CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2023-45059

    Last Modified: 28 Apr 2026

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Gumroad plugin <= 3.1.0 versions.

    Published: 18 Oct 2023
    5.9
    Medium

    CVE-2023-45057

    Last Modified: 28 Apr 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Hitsteps Web Analytics plugin <= 5.86 versions.

    Published: 18 Oct 2023
    5.9
    Medium

    CVE-2023-45056

    Last Modified: 28 Apr 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in 100plugins Open User Map plugin <= 1.3.26 versions.

    Published: 18 Oct 2023
    7.1
    High

    CVE-2023-45054

    Last Modified: 28 Apr 2026

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AWESOME TOGI Product Category Tree plugin <= 2.5 versions.

    Published: 18 Oct 2023
    5.9
    Medium

    CVE-2023-45051

    Last Modified: 28 Apr 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Image vertical reel scroll slideshow plugin <= 9.0 versions.

    Published: 18 Oct 2023
    6.5
    Medium

    CVE-2023-45049

    Last Modified: 28 Apr 2026

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ciprian Popescu YouTube Playlist Player plugin <= 4.6.7 versions.

    Published: 18 Oct 2023
    7.1
    High

    CVE-2023-25476

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ezoic AmpedSense – AdSense Split Tester plugin <= 4.68 versions.

    Published: 18 Oct 2023
    5.9
    Medium

    CVE-2023-45008

    Last Modified: 28 Apr 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPJohnny Comment Reply Email plugin <= 1.0.3 versions.

    Published: 18 Oct 2023
    4.3
    Medium

    CVE-2023-4938

    Last Modified: 8 Apr 2026

    The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_apply_default_combination function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.

    Published: 18 Oct 2023
    4.4
    Medium

    CVE-2023-5621

    Last Modified: 8 Apr 2026

    The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Title field in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 18 Oct 2023
    7.2
    High

    CVE-2023-5538

    Last Modified: 8 Apr 2026

    The MpOperationLogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the IP Request Headers in versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 18 Oct 2023
    4.3
    Medium

    CVE-2023-3254

    Last Modified: 8 Apr 2026

    The Widgets for Google Reviews plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.9. This is due to missing or incorrect nonce validation within setup_no_reg_header.php. This makes it possible for unauthenticated attackers to reset plugin settings and remove reviews via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 18 Oct 2023
    6.5
    Medium

    CVE-2023-35083

    Last Modified: 21 Nov 2024

    Allows an authenticated attacker with network access to read arbitrary files on Endpoint Manager recently discovered on 2022 SU3 and all previous versions potentially leading to the leakage of sensitive information.

    Published: 18 Oct 2023
    9.8
    Critical

    CVE-2023-35084

    Last Modified: 21 Nov 2024

    Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previous versions, which could allow an attacker to execute commands remotely.

    Published: 18 Oct 2023
    7.8
    High

    CVE-2023-46009

    Last Modified: 4 Nov 2025

    gifsicle-1.94 was found to have a floating point exception (FPE) vulnerability via resize_stream at src/xform.c.

    Published: 18 Oct 2023
    6.1
    Medium

    CVE-2023-45909

    Last Modified: 21 Nov 2024

    zzzcms v2.2.0 was discovered to contain an open redirect vulnerability.

    Published: 18 Oct 2023
    6.1
    Medium

    CVE-2023-45958

    Last Modified: 21 Nov 2024

    Thirty Bees Core v1.4.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the backup_pagination parameter at /controller/AdminController.php. This vulnerability allows attackers to execute arbitrary JavaScript in the web browser of a user via a crafted payload.

    Published: 18 Oct 2023
    7.2
    High

    CVE-2023-46004

    Last Modified: 21 Nov 2024

    Sourcecodester Best Courier Management System 1.0 is vulnerable to Arbitrary file upload in the update_user function.

    Published: 18 Oct 2023
    9.8
    Critical

    CVE-2023-46005

    Last Modified: 21 Nov 2024

    Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_branch.php.

    Published: 18 Oct 2023
    9.8
    Critical

    CVE-2023-46006

    Last Modified: 21 Nov 2024

    Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_user.php.

    Published: 18 Oct 2023
    9.8
    Critical

    CVE-2023-46007

    Last Modified: 21 Nov 2024

    Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_staff.php.

