CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2023-5045

    Last Modified: 21 May 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Kayisi allows SQL Injection, Command Line Execution through SQL Injection. This issue affects Kayisi: before 1286.

    Published: 12 Oct 2023
    9.8
    Critical

    CVE-2023-5046

    Last Modified: 21 May 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Procost allows SQL Injection, Command Line Execution through SQL Injection. This issue affects Procost: before 1390.

    Published: 12 Oct 2023
    9.3
    Critical

    CVE-2023-23737

    Last Modified: 21 Nov 2024

    Unauth. SQL Injection (SQLi) vulnerability in MainWP MainWP Broken Links Checker Extension plugin <= 4.0 versions.

    Published: 12 Oct 2023
    8.5
    High

    CVE-2023-23651

    Last Modified: 21 Nov 2024

    Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP Google Analytics Extension plugin <= 4.0.4 versions.

    Published: 12 Oct 2023
    6.1
    Medium

    CVE-2023-5556

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository structurizr/onpremises prior to 3194.

    Published: 12 Oct 2023
    6.1
    Medium

    CVE-2023-5555

    Last Modified: 3 Oct 2025

    Cross-site Scripting (XSS) - Generic in GitHub repository frappe/lms prior to 5614a6203fb7d438be8e2b1e3030e4528d170ec4.

    Published: 12 Oct 2023
    4.8
    Medium

    CVE-2023-5554

    Last Modified: 9 Dec 2025

    Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16.0.

    Published: 12 Oct 2023
    7.1
    High

    CVE-2023-45047

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in LeadSquared, Inc LeadSquared Suite plugin <= 0.7.4 versions.

    Published: 12 Oct 2023
    6.4
    Medium

    CVE-2023-5470

    Last Modified: 8 Apr 2026

    The Etsy Shop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etsy-shop' shortcode in versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 12 Oct 2023
    9.1
    Critical

    CVE-2023-32724

    Last Modified: 3 Nov 2025

    Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory access and manipulation.

    Published: 12 Oct 2023
    8.5
    High

    CVE-2023-32723

    Last Modified: 13 Feb 2025

    Request to LDAP is sent before user permissions are checked.

    Published: 12 Oct 2023
    9.6
    Critical

    CVE-2023-32722

    Last Modified: 3 Nov 2025

    The zabbix/src/libs/zbxjson module is vulnerable to a buffer overflow when parsing JSON files via zbx_json_open.

    Published: 12 Oct 2023
    7.6
    High

    CVE-2023-32721

    Last Modified: 3 Nov 2025

    A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL.

    Published: 12 Oct 2023
    9.8
    Critical

    CVE-2023-29453

    Last Modified: 21 Nov 2024

    Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary Javascript code into the Go template. As ES6 template literals are rather complex, and themselves can do string interpolation, the decision was made to simply disallow Go template actions from being used inside of them (e.g., "var a = {{.}}"), since there is no obviously safe way to allow this behavior. This takes the same approach as github.com/google/safehtml. With fix, Template. Parse returns an Error when it encounters templates like this, with an ErrorCode of value 12. This ErrorCode is currently unexported but will be exported in the release of Go 1.21. Users who rely on the previous behavior can re-enable it using the GODEBUG flag jstmpllitinterp=1, with the caveat that backticks will now be escaped. This should be used with caution.

    Published: 12 Oct 2023
    4.3
    Medium

    CVE-2023-5531

    Last Modified: 8 Apr 2026

    The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the delete functionality. This makes it possible for unauthenticated attackers to delete image lightboxes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 12 Oct 2023
    —
    Unknown

    CVE-2023-45211

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 12 Oct 2023
    —
    Unknown

    CVE-2023-45313

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 12 Oct 2023
    —
    Unknown

    CVE-2023-45216

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 12 Oct 2023
    9.8
    Critical

    CVE-2023-41262

    Last Modified: 21 Nov 2024

    An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint action generateCSV is vulnerable to SQL injection through the sorting parameter, allowing an unauthenticated user to execute arbitrary SQL statements in the context of the application's backend database server.

