CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2023-47662

    Last Modified: 8 Jan 2025

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GoldBroker.Com Live Gold Price & Silver Price Charts Widgets plugin <= 2.4 versions.

    Published: 13 Nov 2023
    7.1
    High

    CVE-2023-47665

    Last Modified: 8 Jan 2025

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in edward_plainview Plainview Protect Passwords plugin <= 1.4 versions.

    Published: 13 Nov 2023
    7.1
    High

    CVE-2023-47673

    Last Modified: 8 Jan 2025

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Stefano Ottolenghi Post Pay Counter plugin <= 2.784 versions.

    Published: 13 Nov 2023
    —
    Unknown

    CVE-2023-6115

    Last Modified: 14 Nov 2023

    DUPLICATE CVE

    Published: 13 Nov 2023
    6.5
    Medium

    CVE-2023-47680

    Last Modified: 8 Jan 2025

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Qode Interactive Qi Addons For Elementor plugin <= 1.6.3 versions.

    Published: 13 Nov 2023
    7.1
    High

    CVE-2023-47684

    Last Modified: 8 Jan 2025

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ThemePunch OHG Essential Grid plugin <= 3.1.0 versions.

    Published: 13 Nov 2023
    7.1
    High

    CVE-2023-47690

    Last Modified: 8 Jan 2025

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Anton Bond Additional Order Filters for WooCommerce plugin <= 1.10 versions.

    Published: 13 Nov 2023
    7.1
    High

    CVE-2023-47695

    Last Modified: 8 Jan 2025

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Scribit Shortcodes Finder plugin <= 1.5.3 versions.

    Published: 13 Nov 2023
    7.1
    High

    CVE-2023-47696

    Last Modified: 8 Jan 2025

    Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3.0 versions.

    Published: 13 Nov 2023
    6.1
    Medium

    CVE-2023-4603

    Last Modified: 8 Apr 2026

    The Star CloudPRNT for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'printersettings' parameter in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 13 Nov 2023
    7.1
    High

    CVE-2023-47697

    Last Modified: 8 Jan 2025

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Event Manager WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin <= 3.1.39 versions.

    Published: 13 Nov 2023
    2.9
    Low

    CVE-2023-47625

    Last Modified: 21 Nov 2024

    PX4 autopilot is a flight control solution for drones. In affected versions a global buffer overflow vulnerability exists in the CrsfParser_TryParseCrsfPacket function in /src/drivers/rc/crsf_rc/CrsfParser.cpp:298 due to the invalid size check. A malicious user may create an RC packet remotely and that packet goes into the device where the _rcs_buf reads. The global buffer overflow vulnerability will be triggered and the drone can behave unexpectedly. This issue has been addressed in version 1.14.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 13 Nov 2023
    6.1
    Medium

    CVE-2023-42813

    Last Modified: 21 Nov 2024

    Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerable component in Kyvernos Notary verifier. An attacker would need control over the registry from which Kyverno would fetch attestations. With such a position, the attacker could return a malicious response to Kyverno, when Kyverno would send a request to the registry. The malicious response would cause denial of service of Kyverno, such that other users' admission requests would be blocked from being processed. This is a vulnerability in a new component released in v1.11.0. The only users affected by this are those that have been building Kyverno from source at the main branch which is not encouraged. Users consuming official Kyverno releases are not affected. There are no known cases of this vulnerability being exploited in the wild.

    Published: 13 Nov 2023
    3.1
    Low

    CVE-2023-42814

    Last Modified: 21 Nov 2024

    Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerable component in Kyvernos Notary verifier. An attacker would need control over the registry from which Kyverno would fetch attestations. With such a position, the attacker could return a malicious response to Kyverno, when Kyverno would send a request to the registry. The malicious response would cause denial of service of Kyverno, such that other users' admission requests would be blocked from being processed. This is a vulnerability in a new component released in v1.11.0. The only users affected by this are those that have been building Kyverno from source at the main branch which is not encouraged. Users consuming official Kyverno releases are not affected. There are no known cases of this vulnerability being exploited in the wild.

    Published: 13 Nov 2023
    3.1
    Low

    CVE-2023-42815

    Last Modified: 21 Nov 2024

    Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerability was in Kyvernos Notary verifier. An attacker would need control over the registry from which Kyverno would fetch signatures. With such a position, the attacker could return a malicious response to Kyverno, when Kyverno would send a request to the registry. The malicious response would cause denial of service of Kyverno, such that other users' admission requests would be blocked from being processed. This is a vulnerability in a new component released in v1.11.0. The only users affected by this are those that have been building Kyverno from source at the main branch which is not encouraged. Users consuming official Kyverno releases are not affected. There are no known cases of this vulnerability being exploited in the wild.

