CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2023-47163

    Last Modified: 8 Jan 2025

    Remarshal prior to v0.17.1 expands YAML alias nodes unlimitedly, hence Remarshal is vulnerable to Billion Laughs Attack. Processing untrusted YAML files may cause a denial-of-service (DoS) condition.

    Published: 13 Nov 2023
    4.1
    Medium

    CVE-2023-31219

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.1.

    Published: 13 Nov 2023
    8.8
    High

    CVE-2023-35041

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability leading to Local File Inclusion (LF) in Webpushr Web Push Notifications Web Push Notifications – Webpushr plugin <= 4.34.0 versions.

    Published: 13 Nov 2023
    —
    Unknown

    CVE-2023-6092

    Last Modified: 14 Nov 2023

    DUPLICATE, accidental request.

    Published: 13 Nov 2023
    6.1
    Medium

    CVE-2023-38364

    Last Modified: 21 Nov 2024

    IBM CICS TX Advanced 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 260821.

    Published: 13 Nov 2023
    4.3
    Medium

    CVE-2023-38363

    Last Modified: 21 Nov 2024

    IBM CICS TX Advanced 10.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 260818.

    Published: 13 Nov 2023
    6.3
    Medium

    CVE-2023-32583

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Prashant Walke WP All Backup plugin <= 2.4.3 versions.

    Published: 13 Nov 2023
    4.3
    Medium

    CVE-2023-32588

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in BRANDbrilliance Post State Tags plugin <= 2.0.6 versions.

    Published: 13 Nov 2023
    —
    Unknown

    CVE-2023-6089

    Last Modified: 14 Nov 2023

    Accidental Request.

    Published: 13 Nov 2023
    4.3
    Medium

    CVE-2023-33207

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Krzysztof Wielogórski Stop Referrer Spam plugin <= 1.3.0 versions.

    Published: 13 Nov 2023
    4.3
    Medium

    CVE-2023-34378

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in scriptburn.Com WP Hide Post plugin <= 2.0.10 versions.

    Published: 13 Nov 2023
    5.4
    Medium

    CVE-2023-34384

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Kebo Kebo Twitter Feed plugin <= 1.5.12 versions.

    Published: 13 Nov 2023
    5.4
    Medium

    CVE-2023-47669

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin <= 3.10.3 versions.

    Published: 13 Nov 2023
    4.3
    Medium

    CVE-2023-46618

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Bala Krishna, Sergey Yakovlev Category SEO Meta Tags plugin <= 2.5 versions.

    Published: 13 Nov 2023
    5.4
    Medium

    CVE-2023-46619

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WebDorado WDSocialWidgets plugin <= 1.0.15 versions.

    Published: 13 Nov 2023
    4.3
    Medium

    CVE-2023-46620

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Fluenx DeepL API translation plugin <= 2.3.9.1 versions.

    Published: 13 Nov 2023
    4.3
    Medium

    CVE-2023-46625

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in DAEXT Autolinks Manager plugin <= 1.10.04 versions.

    Published: 13 Nov 2023
    4.3
    Medium

    CVE-2023-46629

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in themelocation Remove Add to Cart WooCommerce plugin <= 1.4.4.

    Published: 13 Nov 2023
    5.4
    Medium

    CVE-2023-46636

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in David Stöckl Custom Header Images plugin <= 1.2.1 versions.

    Published: 13 Nov 2023
    4.3
    Medium

    CVE-2023-46638

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Webcodin WCP OpenWeather plugin <= 2.5.0 versions.

    Published: 13 Nov 2023
    5.4
    Medium

    CVE-2023-47230

    Last Modified: 8 Jan 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.6.0 versions.

    Published: 13 Nov 2023
    4.3
    Medium

    CVE-2023-26543

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Aleksandr Guidrevitch WP Meteor Website Speed Optimization Addon plugin <= 3.1.4 versions.

    Published: 13 Nov 2023
    4.7
    Medium

    CVE-2023-47801

    Last Modified: 21 Nov 2024

    An issue was discovered in Click Studios Passwordstate before 9811. Existing users (Security Administrators) could use the System Wide API Key to read or delete private password records when specifically used with the PasswordHistory API endpoint. It is also possible to use the Copy/Move Password Record API Key to Copy/Move private password records.

    Published: 13 Nov 2023
    5.5
    Medium

    CVE-2023-46014

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in hospitalLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'hemail' and 'hpassword' parameters.

    Published: 13 Nov 2023
    6.1
    Medium

    CVE-2023-46015

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in index.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via 'msg' parameter in application URL.

    Published: 13 Nov 2023
    6.1
    Medium

    CVE-2023-46016

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'search' parameter in the application URL.

