CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2023-46190

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Novo-media Novo-Map : your WP posts on custom google maps plugin <= 1.1.2 versions.

    Published: 24 Oct 2023
    4.3
    Medium

    CVE-2023-46189

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Simple Calendar – Google Calendar Plugin <= 3.2.5 versions.

    Published: 24 Oct 2023
    4.3
    Medium

    CVE-2023-46152

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7.1 versions.

    Published: 24 Oct 2023
    4.3
    Medium

    CVE-2023-46151

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in AWESOME TOGI Product Category Tree plugin <= 2.5 versions.

    Published: 24 Oct 2023
    5.4
    Medium

    CVE-2023-46150

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WP Military WP Radio plugin <= 3.1.9 versions.

    Published: 24 Oct 2023
    9.8
    Critical

    CVE-2023-5746

    Last Modified: 21 Nov 2024

    A vulnerability regarding use of externally-controlled format string is found in the cgi component. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.5-0185 may be affected: BC500 and TC500.

    Published: 24 Oct 2023
    9.8
    Critical

    CVE-2023-46010

    Last Modified: 9 Jul 2026

    An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.

    Published: 24 Oct 2023
    5.3
    Medium

    CVE-2023-5678

    Last Modified: 12 May 2026

    Issue summary: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow. Impact summary: Applications that use the functions DH_generate_key() to generate an X9.42 DH key may experience long delays. Likewise, applications that use DH_check_pub_key(), DH_check_pub_key_ex() or EVP_PKEY_public_check() to check an X9.42 DH key or X9.42 DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service. While DH_check() performs all the necessary checks (as of CVE-2023-3817), DH_check_pub_key() doesn't make any of these checks, and is therefore vulnerable for excessively large P and Q parameters. Likewise, while DH_generate_key() performs a check for an excessively large P, it doesn't check for an excessively large Q. An application that calls DH_generate_key() or DH_check_pub_key() and supplies a key or parameters obtained from an untrusted source could be vulnerable to a Denial of Service attack. DH_generate_key() and DH_check_pub_key() are also called by a number of other OpenSSL functions. An application calling any of those other functions may similarly be affected. The other functions affected by this are DH_check_pub_key_ex(), EVP_PKEY_public_check(), and EVP_PKEY_generate(). Also vulnerable are the OpenSSL pkey command line application when using the "-pubcheck" option, as well as the OpenSSL genpkey command line application. The OpenSSL SSL/TLS implementation is not affected by this issue. The OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue.

    Published: 24 Oct 2023
    6.1
    Medium

    CVE-2023-36085

    Last Modified: 21 Nov 2024

    The sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdentityServer/core/" endpoint. By modifying the HTTP Host header, an attacker can change webpage links and even redirect users to arbitrary or malicious locations. This can lead to phishing attacks, malware distribution, and unauthorized access to sensitive resources.

    Published: 24 Oct 2023
    8.8
    High

    CVE-2022-38484

    Last Modified: 21 Nov 2024

    An arbitrary file upload and directory traversal vulnerability exist in the file upload functionality of the System Setup menu in AgeVolt Portal prior to version 0.1. A remote authenticated attacker could leverage this vulnerability to upload files to any location on the target operating system with web server privileges.

    Published: 24 Oct 2023
    4.9
    Medium

    CVE-2023-29973

    Last Modified: 21 Nov 2024

    Pfsense CE version 2.6.0 is vulnerable to No rate limit which can lead to an attacker creating multiple malicious users in firewall.

    Published: 24 Oct 2023
    7.5
    High

    CVE-2023-31582

    Last Modified: 21 Nov 2024

    jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less.

    Published: 24 Oct 2023
    5.9
    Medium

    CVE-2023-31580

    Last Modified: 21 Nov 2024

    light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application with a crafted JWT token.

    Published: 24 Oct 2023
    9.8
    Critical

    CVE-2023-31581

    Last Modified: 21 Nov 2024

    Dromara Sureness before v1.0.8 was discovered to use a hardcoded key.

    Published: 24 Oct 2023
    8.2
    High

    CVE-2023-39737

    Last Modified: 21 Nov 2024

    The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

    Published: 24 Oct 2023
    8.2
    High

    CVE-2023-39739

    Last Modified: 21 Nov 2024

    The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

    Published: 24 Oct 2023
    7.5
    High

    CVE-2023-39619

    Last Modified: 21 Nov 2024

    ReDos in NPMJS Node Email Check v.1.0.4 allows an attacker to cause a denial of service via a crafted string to the scpSyntax component.

    Published: 24 Oct 2023
    8.2
    High

    CVE-2023-39735

    Last Modified: 21 Nov 2024

    The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

    Published: 24 Oct 2023
    8.2
    High

    CVE-2023-39736

    Last Modified: 21 Nov 2024

    The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

    Published: 24 Oct 2023
    8.2
    High

    CVE-2023-39732

    Last Modified: 21 Nov 2024

    The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

    Published: 24 Oct 2023
    8.2
    High

    CVE-2023-39733

    Last Modified: 21 Nov 2024

    The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

    Published: 24 Oct 2023
    8.2
    High

    CVE-2023-39734

    Last Modified: 21 Nov 2024

    The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

    Published: 24 Oct 2023
    8.2
    High

    CVE-2023-39740

    Last Modified: 21 Nov 2024

    The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

    Published: 24 Oct 2023
    7.8
    High

    CVE-2023-45555

    Last Modified: 21 Nov 2024

    File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the down_url function in zzz.php file.

