CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2023-5697

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in CodeAstro Internet Banking System 1.0. This affects an unknown part of the file pages_withdraw_money.php. The manipulation of the argument account_number with the input 287359614--><ScRiPt%20>alert(1234)</ScRiPt><!-- leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243135.

    Published: 22 Oct 2023
    3.5
    Low

    CVE-2023-5696

    Last Modified: 21 Nov 2024

    A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file pages_transfer_money.php. The manipulation of the argument account_number with the input 357146928--><ScRiPt%20>alert(9206)</ScRiPt><!-- leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-243134 is the identifier assigned to this vulnerability.

    Published: 22 Oct 2023
    3.5
    Low

    CVE-2023-5695

    Last Modified: 21 Nov 2024

    A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file pages_reset_pwd.php. The manipulation of the argument email with the input testing%40example.com'%26%25<ScRiPt%20>alert(9860)</ScRiPt> leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243133 was assigned to this vulnerability.

    Published: 22 Oct 2023
    3.5
    Low

    CVE-2023-5694

    Last Modified: 21 Nov 2024

    A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been classified as problematic. Affected is an unknown function of the file pages_system_settings.php. The manipulation of the argument sys_name with the input <ScRiPt >alert(991)</ScRiPt> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243132.

    Published: 22 Oct 2023
    6.3
    Medium

    CVE-2023-5693

    Last Modified: 12 Jun 2025

    A vulnerability was found in CodeAstro Internet Banking System 1.0 and classified as critical. This issue affects some unknown processing of the file pages_reset_pwd.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243131.

    Published: 22 Oct 2023
    5.4
    Medium

    CVE-2023-46095

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole Smooth Scroll Links [SSL] plugin <= 1.1.0 versions.

    Published: 22 Oct 2023
    4.3
    Medium

    CVE-2023-46089

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Lee Le @ Userback Userback plugin <= 1.0.13 versions.

    Published: 22 Oct 2023
    4.3
    Medium

    CVE-2023-46085

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.2.4 versions.

    Published: 22 Oct 2023
    5.7
    Medium

    CVE-2023-38735

    Last Modified: 21 Nov 2024

    IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a victim to a phishing site. IBM X-Force ID: 262482.

    Published: 22 Oct 2023
    5.9
    Medium

    CVE-2023-38276

    Last Modified: 21 Nov 2024

    IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid in further attacks against the system. IBM X-Force ID: 260736.

    Published: 22 Oct 2023
    5.9
    Medium

    CVE-2023-38275

    Last Modified: 21 Nov 2024

    IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to further attacks against the system. IBM X-Force ID: 260730.

    Published: 22 Oct 2023
    9.8
    Critical

    CVE-2023-46321

    Last Modified: 21 Nov 2024

    iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs. They may have shell metacharacters for a /usr/bin/man command line.

    Published: 22 Oct 2023
    9.8
    Critical

    CVE-2023-46322

    Last Modified: 21 Nov 2024

    iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The hostname's initial character may be non-alphanumeric. The hostname's other characters may be outside the set of alphanumeric characters, dash, and period.

    Published: 22 Oct 2023
    6.5
    Medium

    CVE-2021-46897

    Last Modified: 21 Nov 2024

    views.py in Wagtail CRX CodeRed Extensions (formerly CodeRed CMS or coderedcms) before 0.22.3 allows upward protected/..%2f..%2f path traversal when serving protected media.

    Published: 22 Oct 2023
    6.1
    Medium

    CVE-2021-46898

    Last Modified: 21 Nov 2024

    views/switch.py in django-grappelli (aka Django Grappelli) before 2.15.2 attempts to prevent external redirection with startswith("/") but this does not consider a protocol-relative URL (e.g., //example.com) attack.

    Published: 22 Oct 2023
    9.8
    Critical

    CVE-2023-46300

    Last Modified: 21 Nov 2024

    iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to tmux integration.

    Published: 22 Oct 2023
    9.8
    Critical

    CVE-2023-46301

    Last Modified: 21 Nov 2024

    iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to upload.

    Published: 22 Oct 2023
    7.5
    High

    CVE-2023-46317

    Last Modified: 21 Nov 2024

    Knot Resolver before 5.7.0 performs many TCP reconnections upon receiving certain nonsensical responses from servers.

    Published: 22 Oct 2023
    7.5
    High

    CVE-2023-46298

    Last Modified: 21 Nov 2024

    Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a denial of service to all users requesting the same URL via that CDN.

    Published: 22 Oct 2023
    7.5
    High

    CVE-2023-46319

    Last Modified: 21 Nov 2024

    WALLIX Bastion 9.x before 9.0.9 and 10.x before 10.0.5 allows unauthenticated access to sensitive information by bypassing access control on a network access administration web interface.

    Published: 22 Oct 2023
    7.5
    High

    CVE-2023-46315

    Last Modified: 21 Nov 2024

    The zanllp sd-webui-infinite-image-browsing (aka Infinite Image Browsing) extension before 977815a for stable-diffusion-webui (aka Stable Diffusion web UI), if Gradio authentication is enabled without secret key configuration, allows remote attackers to read any local file via /file?path= in the URL, as demonstrated by reading /proc/self/environ to discover credentials.

