CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2023-5443

    Last Modified: 21 May 2026

    Improper Protection for Outbound Error Messages and Alert Signals vulnerability in EDM Informatics E-invoice allows Account Footprinting. This issue affects E-invoice: before 2.1.

    Published: 27 Oct 2023
    9.8
    Critical

    CVE-2023-5807

    Last Modified: 20 May 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TRtek Software Education Portal allows SQL Injection. This issue affects Education Portal: before 3.2023.29.

    Published: 27 Oct 2023
    —
    Unknown

    CVE-2023-44377

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 27 Oct 2023
    —
    Unknown

    CVE-2023-44376

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 27 Oct 2023
    7.5
    High

    CVE-2023-5570

    Last Modified: 21 May 2026

    Improper Protection for Outbound Error Messages and Alert Signals vulnerability in Inohom Home Manager Gateway allows Account Footprinting. This issue affects Home Manager Gateway: before v.1.27.12.

    Published: 27 Oct 2023
    9.6
    Critical

    CVE-2023-5820

    Last Modified: 5 Feb 2025

    The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the addedit functionality. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 27 Oct 2023
    4.3
    Medium

    CVE-2023-5821

    Last Modified: 5 Feb 2025

    The Thumbnail carousel slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing nonce validation on the deleteselected function. This makes it possible for unauthenticated attackers to delete sliders in bulk via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 27 Oct 2023
    6.4
    Medium

    CVE-2023-5705

    Last Modified: 8 Apr 2026

    The VK Filter Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vk_filter_search' shortcode in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 27 Oct 2023
    6.4
    Medium

    CVE-2023-5817

    Last Modified: 8 Apr 2026

    The Neon text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's neontext_box shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes (color). This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 27 Oct 2023
    6.4
    Medium

    CVE-2023-5774

    Last Modified: 8 Apr 2026

    The Animated Counters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 27 Oct 2023
    5.9
    Medium

    CVE-2023-46199

    Last Modified: 28 Apr 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Triberr plugin <= 4.1.1 versions.

    Published: 27 Oct 2023
    5.8
    Medium

    CVE-2023-46194

    Last Modified: 28 Apr 2026

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.5 versions.

    Published: 27 Oct 2023
    7.3
    High

    CVE-2023-44220

    Last Modified: 21 Nov 2024

    SonicWall NetExtender Windows (32-bit and 64-bit) client 10.2.336 and earlier versions have a DLL Search Order Hijacking vulnerability in the start-up DLL component. Successful exploitation via a local attacker could result in command execution in the target system.

    Published: 27 Oct 2023
    5.9
    Medium

    CVE-2023-46192

    Last Modified: 28 Apr 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Internet Marketing Ninjas Internal Link Building plugin <= 1.2.3 versions.

    Published: 27 Oct 2023
    7.1
    High

    CVE-2023-46153

    Last Modified: 28 Apr 2026

    Unauth. Stored Cross-Site Scripting (XSS) vulnerability in UserFeedback Team User Feedback plugin <= 1.0.9 versions.

    Published: 27 Oct 2023
    5.9
    Medium

    CVE-2023-46093

    Last Modified: 28 Apr 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in LionScripts.Com Webmaster Tools plugin <= 2.0 versions.

    Published: 27 Oct 2023
    5.9
    Medium

    CVE-2023-46091

    Last Modified: 28 Apr 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bala Krishna, Sergey Yakovlev Category SEO Meta Tags plugin <= 2.5 versions.

    Published: 27 Oct 2023
    7.8
    High

    CVE-2023-44219

    Last Modified: 21 Nov 2024

    A local privilege escalation vulnerability in SonicWall Directory Services Connector Windows MSI client 4.1.21 and earlier versions allows a local low-privileged user to gain system privileges through running the recovery feature.

    Published: 27 Oct 2023
    7.8
    High

    CVE-2023-34057

    Last Modified: 6 Mar 2025

    VMware Tools contains a local privilege escalation vulnerability. A malicious actor with local user access to a guest virtual machine may elevate privileges within the virtual machine.