    Published: 18 Oct 2023
    7.5
    High

    CVE-2023-42319

    Last Modified: 21 Nov 2024

    Geth (aka go-ethereum) through 1.13.4, when --http --graphql is used, allows remote attackers to cause a denial of service (memory consumption and daemon hang) via a crafted GraphQL query. NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic.

    Published: 18 Oct 2023
    7.8
    High

    CVE-2023-43250

    Last Modified: 21 Nov 2024

    XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow. There is a User Mode Write AV via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.

    Published: 18 Oct 2023
    3.6
    Low

    CVE-2023-45145

    Last Modified: 13 Feb 2025

    Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix socket before adjusting its permissions to the user-provided configuration. If a permissive umask(2) is used, this creates a race condition that enables, during a short period of time, another process to establish an otherwise unauthorized connection. This problem has existed since Redis 2.6.0-RC1. This issue has been addressed in Redis versions 7.2.2, 7.0.14 and 6.2.14. Users are advised to upgrade. For users unable to upgrade, it is possible to work around the problem by disabling Unix sockets, starting Redis with a restrictive umask, or storing the Unix socket file in a protected directory.

    Published: 18 Oct 2023
    7.5
    High

    CVE-2023-45383

    Last Modified: 21 Nov 2024

    In the module "SoNice etiquetage" (sonice_etiquetage) up to version 2.5.9 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a path traversal to view all files on the information system.

    Published: 18 Oct 2023
    9.8
    Critical

    CVE-2023-45911

    Last Modified: 9 Jan 2025

    An issue in WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 allows unauthenticated attackers to login as any user without a password.

    Published: 18 Oct 2023
    7.5
    High

    CVE-2023-45912

    Last Modified: 9 Jan 2025

    WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 fails to validate user sessions, allowing unauthenticated attackers to read files from the underlying operating system and obtain directory listings.

    Published: 18 Oct 2023
    7.5
    High

    CVE-2023-5632

    Last Modified: 25 Jun 2025

    In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server without sending data causes the EPOLLOUT event to be added, which results excessive CPU consumption. This could be used by a malicious actor to perform denial of service type attack. This issue is fixed in 2.0.6

    Published: 18 Oct 2023
    7.1
    High

    CVE-2023-5552

    Last Modified: 21 Nov 2024

    A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewall version 19.5 MR3 (19.5.3) and older, if the password type is set to “Specified by sender”.

    Published: 17 Oct 2023
    8.8
    High

    CVE-2023-5626

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) in GitHub repository pkp/ojs prior to 3.3.0-16.

    Published: 17 Oct 2023
    5.3
    Medium

    CVE-2023-3042

    Last Modified: 12 Jun 2025

    In dotCMS, versions mentioned, a flaw in the NormalizationFilter does not strip double slashes (//) from URLs, potentially enabling bypasses for XSS and access controls. An example affected URL is https://demo.dotcms.com//html/portlet/ext/files/edit_text_inc.jsp , which should return a 404 response but didn't. The oversight in the default invalid URL character list can be viewed at the provided GitHub link https://github.com/dotCMS/core/blob/master/dotCMS/src/main/java/com/dotcms/filters/NormalizationFilter.java#L37 .  To mitigate, users can block URLs with double slashes at firewalls or utilize dotCMS config variables. Specifically, they can use the DOT_URI_NORMALIZATION_FORBIDDEN_STRINGS environmental variable to add // to the list of invalid strings. Additionally, the DOT_URI_NORMALIZATION_FORBIDDEN_REGEX variable offers more detailed control, for instance, to block //html.* URLs. Fix Version:23.06+, LTS 22.03.7+, LTS 23.01.4+

    Published: 17 Oct 2023
    8.1
    High

    CVE-2023-45811

    Last Modified: 22 Jul 2025

    Synchrony deobfuscator is a javascript cleaner & deobfuscator. A `__proto__` pollution vulnerability exists in versions before v2.4.4. Successful exploitation could lead to arbitrary code execution. A `__proto__` pollution vulnerability exists in the `LiteralMap` transformer allowing crafted input to modify properties in the Object prototype. A fix has been released in `[email protected]`. Users are advised to upgrade. Users unable to upgrade should launch node with the [--disable-proto=delete][disable-proto] or [--disable-proto=throw][disable-proto] flags

    Published: 17 Oct 2023
    8.8
    High

    CVE-2023-41715

    Last Modified: 16 Dec 2025

    SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside the tunnel.

