CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2023-5430

    Last Modified: 8 Apr 2026

    The Jquery news ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 31 Oct 2023
    8.8
    High

    CVE-2023-5434

    Last Modified: 8 Apr 2026

    The Superb slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 13.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 31 Oct 2023
    8.8
    High

    CVE-2023-5435

    Last Modified: 8 Apr 2026

    The Up down image slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 12.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 31 Oct 2023
    8.8
    High

    CVE-2023-5412

    Last Modified: 8 Apr 2026

    The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 13.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 31 Oct 2023
    8.8
    High

    CVE-2023-5464

    Last Modified: 8 Apr 2026

    The Jquery accordion slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 31 Oct 2023
    8.8
    High

    CVE-2023-5428

    Last Modified: 8 Apr 2026

    The Image vertical reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 31 Oct 2023
    5.4
    Medium

    CVE-2023-5873

    Last Modified: 27 Feb 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 11.1.0.

    Published: 31 Oct 2023
    5.9
    Medium

    CVE-2023-46210

    Last Modified: 28 Apr 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WebCource WC Captcha plugin <= 1.4 versions.

    Published: 31 Oct 2023
    5.7
    Medium

    CVE-2023-5866

    Last Modified: 21 Nov 2024

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.2.1.

    Published: 31 Oct 2023
    5.4
    Medium

    CVE-2023-5867

    Last Modified: 27 Feb 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.2.

    Published: 31 Oct 2023
    9.8
    Critical

    CVE-2023-5865

    Last Modified: 21 Nov 2024

    Insufficient Session Expiration in GitHub repository thorsten/phpmyfaq prior to 3.2.2.

    Published: 31 Oct 2023
    4.8
    Medium

    CVE-2023-5864

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.1.

    Published: 31 Oct 2023
    6.1
    Medium

    CVE-2023-5863

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.2.2.

    Published: 31 Oct 2023
    4.8
    Medium

    CVE-2023-5861

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0.

    Published: 31 Oct 2023
    3.3
    Low

    CVE-2023-5862

    Last Modified: 21 Nov 2024

    Missing Authorization in GitHub repository hamza417/inure prior to Build95.

    Published: 31 Oct 2023
    9.8
    Critical

    CVE-2023-36263

    Last Modified: 12 Jun 2026

    Prestashop opartlimitquantity 1.4.5 and before is vulnerable to SQL Injection. OpartlimitquantityAlertlimitModuleFrontController::displayAjaxPushAlertMessage()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

    Published: 31 Oct 2023
    9.8
    Critical

    CVE-2023-46977

    Last Modified: 21 Nov 2024

    TOTOLINK LR1200GB V9.1.0u.6619_B20230130 was discovered to contain a stack overflow via the password parameter in the function loginAuth.

    Published: 31 Oct 2023
    9.8
    Critical

    CVE-2023-46979

    Last Modified: 21 Nov 2024

    TOTOLINK X6000R V9.4.0cu.852_B20230719 was discovered to contain a command injection vulnerability via the enable parameter in the setLedCfg function.

    Published: 31 Oct 2023
    6.1
    Medium

    CVE-2019-25155

    Last Modified: 21 Nov 2024

    DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because links lack a 'rel="noopener noreferrer"' attribute.

    Published: 31 Oct 2023
    9.8
    Critical

    CVE-2023-46484

    Last Modified: 21 Nov 2024

    An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setLedCfg function.

    Published: 31 Oct 2023
    9.8
    Critical

    CVE-2023-46485

    Last Modified: 21 Nov 2024

    An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setTracerouteCfg function of the stecgi.cgi component.

    Published: 31 Oct 2023
    7.5
    High

    CVE-2023-46992

    Last Modified: 21 Nov 2024

    TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral critical passwords without authentication by visiting specific pages.

    Published: 31 Oct 2023
    7.5
    High

    CVE-2015-20110

    Last Modified: 21 Nov 2024

    JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers can guess tokens by brute forcing one character at a time and observing the timing. This of course drastically reduces the search space to a linear amount of guesses based on the token length times the possible characters.

    Published: 31 Oct 2023
    7.5
    High

    CVE-2023-45955

    Last Modified: 21 Nov 2024

    An issue discovered in Nanoleaf Light strip v3.5.10 allows attackers to cause a denial of service via crafted write binding attribute commands.

    Published: 31 Oct 2023
    8.8
    High

    CVE-2023-45996

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Senayan Library Management Systems Slims v.9 and Bulian v.9.6.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the reborrowLimit parameter in the member_type.php.

    Published: 31 Oct 2023
    9.8
    Critical

    CVE-2023-27846

    Last Modified: 21 Nov 2024

    SQL injection vulnerability found in PrestaShop themevolty v.4.0.8 and before allow a remote attacker to gain privileges via the tvcmsblog, tvcmsvideotab, tvcmswishlist, tvcmsbrandlist, tvcmscategorychainslider, tvcmscategoryproduct, tvcmscategoryslider, tvcmspaymenticon, tvcmstestimonial components.

    Published: 31 Oct 2023
    5.5
    Medium

    CVE-2023-31794

    Last Modified: 21 Nov 2024

    MuPDF v1.21.1 was discovered to contain an infinite recursion in the component pdf_mark_list_push. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

    Published: 31 Oct 2023
    5.3
    Medium

    CVE-2023-37831

    Last Modified: 21 Nov 2024

    An issue discovered in Elenos ETG150 FM transmitter v3.12 allows attackers to enumerate user accounts based on server responses when credentials are submitted.

