CVE Feed

    Dashboard / CVE

    6.6
    Medium

    CVE-2023-6133

    Last Modified: 8 Apr 2026

    The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the 'forminator_allowed_mime_types' function in versions up to, and including, 1.27.0. This makes it possible for authenticated attackers with administrator-level capabilities or above to upload arbitrary files on the affected site's server, but due to the htaccess configuration, remote code cannot be executed.

    Published: 15 Nov 2023
    7.8
    High

    CVE-2023-47586

    Last Modified: 21 Nov 2024

    Multiple heap-based buffer overflow vulnerabilities exist in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens a specially crafted VPR file, information may be disclosed and/or arbitrary code may be executed.

    Published: 15 Nov 2023
    7.8
    High

    CVE-2023-47585

    Last Modified: 21 Nov 2024

    Out-of-bounds read vulnerability exists in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens a specially crafted VPR file, information may be disclosed and/or arbitrary code may be executed.

    Published: 15 Nov 2023
    7.8
    High

    CVE-2023-47584

    Last Modified: 21 Nov 2024

    Out-of-bounds write vulnerability exists in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens a specially crafted VPR file, information may be disclosed and/or arbitrary code may be executed.

    Published: 15 Nov 2023
    7.8
    High

    CVE-2023-47583

    Last Modified: 7 Jan 2025

    Multiple out-of-bounds read vulnerabilities exist in TELLUS Simulator V4.0.17.0 and earlier. If a user opens a specially crafted file (X1 or V9 file), information may be disclosed and/or arbitrary code may be executed.

    Published: 15 Nov 2023
    7.8
    High

    CVE-2023-47582

    Last Modified: 21 Nov 2024

    Access of uninitialized pointer vulnerability exists in TELLUS V4.0.17.0 and earlier and TELLUS Lite V4.0.17.0 and earlier. If a user opens a specially crafted file (X1, V8, or V9 file), information may be disclosed and/or arbitrary code may be executed.

    Published: 15 Nov 2023
    7.8
    High

    CVE-2023-47581

    Last Modified: 29 Nov 2024

    Out-of-bounds read vulnerability exists in TELLUS V4.0.17.0 and earlier and TELLUS Lite V4.0.17.0 and earlier. If a user opens a specially crafted file (X1, V8, or V9 file), information may be disclosed and/or arbitrary code may be executed.

    Published: 15 Nov 2023
    7.8
    High

    CVE-2023-47580

    Last Modified: 21 Nov 2024

    Multiple improper restriction of operations within the bounds of a memory buffer issues exist in TELLUS V4.0.17.0 and earlier and TELLUS Lite V4.0.17.0 and earlier. If a user opens a specially crafted file (X1, V8, or V9 file), information may be disclosed and/or arbitrary code may be executed.

    Published: 15 Nov 2023
    5.3
    Medium

    CVE-2023-6032

    Last Modified: 21 Nov 2024

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file system enumeration and file download when an attacker navigates to the Network Management Card via HTTPS.

    Published: 15 Nov 2023
    6.1
    Medium

    CVE-2023-5987

    Last Modified: 21 Nov 2024

    A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to a cross site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload.

    Published: 15 Nov 2023
    8.2
    High

    CVE-2023-5986

    Last Modified: 2 Dec 2024

    A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed.

    Published: 15 Nov 2023
    4.8
    Medium

    CVE-2023-5985

    Last Modified: 21 Nov 2024

    A CWE-79 Improper Neutralization of Input During Web Page Generation vulnerability exists that could cause compromise of a user’s browser when an attacker with admin privileges has modified system values.

    Published: 15 Nov 2023
    7.2
    High

    CVE-2023-5984

    Last Modified: 30 Sept 2025

    A CWE-494 Download of Code Without Integrity Check vulnerability exists that could allow modified firmware to be uploaded when an authorized admin user begins a firmware update procedure which could result in full control over the device.

    Published: 15 Nov 2023
    9.1
    Critical

    CVE-2023-47678

    Last Modified: 21 Nov 2024

    An improper access control vulnerability exists in RT-AC87U all versions. An attacker may read or write files that are not intended to be accessed by connecting to a target device via tftp.

    Published: 15 Nov 2023
    7.5
    High

    CVE-2023-34062

    Last Modified: 4 Sept 2026

    In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack. Specifically, an application is vulnerable if Reactor Netty HTTP Server is configured to serve static resources.

    Published: 15 Nov 2023
    5.9
    Medium

    CVE-2023-5981

    Last Modified: 25 Mar 2026

    A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.

