CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2023-27436

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Louis Reingold Elegant Custom Fonts plugin <= 1.0 versions.

    Published: 12 Nov 2023
    4.3
    Medium

    CVE-2023-27431

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in ThemeHunk Big Store theme <= 1.9.3 versions.

    Published: 12 Nov 2023
    4.3
    Medium

    CVE-2023-27417

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Timo Reith Affiliate Super Assistent plugin <= 1.5.1 versions.

    Published: 12 Nov 2023
    —
    Unknown

    CVE-2023-6087

    Last Modified: 14 Nov 2023

    Accidental Request.

    Published: 12 Nov 2023
    4.3
    Medium

    CVE-2023-27418

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Side Menu Lite – add sticky fixed buttons plugin <= 4.0 versions.

    Published: 12 Nov 2023
    5.4
    Medium

    CVE-2023-27632

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in mmrs151 Daily Prayer Time plugin <= 2023.03.08 versions.

    Published: 12 Nov 2023
    5.4
    Medium

    CVE-2023-27623

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Jens Törnell WP Page Numbers plugin <= 0.5 versions.

    Published: 12 Nov 2023
    7.8
    High

    CVE-2023-28134

    Last Modified: 21 Nov 2024

    Local attacker can escalate privileges on affected installations of Check Point Harmony Endpoint/ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 12 Nov 2023
    5.4
    Medium

    CVE-2023-27611

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in audrasjb Reusable Blocks Extended plugin <= 0.9 versions.

    Published: 12 Nov 2023
    5.4
    Medium

    CVE-2023-28167

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Vsourz Digital CF7 Invisible reCAPTCHA plugin <= 1.3.3 versions.

    Published: 12 Nov 2023
    5.4
    Medium

    CVE-2023-28172

    Last Modified: 7 May 2025

    Cross-Site Request Forgery (CSRF) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS (formerly WP Google Map Plugin) plugin <= 4.4.2 versions.

    Published: 12 Nov 2023
    4.3
    Medium

    CVE-2023-28173

    Last Modified: 8 Jan 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Images plugin <= 2.1.3 versions.

    Published: 12 Nov 2023
    —
    Unknown

    CVE-2023-6086

    Last Modified: 14 Nov 2023

    Accidental request.

    Published: 12 Nov 2023
    5.4
    Medium

    CVE-2023-28419

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Stranger Studios Force First and Last Name as Display Name plugin <= 1.2 versions.

    Published: 12 Nov 2023
    5.4
    Medium

    CVE-2023-28420

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Leo Caseiro Custom Options Plus plugin <= 1.8.1 versions.

    Published: 12 Nov 2023
    4.3
    Medium

    CVE-2023-28495

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop WP Shortcode by MyThemeShop plugin <= 1.4.16 versions.

    Published: 12 Nov 2023
    5.4
    Medium

    CVE-2023-28497

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Slideshow Gallery LITE plugin <= 1.7.6 versions.

    Published: 12 Nov 2023
    4.3
    Medium

    CVE-2023-28498

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in MotoPress Hotel Booking Lite plugin <= 4.6.0 versions.

    Published: 12 Nov 2023
    5.4
    Medium

    CVE-2023-28618

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Marios Alexandrou Enhanced Plugin Admin plugin <= 1.16 versions.

    Published: 12 Nov 2023
    5.4
    Medium

    CVE-2023-28694

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Wbcom Designs Wbcom Designs – BuddyPress Activity Social Share plugin <= 3.5.0 versions.

    Published: 12 Nov 2023
    4.3
    Medium

    CVE-2023-28696

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Harish Chouhan, Themeist I Recommend This allows Cross Site Request Forgery.This issue affects I Recommend This: from n/a through 3.9.0.

    Published: 12 Nov 2023
    4.3
    Medium

    CVE-2023-28930

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Robin Phillips Mobile Banner plugin <= 1.5 versions.

    Published: 12 Nov 2023
    4.3
    Medium

    CVE-2023-28987

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions.

    Published: 12 Nov 2023
    4.3
    Medium

    CVE-2023-29238

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Whydonate Whydonate – FREE Donate button – Crowdfunding – Fundraising plugin <= 3.12.15 versions.

    Published: 12 Nov 2023
    5.4
    Medium

    CVE-2023-29425

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in plainware.Com ShiftController Employee Shift Scheduling plugin <= 4.9.23 versions.

    Published: 12 Nov 2023
    —
    Unknown

    CVE-2023-6085

    Last Modified: 14 Nov 2023

    Accidental request.

    Published: 12 Nov 2023
    6.5
    Medium

    CVE-2023-42781

    Last Modified: 13 Feb 2025

    Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs.  This is a different issue than CVE-2023-42663 but leading to similar outcome. Users of Apache Airflow are advised to upgrade to version 2.7.3 or newer to mitigate the risk associated with this vulnerability.

    Published: 12 Nov 2023
    4.3
    Medium

    CVE-2023-47037

    Last Modified: 13 Feb 2025

    We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then.  Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.  Users should upgrade to version 2.7.3 or later which has removed the vulnerability.

    Published: 12 Nov 2023
    6.3
    Medium

    CVE-2023-6084

    Last Modified: 21 Nov 2024

    A vulnerability was found in Tongda OA 2017 up to 11.9 and classified as critical. Affected by this issue is some unknown functionality of the file general/vehicle/checkup/delete.php. The manipulation of the argument VU_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-244994 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 12 Nov 2023
    4.6
    Medium

    CVE-2023-43057

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 267484.

