CVE Feed

    Dashboard / CVE

    7.7
    High

    CVE-2023-23366

    Last Modified: 21 Nov 2024

    A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following version: Music Station 5.3.22 and later

    Published: 6 Oct 2023
    7.7
    High

    CVE-2023-23365

    Last Modified: 21 Nov 2024

    A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following version: Music Station 5.3.22 and later

    Published: 6 Oct 2023
    5.4
    Medium

    CVE-2023-44233

    Last Modified: 19 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in FooPlugins Best WordPress Gallery Plugin – FooGallery plugin <= 2.2.44 versions.

    Published: 6 Oct 2023
    4.3
    Medium

    CVE-2023-44243

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Dylan Blokhuis Instant CSS plugin <= 1.2.1 versions.

    Published: 6 Oct 2023
    4.3
    Medium

    CVE-2023-44146

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Checkfront Inc. Checkfront Online Booking System plugin <= 3.6 versions.

    Published: 6 Oct 2023
    5.4
    Medium

    CVE-2023-41950

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Laposta - Roel Bousardt Laposta Signup Basic plugin <= 1.4.1 versions.

    Published: 6 Oct 2023
    4.3
    Medium

    CVE-2023-40607

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in CLUEVO CLUEVO LMS, E-Learning Platform plugin <= 1.10.0 versions.

    Published: 6 Oct 2023
    5.4
    Medium

    CVE-2023-41801

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team Ad Directory & Listings by AWP Classifieds plugin <= 4.3 versions.

    Published: 6 Oct 2023
    5.4
    Medium

    CVE-2023-41732

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in CodePeople CP Blocks plugin <= 1.0.20 versions.

    Published: 6 Oct 2023
    5.4
    Medium

    CVE-2023-41659

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Jules Colle, BDWM Responsive Gallery Grid plugin <= 2.3.10 versions.

    Published: 6 Oct 2023
    5.4
    Medium

    CVE-2023-41654

    Last Modified: 6 Mar 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Andreas Heigl authLdap plugin <= 2.5.8 versions.

    Published: 6 Oct 2023
    4.3
    Medium

    CVE-2023-41650

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Remove/hide Author, Date, Category Like Entry-Meta plugin <= 2.1 versions.

    Published: 6 Oct 2023
    7.5
    High

    CVE-2023-43810

    Last Modified: 21 Nov 2024

    OpenTelemetry, also known as OTel for short, is a vendor-neutral open-source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, logs. Autoinstrumentation out of the box adds the label `http_method` that has unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent. HTTP method for requests can be easily set by an attacker to be random and long. In order to be affected program has to be instrumented for HTTP handlers and does not filter any unknown HTTP methods on the level of CDN, LB, previous middleware, etc. This issue has been patched in version 0.41b0.

    Published: 6 Oct 2023
    9.8
    Critical

    CVE-2023-38703

    Last Modified: 10 Apr 2025

    PJSIP is a free and open source multimedia communication library written in C with high level API in C, C++, Java, C#, and Python languages. SRTP is a higher level media transport which is stacked upon a lower level media transport such as UDP and ICE. Currently a higher level transport is not synchronized with its lower level transport that may introduce use-after-free issue. This vulnerability affects applications that have SRTP capability (`PJMEDIA_HAS_SRTP` is set) and use underlying media transport other than UDP. This vulnerability’s impact may range from unexpected application termination to control flow hijack/memory corruption. The patch is available as a commit in the master branch.

    Published: 6 Oct 2023
    5.3
    Medium

    CVE-2023-43058

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation 23.0.9 is vulnerable to privilege escalation that affects ownership of projects. IBM X-Force ID: 247527.

    Published: 6 Oct 2023
    8.4
    High

    CVE-2023-35897

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a local user to execute arbitrary code on the system using a specially crafted file, caused by a DLL hijacking flaw. IBM X-Force ID: 259246.

    Published: 6 Oct 2023
    5.4
    Medium

    CVE-2023-29235

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Fugu Maintenance Switch plugin <= 1.5.2 versions.

