

    The Website Optimization – Plerdy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tracking code settings in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 22 Nov 2023
    6.4
    Medium

    CVE-2023-5708

    Last Modified: 8 Apr 2026

    The WP Post Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'column' shortcode in all versions up to, and including, 2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 22 Nov 2023
    4.3
    Medium

    CVE-2023-5383

    Last Modified: 8 Apr 2026

    The Funnelforms Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4. This is due to missing or incorrect nonce validation on the fnsf_copy_posts function. This makes it possible for unauthenticated attackers to create copies of arbitrary posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE-2023-5990 appears to be a duplicate of this issue.

    Published: 22 Nov 2023
    4.3
    Medium

    CVE-2023-5387

    Last Modified: 8 Apr 2026

    The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_af2_trigger_dark_mode function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to enable or disable the dark mode plugin setting.

    Published: 22 Nov 2023
    8.8
    High

    CVE-2023-5465

    Last Modified: 8 Apr 2026

    The Popup with fancybox plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 22 Nov 2023
    6.4
    Medium

    CVE-2023-5163

    Last Modified: 8 Apr 2026

    The Weather Atlas Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shortcode-weather-atlas' shortcode in versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 22 Nov 2023
    6.4
    Medium

    CVE-2023-5469

    Last Modified: 8 Apr 2026

    The Drop Shadow Boxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dropshadowbox' shortcode in versions up to, and including, 1.7.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 22 Nov 2023