    Published: 17 Oct 2023
    7.8
    High

    CVE-2023-42507

    Last Modified: 21 Nov 2024

    Stack-based buffer overflow vulnerability exists in OnSinView2 versions 2.0.1 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user open a specially crafted OnSinView2 project file.

    Published: 17 Oct 2023
    7.8
    High

    CVE-2023-42506

    Last Modified: 21 Nov 2024

    Improper restriction of operations within the bounds of a memory buffer issue exists in OnSinView2 versions 2.0.1 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user open a specially crafted OnSinView2 project file.

    Published: 17 Oct 2023
    5.3
    Medium

    CVE-2023-45810

    Last Modified: 21 Nov 2024

    OpenFGA is a flexible authorization/permission engine built for developers and inspired by Google Zanzibar. Affected versions of OpenFGA are vulnerable to a denial of service attack. When a number of `ListObjects` calls are executed, in some scenarios, those calls are not releasing resources even after a response has been sent, and given a sufficient call volume the service as a whole becomes unresponsive. This issue has been addressed in version 1.3.4 and the upgrade is considered backwards compatible. There are no known workarounds for this vulnerability.

    Published: 17 Oct 2023
    7.5
    High

    CVE-2023-41713

    Last Modified: 21 Nov 2024

    SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function.

    Published: 17 Oct 2023
    6.5
    Medium

    CVE-2023-41712

    Last Modified: 21 Nov 2024

    SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp URL endpoint leads to a firewall crash.

    Published: 17 Oct 2023
    6.5
    Medium

    CVE-2023-41711

    Last Modified: 21 Nov 2024

    SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the sonicwall.exp, prefs.exp URL endpoints lead to a firewall crash.

    Published: 17 Oct 2023
    6.5
    Medium

    CVE-2023-39280

    Last Modified: 21 Nov 2024

    SonicOS p ost-authentication Stack-Based Buffer Overflow vulnerability in the ssoStats-s.xml, ssoStats-s.wri URL endpoints leads to a firewall crash.

    Published: 17 Oct 2023
    6.5
    Medium

    CVE-2023-39279

    Last Modified: 21 Nov 2024

    SonicOS post-authentication Stack-Based Buffer Overflow vulnerability in the getPacketReplayData.json URL endpoint leads to a firewall crash.

    Published: 17 Oct 2023
    6.5
    Medium

    CVE-2023-39278

    Last Modified: 21 Nov 2024

    SonicOS post-authentication user assertion failure leads to Stack-Based Buffer Overflow vulnerability via main.cgi leads to a firewall crash.

    Published: 17 Oct 2023
    6.5
    Medium

    CVE-2023-39277

    Last Modified: 21 Nov 2024

    SonicOS post-authentication stack-based buffer overflow vulnerability in the sonicflow.csv and appflowsessions.csv URL endpoints leads to a firewall crash.

    Published: 17 Oct 2023
    6.5
    Medium

    CVE-2023-39276

    Last Modified: 21 Nov 2024

    SonicOS post-authentication stack-based buffer overflow vulnerability in the getBookmarkList.json URL endpoint leads to a firewall crash.

    Published: 17 Oct 2023
    5.9
    Medium

    CVE-2023-22130

    Last Modified: 21 Nov 2024

    Vulnerability in the Sun ZFS Storage Appliance product of Oracle Systems (component: Core). The supported version that is affected is 8.8.60. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Sun ZFS Storage Appliance. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Sun ZFS Storage Appliance. CVSS 3.1 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).

    Published: 17 Oct 2023
    5.5
    Medium

    CVE-2023-22129

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. Note: This vunlerability only affects SPARC Systems. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

    Published: 17 Oct 2023
    3.1
    Low

    CVE-2023-22128

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows unauthenticated attacker with network access via rquota to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Solaris accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).

    Published: 17 Oct 2023
    6.3
    Medium

    CVE-2023-22127

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Content Access SDK, Image Export SDK, PDF Export SDK, HTML Export SDK). The supported version that is affected is 8.5.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data as well as unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).

    Published: 17 Oct 2023
    5.3
    Medium

    CVE-2023-22126

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

    Published: 17 Oct 2023
    5.4
    Medium

    CVE-2023-22125

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 14.5-14.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Trade Finance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Trade Finance accessible data as well as unauthorized read access to a subset of Oracle Banking Trade Finance accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).

    Published: 17 Oct 2023