CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2023-47553

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in User Local Inc UserHeat Plugin.This issue affects UserHeat Plugin: from n/a through 1.1.6.

    Published: 18 Nov 2023
    4.3
    Medium

    CVE-2023-47556

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in James Mehorter Device Theme Switcher.This issue affects Device Theme Switcher: from n/a through 3.0.2.

    Published: 18 Nov 2023
    5.4
    Medium

    CVE-2023-47644

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Memberships, Groups and Communities: from n/a through 5.6.6.

    Published: 18 Nov 2023
    5.4
    Medium

    CVE-2023-47649

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in PriceListo Best Restaurant Menu by PriceListo.This issue affects Best Restaurant Menu by PriceListo: from n/a through 1.3.1.

    Published: 18 Nov 2023
    6.5
    Medium

    CVE-2023-47650

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Peter Sterling Add Local Avatar.This issue affects Add Local Avatar: from n/a through 12.1.

    Published: 18 Nov 2023
    4.3
    Medium

    CVE-2023-47651

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Robert Macchi WP Links Page.This issue affects WP Links Page: from n/a through 4.9.4.

    Published: 18 Nov 2023
    5.4
    Medium

    CVE-2023-47655

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi ANAC XML Bandi di Gara.This issue affects ANAC XML Bandi di Gara: from n/a through 7.5.

    Published: 18 Nov 2023
    6.5
    Medium

    CVE-2023-47664

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in edward_plainview Plainview Protect Passwords.This issue affects Plainview Protect Passwords: from n/a through 1.4.

    Published: 18 Nov 2023
    4.3
    Medium

    CVE-2023-47666

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Code Snippets Pro Code Snippets.This issue affects Code Snippets: from n/a through 3.5.0.

    Published: 18 Nov 2023
    4.3
    Medium

    CVE-2023-47667

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Mammothology WP Full Stripe Free.This issue affects WP Full Stripe Free: from n/a through 7.0.16.

    Published: 18 Nov 2023
    4.3
    Medium

    CVE-2023-47670

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Jongmyoung Kim Korea SNS.This issue affects Korea SNS: from n/a through 1.6.3.

    Published: 18 Nov 2023
    5.4
    Medium

    CVE-2023-47671

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Gopi Ramasamy Vertical scroll recent.This issue affects Vertical scroll recent post: from n/a through 14.0.

    Published: 18 Nov 2023
    4.3
    Medium

    CVE-2023-47672

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Swashata WP Category Post List Widget.This issue affects WP Category Post List Widget: from n/a through 2.0.3.

    Published: 18 Nov 2023
    5.4
    Medium

    CVE-2023-47685

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Lukman Nakib Preloader Matrix.This issue affects Preloader Matrix: from n/a through 2.0.1.

    Published: 18 Nov 2023
    5.9
    Medium

    CVE-2023-38361

    Last Modified: 21 Nov 2024

    IBM CICS TX Advanced 10.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 260770.

    Published: 18 Nov 2023
    8.1
    High

    CVE-2023-40363

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.7 could allow an authenticated user to change installation files due to incorrect file permission settings. IBM X-Force ID: 263332.

    Published: 18 Nov 2023
    —
    Unknown

    CVE-2023-47205

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 18 Nov 2023
    —
    Unknown

    CVE-2023-47208

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 18 Nov 2023
    7.5
    High

    CVE-2023-6187

    Last Modified: 8 Apr 2026

    The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fields' function in versions up to, and including, 2.12.3. This makes it possible for authenticated attackers with subscriber privileges or above, to upload arbitrary files on the affected site's server which may make remote code execution possible. This can be exploited if 2Checkout (deprecated since version 2.6) or PayPal Express is set as the payment method and a custom user field is added that is only visible at profile, and not visible at checkout according to its settings.

    Published: 18 Nov 2023
    8.1
    High

    CVE-2023-4214

    Last Modified: 8 Apr 2026

    The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5. This is due to the plugin generating too weak a reset code, and the code used to reset the password has no attempt or time limit.

    Published: 18 Nov 2023
    6.1
    Medium

    CVE-2023-40817

    Last Modified: 21 Nov 2024

    OpenCRX version 5.2.0 is vulnerable to HTML injection via the Product Configuration Name Field.

    Published: 18 Nov 2023
    6.1
    Medium

    CVE-2023-40816

    Last Modified: 21 Nov 2024

    OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Milestone Name Field.

    Published: 18 Nov 2023
    6.1
    Medium

    CVE-2023-40809

    Last Modified: 21 Nov 2024

    OpenCRX version 5.2.0 is vulnerable to HTML injection via the Activity Search Criteria-Activity Number.

    Published: 18 Nov 2023
    6.1
    Medium

    CVE-2023-40810

    Last Modified: 21 Nov 2024

    OpenCRX version 5.2.0 is vulnerable to HTML injection via Product Name Field.

    Published: 18 Nov 2023
    6.1
    Medium

    CVE-2023-40812

    Last Modified: 21 Nov 2024

    OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Group Name Field.

    Published: 18 Nov 2023
    6.1
    Medium

    CVE-2023-40813

    Last Modified: 21 Nov 2024

    OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Saved Search Creation.

    Published: 18 Nov 2023
    6.1
    Medium

    CVE-2023-40814

    Last Modified: 21 Nov 2024

    OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Name Field.

    Published: 18 Nov 2023
    6.1
    Medium

    CVE-2023-40815

    Last Modified: 21 Nov 2024

    OpenCRX version 5.2.0 is vulnerable to HTML injection via the Category Creation Name Field.