    Published: 24 Oct 2023
    6.5
    Medium

    CVE-2023-43281

    Last Modified: 21 Nov 2024

    Double Free vulnerability in Nothings Stb Image.h v.2.28 allows a remote attacker to cause a denial of service via a crafted file to the stbi_load_gif_main function.

    Published: 24 Oct 2023
    5.4
    Medium

    CVE-2023-43360

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Top Directory parameter in the File Picker Menu component.

    Published: 24 Oct 2023
    4.8
    Medium

    CVE-2023-44767

    Last Modified: 21 Nov 2024

    A File upload vulnerability in RiteCMS 3.0 allows a local attacker to upload a SVG file with XSS content.

    Published: 24 Oct 2023
    5.4
    Medium

    CVE-2023-44769

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Spare aliases from Alias.

    Published: 24 Oct 2023
    9.8
    Critical

    CVE-2023-45554

    Last Modified: 21 Nov 2024

    File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter from jpg, jpeg,gif, and png to jpg, jpeg,gif, png, pphphp.

    Published: 24 Oct 2023
    8
    High

    CVE-2023-45990

    Last Modified: 21 Nov 2024

    Insecure Permissions vulnerability in WenwenaiCMS v.1.0 allows a remote attacker to escalate privileges.

    Published: 24 Oct 2023
    5.5
    Medium

    CVE-2023-46316

    Last Modified: 21 Nov 2024

    In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3, the wrapper scripts do not properly parse command lines.

    Published: 24 Oct 2023
    9.8
    Critical

    CVE-2023-46369

    Last Modified: 21 Nov 2024

    Tenda W18E V16.01.0.8(1576) contains a stack overflow vulnerability via the portMirrorMirroredPorts parameter in the formSetNetCheckTools function.

    Published: 24 Oct 2023
    9.8
    Critical

    CVE-2023-46370

    Last Modified: 21 Nov 2024

    Tenda W18E V16.01.0.8(1576) has a command injection vulnerability via the hostName parameter in the formSetNetCheckTools function.

    Published: 24 Oct 2023
    9.8
    Critical

    CVE-2023-46371

    Last Modified: 21 Nov 2024

    TP-Link device TL-WDR7660 2.0.30 and TL-WR886N 2.0.12 has a stack overflow vulnerability via the function upgradeInfoJsonToBin.

    Published: 24 Oct 2023
    9.8
    Critical

    CVE-2023-46373

    Last Modified: 21 Nov 2024

    TP-Link TL-WDR7660 2.0.30 has a stack overflow vulnerability via the function deviceInfoJsonToBincauses.

    Published: 24 Oct 2023
    9.8
    Critical

    CVE-2023-46574

    Last Modified: 21 Nov 2024

    An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.

    Published: 24 Oct 2023
    4.3
    Medium

    CVE-2023-5721

    Last Modified: 13 Feb 2025

    It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

    Published: 24 Oct 2023
    7.5
    High

    CVE-2023-5724

    Last Modified: 13 Feb 2025

    Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

    Published: 24 Oct 2023
    4.3
    Medium

    CVE-2023-5726

    Last Modified: 21 Nov 2024

    A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. *Note: This issue only affected macOS operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

    Published: 24 Oct 2023
    6.5
    Medium

    CVE-2023-5727

    Last Modified: 21 Nov 2024

    The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which can run commands on a user's computer. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

    Published: 24 Oct 2023
    7.5
    High

    CVE-2023-5728

    Last Modified: 13 Feb 2025

    During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

    Published: 24 Oct 2023
    9.8
    Critical

    CVE-2023-5730

    Last Modified: 13 Feb 2025

    Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

    Published: 24 Oct 2023
    6.5
    Medium

    CVE-2022-38485

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability exists in the AgeVolt Portal prior to version 0.1 that leads to Information Disclosure. A remote authenticated attacker could leverage this vulnerability to read files from any location on the target operating system with web server privileges.

    Published: 24 Oct 2023
    4.3
    Medium

    CVE-2023-5725

    Last Modified: 13 Feb 2025

    A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

    Published: 24 Oct 2023
    6.5
    Medium

    CVE-2023-5732

    Last Modified: 18 Dec 2025

    An attacker could have created a malicious link using bidirectional characters to spoof the location in the address bar when visited. This vulnerability affects Firefox < 117, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

    Published: 24 Oct 2023
    4.1
    Medium

    CVE-2023-33837

    Last Modified: 21 Nov 2024

    IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission. IBM X-Force ID: 256020.

    Published: 23 Oct 2023
    7.2
    High

    CVE-2023-33839

    Last Modified: 21 Nov 2024

    IBM Security Verify Governance 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 256036.

    Published: 23 Oct 2023
    6.8
    Medium

    CVE-2022-22466

    Last Modified: 21 Nov 2024

    IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 225222.

    Published: 23 Oct 2023
    4.8
    Medium

    CVE-2023-33840

    Last Modified: 21 Nov 2024

    IBM Security Verify Governance 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 256037.

    Published: 23 Oct 2023
    4.3
    Medium

    CVE-2023-46288

    Last Modified: 13 Feb 2025

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.4.0 to 2.7.0. Sensitive configuration information has been exposed to authenticated users with the ability to read configuration via Airflow REST API for configuration even when the expose_config option is set to non-sensitive-only. The expose_config option is False by default. It is recommended to upgrade to a version that is not affected if you set expose_config to non-sensitive-only configuration. This is a different error than CVE-2023-45348 which allows authenticated user to retrieve individual configuration values in 2.7.* by specially crafting their request (solved in 2.7.2). Users are recommended to upgrade to version 2.7.2, which fixes the issue and additionally fixes CVE-2023-45348.

    Published: 23 Oct 2023