    Published: 31 Oct 2023
    7.5
    High

    CVE-2023-37832

    Last Modified: 21 Nov 2024

    A lack of rate limiting in Elenos ETG150 FM transmitter v3.12 allows attackers to obtain user credentials via brute force and cause other unspecified impacts.

    Published: 31 Oct 2023
    9.8
    Critical

    CVE-2023-43139

    Last Modified: 21 Nov 2024

    An issue in franfinance before v.2.0.27 allows a remote attacker to execute arbitrary code via the validation.php, and controllers/front/validation.php components.

    Published: 31 Oct 2023
    6.5
    Medium

    CVE-2023-39610

    Last Modified: 21 Nov 2024

    An issue in TP-Link Tapo C100 v1.1.15 Build 211130 Rel.15378n(4555) and before allows attackers to cause a Denial of Service (DoS) via supplying a crafted web request.

    Published: 31 Oct 2023
    5.3
    Medium

    CVE-2023-39695

    Last Modified: 21 Nov 2024

    Insufficient session expiration in Elenos ETG150 FM Transmitter v3.12 allows attackers to arbitrarily change transmitter configuration and data after logging out.

    Published: 31 Oct 2023
    9.8
    Critical

    CVE-2023-42425

    Last Modified: 21 Nov 2024

    An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary code and obtain sensitive information via the cloud connection components.

    Published: 31 Oct 2023
    3.5
    Low

    CVE-2023-43295

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery vulnerability in Click Studios (SA) Pty Ltd Passwordstate v.Build 9785 and before allows a local attacker to execute arbitrary code via a crafted request.

    Published: 31 Oct 2023
    9.8
    Critical

    CVE-2023-45378

    Last Modified: 21 Nov 2024

    In the module "PrestaBlog" (prestablog) version 4.4.7 and before from HDclic for PrestaShop, a guest can perform SQL injection. The script ajax slider_positions.php has a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.

    Published: 31 Oct 2023
    7.5
    High

    CVE-2023-45899

    Last Modified: 21 Nov 2024

    An issue in the component SuperUserSetuserModuleFrontController:init() of idnovate superuser before v2.4.2 allows attackers to bypass authentication via a crafted HTTP call.

    Published: 31 Oct 2023
    5.4
    Medium

    CVE-2023-46040

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via the a crafted payload to the components.php function.

    Published: 31 Oct 2023
    9.8
    Critical

    CVE-2023-46356

    Last Modified: 21 Nov 2024

    In the module "CSV Feeds PRO" (csvfeeds) before 2.6.1 from Bl Modules for PrestaShop, a guest can perform SQL injection. The method `SearchApiCsv::getProducts()` has sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.

    Published: 31 Oct 2023
    6.5
    Medium

    CVE-2023-46361

    Last Modified: 21 Nov 2024

    Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c.

    Published: 31 Oct 2023
    5.4
    Medium

    CVE-2023-46378

    Last Modified: 21 Nov 2024

    Stored Cross Site Scripting (XSS) vulnerability in MiniCMS 1.1.1 allows attackers to run arbitrary code via crafted string appended to /mc-admin/conf.php.

    Published: 31 Oct 2023
    5.4
    Medium

    CVE-2023-46451

    Last Modified: 21 Nov 2024

    Best Courier Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the change username field.

    Published: 31 Oct 2023
    9.8
    Critical

    CVE-2023-46976

    Last Modified: 21 Nov 2024

    TOTOLINK A3300R 17.0.0cu.557_B20221024 contains a command injection via the file_name parameter in the UploadFirmwareFile function.

    Published: 31 Oct 2023
    9.8
    Critical

    CVE-2023-46993

    Last Modified: 21 Nov 2024

    In TOTOLINK A3300R V17.0.0cu.557_B20221024 when dealing with setLedCfg request, there is no verification for the enable parameter, which can lead to command injection.

    Published: 31 Oct 2023
    5.4
    Medium

    CVE-2023-47096

    Last Modified: 21 Nov 2024

    A Reflected Cross-Site Scripting (XSS) vulnerability in the Cloudmin Services Client under System Setting in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the Cloudmin services master field.

    Published: 31 Oct 2023
    5.4
    Medium

    CVE-2023-47099

    Last Modified: 21 Nov 2024

    A Stored Cross-Site Scripting (XSS) vulnerability in the Create Virtual Server in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via Description field while creating the Virtual server.

    Published: 31 Oct 2023
    5.4
    Medium

    CVE-2023-47097

    Last Modified: 21 Nov 2024

    A Stored Cross-Site Scripting (XSS) vulnerability in the Server Template under System Setting in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the Template name field while creating server templates.

    Published: 31 Oct 2023
    4.8
    Medium

    CVE-2023-47098

    Last Modified: 21 Nov 2024

    A Stored Cross-Site Scripting (XSS) vulnerability in the Manage Extra Admins under Administration Options in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the real name or description field.

    Published: 31 Oct 2023
    5.4
    Medium

    CVE-2023-47095

    Last Modified: 21 Nov 2024

    A Stored Cross-Site Scripting (XSS) vulnerability in the Custom fields of Edit Virtual Server under System Customization in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the Batch Label field while details of Virtual Server.

    Published: 31 Oct 2023
    9.8
    Critical

    CVE-2023-47174

    Last Modified: 21 Nov 2024

    Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-1000027. Also, within the specific context of Thorn SFTP gateway, this leads to remote code execution.

    Published: 31 Oct 2023
    2.7
    Low

    CVE-2023-37833

    Last Modified: 21 Nov 2024

    Improper access control in Elenos ETG150 FM transmitter v3.12 allows attackers to make arbitrary configuration edits that are only accessed by privileged users.

    Published: 31 Oct 2023