CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2023-5493

    Last Modified: 21 Nov 2024

    A vulnerability has been found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230928 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /useratte/web.php. The manipulation of the argument file_upload leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-241645 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Oct 2023
    5.4
    Medium

    CVE-2023-44996

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Naresh Parmar Post View Count plugin <= 1.8.2 versions.

    Published: 10 Oct 2023
    5.4
    Medium

    CVE-2023-44995

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in WP Doctor WooCommerce Login Redirect plugin <= 2.2.4 versions.

    Published: 10 Oct 2023
    6.3
    Medium

    CVE-2023-5492

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230928. Affected is an unknown function of the file /sysmanage/licence.php. The manipulation of the argument file_upload leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-241644. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Oct 2023
    6.3
    Medium

    CVE-2023-5491

    Last Modified: 16 Jun 2025

    A vulnerability, which was classified as critical, has been found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230928. This issue affects some unknown processing of the file /sysmanage/updatelib.php. The manipulation of the argument file_upload leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-241643. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Oct 2023
    6.3
    Medium

    CVE-2023-5490

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230928. This vulnerability affects unknown code of the file /useratte/userattestation.php. The manipulation of the argument web_img leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-241642 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Oct 2023
    —
    Unknown

    CVE-2023-45665

    Last Modified: 7 Nov 2023

    This CVE is a duplicate of another CVE.

    Published: 10 Oct 2023
    4.3
    Medium

    CVE-2023-44994

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Bainternet ShortCodes UI plugin <= 1.9.8 versions.

    Published: 10 Oct 2023
    6.3
    Medium

    CVE-2023-5489

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230928. This affects an unknown part of the file /Tool/uploadfile.php. The manipulation of the argument file_upload leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-241641 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Oct 2023
    4.3
    Medium

    CVE-2023-44476

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Andres Felipe Perea V. CopyRightPro plugin <= 2.1 versions.

    Published: 10 Oct 2023
    9.8
    Critical

    CVE-2023-30806

    Last Modified: 22 Nov 2025

    The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /cgi-bin/login.cgi endpoint. This is due to mishandling of shell meta-characters in the PHPSESSID cookie.

    Published: 10 Oct 2023
    5.4
    Medium

    CVE-2023-44475

    Last Modified: 30 Dec 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Michael Simpson Add Shortcodes Actions And Filters plugin <= 2.0.9 versions.

    Published: 10 Oct 2023
    9.8
    Critical

    CVE-2023-30805

    Last Modified: 28 Nov 2025

    The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /LogInOut.php endpoint. This is due to mishandling of shell meta-characters in the "un" parameter.

    Published: 10 Oct 2023
    4.3
    Medium

    CVE-2023-44471

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Bernhard Kau Backend Localization plugin <= 2.1.10 versions.

    Published: 10 Oct 2023
    6.9
    Medium

    CVE-2023-30804

    Last Modified: 1 Oct 2026

    The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authenticated file disclosure vulnerability. A remote and authenticated attacker can read arbitrary system files using the svpn_html/loadfile.php endpoint. This issue is exploitable by a remote and unauthenticated attacker when paired with CVE-2023-30803.

    Published: 10 Oct 2023
    9.8
    Critical

    CVE-2023-30803

    Last Modified: 28 Nov 2025

    The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can bypass authentication and access administrative functionality by sending HTTP requests using a crafted Y-forwarded-for header.

    Published: 10 Oct 2023
    5.3
    Medium

    CVE-2023-30802

    Last Modified: 28 Nov 2025

    The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to a source code disclosure vulnerability. A remote and unauthenticated attacker can obtain PHP source code by sending an HTTP request with an invalid Content-Length field.

    Published: 10 Oct 2023
    6.3
    Medium

    CVE-2023-5488

    Last Modified: 21 Nov 2024

    A vulnerability was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230928. It has been rated as critical. Affected by this issue is some unknown functionality of the file /sysmanage/updatelib.php. The manipulation of the argument file_upload leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-241640. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Oct 2023
    5.4
    Medium

    CVE-2023-44470

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Kvvaradha Kv TinyMCE Editor Add Fonts plugin <= 1.1 versions.

    Published: 10 Oct 2023
    4.3
    Medium

    CVE-2023-44241

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Keap Keap Landing Pages plugin <= 1.4.2 versions.

    Published: 10 Oct 2023
    9.8
    Critical

    CVE-2023-30801

    Last Modified: 21 Nov 2025

    All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials to authenticate and execute arbitrary operating system commands using the "external program" feature in the web user interface. This was reportedly exploited in the wild in March 2023.

    Published: 10 Oct 2023
    7.5
    High

    CVE-2023-5499

    Last Modified: 21 Nov 2024

    Information exposure vulnerability in Shenzhen Reachfar v28, the exploitation of which could allow a remote attacker to retrieve all the week's logs stored in the 'log2' directory. An attacker could retrieve sensitive information such as remembered wifi networks, sent messages, SOS device locations and device configurations.