    Published: 6 Oct 2023
    4.3
    Medium

    CVE-2023-28791

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Gangesh Matta Simple Org Chart plugin <= 2.3.4 versions.

    Published: 6 Oct 2023
    5.4
    Medium

    CVE-2023-27615

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Dipak C. Gajjar WP Super Minify plugin <= 1.5.1 versions.

    Published: 6 Oct 2023
    5.4
    Medium

    CVE-2023-27448

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in MakeStories Team MakeStories (for Google Web Stories) plugin <= 2.8.0 versions.

    Published: 6 Oct 2023
    5.4
    Medium

    CVE-2023-25033

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Sumo Social Share Boost plugin <= 4.5 versions.

    Published: 6 Oct 2023
    4.3
    Medium

    CVE-2022-47175

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in P Royal Royal Elementor Addons and Templates plugin <= 1.3.75 versions.

    Published: 6 Oct 2023
    4.3
    Medium

    CVE-2023-25480

    Last Modified: 19 Mar 2025

    Cross-Site Request Forgery (CSRF) vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.24.1 versions.

    Published: 6 Oct 2023
    4.3
    Medium

    CVE-2023-40671

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in 大侠wp DX-auto-save-images plugin <= 1.4.0 versions.

    Published: 6 Oct 2023
    4.3
    Medium

    CVE-2023-40008

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Gangesh Matta Simple Org Chart plugin <= 2.3.4 versions.

    Published: 6 Oct 2023
    9.1
    Critical

    CVE-2023-36465

    Last Modified: 21 Nov 2024

    Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The `templates` module doesn't enforce the correct permissions, allowing any logged-in user to access to this functionality in the administration panel. An attacker could use this vulnerability to change, create or delete templates of surveys. This issue has been patched in version 0.26.8 and 0.27.4.

    Published: 6 Oct 2023
    7.1
    High

    CVE-2023-45246

    Last Modified: 2 Jan 2025

    Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 36343, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39169.

    Published: 6 Oct 2023
    5.5
    Medium

    CVE-2023-45245

    Last Modified: 21 Nov 2024

    Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 36119.

    Published: 6 Oct 2023
    7.1
    High

    CVE-2023-45244

    Last Modified: 21 Nov 2024

    Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 35895, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 37391.

    Published: 6 Oct 2023
    5.3
    Medium

    CVE-2023-4469

    Last Modified: 8 Apr 2026

    The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the prflxtrflds_export_file function in versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to expose potentially sensitive user data, including data entered into custom fields.

    Published: 6 Oct 2023
    9.8
    Critical

    CVE-2023-4530

    Last Modified: 21 May 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Turna Advertising Administration Panel allows SQL Injection. This issue affects Advertising Administration Panel: before 1.1.

    Published: 6 Oct 2023
    6.3
    Medium

    CVE-2015-10126

    Last Modified: 16 Jun 2025

    A vulnerability classified as critical was found in Easy2Map Photos Plugin 1.0.1 on WordPress. This vulnerability affects unknown code. The manipulation leads to sql injection. The attack can be initiated remotely. Upgrading to version 1.1.0 is able to address this issue. The patch is identified as 503d9ee2482d27c065f78d9546f076a406189908. It is recommended to upgrade the affected component. VDB-241318 is the identifier assigned to this vulnerability.

    Published: 6 Oct 2023
    —
    Unknown

    CVE-2023-5312

    Last Modified: 7 Nov 2023

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-43226. Reason: This candidate is a reservation duplicate of CVE-2023-43226. Notes: All CVE users should reference CVE-2023-43226 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 6 Oct 2023
    4.3
    Medium

    CVE-2023-40556

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Greg Ross Schedule Posts Calendar plugin <= 5.2 versions.

    Published: 6 Oct 2023
    8.3
    High

    CVE-2023-26153

    Last Modified: 21 Nov 2024

    Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value. **Note:** An attacker can use this vulnerability to execute commands on the host system.