    Published: 15 Nov 2023
    9.8
    Critical

    CVE-2023-47308

    Last Modified: 21 Nov 2024

    In the module "Newsletter Popup PRO with Voucher/Coupon code" (newsletterpop) before version 2.6.1 from Active Design for PrestaShop, a guest can perform SQL injection in affected versions. The method `NewsletterpopsendVerificationModuleFrontController::checkEmailSubscription()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

    Published: 15 Nov 2023
    9.8
    Critical

    CVE-2023-41442

    Last Modified: 21 Nov 2024

    An issue in Kloudq Technologies Limited Tor Equip 1.0, Tor Loco Mini 1.0 through 3.1 allows a remote attacker to execute arbitrary code via a crafted request to the MQTT component.

    Published: 15 Nov 2023
    5.3
    Medium

    CVE-2022-32933

    Last Modified: 18 Mar 2025

    An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Monterey 12.5. A website may be able to track the websites a user visited in Safari private browsing mode.

    Published: 15 Nov 2023
    5.3
    Medium

    CVE-2023-6393

    Last Modified: 29 Sept 2026

    A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the cached Uni reuses the initial "completion" context, the processing switches to the cached Uni instead of the request context. This is a problem if the cached Uni context contains sensitive information, and could allow a malicious user to benefit from a POST request returning the response that is meant for another user, gaining access to sensitive data.

    Published: 15 Nov 2023
    7.8
    High

    CVE-2023-6175

    Last Modified: 27 Mar 2026

    NetScreen file parser crash in Wireshark 4.0.0 to 4.0.10 and 3.6.0 to 3.6.18 allows denial of service via crafted capture file

    Published: 15 Nov 2023
    4.7
    Medium

    CVE-2022-32919

    Last Modified: 17 Jun 2025

    The issue was addressed with improved UI handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Visiting a website that frames malicious content may lead to UI spoofing.

    Published: 15 Nov 2023
    7.5
    High

    CVE-2023-47347

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP messages whose Sequence Number is mutated to overflow bytes.

    Published: 15 Nov 2023
    6.1
    Medium

    CVE-2023-41597

    Last Modified: 21 Nov 2024

    EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.

    Published: 15 Nov 2023
    6.1
    Medium

    CVE-2023-41699

    Last Modified: 21 Nov 2024

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server, Micro and Embedded (Servlet Implementation modules) allows Redirect Access to Libraries.This issue affects Payara Server, Micro and Embedded: from 5.0.0 before 5.57.0, from 4.1.2.191 before 4.1.2.191.46, from 6.0.0 before 6.8.0, from 6.2023.1 before 6.2023.11.

    Published: 15 Nov 2023
    9.8
    Critical

    CVE-2023-43979

    Last Modified: 21 Nov 2024

    ETS Soft ybc_blog before v4.4.0 was discovered to contain a SQL injection vulnerability via the component Ybc_blogBlogModuleFrontController::getPosts().

    Published: 15 Nov 2023
    5.4
    Medium

    CVE-2023-47309

    Last Modified: 21 Nov 2024

    Nukium nkmgls before version 3.0.2 is vulnerable to Cross Site Scripting (XSS) via NkmGlsCheckoutModuleFrontController::displayAjaxSavePhoneMobile.

    Published: 15 Nov 2023
    7.5
    High

    CVE-2023-47345

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP message with malformed PFCP Heartbeat message whose Recovery Time Stamp IE length is mutated to zero.

    Published: 15 Nov 2023
    8.8
    High

    CVE-2023-47444

    Last Modified: 21 Nov 2024

    An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privilege can write arbitrary untrusted data inside config.php and admin/config.php, resulting in remote code execution on the underlying server.

    Published: 15 Nov 2023
    9.8
    Critical

    CVE-2023-47445

    Last Modified: 21 Nov 2024

    Pre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page.

    Published: 15 Nov 2023
    5.4
    Medium

    CVE-2023-47446

    Last Modified: 21 Nov 2024

    Pre-School Enrollment version 1.0 is vulnerable to Cross Site Scripting (XSS) on the profile.php page via fullname parameter.

    Published: 15 Nov 2023
    7.8
    High

    CVE-2023-48011

    Last Modified: 21 Nov 2024

    GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a heap-use-after-free via the flush_ref_samples function at /gpac/src/isomedia/movie_fragments.c.

    Published: 15 Nov 2023
    7.8
    High

    CVE-2023-48013

    Last Modified: 21 Nov 2024

    GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a double free via the gf_filterpacket_del function at /gpac/src/filter_core/filter.c.

    Published: 15 Nov 2023
    7.8
    High

    CVE-2023-48014

    Last Modified: 21 Nov 2024

    GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a stack overflow via the hevc_parse_vps_extension function at /media_tools/av_parsers.c.

    Published: 15 Nov 2023
    5.4
    Medium

    CVE-2023-48087

    Last Modified: 21 Nov 2024

    xxl-job-admin 2.4.0 is vulnerable to Insecure Permissions via /xxl-job-admin/joblog/clearLog and /xxl-job-admin/joblog/logDetailCat.