    Published: 27 Oct 2023
    6.4
    Medium

    CVE-2023-5051

    Last Modified: 8 Apr 2026

    The CallRail Phone Call Tracking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'callrail_form' shortcode in versions up to, and including, 0.5.2 due to insufficient input sanitization and output escaping on the 'form_id' user supplied attribute. This makes it possible for authenticated attackers with contributor level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 27 Oct 2023
    —
    Unknown

    CVE-2023-44375

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 27 Oct 2023
    —
    Unknown

    CVE-2023-44162

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 27 Oct 2023
    —
    Unknown

    CVE-2023-43738

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 27 Oct 2023
    6.3
    Medium

    CVE-2023-5814

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been classified as critical. This affects an unknown part of the file /classes/Master.php?f=save_reminder. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The identifier VDB-243645 was assigned to this vulnerability.

    Published: 27 Oct 2023
    6.3
    Medium

    CVE-2023-5813

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Task Reminder System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=delete_reminder. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The identifier of this vulnerability is VDB-243644.

    Published: 27 Oct 2023
    4.7
    Medium

    CVE-2023-5812

    Last Modified: 21 Nov 2024

    A vulnerability has been found in flusity CMS and classified as critical. Affected by this vulnerability is the function handleFileUpload of the file core/tools/upload.php. The manipulation of the argument uploaded_file leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The associated identifier of this vulnerability is VDB-243643.

    Published: 27 Oct 2023
    2.4
    Low

    CVE-2023-5811

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, was found in flusity CMS. Affected is the function loadPostAddForm of the file core/tools/posts.php. The manipulation of the argument menu_id leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The patch is identified as 6943991c62ed87c7a57989a0cb7077316127def8. It is recommended to apply a patch to fix this issue. VDB-243642 is the identifier assigned to this vulnerability.

    Published: 27 Oct 2023
    2.4
    Low

    CVE-2023-5810

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, has been found in flusity CMS. This issue affects the function loadPostAddForm of the file core/tools/posts.php. The manipulation of the argument edit_post_id leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The identifier of the patch is 6943991c62ed87c7a57989a0cb7077316127def8. It is recommended to apply a patch to fix this issue. The identifier VDB-243641 was assigned to this vulnerability.

    Published: 27 Oct 2023
    4
    Medium

    CVE-2023-46246

    Last Modified: 23 Jun 2026

    Vim is an improved version of the good old UNIX editor Vi. Heap-use-after-free in memory allocated in the function `ga_grow_inner` in in the file `src/alloc.c` at line 748, which is freed in the file `src/ex_docmd.c` in the function `do_cmdline` at line 1010 and then used again in `src/cmdhist.c` at line 759. When using the `:history` command, it's possible that the provided argument overflows the accepted value. Causing an Integer Overflow and potentially later an use-after-free. This vulnerability has been patched in version 9.0.2068.

    Published: 27 Oct 2023
    7.5
    High

    CVE-2024-1635

    Last Modified: 2 Oct 2026

    A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then closes the connection immediately, the server will end with both memory and open file limits exhausted at some point, depending on the amount of memory available. At HTTP upgrade to remoting, the WriteTimeoutStreamSinkConduit leaks connections if RemotingConnection is closed by Remoting ServerConnectionOpenListener. Because the remoting connection originates in Undertow as part of the HTTP upgrade, there is an external layer to the remoting connection. This connection is unaware of the outermost layer when closing the connection during the connection opening procedure. Hence, the Undertow WriteTimeoutStreamSinkConduit is not notified of the closed connection in this scenario. Because WriteTimeoutStreamSinkConduit creates a timeout task, the whole dependency tree leaks via that task, which is added to XNIO WorkerThread. So, the workerThread points to the Undertow conduit, which contains the connections and causes the leak.

    Published: 27 Oct 2023
    9.8
    Critical

    CVE-2023-45498

    Last Modified: 12 Jun 2025

    VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability.