    Published: 22 Oct 2023
    7.5
    High

    CVE-2023-46303

    Last Modified: 4 Nov 2025

    link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources outside of the document root.

    Published: 22 Oct 2023
    8.4
    High

    CVE-2023-46306

    Last Modified: 21 Nov 2024

    The web administration interface in NetModule Router Software (NRSW) 4.6 before 4.6.0.106 and 4.8 before 4.8.0.101 executes an OS command constructed with unsanitized user input: shell metacharacters in the /admin/gnssAutoAlign.php device_id parameter. This occurs because another thread can be started before the trap that triggers the cleanup function. A successful exploit could allow an authenticated user to execute arbitrary commands with elevated privileges. NOTE: this is different from CVE-2023-0861 and CVE-2023-0862, which were fixed in version 4.6.0.105.

    Published: 22 Oct 2023
    5.4
    Medium

    CVE-2023-46078

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in PluginEver WC Serial Numbers plugin <= 1.6.3 versions.

    Published: 21 Oct 2023
    4.3
    Medium

    CVE-2023-46067

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Qwerty23 Rocket Font plugin <= 1.2.3 versions.

    Published: 21 Oct 2023
    5.3
    Medium

    CVE-2023-4939

    Last Modified: 8 Apr 2026

    The SALESmanago plugin for WordPress is vulnerable to Log Injection in versions up to, and including, 3.2.4. This is due to the use of a weak authentication token for the /wp-json/salesmanago/v1/callbackApiV3 API endpoint which is simply a SHA1 hash of the site URL and client ID found in the page source of the website. This makes it possible for unauthenticated attackers to inject arbitrary content into the log files, and when combined with another vulnerability this could have significant consequences.

    Published: 21 Oct 2023
    6.4
    Medium

    CVE-2023-5205

    Last Modified: 8 Apr 2026

    The Add Custom Body Class plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_custom_body_class' value in versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 21 Oct 2023
    6.1
    Medium

    CVE-2023-4635

    Last Modified: 8 Apr 2026

    The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 21 Oct 2023
    4.7
    Medium

    CVE-2023-5684

    Last Modified: 21 Nov 2024

    A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231012. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /importexport.php. The manipulation leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243061 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 21 Oct 2023
    6.3
    Medium

    CVE-2023-5683

    Last Modified: 21 Nov 2024

    A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231010 and classified as critical. This issue affects some unknown processing of the file /sysmanage/importconf.php. The manipulation of the argument btn_file_renew leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243059. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 21 Oct 2023
    7.5
    High

    CVE-2023-5132

    Last Modified: 8 Apr 2026

    The Soisy Pagamento Rateale plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the parseRemoteRequest function in versions up to, and including, 6.0.1. This makes it possible for unauthenticated attackers with knowledge of an existing WooCommerce Order ID to expose sensitive WooCommerce order information (e.g., Name, Address, Email Address, and other order metadata).

    Published: 21 Oct 2023
    5.4
    Medium

    CVE-2023-46003

    Last Modified: 21 Nov 2024

    I-doit pro 25 and below is vulnerable to Cross Site Scripting (XSS) via index.php.

    Published: 21 Oct 2023
    6.1
    Medium

    CVE-2023-38192

    Last Modified: 21 Nov 2024

    An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords.

    Published: 21 Oct 2023
    8.8
    High

    CVE-2023-38193

    Last Modified: 21 Nov 2024

    An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line.

    Published: 21 Oct 2023
    6.1
    Medium

    CVE-2023-38194

    Last Modified: 21 Nov 2024

    An issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter.

    Published: 21 Oct 2023
    8.8
    High

    CVE-2023-38190

    Last Modified: 21 Nov 2024

    An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Export SQL Injection via the size parameter.

    Published: 21 Oct 2023
    5.4
    Medium

    CVE-2023-46054

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in WBCE CMS v.1.6.1 and before allows a remote attacker to escalate privileges via a crafted script to the website_footer parameter in the admin/settings/save.php component.

    Published: 21 Oct 2023
    8.8
    High

    CVE-2023-46055

    Last Modified: 21 Nov 2024

    An issue in ThingNario Photon v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the ping function to the "thingnario Logger Maintenance Webpage" endpoint.

    Published: 21 Oct 2023
    5.3
    Medium

    CVE-2023-45682

    Last Modified: 21 Nov 2024

    stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds read in `DECODE` macro when `var` is negative. As it can be seen in the definition of `DECODE_RAW` a negative `var` is a valid value. This issue may be used to leak internal memory allocation information.

    Published: 20 Oct 2023
    7.3
    High

    CVE-2023-45681

    Last Modified: 13 Feb 2025

    stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory write past an allocated heap buffer in `start_decoder`. The root cause is a potential integer overflow in `sizeof(char*) * (f->comment_list_length)` which may make `setup_malloc` allocate less memory than required. Since there is another integer overflow an attacker may overflow it too to force `setup_malloc` to return 0 and make the exploit more reliable. This issue may lead to code execution.

