CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2023-45643

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Anurag Deshmukh CPT Shortcode Generator plugin <= 1.0 versions.

    Published: 16 Oct 2023
    5.4
    Medium

    CVE-2023-45642

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Hassan Ali Snap Pixel plugin <= 1.5.7 versions.

    Published: 16 Oct 2023
    5.5
    Medium

    CVE-2023-4457

    Last Modified: 21 Nov 2024

    Grafana is an open-source platform for monitoring and observability. The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability. The plugin did not properly sanitize error messages, making it potentially expose the Google Sheet API-key that is configured for the data source. This vulnerability was fixed in version 1.2.2.

    Published: 16 Oct 2023
    5.4
    Medium

    CVE-2023-45641

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Caret Inc. Caret Country Access Limit plugin <= 1.0.2 versions.

    Published: 16 Oct 2023
    4.3
    Medium

    CVE-2023-45639

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Codex-m Sort SearchResult By Title plugin <= 10.0 versions.

    Published: 16 Oct 2023
    10
    Critical

    CVE-2023-3991

    Last Modified: 21 Nov 2024

    An OS command injection vulnerability exists in the httpd iperfrun.cgi functionality of FreshTomato 2023.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 16 Oct 2023
    6.5
    Medium

    CVE-2023-45638

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in euPago Eupago Gateway For Woocommerce plugin <= 3.1.9 versions.

    Published: 16 Oct 2023
    5.4
    Medium

    CVE-2023-45656

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Kevin Weber Lazy Load for Videos plugin <= 2.18.2 versions.

    Published: 16 Oct 2023
    4.3
    Medium

    CVE-2023-45655

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in PixelGrade PixFields plugin <= 0.7.0 versions.

    Published: 16 Oct 2023
    4.3
    Medium

    CVE-2023-45654

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.7 versions.

    Published: 16 Oct 2023
    4.3
    Medium

    CVE-2023-45653

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Galaxy Weblinks Video Playlist For YouTube plugin <= 6.0 versions.

    Published: 16 Oct 2023
    4.3
    Medium

    CVE-2023-45651

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi WP Attachments allows Cross Site Request Forgery.This issue affects WP Attachments: from n/a through 5.0.11.

    Published: 16 Oct 2023
    4.3
    Medium

    CVE-2023-4834

    Last Modified: 21 Nov 2024

    In Red Lion Europe mbCONNECT24 and mymbCONNECT24 and Helmholz myREX24 and myREX24.virtual up to and including 2.14.2 an improperly implemented access validation allows an authenticated, low privileged attacker to gain read access to limited, non-critical device information in his account he should not have access to.

    Published: 16 Oct 2023
    4.3
    Medium

    CVE-2023-45650

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Fla-shop.Com HTML5 Maps plugin <= 1.7.1.4 versions.

    Published: 16 Oct 2023
    6.1
    Medium

    CVE-2023-4620

    Last Modified: 2 May 2025

    The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators

    Published: 16 Oct 2023
    7.2
    High

    CVE-2023-3392

    Last Modified: 21 Nov 2024

    The Read More & Accordion WordPress plugin before 3.2.7 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

    Published: 16 Oct 2023
    8.8
    High

    CVE-2023-4827

    Last Modified: 23 Apr 2025

    The File Manager Pro WordPress plugin before 1.8 does not properly check the CSRF nonce in the `fs_connector` AJAX action. This allows attackers to make highly privileged users perform unwanted file system actions via CSRF attacks by using GET requests, such as uploading a web shell.

    Published: 16 Oct 2023
    5.4
    Medium

    CVE-2023-45629

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 versions.

    Published: 16 Oct 2023
    4.3
    Medium

    CVE-2023-45606

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Lasso Simple URLs plugin <= 120 versions.

    Published: 16 Oct 2023
    4.3
    Medium

    CVE-2023-45605

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Christopher Finke Feed Statistics plugin <= 4.1 versions.

    Published: 16 Oct 2023
    5.5
    Medium

    CVE-2023-5595

    Last Modified: 21 Nov 2024

    Denial of Service in GitHub repository gpac/gpac prior to 2.3.0-DEV.

    Published: 16 Oct 2023
    4.3
    Medium

    CVE-2023-45274

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in SendPulse SendPulse Free Web Push plugin <= 1.3.1 versions.

    Published: 16 Oct 2023
    4.3
    Medium

    CVE-2023-45273

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Matt McKenny Stout Google Calendar plugin <= 1.2.3 versions.

    Published: 16 Oct 2023
    3.5
    Low

    CVE-2023-5421

    Last Modified: 21 Nov 2024

    An attacker who is logged into OTRS as an user with privileges to create and change customer user data may manipulate the CustomerID field to execute JavaScript code that runs immediatly after the data is saved.The issue onlyoccurs if the configuration for AdminCustomerUser::UseAutoComplete was changed before. This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before 8.0.37; ((OTRS)) Community Edition: from 6.0.X through 6.0.34.

    Published: 16 Oct 2023
    5.3
    Medium

    CVE-2023-38059

    Last Modified: 21 Nov 2024

    The loading of external images is not blocked, even if configured, if the attacker uses protocol-relative URL in the payload. This can be used to retreive the IP of the user.This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before 8.0.37; ((OTRS)) Community Edition: from 6.0.X through 6.0.34.