    Published: 13 Nov 2023
    6.1
    Medium

    CVE-2023-42816

    Last Modified: 21 Nov 2024

    Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerability was in Kyvernos Notary verifier. An attacker would need control over the registry from which Kyverno would fetch signatures. With such a position, the attacker could return a malicious response to Kyverno, when Kyverno would send a request to the registry. The malicious response would cause denial of service of Kyverno, such that other users' admission requests would be blocked from being processed. This is a vulnerability in a new component released in v1.11.0. The only users affected by this are those that have been building Kyverno from source at the main branch which is not encouraged. Users consuming official Kyverno releases are not affected. There are no known cases of this vulnerability being exploited in the wild.

    Published: 13 Nov 2023
    7.5
    High

    CVE-2023-47117

    Last Modified: 8 Jan 2025

    Label Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. This vulnerability has been addressed in commit `f931d9d129` which is included in the 1.9.2post0 release. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 13 Nov 2023
    8.8
    High

    CVE-2023-47621

    Last Modified: 21 Nov 2024

    Guest Entries is a php library which allows users to create, update & delete entries from the front-end of a site. In affected versions the file uploads feature did not prevent the upload of PHP files. This may lead to code execution on the server by authenticated users. This vulnerability is fixed in v3.1.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 13 Nov 2023
    2.4
    Low

    CVE-2023-6103

    Last Modified: 8 Jan 2025

    A vulnerability has been found in Intelbras RX 1500 1.1.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /WiFi.html of the component SSID Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-245065 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 13 Nov 2023
    5.3
    Medium

    CVE-2023-6102

    Last Modified: 8 Jan 2025

    A vulnerability, which was classified as problematic, was found in Maiwei Safety Production Control Platform 4.1. Affected is an unknown function of the file /Content/Plugins/uploader/FileChoose.html?fileUrl=/Upload/File/Pics/&parent. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-245064. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 13 Nov 2023
    7.1
    High

    CVE-2023-31230

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Haoqisir Baidu Tongji generator allows Stored XSS.This issue affects Baidu Tongji generator: from n/a through 1.0.2.

    Published: 13 Nov 2023
    6.1
    Medium

    CVE-2023-32123

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Dream-Theme The7 allows Stored XSS.This issue affects The7: from n/a through 11.7.3.

    Published: 13 Nov 2023
    4.3
    Medium

    CVE-2023-35877

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Vadym K. Extra User Details allows Stored XSS.This issue affects Extra User Details: from n/a through 0.5.

    Published: 13 Nov 2023
    7.1
    High

    CVE-2023-39166

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in tagDiv tagDiv Composer allows Cross-Site Scripting (XSS).This issue affects tagDiv Composer: from n/a before 4.4.

    Published: 13 Nov 2023
    5.3
    Medium

    CVE-2023-6101

    Last Modified: 8 Jan 2025

    A vulnerability, which was classified as problematic, has been found in Maiwei Safety Production Control Platform 4.1. This issue affects some unknown processing of the file /TC/V2.7/ha.html of the component Intelligent Monitoring. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-245063. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 13 Nov 2023
    5.3
    Medium

    CVE-2023-6100

    Last Modified: 8 Jan 2025

    A vulnerability classified as problematic was found in Maiwei Safety Production Control Platform 4.1. This vulnerability affects unknown code of the file /api/DataDictionary/GetItemList. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-245062 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 13 Nov 2023
    7.3
    High

    CVE-2023-6099

    Last Modified: 8 Jan 2025

    A vulnerability classified as critical has been found in Shenzhen Youkate Industrial Facial Love Cloud Payment System up to 1.0.55.0.0.1. This affects an unknown part of the file /SystemMng.ashx of the component Account Handler. The manipulation of the argument operatorRole with the input 00 leads to improper privilege management. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-245061 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 13 Nov 2023
    —
    Unknown

    CVE-2023-6107

    Last Modified: 14 Nov 2023

    Accidental Request.

    Published: 13 Nov 2023
    —
    Unknown

    CVE-2023-6106

    Last Modified: 14 Nov 2023

    Accidental request.

    Published: 13 Nov 2023
    6.3
    Medium

    CVE-2023-6098

    Last Modified: 21 Nov 2024

    An XSS vulnerability has been discovered in ICS Business Manager affecting version 7.06.0028.7066. A remote attacker could send a specially crafted string exploiting the obdd_act parameter, allowing the attacker to steal an authenticated user's session, and perform actions within the application.