    Published: 13 Nov 2023
    5.5
    Medium

    CVE-2023-46017

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in receiverLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'remail' and 'rpassword' parameters.

    Published: 13 Nov 2023
    5.5
    Medium

    CVE-2023-46018

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in receiverReg.php in Code-Projects Blood Bank 1.0 \allows attackers to run arbitrary SQL commands via 'remail' parameter.

    Published: 13 Nov 2023
    6.1
    Medium

    CVE-2023-46019

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'error' parameter.

    Published: 13 Nov 2023
    6.1
    Medium

    CVE-2023-46020

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in updateprofile.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'rename', 'remail', 'rphone' and 'rcity' parameters.

    Published: 13 Nov 2023
    5.5
    Medium

    CVE-2023-46021

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in cancel.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary commands via the 'reqid' parameter.

    Published: 13 Nov 2023
    7.5
    High

    CVE-2023-47346

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in free5gc 3.3.0, UPF 1.2.0, and SMF 1.2.0 allows attackers to cause a denial of service via crafted PFCP messages.

    Published: 13 Nov 2023
    8.8
    High

    CVE-2023-48058

    Last Modified: 4 Apr 2025

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/run

    Published: 13 Nov 2023
    8.8
    High

    CVE-2023-48060

    Last Modified: 4 Apr 2025

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/add

    Published: 13 Nov 2023
    4.3
    Medium

    CVE-2023-48063

    Last Modified: 4 Apr 2025

    An issue was discovered in dreamer_cms 4.1.3. There is a CSRF vulnerability that can delete a theme project via /admin/category/delete.

    Published: 13 Nov 2023
    5.4
    Medium

    CVE-2023-48068

    Last Modified: 21 Nov 2024

    DedeCMS v6.2 was discovered to contain a Cross-site Scripting (XSS) vulnerability via spec_add.php.

    Published: 13 Nov 2023
    5.9
    Medium

    CVE-2023-46445

    Last Modified: 25 Feb 2026

    An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "Rogue Extension Negotiation."

    Published: 13 Nov 2023
    6.8
    Medium

    CVE-2023-46446

    Last Modified: 25 Feb 2026

    An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulation, aka a "Rogue Session Attack."

    Published: 13 Nov 2023
    8.8
    High

    CVE-2023-44429

    Last Modified: 17 Mar 2026

    GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of AV1 encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22226.

    Published: 13 Nov 2023
    8.8
    High

    CVE-2023-44446

    Last Modified: 17 Mar 2026

    GStreamer MXF File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of MXF video files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22299.

    Published: 13 Nov 2023
    5.4
    Medium

    CVE-2023-26531

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in 闪电博 多合一搜索自动推送管理插件-支持Baidu/Google/Bing/IndexNow/Yandex/头条 allows Cross Site Request Forgery.This issue affects 多合一搜索自动推送管理插件-支持Baidu/Google/Bing/IndexNow/Yandex/头条: from n/a through 4.2.7.

    Published: 12 Nov 2023
    4.3
    Medium

    CVE-2023-26524

    Last Modified: 8 Jan 2025

    Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.10 versions.

    Published: 12 Nov 2023
    8.8
    High

    CVE-2023-26516

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in WPIndeed Debug Assistant plugin <= 1.4 versions.

    Published: 12 Nov 2023
    5.4
    Medium

    CVE-2023-26518

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in AccessPress Themes WP TFeed plugin <= 1.6.9 versions.

    Published: 12 Nov 2023
    5.4
    Medium

    CVE-2023-26514

    Last Modified: 8 Jan 2025

    Cross-Site Request Forgery (CSRF) vulnerability in WPGrim Dynamic XML Sitemaps Generator for Google plugin <= 1.3.3 versions.

    Published: 12 Nov 2023
    5.4
    Medium

    CVE-2023-27445

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Meril Inc. Blog Floating Button plugin <= 1.4.12 versions.

    Published: 12 Nov 2023
    5.4
    Medium

    CVE-2023-27441

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in gl_SPICE New Adman plugin <= 1.6.8 versions.

    Published: 12 Nov 2023
    4.3
    Medium

    CVE-2023-27438

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Evgen Yurchenko WP Translitera plugin <= p1.2.5 versions.

    Published: 12 Nov 2023
    4.3
    Medium

    CVE-2023-27434

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WPGrim Classic Editor and Classic Widgets plugin <= 1.2.5 versions.

    Published: 12 Nov 2023
    —
    Unknown

    CVE-2023-6088

    Last Modified: 14 Nov 2023

    Accidental Request.

    Published: 12 Nov 2023