CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2023-6076

    Last Modified: 27 Feb 2025

    A vulnerability classified as problematic was found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file booking-details.php of the component Reservation Status Handler. The manipulation of the argument bid leads to information disclosure. The attack can be launched remotely. The identifier VDB-244945 was assigned to this vulnerability.

    Published: 10 Nov 2023
    3.4
    Low

    CVE-2023-47121

    Last Modified: 27 Feb 2025

    Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, the embedding feature is susceptible to server side request forgery. The issue is patched in version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches. As a workaround, disable the Embedding feature.

    Published: 10 Nov 2023
    7.5
    High

    CVE-2023-47120

    Last Modified: 21 Nov 2024

    Discourse is an open source platform for community discussion. In versions 3.1.0 through 3.1.2 of the `stable` branch and versions 3.1.0,beta6 through 3.2.0.beta2 of the `beta` and `tests-passed` branches, Redis memory can be depleted by crafting a site with an abnormally long favicon URL and drafting multiple posts which Onebox it. The issue is patched in version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches. There are no known workarounds.

    Published: 10 Nov 2023
    5.3
    Medium

    CVE-2023-47119

    Last Modified: 21 Nov 2024

    Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, some links can inject arbitrary HTML tags when rendered through our Onebox engine. The issue is patched in version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches. There are no known workarounds.

    Published: 10 Nov 2023
    3.5
    Low

    CVE-2023-6075

    Last Modified: 27 Feb 2025

    A vulnerability classified as problematic has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file index.php of the component Reservation Request Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-244944.

    Published: 10 Nov 2023
    4.3
    Medium

    CVE-2023-46130

    Last Modified: 21 Nov 2024

    Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, some theme components allow users to add svgs with unlimited `height` attributes, and this can affect the availability of subsequent replies in a topic. Most Discourse instances are unaffected, only instances with the svgbob or the mermaid theme component are within scope. The issue is patched in version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches. As a workaround, disable or remove the relevant theme components.

    Published: 10 Nov 2023
    4.7
    Medium

    CVE-2023-23367

    Last Modified: 26 Feb 2025

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build 20230421 and later QuTS hero h5.0.1.2376 build 20230421 and later QuTScloud c5.1.0.2498 and later

    Published: 10 Nov 2023
    3.3
    Low

    CVE-2023-45816

    Last Modified: 21 Nov 2024

    Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, there is an edge case where a bookmark reminder is sent and an unread notification is generated, but the underlying bookmarkable (e.g. post, topic, chat message) security has changed, making it so the user can no longer access the underlying resource. As of version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, bookmark reminders are now no longer sent if the user does not have access to the underlying bookmarkable, and also the unread bookmark notifications are always filtered by access. There are no known workarounds.

    Published: 10 Nov 2023
    4.3
    Medium

    CVE-2023-45806

    Last Modified: 21 Nov 2024

    Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, if a user has been quoted and uses a `|` in their full name, they might be able to trigger a bug that generates a lot of duplicate content in all the posts they've been quoted by updating their full name again. Version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches contain a patch for this issue. No known workaround exists, although one can stop the "bleeding" by ensuring users only use alphanumeric characters in their full name field.

    Published: 10 Nov 2023
    6.3
    Medium

    CVE-2023-6074

    Last Modified: 26 Feb 2025

    A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file check-status.php of the component Booking Reservation Handler. The manipulation leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-244943.

    Published: 10 Nov 2023
    4.3
    Medium

    CVE-2023-29426

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Robert Schulz (sprd.Net AG) Spreadshop plugin <= 1.6.5 versions.

    Published: 10 Nov 2023
    5.3
    Medium

    CVE-2023-29428

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in SuPlugins Superb Social Media Share Buttons and Follow Buttons for WordPress plugin <= 1.1.3 versions.

    Published: 10 Nov 2023
    4.3
    Medium

    CVE-2023-29440

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Job Board plugin <= 2.10.3 versions.

    Published: 10 Nov 2023
    5.4
    Medium

    CVE-2023-30478

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters plugin <= 4.8.8 versions.

    Published: 10 Nov 2023
    4.3
    Medium

    CVE-2023-31077

    Last Modified: 29 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ReCorp Export WP Page to Static HTML/CSS plugin <= 2.1.9 versions.

    Published: 10 Nov 2023
    4.3
    Medium

    CVE-2023-31078

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Marco Steinbrecher WP BrowserUpdate plugin <= 4.4.1 versions.

    Published: 10 Nov 2023
    6.1
    Medium

    CVE-2023-47164

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in HOTELDRUID 3.0.5 and earlier allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.

    Published: 10 Nov 2023
    5.7
    Medium

    CVE-2023-6073

    Last Modified: 27 Feb 2025

    Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls.

    Published: 10 Nov 2023
    6.2
    Medium

    CVE-2023-45167

    Last Modified: 21 Nov 2024

    IBM AIX's 7.3 Python implementation could allow a non-privileged local user to exploit a vulnerability to cause a denial of service. IBM X-Force ID: 267965.