    Published: 18 Nov 2023
    8.8
    High

    CVE-2023-48017

    Last Modified: 4 Apr 2025

    Dreamer_cms 4.1.3 is vulnerable to Cross Site Request Forgery (CSRF) via Add permissions to CSRF in Permission Management.

    Published: 18 Nov 2023
    6.5
    Medium

    CVE-2023-48736

    Last Modified: 21 Nov 2024

    In International Color Consortium DemoIccMAX 3e7948b, CIccCLUT::Interp2d in IccTagLut.cpp in libSampleICC.a has an out-of-bounds read.

    Published: 18 Nov 2023
    —
    Unknown

    CVE-2023-48721

    Last Modified: 2 Jan 2024

    Not used

    Published: 17 Nov 2023
    5.3
    Medium

    CVE-2023-46745

    Last Modified: 21 Nov 2024

    LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. In affected versions the login method has no rate limit. An attacker may be able to leverage this vulnerability to gain access to user accounts. This issue has been addressed in version 23.11.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 17 Nov 2023
    7.5
    High

    CVE-2023-48238

    Last Modified: 8 Jun 2026

    joaquimserafim/json-web-token is a javascript library use to interact with JSON Web Tokens (JWT) which are a compact URL-safe means of representing claims to be transferred between two parties. Versions prior to 4.0.0 are vulnerable to a JWT algorithm confusion attack. On line 86 of the 'index.js' file, the algorithm to use for verifying the signature of the JWT token is taken from the JWT token, which at that point is still unverified and thus shouldn't be trusted. To exploit this vulnerability, an attacker needs to craft a malicious JWT token containing the HS256 algorithm, signed with the public RSA key of the victim application. This attack will only work against this library is the RS256 algorithm is in use, however it is a best practice to use that algorithm. Version 4.0.0 fixes the issue.

    Published: 17 Nov 2023
    4.3
    Medium

    CVE-2023-48294

    Last Modified: 21 Nov 2024

    LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. In affected versions of LibreNMS when a user accesses their device dashboard, one request is sent to `graph.php` to access graphs generated on the particular Device. This request can be accessed by a low privilege user and they can enumerate devices on librenms with their id or hostname. Leveraging this vulnerability a low privilege user can see all devices registered by admin users. This vulnerability has been addressed in commit `489978a923` which has been included in release version 23.11.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 17 Nov 2023
    6.3
    Medium

    CVE-2023-48295

    Last Modified: 21 Nov 2024

    LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. Affected versions are subject to a cross site scripting (XSS) vulnerability in the device group popups. This issue has been addressed in commit `faf66035ea` which has been included in release version 23.11.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 17 Nov 2023
    4.7
    Medium

    CVE-2023-6188

    Last Modified: 21 Nov 2024

    A vulnerability was found in GetSimpleCMS 3.3.16/3.4.0a. It has been rated as critical. This issue affects some unknown processing of the file /admin/theme-edit.php. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-245735.

    Published: 17 Nov 2023
    7.8
    High

    CVE-2023-6179

    Last Modified: 21 Nov 2024

    Honeywell ProWatch, 4.5, including all Service Pack versions, contain a Vulnerability in Application Server's executable folder(s). A(n) attacker could potentially exploit this vulnerability, leading to a standard user to have arbitrary system code execution. Honeywell recommends updating to the most recent version of this product, service or offering (Pro-watch 6.0.2, 6.0, 5.5.2,5.0.5).

    Published: 17 Nov 2023
    9.8
    Critical

    CVE-2023-44351

    Last Modified: 21 Nov 2024

    Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

    Published: 17 Nov 2023
    4.3
    Medium

    CVE-2023-44355

    Last Modified: 21 Nov 2024

    Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to impact a minor integrity feature. Exploitation of this issue does require user interaction.

    Published: 17 Nov 2023
    7.5
    High

    CVE-2023-26347

    Last Modified: 21 Nov 2024

    Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.

    Published: 17 Nov 2023
    6.1
    Medium

    CVE-2023-44352

    Last Modified: 21 Nov 2024

    Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

    Published: 17 Nov 2023
    9.8
    Critical

    CVE-2023-44353

    Last Modified: 21 Nov 2024

    Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

    Published: 17 Nov 2023
    9.8
    Critical

    CVE-2023-44350

    Last Modified: 21 Nov 2024

    Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

    Published: 17 Nov 2023
    7.5
    High

    CVE-2023-22275

    Last Modified: 21 Nov 2024

    Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this issue does not require user interaction.

    Published: 17 Nov 2023
    7.5
    High

    CVE-2023-22272

    Last Modified: 21 Nov 2024

    Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Input Validation vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this issue does not require user interaction.

    Published: 17 Nov 2023
    6.5
    Medium

    CVE-2023-22268

    Last Modified: 21 Nov 2024

    Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to information disclosure by an low-privileged authenticated attacker. Exploitation of this issue does not require user interaction.

    Published: 17 Nov 2023
    7.5
    High

    CVE-2023-22274

    Last Modified: 21 Nov 2024

    Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this issue does not require user interaction.

    Published: 17 Nov 2023
    7.2
    High

    CVE-2023-22273

    Last Modified: 16 Dec 2025

    Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to Remote Code Execution by an admin authenticated attacker. Exploitation of this issue does not require user interaction.

    Published: 17 Nov 2023
    9.8
    Critical

    CVE-2023-44324

    Last Modified: 25 Nov 2024

    Adobe FrameMaker Publishing Server versions 2022 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An unauthenticated attacker can abuse this vulnerability to access the API and leak default admin's password. Exploitation of this issue does not require user interaction.

    Published: 17 Nov 2023
    7.8
    High

    CVE-2023-47068

    Last Modified: 21 Nov 2024

    Adobe After Effects version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 17 Nov 2023