    Published: 20 Oct 2023
    5.3
    Medium

    CVE-2023-45680

    Last Modified: 21 Nov 2024

    stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allocation failure in `start_decoder`. In that case the function returns early, the `f->comment_list` is set to `NULL`, but `f->comment_list_length` is not reset. Later in `vorbis_deinit` it tries to dereference the `NULL` pointer. This issue may lead to denial of service.

    Published: 20 Oct 2023
    7.3
    High

    CVE-2023-45679

    Last Modified: 21 Nov 2024

    stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allocation failure in `start_decoder`. In that case the function returns early, but some of the pointers in `f->comment_list` are left initialized and later `setup_free` is called on these pointers in `vorbis_deinit`. This issue may lead to code execution.

    Published: 20 Oct 2023
    6.5
    Medium

    CVE-2023-45678

    Last Modified: 21 Nov 2024

    stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of buffer write in `start_decoder` because at maximum `m->submaps` can be 16 but `submap_floor` and `submap_residue` are declared as arrays of 15 elements. This issue may lead to code execution.

    Published: 20 Oct 2023
    7.3
    High

    CVE-2023-45677

    Last Modified: 21 Nov 2024

    stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds write in `f->vendor[len] = (char)'\0';`. The root cause is that if `len` read in `start_decoder` is a negative number and `setup_malloc` successfully allocates memory in that case, but memory write is done with a negative index `len`. Similarly if len is INT_MAX the integer overflow len+1 happens in `f->vendor = (char*)setup_malloc(f, sizeof(char) * (len+1));` and `f->comment_list[i] = (char*)setup_malloc(f, sizeof(char) * (len+1));`. This issue may lead to code execution.

    Published: 20 Oct 2023
    7.3
    High

    CVE-2023-45676

    Last Modified: 21 Nov 2024

    stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds write in `f->vendor[i] = get8_packet(f);`. The root cause is an integer overflow in `setup_malloc`. A sufficiently large value in the variable `sz` overflows with `sz+7` in and the negative value passes the maximum available memory buffer check. This issue may lead to code execution.

    Published: 20 Oct 2023
    6.5
    Medium

    CVE-2023-45675

    Last Modified: 13 Feb 2025

    stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds write in `f->vendor[len] = (char)'\0';`. The root cause is that if the len read in `start_decoder` is `-1` and `len + 1` becomes 0 when passed to `setup_malloc`. The `setup_malloc` behaves differently when `f->alloc.alloc_buffer` is pre-allocated. Instead of returning `NULL` as in `malloc` case it shifts the pre-allocated buffer by zero and returns the currently available memory block. This issue may lead to code execution.

    Published: 20 Oct 2023
    5.3
    Medium

    CVE-2023-45667

    Last Modified: 13 Feb 2025

    stb_image is a single file MIT licensed library for processing images. If `stbi__load_gif_main` in `stbi_load_gif_from_memory` fails it returns a null pointer and may keep the `z` variable uninitialized. In case the caller also sets the flip vertically flag, it continues and calls `stbi__vertical_flip_slices` with the null pointer result value and the uninitialized `z` value. This may result in a program crash.

    Published: 20 Oct 2023
    7.3
    High

    CVE-2023-45666

    Last Modified: 13 Feb 2025

    stb_image is a single file MIT licensed library for processing images. It may look like `stbi__load_gif_main` doesn’t give guarantees about the content of output value `*delays` upon failure. Although it sets `*delays` to zero at the beginning, it doesn’t do it in case the image is not recognized as GIF and a call to `stbi__load_gif_main_outofmem` only frees possibly allocated memory in `*delays` without resetting it to zero. Thus it would be fair to say the caller of `stbi__load_gif_main` is responsible to free the allocated memory in `*delays` only if `stbi__load_gif_main` returns a non null value. However at the same time the function may return null value, but fail to free the memory in `*delays` if internally `stbi__convert_format` is called and fails. Thus the issue may lead to a memory leak if the caller chooses to free `delays` only when `stbi__load_gif_main` didn’t fail or to a double-free if the `delays` is always freed

    Published: 20 Oct 2023
    7.3
    High

    CVE-2023-45664

    Last Modified: 13 Feb 2025

    stb_image is a single file MIT licensed library for processing images. A crafted image file can trigger `stbi__load_gif_main_outofmem` attempt to double-free the out variable. This happens in `stbi__load_gif_main` because when the `layers * stride` value is zero the behavior is implementation defined, but common that realloc frees the old memory and returns null pointer. Since it attempts to double-free the memory a few lines below the first “free”, the issue can be potentially exploited only in a multi-threaded environment. In the worst case this may lead to code execution.

    Published: 20 Oct 2023
    5.3
    Medium

    CVE-2023-45663

    Last Modified: 13 Feb 2025

    stb_image is a single file MIT licensed library for processing images. The stbi__getn function reads a specified number of bytes from context (typically a file) into the specified buffer. In case the file stream points to the end, it returns zero. There are two places where its return value is not checked: In the `stbi__hdr_load` function and in the `stbi__tga_load` function. The latter of the two is likely more exploitable as an attacker may also control the size of an uninitialized buffer.

    Published: 20 Oct 2023