CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2023-43804

    Last Modified: 3 Nov 2025

    urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly. This issue has been patched in urllib3 version 1.26.17 or 2.0.5.

    Published: 4 Oct 2023
    5.3
    Medium

    CVE-2023-5371

    Last Modified: 27 Mar 2026

    RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file

    Published: 4 Oct 2023
    4
    Medium

    CVE-2022-22447

    Last Modified: 21 Nov 2024

    IBM Disconnected Log Collector 1.0 through 1.8.2 is vulnerable to potential security misconfigurations that could disclose unintended information. IBM X-Force ID: 224648.

    Published: 3 Oct 2023
    7.8
    High

    CVE-2023-4911

    Last Modified: 12 May 2026

    A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.

    Published: 3 Oct 2023
    4.7
    Medium

    CVE-2023-34970

    Last Modified: 7 Mar 2025

    A local non-privileged user can make improper GPU processing operations to access a limited amount outside of buffer bounds or to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory

    Published: 3 Oct 2023
    4.7
    Medium

    CVE-2023-33200

    Last Modified: 7 Mar 2025

    A local non-privileged user can make improper GPU processing operations to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory.

    Published: 3 Oct 2023
    4.7
    Medium

    CVE-2023-4564

    Last Modified: 21 Nov 2024

    This vulnerability could allow an attacker to store a malicious JavaScript payload in the broadcast message parameter within the admin panel.

    Published: 3 Oct 2023
    4.7
    Medium

    CVE-2023-3196

    Last Modified: 21 Nov 2024

    This vulnerability could allow an attacker to store a malicious JavaScript payload in the login footer and login page description parameters within the administration panel.

    Published: 3 Oct 2023
    7.2
    High

    CVE-2023-4817

    Last Modified: 21 Nov 2024

    This vulnerability allows an authenticated attacker to upload malicious files by bypassing the restrictions of the upload functionality, compromising the entire device.

    Published: 3 Oct 2023
    6.5
    Medium

    CVE-2023-4885

    Last Modified: 21 Nov 2024

    Man in the Middle vulnerability, which could allow an attacker to intercept VNF (Virtual Network Function) communications resulting in the exposure of sensitive information.

    Published: 3 Oct 2023
    6.5
    Medium

    CVE-2023-4884

    Last Modified: 21 Nov 2024

    An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication.

    Published: 3 Oct 2023
    7.5
    High

    CVE-2023-4883

    Last Modified: 21 Nov 2024

    Invalid pointer release vulnerability. Exploitation of this vulnerability could allow an attacker to interrupt the correct operation of the service by sending a specially crafted json string to the VNF (Virtual Network Function), and triggering the ogs_sbi_message_free function, which could cause a service outage.

    Published: 3 Oct 2023
    7.5
    High

    CVE-2023-4882

    Last Modified: 21 Nov 2024

    DOS vulnerability that could allow an attacker to register a new VNF (Virtual Network Function) value. This action could trigger the args_assets() function defined in the arg-log.php file, which would then execute the args-abort.c file, causing the service to crash.

    Published: 3 Oct 2023
    6.7
    Medium

    CVE-2023-4886

    Last Modified: 25 Feb 2026

    A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable.

    Published: 3 Oct 2023
    6.5
    Medium

    CVE-2023-4929

    Last Modified: 21 Nov 2024

    All firmware versions of the NPort 5000 Series are affected by an improper validation of integrity check vulnerability. This vulnerability results from insufficient checks on firmware updates or upgrades, potentially allowing malicious users to manipulate the firmware and gain control of devices.

    Published: 3 Oct 2023
    —
    Unknown

    CVE-2023-5361

    Last Modified: 5 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-40558

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in eMarket Design YouTube Video Gallery by YouTube Showcase plugin <= 3.3.5 versions.

    Published: 3 Oct 2023
    8.2
    High

    CVE-2023-3350

    Last Modified: 21 Nov 2024

    A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the log file, an attacker could retrieve the SQL query sent to the application in plaint text. This log file contains the password hashes coded with AES-CBC-128 bits algorithm, which can be decrypted with a .NET function, obtaining the username's password in plain text.

    Published: 3 Oct 2023
    8.2
    High

    CVE-2023-3349

    Last Modified: 21 Nov 2024

    Information exposure vulnerability in IBERMATICA RPS 2019, which exploitation could allow an unauthenticated user to retrieve sensitive information, such as usernames, IP addresses or SQL queries sent to the application. By accessing the URL /RPS2019Service/status.html, the application enables the logging mechanism by generating the log file, which can be downloaded.

    Published: 3 Oct 2023
    4.3
    Medium

    CVE-2023-39158

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Banner Management For WooCommerce plugin <= 2.4.2 versions.

    Published: 3 Oct 2023
    4.3
    Medium

    CVE-2023-41244

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Buildfail Localize Remote Images plugin <= 1.0.9 versions.

    Published: 3 Oct 2023
    8.8
    High

    CVE-2023-0506

    Last Modified: 21 Nov 2024

    The web service of ByDemes Group Airspace CCTV Web Service in its 2.616.BY00.11 version, contains a privilege escalation vulnerability, detected in the Camera Control Panel, whose exploitation could allow a low-privileged attacker to gain administrator access.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-41693

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in edward_plainview MyCryptoCheckout plugin <= 2.125 versions.