    Published: 13 Nov 2023
    9.4
    Critical

    CVE-2023-6097

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability has been found in ICS Business Manager, affecting version 7.06.0028.7089. This vulnerability could allow a remote user to send a specially crafted SQL query and retrieve all the information stored in the database. The data could also be modified or deleted, causing the application to malfunction.

    Published: 13 Nov 2023
    —
    Unknown

    CVE-2023-6104

    Last Modified: 13 Feb 2025

    The CVE Record was published by accident.

    Published: 13 Nov 2023
    7.1
    High

    CVE-2023-40335

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Jeremy O'Connell Cleverwise Daily Quotes allows Stored XSS.This issue affects Cleverwise Daily Quotes: from n/a through 3.2.

    Published: 13 Nov 2023
    5.4
    Medium

    CVE-2023-46092

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in LionScripts.Com Webmaster Tools allows Stored XSS.This issue affects Webmaster Tools: from n/a through 2.0.

    Published: 13 Nov 2023
    7.2
    High

    CVE-2023-5747

    Last Modified: 21 Nov 2024

    Bashis, a Security Researcher at IPVM has found a flaw that allows for a remote code execution during the installation of Wave on the camera device. The Wave server application in camera device was vulnerable to command injection allowing an attacker to run arbitrary code. HanwhaVision has released patched firmware for the highlighted flaw. Please refer to the hanwhavision security report for more information and solution."

    Published: 13 Nov 2023
    7.1
    High

    CVE-2023-5037

    Last Modified: 21 Nov 2024

    badmonkey, a Security Researcher has found a flaw that allows for a authenticated command injection on the camera. An attacker could inject malicious into request packets to execute command. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.

    Published: 13 Nov 2023
    6.4
    Medium

    CVE-2023-4775

    Last Modified: 8 Apr 2026

    The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'advanced_iframe' shortcode in versions up to, and including, 2023.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2023-51690 appears to be a potential duplicate of this issue.

    Published: 13 Nov 2023
    6.4
    Medium

    CVE-2023-5741

    Last Modified: 8 Apr 2026

    The POWR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'powr-powr-pack' shortcode in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 13 Nov 2023
    4.3
    Medium

    CVE-2023-46201

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Jeff Sherk Auto Login New User After Registration allows Stored XSS.This issue affects Auto Login New User After Registration: from n/a through 1.9.6.

    Published: 13 Nov 2023
    7.1
    High

    CVE-2023-46634

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in phoeniixx Custom My Account for Woocommerce allows Cross-Site Scripting (XSS).This issue affects Custom My Account for Woocommerce: from n/a through 2.1.

    Published: 13 Nov 2023
    7.1
    High

    CVE-2023-47516

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Stark Digital Category Post List Widget allows Stored XSS.This issue affects Category Post List Widget: from n/a through 2.0.

    Published: 13 Nov 2023
    7.1
    High

    CVE-2023-47652

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links allows Stored XSS.This issue affects Auto Affiliate Links: from n/a through 6.4.2.4.

    Published: 13 Nov 2023
    5.8
    Medium

    CVE-2022-45835

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in PhonePe PhonePe Payment Solutions.This issue affects PhonePe Payment Solutions: from n/a through 1.0.15.

    Published: 13 Nov 2023
    4.4
    Medium

    CVE-2023-23684

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in WPGraphQL.This issue affects WPGraphQL: from n/a through 1.14.5.

    Published: 13 Nov 2023
    7.1
    High

    CVE-2023-23800

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Vova Anokhin WP Shortcodes Plugin — Shortcodes Ultimate.This issue affects WP Shortcodes Plugin — Shortcodes Ultimate: from n/a through 5.12.6.

    Published: 13 Nov 2023
    4.1
    Medium

    CVE-2023-46207

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing.This issue affects Motors – Car Dealer, Classifieds & Listing: from n/a through 1.4.6.

    Published: 13 Nov 2023
    6.4
    Medium

    CVE-2023-41239

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Blubrry PowerPress Podcasting plugin by Blubrry.This issue affects PowerPress Podcasting plugin by Blubrry: from n/a through 11.0.6.

    Published: 13 Nov 2023
    4.4
    Medium

    CVE-2023-37978

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Dimitar Ivanov HTTP Headers.This issue affects HTTP Headers: from n/a through 1.18.11.

    Published: 13 Nov 2023
    5.5
    Medium

    CVE-2023-38515

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 3.7.56.

    Published: 13 Nov 2023
    4.4
    Medium

    CVE-2023-34013

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Poll Maker Team Poll Maker – Best WordPress Poll Plugin.This issue affects Poll Maker – Best WordPress Poll Plugin: from n/a through 4.6.2.

    Published: 13 Nov 2023