CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2022-47891

    Last Modified: 21 Nov 2024

    All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the administrator password via the legitimate recovery function.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-2830

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Trustindex.Io WP Testimonials plugin <= 1.4.2 versions.

    Published: 3 Oct 2023
    6.5
    Medium

    CVE-2023-4100

    Last Modified: 21 Nov 2024

    Allows an attacker to perform XSS attacks stored on certain resources. Exploiting this vulnerability can lead to a DoS condition, among other actions.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-39989

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in 99robots Header Footer Code Manager plugin <= 1.1.34 versions.

    Published: 3 Oct 2023
    4.3
    Medium

    CVE-2023-39917

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery Team Photo Gallery by Ays – Responsive Image Gallery plugin <= 5.2.6 versions.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-39165

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets plugin <= 2.2.8 versions.

    Published: 3 Oct 2023
    7.6
    High

    CVE-2023-4099

    Last Modified: 21 Nov 2024

    The QSige Monitor application does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-39923

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme The Post Grid plugin <= 7.2.7 versions.

    Published: 3 Oct 2023
    8.8
    High

    CVE-2023-4098

    Last Modified: 21 Nov 2024

    It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application.

    Published: 3 Oct 2023
    4.3
    Medium

    CVE-2023-25989

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed Widget, Meks Simple Flickr Widget, Meks Easy Ads Widget, Meks Smart Social Widget plugins leading to dismiss or the popup.

    Published: 3 Oct 2023
    8.8
    High

    CVE-2023-4097

    Last Modified: 21 Nov 2024

    The file upload functionality is not implemented correctly and allows uploading of any type of file. As a prerequisite, it is necessary for the attacker to log into the application with a valid username.

    Published: 3 Oct 2023
    6.7
    Medium

    CVE-2023-0828

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) vulnerability in Syslog Section of Pandora FMS allows attacker to cause that users cookie value will be transferred to the attackers users server. This issue affects Pandora FMS v767 version and prior versions on all platforms.

    Published: 3 Oct 2023
    6.7
    Medium

    CVE-2023-24518

    Last Modified: 21 Nov 2024

    A Cross-site Request Forgery (CSRF) vulnerability in Pandora FMS allows an attacker to force authenticated users to send a request to a web application they are currently authenticated against. This issue affects Pandora FMS version 767 and earlier versions on all platforms.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-25463

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Gopi Ramasamy WP tell a friend popup form plugin <= 7.1 versions.

    Published: 3 Oct 2023
    4.3
    Medium

    CVE-2023-38390

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Anshul Labs Mobile Address Bar Changer plugin <= 3.0 versions.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-38396

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Alain Gonzalez plugin <= 3.1.2 versions.

    Published: 3 Oct 2023
    4.3
    Medium

    CVE-2023-37990

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Mike Perelink Pro plugin <= 2.1.4 versions.

    Published: 3 Oct 2023
    4.3
    Medium

    CVE-2023-38398

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Taboola plugin <= 2.0.1 versions.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2022-46841

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Soflyy Oxygen Builder plugin <= 4.4 versions.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-38381

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Cyle Conoly WP-FlyBox plugin <= 6.46 versions.

    Published: 3 Oct 2023
    4.3
    Medium

    CVE-2023-37998

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Saas Disabler allows Cross Site Request Forgery.This issue affects Disabler: from n/a through 3.0.3.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-37996

    Last Modified: 19 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in GTmetrix GTmetrix for WordPress plugin <= 0.4.7 versions.

    Published: 3 Oct 2023
    5.4
    Medium

    CVE-2023-37992

    Last Modified: 19 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in PressPage Entertainment Inc. Smarty for WordPress plugin <= 3.1.35 versions.

    Published: 3 Oct 2023
    4.3
    Medium

    CVE-2023-37991

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Monchito.Net WP Emoji One plugin <= 0.6.0 versions.

    Published: 3 Oct 2023
    4.3
    Medium

    CVE-2023-37891

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in OptiMonk OptiMonk: Popups, Personalization & A/B Testing plugin <= 2.0.4 versions.

    Published: 3 Oct 2023
    9.4
    Critical

    CVE-2023-3654

    Last Modified: 21 Nov 2024

    cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by a origin bypass via the host header in an HTTP request. This vulnerability can be triggered by an HTTP endpoint exposed to the network.

    Published: 3 Oct 2023
    8.8
    High

    CVE-2023-44218

    Last Modified: 21 Nov 2024

    A flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system with 'SYSTEM' level privileges, leading to a local privilege escalation (LPE) vulnerability.