    Published: 27 Oct 2023
    8.8
    High

    CVE-2023-35794

    Last Modified: 21 Nov 2024

    An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) can be accessed without authentication. Specifically, there is no session cookie validation on the Access Controller; instead, there is only Basic Authentication to the SSH console.

    Published: 27 Oct 2023
    6.5
    Medium

    CVE-2022-34832

    Last Modified: 21 Nov 2024

    An issue was discovered in VERMEG AgileReporter 21.3. XXE can occur via an XML document to the Analysis component.

    Published: 27 Oct 2023
    10
    Critical

    CVE-2023-46604

    Last Modified: 4 Nov 2025

    The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.

    Published: 27 Oct 2023
    9.8
    Critical

    CVE-2023-46853

    Last Modified: 21 Nov 2024

    In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.

    Published: 27 Oct 2023
    9.8
    Critical

    CVE-2023-45499

    Last Modified: 21 Nov 2024

    VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials.

    Published: 27 Oct 2023
    5.4
    Medium

    CVE-2022-34833

    Last Modified: 21 Nov 2024

    An issue was discovered in VERMEG AgileReporter 21.3. An admin can enter an XSS payload in the Analysis component.

    Published: 27 Oct 2023
    4.8
    Medium

    CVE-2022-34834

    Last Modified: 21 Nov 2024

    An issue was discovered in VERMEG AgileReporter 21.3. Attackers can gain privileges via an XSS payload in an Add Comment action to the Activity log.

    Published: 27 Oct 2023
    9.8
    Critical

    CVE-2023-46509

    Last Modified: 21 Nov 2024

    An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.

    Published: 27 Oct 2023
    7.2
    High

    CVE-2023-46818

    Last Modified: 21 Nov 2024

    An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled.

    Published: 27 Oct 2023
    6.1
    Medium

    CVE-2023-46505

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in FanCMS v.1.0.0 allows an attacker to execute arbitrary code via the content1 parameter in the demo.php file.

    Published: 27 Oct 2023
    8.8
    High

    CVE-2023-46375

    Last Modified: 21 Nov 2024

    ZenTao Biz version 4.1.3 and before is vulnerable to Cross Site Request Forgery (CSRF).

    Published: 27 Oct 2023
    7.5
    High

    CVE-2023-46376

    Last Modified: 21 Nov 2024

    Zentao Biz version 8.7 and before is vulnerable to Information Disclosure.

    Published: 27 Oct 2023
    7.5
    High

    CVE-2023-46393

    Last Modified: 21 Nov 2024

    gougucms v4.08.18 was discovered to contain a password reset poisoning vulnerability which allows attackers to arbitrarily reset users' passwords via a crafted packet.

    Published: 27 Oct 2023
    5.4
    Medium

    CVE-2023-46394

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in /home/user/edit_submit of gougucms v4.08.18 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the headimgurl parameter.

    Published: 27 Oct 2023
    5.5
    Medium

    CVE-2023-46407

    Last Modified: 11 Aug 2025

    FFmpeg prior to commit bf814 was discovered to contain an out of bounds read via the dist->alphabet_size variable in the read_vlc_prefix() function.

    Published: 27 Oct 2023
    6.5
    Medium

    CVE-2023-46490

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actions() function in the managers.php function.

    Published: 27 Oct 2023
    6.1
    Medium

    CVE-2023-46503

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in PwnCYN YXBOOKCMS v.1.0.2 allows a remote attacker to execute arbitrary code via the reader management and book input modules.

    Published: 27 Oct 2023
    5.4
    Medium

    CVE-2023-46504

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in PwnCYN YXBOOKCMS v.1.0.2 allows a physically proximate attacker to execute arbitrary code via the library name function in the general settings component.

    Published: 27 Oct 2023
    9.8
    Critical

    CVE-2023-46510

    Last Modified: 21 Nov 2024

    An issue in ZIONCOM (Hong Kong) Technology Limited A7000R v.4.1cu.4154 allows an attacker to execute arbitrary code via the cig-bin/cstecgi.cgi to the settings/setPasswordCfg function.

    Published: 27 Oct 2023