    Published: 10 Oct 2023
    9.4
    Critical

    CVE-2023-4966

    Last Modified: 24 Oct 2025

    Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

    Published: 10 Oct 2023
    7.4
    High

    CVE-2023-45226

    Last Modified: 21 Nov 2024

    The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacker with the ability to intercept traffic to impersonate the SPK Secure Shell (SSH) server on those containers. This is only exposed when ssh debug is enabled.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Published: 10 Oct 2023
    4.4
    Medium

    CVE-2023-45219

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 10 Oct 2023
    8.7
    High

    CVE-2023-43746

    Last Modified: 21 Nov 2024

    When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing BIG-IP external monitor on a BIG-IP system.  A successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 10 Oct 2023
    7.8
    High

    CVE-2023-43611

    Last Modified: 21 Nov 2024

    The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process.  This vulnerability is due to an incomplete fix for CVE-2023-38418.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Published: 10 Oct 2023
    5.5
    Medium

    CVE-2023-43485

    Last Modified: 21 Nov 2024

    When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 10 Oct 2023
    7.2
    High

    CVE-2023-42768

    Last Modified: 21 Nov 2024

    When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's role is reverted back to a non-admin role via the Configuration utility, tmsh, or iControl REST. BIG-IP non-admin user can still have access to iControl REST admin resource.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 10 Oct 2023
    4.3
    Medium

    CVE-2023-41964

    Last Modified: 21 Nov 2024

    The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 10 Oct 2023
    9.9
    Critical

    CVE-2023-41373

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 10 Oct 2023
    5.5
    Medium

    CVE-2023-41253

    Last Modified: 21 Nov 2024

    When on BIG-IP DNS or BIG-IP LTM enabled with DNS Services License, and a TSIG key is created, it is logged in plaintext in the audit log.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 10 Oct 2023
    7.5
    High

    CVE-2023-41085

    Last Modified: 21 Nov 2024

    When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 10 Oct 2023
    7.5
    High

    CVE-2023-40542

    Last Modified: 19 Sept 2025

    When TCP Verified Accept is enabled on a TCP profile that is configured on a Virtual Server, undisclosed requests can cause an increase in memory resource utilization.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Published: 10 Oct 2023
    8.1
    High

    CVE-2023-40537

    Last Modified: 21 Nov 2024

    An authenticated user's session cookie may remain valid for a limited time after logging out from the BIG-IP Configuration utility on a multi-blade VIPRION platform.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 10 Oct 2023
    7.5
    High

    CVE-2023-40534

    Last Modified: 21 Nov 2024

    When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using the HTTP_REQUEST event or Local Traffic Policy are associated with the virtual server, undisclosed requests can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 10 Oct 2023
    4.4
    Medium

    CVE-2023-39447

    Last Modified: 21 Nov 2024

    When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 10 Oct 2023
    7.3
    High

    CVE-2023-5450

    Last Modified: 21 Nov 2024

    An insufficient verification of data vulnerability exists in BIG-IP Edge Client Installer on macOS that may allow an attacker elevation of privileges during the installation process.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 10 Oct 2023
    7.8
    High

    CVE-2023-45601

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.262), Parasolid V35.1 (All versions < V35.1.250), Parasolid V36.0 (All versions < V36.0.169), Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (All versions < V2302.0003). The affected applications contain a stack overflow vulnerability while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21290)

    Published: 10 Oct 2023
    7.8
    High

    CVE-2023-45205

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SICAM PAS/PQS (All versions >= V8.00 < V8.20). The affected application is installed with specific files and folders with insecure permissions. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges to `NT AUTHORITY/SYSTEM`.

    Published: 10 Oct 2023
    7.8
    High

    CVE-2023-45204

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (All versions < V2302.0003). The affected applications contain a type confusion vulnerability while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21268)

    Published: 10 Oct 2023
    4.7
    Medium

    CVE-2023-44315

    Last Modified: 27 Feb 2025

    A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application improperly sanitizes certain SNMP configuration data retrieved from monitored devices. An attacker with access to a monitored device could prepare a stored cross-site scripting (XSS) attack that may lead to unintentional modification of application data by legitimate users.

    Published: 10 Oct 2023
    7.8
    High

    CVE-2023-44087

    Last Modified: 27 Feb 2025

    A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (All versions < V2302.0003). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted SPP files. This could allow an attacker to execute code in the context of the current process.

    Published: 10 Oct 2023
    7.8
    High

    CVE-2023-44086

    Last Modified: 27 Feb 2025

    A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (All versions < V2302.0003). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted SPP files. This could allow an attacker to execute code in the context of the current process.

    Published: 10 Oct 2023
    7.8
    High

    CVE-2023-44085

    Last Modified: 27 Feb 2025

    A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (All versions < V2302.0003). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted SPP files. This could allow an attacker to execute code in the context of the current process.

    Published: 10 Oct 2023
    7.8
    High

    CVE-2023-44084

    Last Modified: 27 Feb 2025

    A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (All versions < V2302.0003). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted SPP files. This could allow an attacker to execute code in the context of the current process.

    Published: 10 Oct 2023
    7.8
    High

    CVE-2023-44083

    Last Modified: 27 Feb 2025

    A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (All versions < V2302.0003). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process.

    Published: 10 Oct 2023
    7.8
    High

    CVE-2023-44082

    Last Modified: 27 Feb 2025

    A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (All versions < V2302.0003). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process.

    Published: 10 Oct 2023
    7.8
    High

    CVE-2023-44081

    Last Modified: 27 Feb 2025

    A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (All versions < V2302.0003). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process.

    Published: 10 Oct 2023
    9.8
    Critical

    CVE-2023-43625

    Last Modified: 27 Feb 2025

    A vulnerability has been identified in Simcenter Amesim (All versions < V2021.1). The affected application contains a SOAP endpoint that could allow an unauthenticated remote attacker to perform DLL injection and execute arbitrary code in the context of the affected application process.

    Published: 10 Oct 2023