    Published: 6 Oct 2023
    8.8
    High

    CVE-2023-44061

    Last Modified: 21 Nov 2024

    File Upload vulnerability in Simple and Nice Shopping Cart Script v.1.0 allows a remote attacker to execute arbitrary code via the upload function in the edit profile component.

    Published: 6 Oct 2023
    5.4
    Medium

    CVE-2023-44765

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability in Concrete CMS versions 8.5.12 and below, and 9.0 through 9.2.1 allows an attacker to execute arbitrary code via a crafted script to Plural Handle of the Data Objects from System & Settings.

    Published: 6 Oct 2023
    4.8
    Medium

    CVE-2023-44766

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a crafted script to the SEO - Extra from Page Settings. NOTE: the vendor disputes this because this SEO-related header change can only be made by an admin, and allowing an admin to place JavaScript there is an intentional customization feature.

    Published: 6 Oct 2023
    5.4
    Medium

    CVE-2023-44762

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability in Concrete CMS from versions 9.2.0 to 9.2.2 allows an attacker to execute arbitrary code via a crafted script to the Tags from Settings - Tags.

    Published: 6 Oct 2023
    5.4
    Medium

    CVE-2023-44764

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability in Concrete CMS before 9.2.3 exists via the Name parameter during installation (aka Site of Installation or Settings).

    Published: 6 Oct 2023
    5.4
    Medium

    CVE-2023-44770

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows an attacker to execute arbitrary code via a crafted script to the Organizer - Spare alias.

    Published: 6 Oct 2023
    5.4
    Medium

    CVE-2023-44771

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Page Layout.

    Published: 6 Oct 2023
    9.8
    Critical

    CVE-2023-44807

    Last Modified: 21 Nov 2024

    D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the cancelPing function.

    Published: 6 Oct 2023
    7.5
    High

    CVE-2023-44860

    Last Modified: 21 Nov 2024

    An issue in NETIS SYSTEMS N3Mv2 v.1.0.1.865 allows a remote attacker to cause a denial of service via the authorization component in the HTTP request.

    Published: 6 Oct 2023
    7.5
    High

    CVE-2023-45282

    Last Modified: 21 Nov 2024

    In NASA Open MCT (aka openmct) before 3.1.0, prototype pollution can occur via an import action.

    Published: 6 Oct 2023
    7.8
    High

    CVE-2023-36123

    Last Modified: 21 Nov 2024

    Directory Traversal vulnerability in Hex-Dragon Plain Craft Launcher 2 version Alpha 1.3.9, allows local attackers to execute arbitrary code and gain sensitive information.

    Published: 6 Oct 2023
    6.8
    Medium

    CVE-2023-42445

    Last Modified: 16 Jun 2025

    Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, resolving XML external entities is not disabled. Combined with an Out Of Band XXE attack (OOB-XXE), just parsing XML can lead to exfiltration of local text files to a remote server. Gradle parses XML files for several purposes. Most of the time, Gradle parses XML files it generated or were already present locally. Only Ivy XML descriptors and Maven POM files can be fetched from remote repositories and parsed by Gradle. In Gradle 7.6.3 and 8.4, resolving XML external entities has been disabled for all use cases to protect against this vulnerability. Gradle will now refuse to parse XML files that have XML external entities.

    Published: 6 Oct 2023
    5.4
    Medium

    CVE-2023-44758

    Last Modified: 21 Nov 2024

    GDidees CMS 3.0 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload to the Page Title.

    Published: 6 Oct 2023
    5.4
    Medium

    CVE-2023-44761

    Last Modified: 21 Nov 2024

    Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS versions affected to 8.5.13 and below, and 9.0.0 through 9.2.1 allow a local attacker to execute arbitrary code via a crafted script to the Forms of the Data objects.

    Published: 6 Oct 2023
    8.4
    High

    CVE-2023-45303

    Last Modified: 21 Nov 2024

    ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute (for content sent to the /api/admin/settings endpoint).

    Published: 6 Oct 2023