CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2023-34024

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Guillemant David WP Full Auto Tags Manager plugin <= 2.2 versions.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-34025

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in LWS LWS Hide Login plugin <= 2.1.6 versions.

    Published: 9 Nov 2023
    4.3
    Medium

    CVE-2023-34031

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Pascal Casier bbPress Toolkit plugin <= 1.0.12 versions.

    Published: 9 Nov 2023
    3.3
    Low

    CVE-2023-5551

    Last Modified: 21 Nov 2024

    Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.

    Published: 9 Nov 2023
    6.5
    Medium

    CVE-2023-5550

    Last Modified: 21 Nov 2024

    In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.

    Published: 9 Nov 2023
    3.3
    Low

    CVE-2023-5549

    Last Modified: 21 Nov 2024

    Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.

    Published: 9 Nov 2023
    3.3
    Low

    CVE-2023-5548

    Last Modified: 21 Nov 2024

    Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.

    Published: 9 Nov 2023
    3.3
    Low

    CVE-2023-5547

    Last Modified: 21 Nov 2024

    The course upload preview contained an XSS risk for users uploading unsafe data.

    Published: 9 Nov 2023
    4.3
    Medium

    CVE-2023-5546

    Last Modified: 21 Nov 2024

    ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.

    Published: 9 Nov 2023
    3.3
    Low

    CVE-2023-5545

    Last Modified: 21 Nov 2024

    H5P metadata automatically populated the author with the user's username, which could be sensitive information.

    Published: 9 Nov 2023
    6.5
    Medium

    CVE-2023-5544

    Last Modified: 21 Nov 2024

    Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.

    Published: 9 Nov 2023
    4.3
    Medium

    CVE-2023-34033

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Malinky Ajax Pagination and Infinite Scroll plugin <= 2.0.1 versions.

    Published: 9 Nov 2023
    6.5
    Medium

    CVE-2023-34169

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in SAKURA Internet Inc. TS Webfonts for さくらのレンタルサーバ plugin <= 3.1.2 versions.

    Published: 9 Nov 2023
    3.3
    Low

    CVE-2023-5542

    Last Modified: 21 Nov 2024

    Students in "Only see own membership" groups could see other students in the group, which should be hidden.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-34171

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Alex Raven WP Report Post plugin <= 2.1.2 versions.

    Published: 9 Nov 2023
    3.3
    Low

    CVE-2023-5541

    Last Modified: 21 Nov 2024

    The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.

    Published: 9 Nov 2023
    4.7
    Medium

    CVE-2023-5540

    Last Modified: 21 Nov 2024

    A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-34177

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Kenth Hagström WP-Cache.Com plugin <= 1.1.1 versions.

    Published: 9 Nov 2023
    4.7
    Medium

    CVE-2023-5539

    Last Modified: 21 Nov 2024

    A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-34178

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Groundhogg Inc. Groundhogg plugin <= 2.7.11 versions.

    Published: 9 Nov 2023
    4.3
    Medium

    CVE-2023-34181

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WP-Cirrus plugin <= 0.6.11 versions.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-34182

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Peter Shaw LH Password Changer plugin <= 1.55 versions.

    Published: 9 Nov 2023
    5.5
    Medium

    CVE-2023-6054

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.9. This affects an unknown part of the file general/wiki/cp/manage/lock.php. The manipulation of the argument TERM_ID_STR leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-244875. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 9 Nov 2023
    6.3
    Medium

    CVE-2023-6053

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in Tongda OA 2017 up to 11.9. Affected by this issue is some unknown functionality of the file general/system/censor_words/manage/delete.php. The manipulation of the argument DELETE_STR leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-244874 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 9 Nov 2023
    4.3
    Medium

    CVE-2023-34371

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Didier Sampaolo SpamReferrerBlock plugin <= 2.22 versions.

    Published: 9 Nov 2023
    4.3
    Medium

    CVE-2023-47238

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WebberZone Top 10 – WordPress Popular posts by WebberZone plugin <= 3.3.2 versions.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-47237

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson Auto Publish for Google My Business plugin <= 3.7 versions.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-46614

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Mat Bao Corp WP Helper Premium plugin <= 4.5.1 versions.

    Published: 9 Nov 2023
    4.3
    Medium

    CVE-2023-34386

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WPClever WPC Smart Wishlist for WooCommerce plugin <= 4.7.1 versions.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-31087

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in JoomSky JS Job Manager plugin <= 2.0.0 versions.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-34002

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory Manager plugin <= 2.1.0.13 versions.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-25975

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Frédéric Sheedy Etsy Shop plugin <= 3.0.3 versions.

    Published: 9 Nov 2023
    8.1
    High

    CVE-2023-47610

    Last Modified: 27 Feb 2025

    A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists in Telit Cinterion EHS5/6/8 that could allow a remote unauthenticated attacker to execute arbitrary code on the targeted system by sending a specially crafted SMS message.