    Published: 3 Oct 2023
    7.8
    High

    CVE-2023-44217

    Last Modified: 21 Nov 2024

    A local privilege escalation vulnerability in SonicWall Net Extender MSI client for Windows 10.2.336 and earlier versions allows a local low-privileged user to gain system privileges through running repair functionality.

    Published: 3 Oct 2023
    7.5
    High

    CVE-2023-3655

    Last Modified: 17 Jun 2025

    cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by a dangerous methods, that allows to leak the database (system settings, user accounts,...). This vulnerability can be triggered by an HTTP endpoint exposed to the network.

    Published: 3 Oct 2023
    9.8
    Critical

    CVE-2023-3656

    Last Modified: 21 Nov 2024

    cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by an unauthenticated remote code execution vulnerability. This vulnerability can be triggered by an HTTP endpoint exposed to the network.

    Published: 3 Oct 2023
    8.4
    High

    CVE-2023-33039

    Last Modified: 27 Feb 2025

    Memory corruption in Automotive Display while destroying the image handle created using connected display driver.

    Published: 3 Oct 2023
    7.8
    High

    CVE-2023-33035

    Last Modified: 11 Aug 2025

    Memory corruption while invoking callback function of AFE from ADSP.

    Published: 3 Oct 2023
    7.8
    High

    CVE-2023-33034

    Last Modified: 11 Aug 2025

    Memory corruption while parsing the ADSP response command.

    Published: 3 Oct 2023
    8.4
    High

    CVE-2023-33029

    Last Modified: 11 Aug 2025

    Memory corruption in DSP Service during a remote call from HLOS to DSP.

    Published: 3 Oct 2023
    9.8
    Critical

    CVE-2023-33028

    Last Modified: 11 Aug 2025

    Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.

    Published: 3 Oct 2023
    7.5
    High

    CVE-2023-33027

    Last Modified: 11 Aug 2025

    Transient DOS in WLAN Firmware while parsing rsn ies.

    Published: 3 Oct 2023
    7.5
    High

    CVE-2023-33026

    Last Modified: 11 Aug 2025

    Transient DOS in WLAN Firmware while parsing a NAN management frame.

    Published: 3 Oct 2023
    6.1
    Medium

    CVE-2023-28571

    Last Modified: 11 Aug 2025

    Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan.

    Published: 3 Oct 2023
    9.1
    Critical

    CVE-2023-28540

    Last Modified: 27 Feb 2025

    Cryptographic issue in Data Modem due to improper authentication during TLS handshake.

    Published: 3 Oct 2023
    6.6
    Medium

    CVE-2023-28539

    Last Modified: 11 Aug 2025

    Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command.

    Published: 3 Oct 2023
    9.8
    Critical

    CVE-2023-24855

    Last Modified: 11 Aug 2025

    Memory corruption in Modem while processing security related configuration before AS Security Exchange.

    Published: 3 Oct 2023
    8.4
    High

    CVE-2023-24853

    Last Modified: 27 Feb 2025

    Memory Corruption in HLOS while registering for key provisioning notify.

    Published: 3 Oct 2023
    7.8
    High

    CVE-2023-24850

    Last Modified: 11 Aug 2025

    Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.

    Published: 3 Oct 2023
    8.2
    High

    CVE-2023-24849

    Last Modified: 11 Aug 2025

    Information Disclosure in data Modem while parsing an FMTP line in an SDP message.

    Published: 3 Oct 2023
    8.2
    High

    CVE-2023-24848

    Last Modified: 11 Aug 2025

    Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.

    Published: 3 Oct 2023
    7.5
    High

    CVE-2023-24847

    Last Modified: 11 Aug 2025

    Transient DOS in Modem while allocating DSM items.

    Published: 3 Oct 2023
    8.4
    High

    CVE-2023-24844

    Last Modified: 27 Feb 2025

    Memory Corruption in Core while invoking a call to Access Control core library with hardware protected address range.

    Published: 3 Oct 2023
    7.5
    High

    CVE-2023-24843

    Last Modified: 11 Aug 2025

    Transient DOS in Modem while triggering a camping on an 5G cell.

    Published: 3 Oct 2023
    8.2
    High

    CVE-2023-22385

    Last Modified: 11 Aug 2025

    Memory Corruption in Data Modem while making a MO call or MT VOLTE call.

    Published: 3 Oct 2023
    6.7
    Medium

    CVE-2023-22384

    Last Modified: 27 Feb 2025

    Memory Corruption in VR Service while sending data using Fast Message Queue (FMQ).

    Published: 3 Oct 2023