CVE Feed

    Dashboard / CVE

    7.6
    High

    CVE-2023-32508

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolf van Gelder Order Your Posts Manually allows SQL Injection.This issue affects Order Your Posts Manually: from n/a through 2.2.5.

    Published: 3 Nov 2023
    7.6
    High

    CVE-2023-32121

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Highfivery LLC Zero Spam for WordPress allows SQL Injection.This issue affects Zero Spam for WordPress: from n/a through 5.4.4.

    Published: 3 Nov 2023
    8.2
    High

    CVE-2022-46818

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Gopi Ramasamy Email posts to subscribers allows SQL Injection.This issue affects Email posts to subscribers: from n/a through 6.2.

    Published: 3 Nov 2023
    6.1
    Medium

    CVE-2023-5946

    Last Modified: 5 Feb 2025

    The Digirisk plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'current_group_id' parameter in version 6.0.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 3 Nov 2023
    6
    Medium

    CVE-2022-47426

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Neshan Maps Platform Neshan Maps neshan-maps allows SQL Injection.This issue affects Neshan Maps: from n/a through 1.1.4.

    Published: 3 Nov 2023
    8.5
    High

    CVE-2022-46859

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows SQL Injection.This issue affects Spiffy Calendar: from n/a through 4.9.1.

    Published: 3 Nov 2023
    7.1
    High

    CVE-2023-26015

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Chris Richardson MapPress Maps for WordPress mappress-google-maps-for-wordpress allows SQL Injection.This issue affects MapPress Maps for WordPress: from n/a through 2.85.4.

    Published: 3 Nov 2023
    8.2
    High

    CVE-2022-46808

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Repute Infosystems ARMember armember-membership allows SQL Injection.This issue affects ARMember: from n/a through 3.4.11.

    Published: 3 Nov 2023
    4.3
    Medium

    CVE-2023-5945

    Last Modified: 5 Feb 2025

    The video carousel slider with lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the responsive_video_gallery_with_lightbox_video_management_func() function. This makes it possible for unauthenticated attackers to delete videos hosted from the video slider via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 3 Nov 2023
    6.4
    Medium

    CVE-2023-5707

    Last Modified: 8 Apr 2026

    The SEO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slider' shortcode and post meta in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 3 Nov 2023
    8.2
    High

    CVE-2022-47445

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Web-X Be POPIA Compliant be-popia-compliant allows SQL Injection.This issue affects Be POPIA Compliant: from n/a through 1.2.0.

    Published: 3 Nov 2023
    10
    Critical

    CVE-2023-25960

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zendrop Zendrop – Global Dropshipping zendrop-dropshipping-and-fulfillment allows SQL Injection.This issue affects Zendrop – Global Dropshipping: from n/a through 1.0.0.

    Published: 3 Nov 2023
    8.2
    High

    CVE-2022-45805

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paytm Paytm Payment Gateway paytm-payments allows SQL Injection.This issue affects Paytm Payment Gateway: from n/a through 2.7.3.

    Published: 3 Nov 2023
    9.8
    Critical

    CVE-2023-3277

    Last Modified: 8 Apr 2026

    The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in as any user as long as they know the user's email address.

    Published: 3 Nov 2023
    6.7
    Medium

    CVE-2022-47588

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tips and Tricks HQ, Peter Petreski Simple Photo Gallery simple-photo-gallery allows SQL Injection.This issue affects Simple Photo Gallery: from n/a through v1.8.1.

    Published: 3 Nov 2023
    8.5
    High

    CVE-2023-34383

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP Project Manager wedevs-project-manager allows SQL Injection.This issue affects WP Project Manager: from n/a through 2.6.0.

    Published: 3 Nov 2023
    8.2
    High

    CVE-2023-41652

    Last Modified: 29 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker rsvpmaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 10.6.6.

    Published: 3 Nov 2023
    6.1
    Medium

    CVE-2023-4592

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting vulnerability has been detected in WPN-XM Serverstack affecting version 0.8.6. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload through the /tools/webinterface/index.php parameter and retrieve the cookie session details of an authenticated user, resulting in a session hijacking.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-4591

    Last Modified: 21 Nov 2024

    A local file inclusion vulnerability has been found in WPN-XM Serverstack affecting version 0.8.6, which would allow an unauthenticated user to perform a local file inclusion (LFI) via the /tools/webinterface/index.php?page parameter by sending a GET request. This vulnerability could lead to the loading of a PHP file on the server, leading to a critical webshell exploit.

    Published: 3 Nov 2023
    6.6
    Medium

    CVE-2023-4769

    Last Modified: 21 Nov 2024

    A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerability could allow an authenticated attacker to launch targeted attacks, such as a cross-port attack, service enumeration and other attacks via HTTP requests.

    Published: 3 Nov 2023
    6.1
    Medium

    CVE-2023-4768

    Last Modified: 21 Nov 2024

    A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.pdf.

    Published: 3 Nov 2023
    6.1
    Medium

    CVE-2023-4767

    Last Modified: 21 Nov 2024

    A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.csv.