    Published: 15 Nov 2023
    5.4
    Medium

    CVE-2023-48088

    Last Modified: 21 Nov 2024

    xxl-job-admin 2.4.0 is vulnerable to Cross Site Scripting (XSS) via /xxl-job-admin/joblog/logDetailPage.

    Published: 15 Nov 2023
    8.8
    High

    CVE-2023-48089

    Last Modified: 21 Nov 2024

    xxl-job-admin 2.4.0 is vulnerable to Remote Code Execution (RCE) via /xxl-job-admin/jobcode/save.

    Published: 15 Nov 2023
    5.4
    Medium

    CVE-2023-48197

    Last Modified: 29 Sept 2025

    Cross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and earlier allows attackers to obtain victim's cookies when the victim clicks on the "see QR code" function.

    Published: 15 Nov 2023
    5.4
    Medium

    CVE-2023-48198

    Last Modified: 29 Sept 2025

    A Cross-Site Scripting (XSS) vulnerability in the 'product description' component within '/api/stock/products' of Grocy version <= 4.0.3 allows attackers to obtain a victim's cookies.

    Published: 15 Nov 2023
    6.5
    Medium

    CVE-2023-48204

    Last Modified: 21 Nov 2024

    An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters parameter of the api/method/getHtml component.

    Published: 15 Nov 2023
    4.1
    Medium

    CVE-2023-5676

    Last Modified: 3 Nov 2025

    In Eclipse OpenJ9 before version 0.41.0, the JVM can be forced into an infinite busy hang on a spinlock or a segmentation fault if a shutdown signal (SIGTERM, SIGINT or SIGHUP) is received before the JVM has finished initializing.

    Published: 15 Nov 2023
    7.8
    High

    CVE-2023-48199

    Last Modified: 29 Sept 2025

    HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTML content without script execution. This occurs when user-supplied data is not appropriately sanitized, enabling the injection of HTML tags through parameter values. The attacker can then manipulate page content in the QR code detail popup, often coupled with social engineering tactics, exploiting both the trust of users and the application's lack of proper input handling.

    Published: 15 Nov 2023
    5.4
    Medium

    CVE-2023-48200

    Last Modified: 29 Sept 2025

    Cross Site Scripting vulnerability in Grocy v.4.0.3 allows a local attacker to execute arbitrary code and obtain sensitive information via the equipment description component within /equipment/ component.

    Published: 15 Nov 2023
    9.6
    Critical

    CVE-2023-48365

    Last Modified: 31 Oct 2025

    Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attacker is able to elevate their privilege by tunneling HTTP requests, allowing them to execute HTTP requests on the backend server that hosts the repository application. The fixed versions are August 2023 Patch 2, May 2023 Patch 6, February 2023 Patch 10, November 2022 Patch 12, August 2022 Patch 14, May 2022 Patch 16, February 2022 Patch 15, and November 2021 Patch 17. NOTE: this issue exists because of an incomplete fix for CVE-2023-41265.

    Published: 15 Nov 2023
    8.8
    High

    CVE-2023-40923

    Last Modified: 24 Feb 2026

    MyPrestaModules ordersexport before v5.0 was discovered to contain multiple SQL injection vulnerabilities at send.php via the key and save_setting parameters.

    Published: 15 Nov 2023
    6.3
    Medium

    CVE-2023-6174

    Last Modified: 27 Mar 2026

    SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or crafted capture file

    Published: 15 Nov 2023
    5
    Medium

    CVE-2023-46121

    Last Modified: 21 Nov 2024

    yt-dlp is a youtube-dl fork with additional features and fixes. The Generic Extractor in yt-dlp is vulnerable to an attacker setting an arbitrary proxy for a request to an arbitrary url, allowing the attacker to MITM the request made from yt-dlp's HTTP session. This could lead to cookie exfiltration in some cases. Version 2023.11.14 removed the ability to smuggle `http_headers` to the Generic extractor, as well as other extractors that use the same pattern. Users are advised to upgrade. Users unable to upgrade should disable the Ggneric extractor (or only pass trusted sites with trusted content) and ake caution when using `--no-check-certificate`.

    Published: 14 Nov 2023
    9.1
    Critical

    CVE-2023-39337

    Last Modified: 21 Nov 2024

    A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled device identifier to access and extract sensitive information, including device and environment configuration details, as well as secrets. This vulnerability poses a serious security risk, potentially exposing confidential data and system integrity.

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-41718

    Last Modified: 7 Jan 2025

    When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file.

    Published: 14 Nov 2023
    9.8
    Critical

    CVE-2023-39335

    Last Modified: 21 Nov 2024

    A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated threat actor to impersonate any existing user during the device enrollment process. This issue poses a significant security risk, as it enables unauthorized access and potential misuse of user accounts and resources.

    Published: 14 Nov 2023