CVE Feed

    Dashboard / CVE

    7.4
    High

    CVE-2023-40375

    Last Modified: 21 Nov 2024

    Integrated application server for IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system. IBM X-Force ID: 263580.

    Published: 28 Sept 2023
    5.3
    Medium

    CVE-2023-43044

    Last Modified: 21 Nov 2024

    IBM License Metric Tool 9.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 266893.

    Published: 28 Sept 2023
    8.8
    High

    CVE-2023-5187

    Last Modified: 13 Feb 2025

    Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 28 Sept 2023
    8.8
    High

    CVE-2023-5186

    Last Modified: 13 Feb 2025

    Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: High)

    Published: 28 Sept 2023
    6.3
    Medium

    CVE-2023-40307

    Last Modified: 21 Nov 2024

    An attacker with standard privileges on macOS when requesting administrator privileges from the application can submit input which causes a buffer overflow resulting in a crash of the application. This could make the application unavailable and allow reading or modification of data.

    Published: 28 Sept 2023
    5.3
    Medium

    CVE-2022-47187

    Last Modified: 21 Nov 2024

    There is a file upload XSS vulnerability in Generex CS141 below 2.06 version. The web application allows file uploading, making it possible to upload a file with HTML content. When HTML files are allowed, XSS payload can be injected into the uploaded file.

    Published: 28 Sept 2023
    7.5
    High

    CVE-2022-47186

    Last Modified: 21 Nov 2024

    There is an unrestricted upload of file vulnerability in Generex CS141 below 2.06 version. An attacker could upload and/or delete any type of file, without any format restriction and without any authentication, in the "upload" directory.

    Published: 28 Sept 2023
    6.1
    Medium

    CVE-2023-26149

    Last Modified: 21 Nov 2024

    Versions of the package quill-mention before 4.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization, via the renderList function. **Note:** If the mentions list is sourced from unsafe (user-sourced) data, this might allow an injection attack when a Quill user hits @.

    Published: 28 Sept 2023
    7.4
    High

    CVE-2023-26145

    Last Modified: 21 Nov 2024

    This affects versions of the package pydash before 6.0.0. A number of pydash methods such as pydash.objects.invoke() and pydash.collections.invoke_map() accept dotted paths (Deep Path Strings) to target a nested Python object, relative to the original source object. These paths can be used to target internal class attributes and dict items, to retrieve, modify or invoke nested Python objects. **Note:** The pydash.objects.invoke() method is vulnerable to Command Injection when the following prerequisites are satisfied: 1) The source object (argument 1) is not a built-in object such as list/dict (otherwise, the __init__.__globals__ path is not accessible) 2) The attacker has control over argument 2 (the path string) and argument 3 (the argument to pass to the invoked method) The pydash.collections.invoke_map() method is also vulnerable, but is harder to exploit as the attacker does not have direct control over the argument to be passed to the invoked function.

    Published: 28 Sept 2023
    6.4
    Medium

    CVE-2023-5233

    Last Modified: 8 Apr 2026

    The Font Awesome Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fawesome' shortcode in versions up to, and including, 5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 28 Sept 2023
    6.4
    Medium

    CVE-2023-5230

    Last Modified: 8 Apr 2026

    The TM WooCommerce Compare & Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tm_woo_wishlist_table' shortcode in versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 28 Sept 2023
    6.4
    Medium

    CVE-2023-5232

    Last Modified: 8 Apr 2026

    The Font Awesome More Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' shortcode in versions up to, and including, 3.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 28 Sept 2023
    6.1
    Medium

    CVE-2023-5244

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 2.0.

    Published: 28 Sept 2023
    7.5
    High

    CVE-2023-43863

    Last Modified: 21 Nov 2024

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanDhcpplus function.

    Published: 28 Sept 2023
    6
    Medium

    CVE-2023-5090

    Last Modified: 8 Nov 2025

    A flaw was found in KVM. An improper check in svm_set_x2apic_msr_interception() may allow direct access to host x2apic msrs when the guest resets its apic, potentially leading to a denial of service condition.