    Published: 11 Nov 2023
    4.3
    Medium

    CVE-2023-5959

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, was found in Byzoro Smart S85F Management Platform V31R02B10-01. Affected is an unknown function of the file /login.php. The manipulation of the argument txt_newpwd leads to weak password recovery. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-244992. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Nov 2023
    9.8
    Critical

    CVE-2023-46850

    Last Modified: 16 Dec 2025

    Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.

    Published: 11 Nov 2023
    7.5
    High

    CVE-2023-46849

    Last Modified: 11 Jun 2025

    Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.

    Published: 11 Nov 2023
    7.5
    High

    CVE-2023-47390

    Last Modified: 21 Nov 2024

    Headscale through 0.22.3 writes bearer tokens to info-level logs.

    Published: 11 Nov 2023
    10
    Critical

    CVE-2023-4804

    Last Modified: 16 Dec 2025

    An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.

    Published: 10 Nov 2023
    —
    Unknown

    CVE-2023-6083

    Last Modified: 14 Nov 2023

    Accidental Request.

    Published: 10 Nov 2023
    4.2
    Medium

    CVE-2023-47122

    Last Modified: 21 Nov 2024

    Gitsign is software for keyless Git signing using Sigstore. In versions of gitsign starting with 0.6.0 and prior to 0.8.0, Rekor public keys were fetched via the Rekor API, instead of through the local TUF client. If the upstream Rekor server happened to be compromised, gitsign clients could potentially be tricked into trusting incorrect signatures. There is no known compromise the default public good instance (`rekor.sigstore.dev`) - anyone using this instance is unaffected. This issue was fixed in v0.8.0. No known workarounds are available.

    Published: 10 Nov 2023
    7.1
    High

    CVE-2023-36027

    Last Modified: 8 Oct 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 10 Nov 2023
    8.3
    High

    CVE-2023-47129

    Last Modified: 21 Nov 2024

    Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded. This only affects forms using the "Forms" feature and not just _any_ arbitrary form. This does not affect the control panel. This issue has been patched in 3.4.13 and 4.33.0.

    Published: 10 Nov 2023
    9.1
    Critical

    CVE-2023-47128

    Last Modified: 21 Nov 2024

    Piccolo is an object-relational mapping and query builder which supports asyncio. Prior to version 1.1.1, the handling of named transaction `savepoints` in all database implementations is vulnerable to SQL Injection via f-strings. While the likelihood of an end developer exposing a `savepoints` `name` parameter to a user is highly unlikely, it would not be unheard of. If a malicious user was able to abuse this functionality they would have essentially direct access to the database and the ability to modify data to the level of permissions associated with the database user. A non exhaustive list of actions possible based on database permissions is: Read all data stored in the database, including usernames and password hashes; insert arbitrary data into the database, including modifying existing records; and gain a shell on the underlying server. Version 1.1.1 fixes this issue.

    Published: 10 Nov 2023
    6.1
    Medium

    CVE-2023-46735

    Last Modified: 21 Nov 2024

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in version 6.0.0 and prior to version 6.3.8, the error message in `WebhookController` returns unescaped user-submitted input. As of version 6.3.8, `WebhookController` now doesn't return any user-submitted input in its response.

    Published: 10 Nov 2023
    6.1
    Medium

    CVE-2023-46734

    Last Modified: 13 Feb 2025

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escapes the output of the affected filters.

    Published: 10 Nov 2023
    —
    Unknown

    CVE-2023-6079

    Last Modified: 15 Nov 2023

    appears to be a duplicate of CVE-2023-40206

    Published: 10 Nov 2023
    6.5
    Medium

    CVE-2023-46733

    Last Modified: 21 Nov 2024

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5.4.21 and 6.2.7 and prior to versions 5.4.31 and 6.3.8, `SessionStrategyListener` does not migrate the session after every successful login. It does so only in case the logged in user changes by means of checking the user identifier. In some use cases, the user identifier doesn't change between the verification phase and the successful login, while the token itself changes from one type (partially-authenticated) to another (fully-authenticated). When this happens, the session id should be regenerated to prevent possible session fixations, which is not the case at the moment. As of versions 5.4.31 and 6.3.8, Symfony now checks the type of the token in addition to the user identifier before deciding whether the session id should be regenerated.

    Published: 10 Nov 2023
    8.1
    High

    CVE-2023-4949

    Last Modified: 21 Nov 2024

    An attacker with local access to a system (either through a disk or external drive) can present a modified XFS partition to grub-legacy in such a way to exploit a memory corruption in grub’s XFS file system implementation.

    Published: 10 Nov 2023
    7.8
    High

    CVE-2023-47611

    Last Modified: 21 Nov 2024

    A CWE-269: Improper Privilege Management vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow a local, low privileged attacker to elevate privileges to "manufacturer" level on the targeted system.

    Published: 10 Nov 2023
    7.4
    High

    CVE-2023-41285

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: QuMagie 2.1.4 and later

    Published: 10 Nov 2023
    7.4
    High

    CVE-2023-41284

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: QuMagie 2.1.4 and later

    Published: 10 Nov 2023
    8.8
    High

    CVE-2023-39295

    Last Modified: 21 Nov 2024

    An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: QuMagie 2.1.3 and later

    Published: 10 Nov 2023
    3.3
    Low

    CVE-2023-47614

    Last Modified: 21 Nov 2024

    A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow a local, low privileged attacker to disclose hidden virtual paths and file names on the targeted system.

    Published: 10 Nov 2023