    Published: 3 Oct 2023
    6.3
    Medium

    CVE-2023-27435

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Sami Ahmed Siddiqui HTTP Auth plugin <= 0.3.2 versions.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-32091

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in POEditor plugin <= 0.9.4 versions.

    Published: 3 Oct 2023
    5.3
    Medium

    CVE-2023-2544

    Last Modified: 21 Nov 2024

    Authorization bypass vulnerability in UPV PEIX, affecting the component "pdf_curri_new.php". Through a POST request, an authenticated user could change the ID parameter to retrieve all the stored information of other registered users.

    Published: 3 Oct 2023
    6.5
    Medium

    CVE-2023-32792

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker to eliminate roles within the platform by sending a specifically crafted query to the server. The vulnerability is based on the absence of proper validation of the origin of incoming requests.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-40009

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Pipes plugin <= 1.4.0 versions.

    Published: 3 Oct 2023
    6.5
    Medium

    CVE-2023-32791

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker to manipulate and delete user accounts within the platform by sending a specifically crafted query to the server. The vulnerability is based on the lack of proper validation of the origin of incoming requests.

    Published: 3 Oct 2023
    4.6
    Medium

    CVE-2023-32790

    Last Modified: 21 Nov 2024

    Cross-Site Scripting (XSS) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker to inject a malicious JavaScript payload into the 'Full Name' field during a user edit, due to improper sanitization of the input parameter.

    Published: 3 Oct 2023
    4.3
    Medium

    CVE-2023-39159

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Fraud Prevention For Woocommerce plugin <= 2.1.5 versions.

    Published: 3 Oct 2023
    4.3
    Medium

    CVE-2023-40212

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Product Attachment for WooCommerce plugin <= 2.1.8 versions.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-40199

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in CRUDLab WP Like Button plugin <= 1.7.0 versions.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-40198

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Antsanchez Easy Cookie Law plugin <= 3.1 versions.

    Published: 3 Oct 2023
    6.5
    Medium

    CVE-2023-42508

    Last Modified: 21 Nov 2024

    JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, which can lead to unauthenticated users being able to send emails with manipulated email body.

    Published: 3 Oct 2023
    6.3
    Medium

    CVE-2023-32671

    Last Modified: 21 Nov 2024

    A stored XSS vulnerability has been found on BuddyBoss Platform affecting version 2.2.9. This vulnerability allows an attacker to store a malicious javascript payload via POST request when sending an invitation.

    Published: 3 Oct 2023
    9
    Critical

    CVE-2023-32670

    Last Modified: 21 Nov 2024

    Cross-Site Scripting vulnerability in BuddyBoss 2.2.9 version , which could allow a local attacker with basic privileges to execute a malicious payload through the "[name]=image.jpg" parameter, allowing to assign a persistent javascript payload that would be triggered when the associated image is loaded.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-32669

    Last Modified: 21 Nov 2024

    Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated user to access and rename other users' albums. This vulnerability can be exploited by changing the album identification (id).

    Published: 3 Oct 2023
    6.5
    Medium

    CVE-2023-40201

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in FuturioWP Futurio Extra plugin <= 1.8.4 versions leads to activation of arbitrary plugin.

    Published: 3 Oct 2023
    8.8
    High

    CVE-2023-2681

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability has been found on Jorani version 1.0.0. This vulnerability allows an authenticated remote user, with low privileges, to send queries with malicious SQL code on the "/leaves/validate" path and the “id” parameter, managing to extract arbritary information from the database.

    Published: 3 Oct 2023
    6.5
    Medium

    CVE-2023-5353

    Last Modified: 21 Nov 2024

    Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-40202

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Hannes Etzelstorfer // codemiq WP HTML Mail plugin <= 3.4.1 versions.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-5351

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1.

    Published: 3 Oct 2023
    9.1
    Critical

    CVE-2023-5350

    Last Modified: 21 Nov 2024

    SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.

    Published: 3 Oct 2023
    8.8
    High

    CVE-2023-4103

    Last Modified: 21 Nov 2024

    QSige statistics are affected by a remote SQLi vulnerability. It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application.

    Published: 3 Oct 2023
    8.8
    High

    CVE-2023-4102

    Last Modified: 21 Nov 2024

    QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application.

    Published: 3 Oct 2023
    10
    Critical

    CVE-2022-47893

    Last Modified: 21 Nov 2024

    There is a remote code execution vulnerability that affects all versions of NetMan 204. A remote attacker could upload a firmware file containing a webshell, that could allow him to execute arbitrary code as root.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-40210

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Sean Barton (Tortoise IT) SB Child List plugin <= 4.5 versions.

    Published: 3 Oct 2023
    5.3
    Medium

    CVE-2022-47892

    Last Modified: 21 Nov 2024

    All versions of NetMan 204 could allow an unauthenticated remote attacker to read a file (config.cgi) containing sensitive information, like credentials.

    Published: 3 Oct 2023
    8.8
    High

    CVE-2023-4101

    Last Modified: 21 Nov 2024

    The QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application.

    Published: 3 Oct 2023