    Published: 10 Nov 2023
    9.3
    Critical

    CVE-2023-46729

    Last Modified: 21 Nov 2024

    sentry-javascript provides Sentry SDKs for JavaScript. An unsanitized input of Next.js SDK tunnel endpoint allows sending HTTP requests to arbitrary URLs and reflecting the response back to the user. This issue only affects users who have Next.js SDK tunneling feature enabled. The problem has been fixed in version 7.77.0.

    Published: 10 Nov 2023
    9.9
    Critical

    CVE-2023-6069

    Last Modified: 21 Nov 2024

    Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0.

    Published: 10 Nov 2023
    7.5
    High

    CVE-2023-47108

    Last Modified: 28 Oct 2025

    OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. Starting in version 0.37.0 and prior to version 0.46.0, the grpc Unary Server Interceptor out of the box adds labels `net.peer.sock.addr` and `net.peer.sock.port` that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent. An attacker can easily flood the peer address and port for requests. Version 0.46.0 contains a fix for this issue. As a workaround to stop being affected, a view removing the attributes can be used. The other possibility is to disable grpc metrics instrumentation by passing `otelgrpc.WithMeterProvider` option with `noop.NewMeterProvider`.

    Published: 10 Nov 2023
    9.8
    Critical

    CVE-2023-39796

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the DB_RECORD_TABLE parameter.

    Published: 10 Nov 2023
    9.8
    Critical

    CVE-2023-47800

    Last Modified: 21 Nov 2024

    Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threat actor to perform remote code execution, data exfiltration, or other nefarious actions such as tampering with data or destroying/disrupting MSSQL services.

    Published: 10 Nov 2023
    9.8
    Critical

    CVE-2023-47246

    Last Modified: 31 Oct 2025

    In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

    Published: 10 Nov 2023
    7.1
    High

    CVE-2023-36024

    Last Modified: 8 Oct 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 9 Nov 2023
    7.3
    High

    CVE-2023-36014

    Last Modified: 9 Oct 2025

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-31086

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Igor Benic Simple Giveaways – Grow your business, email lists and traffic with contests plugin <= 2.46.0 versions.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-31088

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Faraz Quazi Floating Action Button plugin <= 1.2.1 versions.

    Published: 9 Nov 2023
    4.3
    Medium

    CVE-2023-31093

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Chronosly Chronosly Events Calendar plugin <= 2.6.2 versions.

    Published: 9 Nov 2023
    5.9
    Medium

    CVE-2018-8863

    Last Modified: 21 Nov 2024

    The HTTP header in Philips EncoreAnywhere contains data an attacker may be able to use to gain sensitive information.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-31235

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database plugin <= 2.4.9 versions.

    Published: 9 Nov 2023
    4.3
    Medium

    CVE-2023-32092

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin <= 6.0.9.0 versions.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-32093

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Criss Swaim TPG Redirect plugin <= 1.0.7 versions.

    Published: 9 Nov 2023
    4.3
    Medium

    CVE-2023-32125

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Daniel Powney Multi Rating plugin <= 5.0.6 versions.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-32500

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in xtemos WoodMart - Multipurpose WooCommerce Theme <= 7.1.1 versions.

    Published: 9 Nov 2023
    4.3
    Medium

    CVE-2023-32501

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.6.1 versions.

    Published: 9 Nov 2023
    4.3
    Medium

    CVE-2023-32502

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Sybre Waaijer Pro Mime Types – Manage file media types plugin <= 1.0.7 versions.

    Published: 9 Nov 2023
    3.3
    Low

    CVE-2023-5543

    Last Modified: 21 Nov 2024

    When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting.

    Published: 9 Nov 2023
    4.3
    Medium

    CVE-2023-32512

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ShortPixel ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin <= 3.7.1 versions.

    Published: 9 Nov 2023
    5.3
    Medium

    CVE-2023-32579

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Designs & Code Forget About Shortcode Buttons plugin <= 2.1.2 versions.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-32587

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WP Reactions, LLC WP Reactions Lite plugin <= 1.3.8 versions.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-32592

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Palasthotel by Edward Bock, Katharina Rompf Sunny Search plugin <= 1.0.2 versions.

    Published: 9 Nov 2023
    4.3
    Medium

    CVE-2023-32594

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Benedict B., Maciej Gryniuk Hyphenator plugin <= 5.1.5 versions.

    Published: 9 Nov 2023
    8.1
    High

    CVE-2023-4379

    Last Modified: 21 Apr 2026

    An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Code owner approval was not removed from merge requests when the target branch was updated.

    Published: 9 Nov 2023
    4.3
    Medium

    CVE-2023-32602

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in LOKALYZE CALL ME NOW plugin <= 3.0 versions.

    Published: 9 Nov 2023
    4.3
    Medium

    CVE-2023-32739

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Web_Trendy WP Custom Cursors | WordPress Cursor Plugin plugin < 3.2 versions.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-32744

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Product Recommendations plugin <= 2.3.0 versions.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-32745

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce AutomateWoo plugin <= 5.7.1 versions.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-32794

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Product Add-Ons plugin <= 6.1.3 versions.

    Published: 9 Nov 2023