    Published: 12 Oct 2023
    3.7
    Low

    CVE-2023-41263

    Last Modified: 21 Nov 2024

    An issue was discovered in Plixer Scrutinizer before 19.3.1. It exposes debug logs to unauthenticated users at the /debug/ URL path. With knowledge of valid IP addresses and source types, an unauthenticated attacker can download debug logs containing application-related information.

    Published: 12 Oct 2023
    7.5
    High

    CVE-2023-40829

    Last Modified: 21 Nov 2024

    There is an interface unauthorized access vulnerability in the background of Tencent Enterprise Wechat Privatization 2.5.x and 2.6.930000.

    Published: 12 Oct 2023
    9.8
    Critical

    CVE-2023-40833

    Last Modified: 21 Nov 2024

    An issue in Thecosy IceCMS v.1.0.0 allows a remote attacker to gain privileges via the Id and key parameters in getCosSetting.

    Published: 12 Oct 2023
    5.3
    Medium

    CVE-2023-41261

    Last Modified: 21 Nov 2024

    An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint action generateCSV does not require authentication and allows an unauthenticated user to export a report and access the results.

    Published: 12 Oct 2023
    8.8
    High

    CVE-2023-43147

    Last Modified: 21 Nov 2024

    PHPJabbers Limo Booking Software 1.0 is vulnerable to Cross Site Request Forgery (CSRF) to add an admin user via the Add Users Function, aka an index.php?controller=pjAdminUsers&action=pjActionCreate URI.

    Published: 12 Oct 2023
    8.8
    High

    CVE-2023-43149

    Last Modified: 21 Nov 2024

    SPA-Cart 1.9.0.3 is vulnerable to Cross Site Request Forgery (CSRF) that allows a remote attacker to add an admin user with role status.

    Published: 12 Oct 2023
    7.5
    High

    CVE-2023-45142

    Last Modified: 13 Feb 2025

    OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. A handler wrapper out of the box adds labels `http.user_agent` and `http.method` that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent to it. HTTP header User-Agent or HTTP method for requests can be easily set by an attacker to be random and long. The library internally uses `httpconv.ServerRequest` that records every value for HTTP `method` and `User-Agent`. In order to be affected, a program has to use the `otelhttp.NewHandler` wrapper and not filter any unknown HTTP methods or User agents on the level of CDN, LB, previous middleware, etc. Version 0.44.0 fixed this issue when the values collected for attribute `http.request.method` were changed to be restricted to a set of well-known values and other high cardinality attributes were removed. As a workaround to stop being affected, `otelhttp.WithFilter()` can be used, but it requires manual careful configuration to not log certain requests entirely. For convenience and safe usage of this library, it should by default mark with the label `unknown` non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it.

    Published: 12 Oct 2023
    7.5
    High

    CVE-2023-45510

    Last Modified: 21 Nov 2024

    tsMuxer version git-2539d07 was discovered to contain an alloc-dealloc-mismatch (operator new [] vs operator delete) error.

    Published: 12 Oct 2023
    5.5
    Medium

    CVE-2023-45511

    Last Modified: 21 Nov 2024

    A memory leak in tsMuxer version git-2539d07 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.

    Published: 12 Oct 2023
    6.7
    Medium

    CVE-2023-4822

    Last Modified: 30 Jan 2026

    Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations, and allows a user with Organization Admin permissions in one organization to change the permissions associated with Organization Viewer, Organization Editor and Organization Admin roles in all organizations. It also allows an Organization Admin to assign or revoke any permissions that they have to any user globally. This means that any Organization Admin can elevate their own permissions in any organization that they are already a member of, or elevate or restrict the permissions of any other user. The vulnerability does not allow a user to become a member of an organization that they are not already a member of, or to add any other users to an organization that the current user is not a member of.

    Published: 12 Oct 2023
    7.5
    High

    CVE-2023-5072

    Last Modified: 19 Sept 2025

    Denial of Service in JSON-Java versions up to and including 20230618.  A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.