    Published: 3 Nov 2023
    6.8
    Medium

    CVE-2023-5763

    Last Modified: 21 Nov 2024

    In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote attackers to load malicious code on the server via access to insecure ORB listeners.

    Published: 3 Nov 2023
    5.5
    Medium

    CVE-2023-5948

    Last Modified: 21 Nov 2024

    Improper Authorization in GitHub repository teamamaze/amazefileutilities prior to 1.91.

    Published: 3 Nov 2023
    6.5
    Medium

    CVE-2023-41356

    Last Modified: 21 Nov 2024

    NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and read arbitrary system files.

    Published: 3 Nov 2023
    8.8
    High

    CVE-2023-41357

    Last Modified: 21 Nov 2024

    Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filtering and validation during file upload. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute scripts onto arbitrary directories to perform arbitrary system operations or disrupt service.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-41344

    Last Modified: 21 Nov 2024

    NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and read arbitrary system files.

    Published: 3 Nov 2023
    9.8
    Critical

    CVE-2023-41355

    Last Modified: 21 Nov 2024

    Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resulting in a denial of service or sensitive information leaking.

    Published: 3 Nov 2023
    4
    Medium

    CVE-2023-41354

    Last Modified: 21 Nov 2024

    Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated remote attacker can exploit this vulnerability by sending a crafted package, resulting in partially sensitive information exposed to an actor.

    Published: 3 Nov 2023
    8.8
    High

    CVE-2023-41353

    Last Modified: 21 Nov 2024

    Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user privilege can easily infer the administrator password from system information after logging system, resulting in admin access and performing arbitrary system operations or disrupt service.

    Published: 3 Nov 2023
    7.2
    High

    CVE-2023-41352

    Last Modified: 21 Nov 2024

    Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient filtering for user input. A remote attacker with administrator privilege can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services.

    Published: 3 Nov 2023
    9.8
    Critical

    CVE-2023-41351

    Last Modified: 21 Nov 2024

    Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log in as any existing users, such as an administrator, to perform arbitrary system operations or disrupt service.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-41350

    Last Modified: 21 Nov 2024

    Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very easy for bots to bypass the captcha check and more susceptible to brute force attacks.

    Published: 3 Nov 2023
    8.8
    High

    CVE-2023-41348

    Last Modified: 21 Nov 2024

    ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its code-authentication module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services.

    Published: 3 Nov 2023
    8.8
    High

    CVE-2023-41347

    Last Modified: 21 Nov 2024

    ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its check token module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services.

    Published: 3 Nov 2023
    8.8
    High

    CVE-2023-41346

    Last Modified: 21 Nov 2024

    ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-refresh module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services.

    Published: 3 Nov 2023
    8.8
    High

    CVE-2023-41345

    Last Modified: 21 Nov 2024

    ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-generated module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system, or terminate services.

    Published: 3 Nov 2023
    5.4
    Medium

    CVE-2023-41343

    Last Modified: 21 Nov 2024

    Rogic No-Code Database Builder's file uploading function has insufficient filtering for special characters. A remote attacker with regular user privilege can inject JavaScript to perform XSS (Stored Cross-Site Scripting) attack.

    Published: 3 Nov 2023
    —
    Unknown

    CVE-2023-46702

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 3 Nov 2023
    —
    Unknown

    CVE-2023-47206

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 3 Nov 2023
    —
    Unknown

    CVE-2023-46710

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 3 Nov 2023
    —
    Unknown

    CVE-2023-42432

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 3 Nov 2023
    5.4
    Medium

    CVE-2023-35896

    Last Modified: 21 Nov 2024

    IBM Content Navigator 3.0.13 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 259247.

    Published: 3 Nov 2023
    —
    Unknown

    CVE-2023-5947

    Last Modified: 27 Feb 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-7247. Reason: This candidate is a duplicate of CVE-2023-7247. Notes: All CVE users should reference CVE-2023-7247 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 3 Nov 2023
    6.6
    Medium

    CVE-2023-36022

    Last Modified: 9 Oct 2025

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

    Published: 3 Nov 2023
    4.3
    Medium

    CVE-2023-36029

    Last Modified: 8 Oct 2025

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

    Published: 3 Nov 2023
    7.3
    High

    CVE-2023-36034

    Last Modified: 8 Oct 2025

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

    Published: 3 Nov 2023
    6.7
    Medium

    CVE-2023-46176

    Last Modified: 21 Nov 2024

    IBM MQ Appliance 9.3 CD could allow a local attacker to gain elevated privileges on the system, caused by improper validation of security keys. IBM X-Force ID: 269535.

    Published: 3 Nov 2023
    7.5
    High

    CVE-2023-52355

    Last Modified: 2 Oct 2026

    An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

    Published: 3 Nov 2023
    4.3
    Medium

    CVE-2023-47233

    Last Modified: 12 May 2026

    The brcm80211 component in the Linux kernel through 6.5.10 has a brcmf_cfg80211_detach use-after-free in the device unplugging (disconnect the USB by hotplug) code. For physically proximate attackers with local access, this "could be exploited in a real world scenario." This is related to brcmf_cfg80211_escan_timeout_worker in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c.

    Published: 3 Nov 2023