CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2023-32572

    Last Modified: 21 Nov 2024

    A flaw exists in FlashArray Purity wherein under limited circumstances, an array administrator can alter the retention lock of a pgroup and disable pgroup SafeMode protection.

    Published: 2 Oct 2023
    4.4
    Medium

    CVE-2023-28373

    Last Modified: 21 Nov 2024

    A flaw exists in FlashArray Purity whereby an array administrator by configuring an external key manager can affect the availability of data on the system including snapshots protected by SafeMode.

    Published: 2 Oct 2023
    7.7
    High

    CVE-2023-36627

    Last Modified: 21 Nov 2024

    A flaw exists in FlashBlade Purity whereby a user with access to an administrative account on a FlashBlade that is configured with timezone-dependent snapshot schedules can configure a timezone to prevent the schedule from functioning properly.

    Published: 2 Oct 2023
    7.7
    High

    CVE-2023-31042

    Last Modified: 21 Nov 2024

    A flaw exists in FlashBlade Purity whereby an authenticated user with access to FlashBlade’s object store protocol can impact the availability of the system’s data access and replication protocols.

    Published: 2 Oct 2023
    6.5
    Medium

    CVE-2023-28372

    Last Modified: 21 Nov 2024

    A flaw exists in FlashBlade Purity (OE) Version 4.1.0 whereby a user with privileges to extend an object’s retention period can affect the availability of the object lock.

    Published: 2 Oct 2023
    9.8
    Critical

    CVE-2023-4659

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the platform as an administrator, simply by changing the token value to "admin". It is also possible to perform POST, GET and DELETE requests without any token value. Therefore, an unprivileged remote user is able to create, delete and modify users within theapplication.

    Published: 2 Oct 2023
    6.3
    Medium

    CVE-2015-10124

    Last Modified: 21 Nov 2024

    A vulnerability was found in Most Popular Posts Widget Plugin up to 0.8 on WordPress. It has been classified as critical. Affected is the function add_views/show_views of the file functions.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. Upgrading to version 0.9 is able to address this issue. The patch is identified as a99667d11ac8d320006909387b100e9a8b5c12e1. It is recommended to upgrade the affected component. VDB-241026 is the identifier assigned to this vulnerability.

    Published: 2 Oct 2023
    9.9
    Critical

    CVE-2023-3744

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to internal services or upload the contents of relevant files via the "scrape_image.php" file in the imageURL parameter.

    Published: 2 Oct 2023
    5.3
    Medium

    CVE-2023-3770

    Last Modified: 21 Nov 2024

     Incorrect validation vulnerability of the data entered, allowing an attacker with access to the network on which the affected device is located to use the discovery port protocol (1925/UDP) to obtain device-specific information without the need for authentication.

    Published: 2 Oct 2023
    8.6
    High

    CVE-2023-3769

    Last Modified: 21 Nov 2024

    Incorrect data input validation vulnerability, which could allow an attacker with access to the network to implement fuzzing techniques that would allow him to gain knowledge about specially crafted packets that would create a DoS condition through the MMS protocol when initiating communication, achieving a complete system reboot of the device and its services.

    Published: 2 Oct 2023
    8.2
    High

    CVE-2023-5106

    Last Modified: 7 Apr 2026

    An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.

    Published: 2 Oct 2023
    8.6
    High

    CVE-2023-3768

    Last Modified: 21 Nov 2024

    Incorrect data input validation vulnerability, which could allow an attacker with access to the network to implement fuzzing techniques that would allow him to gain knowledge about specially crafted packets that would create a DoS condition through the MMS protocol when initiating communication, achieving a complete system reboot of the device and its services.

    Published: 2 Oct 2023
    4.3
    Medium

    CVE-2023-5160

    Last Modified: 21 Nov 2024

    Mattermost fails to check the Show Full Name option at the /api/v4/teams/TEAM_ID/top/team_members endpoint allowing a member to get the full name of another user even if the Show Full Name option was disabled

    Published: 2 Oct 2023
    5.9
    Medium

    CVE-2023-44228

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Onclick show popup plugin <= 8.1 versions.

    Published: 2 Oct 2023
    5.9
    Medium

    CVE-2023-44266

    Last Modified: 19 Feb 2025

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jewel Theme WP Adminify plugin <= 3.1.6 versions.

    Published: 2 Oct 2023
    5.9
    Medium

    CVE-2023-44230

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Popup contact form plugin <= 7.1 versions.

    Published: 2 Oct 2023
    5.9
    Medium

    CVE-2023-44265

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Popup contact form plugin <= 7.1 versions.

    Published: 2 Oct 2023
    6.5
    Medium

    CVE-2023-44264

    Last Modified: 21 Nov 2024

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Arrow Plugins The Awesome Feed – Custom Feed plugin <= 2.2.5 versions.

    Published: 2 Oct 2023
    6.5
    Medium

    CVE-2023-44242

    Last Modified: 21 Nov 2024

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in 2J Slideshow Team Slideshow, Image Slider by 2J plugin <= 1.3.54 versions.

    Published: 2 Oct 2023
    7.1
    High

    CVE-2023-44245

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Leap Contractor Contact Form Website to Workflow Tool plugin <= 4.0.0 versions.

    Published: 2 Oct 2023
    5.9
    Medium

    CVE-2023-44262

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Renzo Johnson Blocks plugin <= 1.6.41 versions.