    Published: 16 Oct 2023
    8.7
    High

    CVE-2023-5422

    Last Modified: 21 Nov 2024

    The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the SSL_get_verify_result() function is not used the certificated is trusted always and it can not be ensured that the certificate satisfies all necessary security requirements. This could allow an attacker to use an invalid certificate to claim to be a trusted host, use expired certificates, or conduct other attacks that could be detected if the certificate is properly validated. This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before 8.0.37; ((OTRS)) Community Edition: from 6.0.X through 6.0.34.

    Published: 16 Oct 2023
    6.5
    Medium

    CVE-2023-43666

    Last Modified: 21 Nov 2024

    Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  General user can view all user data like Admin account. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/8623

    Published: 16 Oct 2023
    7.5
    High

    CVE-2023-43667

    Last Modified: 16 Jun 2025

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can create misleading or false log records, making it harder to audit and trace malicious activities. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8628

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-43668

    Last Modified: 21 Nov 2024

    Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  some sensitive params checks will be bypassed, like "autoDeserizalize","allowLoadLocalInfile".... .   Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/8604

    Published: 16 Oct 2023
    6.1
    Medium

    CVE-2023-45757

    Last Modified: 13 Feb 2025

    Security vulnerability in Apache bRPC <=1.6.0 on all platforms allows attackers to inject XSS code to the builtin rpcz page. An attacker that can send http request to bRPC server with rpcz enabled can inject arbitrary XSS code to the builtin rpcz page. Solution (choose one of three): 1. upgrade to bRPC > 1.6.0, download link: https://dist.apache.org/repos/dist/release/brpc/1.6.1/ 2. If you are using an old version of bRPC and hard to upgrade, you can apply this patch:  https://github.com/apache/brpc/pull/2411 3. disable rpcz feature

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-45158

    Last Modified: 21 Nov 2024

    An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifySendHandler for logging (not the default configuration), a crafted web request may execute an arbitrary OS command on the web server using the product.

    Published: 16 Oct 2023
    6.5
    Medium

    CVE-2023-21415

    Last Modified: 21 Nov 2024

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del.cgi is vulnerable to path traversal attacks that allows for file deletion. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

    Published: 16 Oct 2023
    7.1
    High

    CVE-2023-21414

    Last Modified: 21 Nov 2024

    NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

    Published: 16 Oct 2023
    9.1
    Critical

    CVE-2023-21413

    Last Modified: 16 Jun 2025

    GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis device. The application handling service in AXIS OS was vulnerable to command injection allowing an attacker to run arbitrary code. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

    Published: 16 Oct 2023
    8.4
    High

    CVE-2023-38280

    Last Modified: 21 Nov 2024

    IBM HMC (Hardware Management Console) 10.1.1010.0 and 10.2.1030.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 260740.

    Published: 16 Oct 2023
    4.9
    Medium

    CVE-2023-40377

    Last Modified: 21 Nov 2024

    Backup, Recovery, and Media Services (BRMS) for IBM i 7.2, 7.3, and 7.4 contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain component access to the host operating system. IBM X-Force ID: 263583.

    Published: 16 Oct 2023
    5.3
    Medium

    CVE-2023-33836

    Last Modified: 21 Nov 2024

    IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 256016.

    Published: 16 Oct 2023
    6.5
    Medium

    CVE-2023-5591

    Last Modified: 21 Nov 2024

    SQL Injection in GitHub repository librenms/librenms prior to 23.10.0.

    Published: 16 Oct 2023
    7.8
    High

    CVE-2023-45898

    Last Modified: 12 May 2026

    The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent.

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-36340

    Last Modified: 21 Nov 2024

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.

    Published: 16 Oct 2023
    5.4
    Medium

    CVE-2023-40851

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to run arbitrary code via fname, lname, email, and contact fields of the user registration page.

    Published: 16 Oct 2023
    6.1
    Medium

    CVE-2022-48612

    Last Modified: 21 Nov 2024

    A Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.7 allows remote attackers to inject JavaScript into any webpage, because a regular expression (validating whether a URL is controlled by ClassLink) is not present in all applicable places.

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-36947

    Last Modified: 21 Nov 2024

    TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule.

    Published: 16 Oct 2023
    7.8
    High

    CVE-2023-20598

    Last Modified: 21 Nov 2024

    An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over arbitrary hardware ports or physical addresses resulting in a potential arbitrary code execution.

    Published: 16 Oct 2023
    7.5
    High

    CVE-2023-45985

    Last Modified: 21 Nov 2024

    TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to contain a stack overflow in the function setParentalRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 16 Oct 2023
    6.5
    Medium

    CVE-2023-29484

    Last Modified: 21 Nov 2024

    In Terminalfour before 8.3.16, misconfigured LDAP users are able to login with an invalid password.

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-36950

    Last Modified: 21 Nov 2024

    TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-36952

    Last Modified: 21 Nov 2024

    TOTOLINK CP300+ V5.2cu.7594_B20200910 was discovered to contain a stack overflow via the pingIp parameter in the function setDiagnosisCfg.

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-36953

    Last Modified: 21 Nov 2024

    TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.

    Published: 16 Oct 2023
    9.8
    Critical

    CVE-2023-36954

    Last Modified: 21 Nov 2024

    TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.

    Published: 16 Oct 2023