    Published: 9 Nov 2023
    —
    Unknown

    CVE-2023-6060

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 9 Nov 2023
    5.3
    Medium

    CVE-2023-45284

    Last Modified: 21 Nov 2024

    On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed by spaces, such as "COM1 ", and reserved names "COM" and "LPT" followed by superscript 1, 2, or 3, are incorrectly reported as local. With fix, IsLocal now correctly reports these names as non-local.

    Published: 9 Nov 2023
    7.5
    High

    CVE-2023-45283

    Last Modified: 13 Feb 2025

    The filepath package does not recognize paths with a \??\ prefix as special. On Windows, a path beginning with \??\ is a Root Local Device path equivalent to a path beginning with \\?\. Paths with a \??\ prefix may be used to access arbitrary locations on the system. For example, the path \??\c:\x is equivalent to the more common path c:\x. Before fix, Clean could convert a rooted path such as \a\..\??\b into the root local device path \??\b. Clean will now convert this to .\??\b. Similarly, Join(\, ??, b) could convert a seemingly innocent sequence of path elements into the root local device path \??\b. Join will now convert this to \.\??\b. In addition, with fix, IsAbs now correctly reports paths beginning with \??\ as absolute, and VolumeName correctly reports the \??\ prefix as a volume name. UPDATE: Go 1.20.11 and Go 1.21.4 inadvertently changed the definition of the volume name in Windows paths starting with \?, resulting in filepath.Clean(\?\c:) returning \?\c: rather than \?\c:\ (among other effects). The previous behavior has been restored.

    Published: 9 Nov 2023
    4.3
    Medium

    CVE-2023-36688

    Last Modified: 29 Apr 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Michael Mann Simple Site Verify plugin <= 1.0.7 versions.

    Published: 9 Nov 2023
    5.4
    Medium

    CVE-2023-25994

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Alex Benfica Publish to Schedule plugin <= 4.4.2 versions.

    Published: 9 Nov 2023
    7.3
    High

    CVE-2023-46743

    Last Modified: 21 Nov 2024

    application-collabora is an integration of Collabora Online in XWiki. As part of the application use cases, depending on the rights that a user has over a document, they should be able to open the office attachments files in view or edit mode. Currently, if a user opens an attachment file in edit mode in collabora, this right will be preserved for all future users, until the editing session is closes, even if some of them have only view right. Collabora server is the one issuing this request and it seems that the `userCanWrite` query parameter is cached, even if, for example, token is not. This issue has been patched in version 1.3.

    Published: 9 Nov 2023
    9.1
    Critical

    CVE-2023-47110

    Last Modified: 21 Nov 2024

    blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store is trustworthy. An ajax function in module blockreassurance allows modifying any value in the configuration table. This vulnerability has been patched in version 5.1.4.

    Published: 9 Nov 2023
    8
    High

    CVE-2023-41137

    Last Modified: 21 Nov 2024

    Symmetric encryption used to protect messages between the AppsAnywhere server and client can be broken by reverse engineering the client and used to impersonate the AppsAnywhere server.

    Published: 9 Nov 2023
    8
    High

    CVE-2023-40055

    Last Modified: 21 Nov 2024

    The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33227

    Published: 9 Nov 2023
    8
    High

    CVE-2023-40054

    Last Modified: 21 Nov 2024

    The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33226

    Published: 9 Nov 2023
    7.5
    High

    CVE-2023-41138

    Last Modified: 21 Nov 2024

    The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user process.

    Published: 9 Nov 2023
    9.8
    Critical

    CVE-2023-43791

    Last Modified: 21 Nov 2024

    Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within the ORM Leak vulnerability to impersonate any account on Label Studio. An attacker could exploit these vulnerabilities to escalate their privileges from a low privilege user to a Django Super Administrator user. The vulnerability was found to affect versions before `1.8.2`, where a patch was introduced.

    Published: 9 Nov 2023
    9.8
    Critical

    CVE-2023-4612

    Last Modified: 26 Feb 2025

    Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date of publication there is no patch, and the vendor does not treat it as a vulnerability.

    Published: 9 Nov 2023
    3.3
    Low

    CVE-2023-47615

    Last Modified: 21 Nov 2024

    A CWE-526: Exposure of Sensitive Information Through Environmental Variables vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow a local, low privileged attacker to get access to a sensitive data on the targeted system.

    Published: 9 Nov 2023
    6.3
    Medium

    CVE-2023-6052

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in Tongda OA 2017 up to 11.9. Affected is an unknown function of the file general/system/censor_words/module/delete.php. The manipulation of the argument DELETE_STR leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-244872. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 9 Nov 2023
    2.4
    Low

    CVE-2023-47616

    Last Modified: 21 Nov 2024

    A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow an attacker with physical access to the target system to get access to a sensitive data on the targeted system.

    Published: 9 Nov 2023
    6.8
    Medium

    CVE-2023-47612

    Last Modified: 21 Nov 2024

    A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow an attacker with physical access to the target system to obtain a read/write access to any files and directories on the targeted system, including hidden files and directories.

    Published: 9 Nov 2023