    Published: 2 Oct 2023
    6.5
    Medium

    CVE-2023-44145

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in jesweb.Dev Anchor Episodes Index (Spotify for Podcasters) plugin <= 2.1.7 versions.

    Published: 2 Oct 2023
    7.1
    High

    CVE-2023-44144

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Dreamfox Payment gateway per Product for WooCommerce plugin <= 3.2.7 versions.

    Published: 2 Oct 2023
    5.9
    Medium

    CVE-2023-44263

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Riyaz Social Metrics plugin <= 2.2 versions.

    Published: 2 Oct 2023
    5.9
    Medium

    CVE-2023-44239

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jobin Jose WWM Social Share On Image Hover plugin <= 2.2 versions.

    Published: 2 Oct 2023
    7.1
    High

    CVE-2023-44244

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.44 versions.

    Published: 2 Oct 2023
    6.5
    Medium

    CVE-2023-44477

    Last Modified: 21 Nov 2024

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Boxy Studio Cooked plugin <= 1.7.13 versions.

    Published: 2 Oct 2023
    7.1
    High

    CVE-2023-44474

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MD Jakir Hosen Tiger Forms – Drag and Drop Form Builder plugin <= 2.0.0 versions.

    Published: 2 Oct 2023
    5.9
    Medium

    CVE-2023-41859

    Last Modified: 19 Feb 2025

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ashok Rane Order Delivery Date for WP e-Commerce plugin <= 1.2 versions.

    Published: 2 Oct 2023
    7.1
    High

    CVE-2023-41856

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ClickToTweet.Com Click To Tweet plugin <= 2.0.14 versions.

    Published: 2 Oct 2023
    5.9
    Medium

    CVE-2023-41855

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Regpacks Regpack plugin <= 0.1 versions.

    Published: 2 Oct 2023
    6.5
    Medium

    CVE-2023-41847

    Last Modified: 21 Nov 2024

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WEN Solutions Notice Bar plugin <= 3.1.0 versions.

    Published: 2 Oct 2023
    5.9
    Medium

    CVE-2023-41800

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in UniConsent UniConsent CMP for GDPR CPRA GPP TCF plugin <= 1.4.2 versions.

    Published: 2 Oct 2023
    6.5
    Medium

    CVE-2023-41797

    Last Modified: 21 Nov 2024

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Gold Plugins Locations plugin <= 4.0 versions.

    Published: 2 Oct 2023
    5.9
    Medium

    CVE-2023-44479

    Last Modified: 19 Feb 2025

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jim Krill WP Jump Menu plugin <= 3.6.4 versions.

    Published: 2 Oct 2023
    5.9
    Medium

    CVE-2023-41737

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPGens Swifty Bar, sticky bar by WPGens plugin <= 1.2.10 versions.

    Published: 2 Oct 2023
    5.9
    Medium

    CVE-2023-41736

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Email posts to subscribers plugin <= 6.2 versions.

    Published: 2 Oct 2023
    5.9
    Medium

    CVE-2023-41734

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nigauri Insert Estimated Reading Time plugin <= 1.2 versions.

    Published: 2 Oct 2023
    5.9
    Medium

    CVE-2023-41733

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in YYDevelopment Back To The Top Button plugin <= 2.1.5 versions.

    Published: 2 Oct 2023
    5.9
    Medium

    CVE-2023-41731

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution WordPress publish post email notification plugin <= 1.0.2.2 versions.

    Published: 2 Oct 2023
    5.9
    Medium

    CVE-2023-41729

    Last Modified: 28 Apr 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SendPress Newsletters plugin <= 1.22.3.31 versions.

    Published: 2 Oct 2023
    6.5
    Medium

    CVE-2023-41728

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rescue Themes Rescue Shortcodes allows Stored XSS.This issue affects Rescue Shortcodes: from n/a through 2.5.

    Published: 2 Oct 2023
    7.1
    High

    CVE-2023-41692

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Hennessey Digital Attorney theme <= 3 theme.

    Published: 2 Oct 2023
    5.5
    Medium

    CVE-2023-42132

    Last Modified: 21 Nov 2024

    FD Application Apr. 2022 Edition (Version 9.01) and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.

    Published: 2 Oct 2023
    6.7
    Medium

    CVE-2023-32830

    Last Modified: 21 Nov 2024

    In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03802522; Issue ID: DTV03802522.

    Published: 2 Oct 2023
    6.7
    Medium

    CVE-2023-32829

    Last Modified: 21 Nov 2024

    In apusys, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07713478; Issue ID: ALPS07713478.

    Published: 2 Oct 2023
    6.7
    Medium

    CVE-2023-32828

    Last Modified: 21 Nov 2024

    In vpu, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767817; Issue ID: ALPS07767817.

    Published: 2 Oct 2023
    6.7
    Medium

    CVE-2023-32827

    Last Modified: 21 Nov 2024

    In camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07993539; Issue ID: ALPS07993539.

    Published: 2 Oct 2023
    6.7
    Medium

    CVE-2023-32826

    Last Modified: 21 Nov 2024

    In camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07993539; Issue ID: ALPS07993544.

    Published: 2 Oct 2023
    6.7
    Medium

    CVE-2023-32824

    Last Modified: 21 Nov 2024

    In rpmb , there is a possible double free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07912966; Issue ID: ALPS07912961.

    Published: 2 Oct 2023