    Published: 12 Oct 2023
    6.5
    Medium

    CVE-2023-5388

    Last Modified: 4 Nov 2025

    NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

    Published: 12 Oct 2023
    7
    High

    CVE-2023-5972

    Last Modified: 21 Nov 2024

    A null pointer dereference flaw was found in the nft_inner.c functionality of netfilter in the Linux kernel. This issue could allow a local user to crash the system or escalate their privileges on the system.

    Published: 12 Oct 2023
    7.8
    High

    CVE-2023-23632

    Last Modified: 3 Nov 2025

    BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed secret verification process in the BYOT shell jump sessions, allowing unauthorized access to jump items by guessing only the first character of the secret.

    Published: 12 Oct 2023
    4.3
    Medium

    CVE-2023-45362

    Last Modified: 4 Nov 2025

    An issue was discovered in DifferenceEngine.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. diff-multi-sameuser (aka "X intermediate revisions by the same user not shown") ignores username suppression. This is an information leak.

    Published: 12 Oct 2023
    5.4
    Medium

    CVE-2023-45360

    Last Modified: 4 Nov 2025

    An issue was discovered in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. There is XSS in youhavenewmessagesmanyusers and youhavenewmessages i18n messages. This is related to MediaWiki:Youhavenewmessagesfromusers.

    Published: 12 Oct 2023
    8.1
    High

    CVE-2023-43148

    Last Modified: 21 Nov 2024

    SPA-Cart 1.9.0.3 has a Cross Site Request Forgery (CSRF) vulnerability that allows a remote attacker to delete all accounts.

    Published: 12 Oct 2023
    5.5
    Medium

    CVE-2023-42298

    Last Modified: 21 Nov 2024

    An issue in GPAC GPAC v.2.2.1 and before allows a local attacker to cause a denial of service via the Q_DecCoordOnUnitSphere function of file src/bifs/unquantize.c.

    Published: 12 Oct 2023
    3.9
    Low

    CVE-2023-45143

    Last Modified: 13 Feb 2025

    Undici is an HTTP/1.1 client written from scratch for Node.js. Prior to version 5.26.2, Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Cookie` headers. By design, `cookie` headers are forbidden request headers, disallowing them to be set in RequestInit.headers in browser environments. Since undici handles headers more liberally than the spec, there was a disconnect from the assumptions the spec made, and undici's implementation of fetch. As such this may lead to accidental leakage of cookie to a third-party site or a malicious attacker who can control the redirection target (ie. an open redirector) to leak the cookie to the third party site. This was patched in version 5.26.2. There are no known workarounds.

    Published: 12 Oct 2023
    4.7
    Medium

    CVE-2024-0232

    Last Modified: 21 Nov 2025

    A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.

    Published: 12 Oct 2023
    6.3
    Medium

    CVE-2023-5473

    Last Modified: 13 Feb 2025

    Use after free in Cast in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

    Published: 11 Oct 2023
    4.3
    Medium

    CVE-2023-5486

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Input in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)

    Published: 11 Oct 2023
    4.3
    Medium

    CVE-2023-5477

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Installer in Google Chrome prior to 118.0.5993.70 allowed a local attacker to bypass discretionary access control via a crafted command. (Chromium security severity: Low)

    Published: 11 Oct 2023
    4.3
    Medium

    CVE-2023-5478

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

    Published: 11 Oct 2023
    4.3
    Medium

    CVE-2023-5485

    Last Modified: 16 Jun 2025

    Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass autofill restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 11 Oct 2023
    6.5
    Medium

    CVE-2023-5479

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Extensions API in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 11 Oct 2023
    8.8
    High

    CVE-2023-5474

    Last Modified: 1 May 2025

    Heap buffer overflow in PDF in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)

    Published: 11 Oct 2023
    8.8
    High

    CVE-2023-5476

    Last Modified: 1 May 2025

    Use after free in Blink History in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

    Published: 11 Oct 2023
    6.5
    Medium

    CVE-2023-5481

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Downloads in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

    Published: 11 Oct 2023
    6.5
    Medium

    CVE-2023-5483

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Intents in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 11 Oct 2023
    6.5
    Medium

    CVE-2023-5475

    Last Modified: 13 Feb 2025

    Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severity: Medium)

    Published: 11 Oct 2023