    Published: 28 Sept 2023
    5.4
    Medium

    CVE-2023-44276

    Last Modified: 21 Nov 2024

    OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.

    Published: 28 Sept 2023
    5.4
    Medium

    CVE-2023-44275

    Last Modified: 21 Nov 2024

    OPNsense before 23.7.5 allows XSS via the index.php column_count parameter to the Lobby Dashboard.

    Published: 28 Sept 2023
    9.8
    Critical

    CVE-2023-44273

    Last Modified: 21 Nov 2024

    Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensure that the data is in a certain interval.

    Published: 28 Sept 2023
    8.8
    High

    CVE-2023-39928

    Last Modified: 4 Nov 2025

    A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to to visit a malicious webpage to trigger this vulnerability.

    Published: 28 Sept 2023
    8.8
    High

    CVE-2023-38874

    Last Modified: 21 Nov 2024

    A remote code execution (RCE) vulnerability via an insecure file upload exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). A malicious attacker can upload a PHP web shell as an attachment when adding a new cash book entry. Afterwards, the attacker may visit the web shell and execute arbitrary commands.

    Published: 28 Sept 2023
    6.5
    Medium

    CVE-2023-43323

    Last Modified: 21 Nov 2024

    mooSocial 3.1.8 is vulnerable to external service interaction on post function. When executed, the server sends a HTTP and DNS request to external server. The Parameters effected are multiple - messageText, data[wall_photo], data[userShareVideo] and data[userShareLink].

    Published: 28 Sept 2023
    9.8
    Critical

    CVE-2023-30415

    Last Modified: 21 Nov 2024

    Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /inquiries/view_inquiry.php.

    Published: 28 Sept 2023
    7.8
    High

    CVE-2023-5633

    Last Modified: 25 Feb 2026

    The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in the way memory objects were handled when they were being used to store a surface. When running inside a VMware guest with 3D acceleration enabled, a local, unprivileged user could potentially use this flaw to escalate their privileges.

    Published: 28 Sept 2023
    9.8
    Critical

    CVE-2023-38870

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book has a feature to list accomplishments by category, and the 'category_id' parameter is vulnerable to SQL Injection.

    Published: 28 Sept 2023
    5.3
    Medium

    CVE-2023-38871

    Last Modified: 21 Nov 2024

    The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer has a user enumeration vulnerability in the login and forgot password functionalities. The app reacts differently when a user or email address is valid, and when it's not. This may allow an attacker to determine whether a user or email address is valid, or brute force valid usernames and email addresses.

    Published: 28 Sept 2023
    3.7
    Low

    CVE-2023-38872

    Last Modified: 21 Nov 2024

    An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of the attachment.

    Published: 28 Sept 2023
    6.5
    Medium

    CVE-2023-38873

    Last Modified: 21 Nov 2024

    The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer is vulnerable to Clickjacking. Clickjacking, also known as a "UI redress attack", is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they were intending to click on the top-level page. Thus, the attacker is "hijacking" clicks meant for their page and routing them to another page, most likely owned by another application, domain, or both.

    Published: 28 Sept 2023
    8.8
    High

    CVE-2023-38877

    Last Modified: 21 Nov 2024

    A host header injection vulnerability exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and thus leak the password reset token. This allows an attacker to reset other users' passwords.

    Published: 28 Sept 2023
    7.8
    High

    CVE-2023-41444

    Last Modified: 21 Nov 2024

    An issue in Binalyze IREC.sys v.3.11.0 and before allows a local attacker to execute arbitrary code and escalate privileges via the fun_1400084d0 function in IREC.sys driver.

    Published: 28 Sept 2023
    6.1
    Medium

    CVE-2023-41446

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted script to the title parameter in the index.php component.

    Published: 28 Sept 2023
    6.1
    Medium

    CVE-2023-41447

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the subcmd parameter in the index.php component.

    Published: 28 Sept 2023
    8.8
    High

    CVE-2023-41450

    Last Modified: 21 Nov 2024

    An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.

    Published: 28 Sept 2023
    4.7
    Medium

    CVE-2023-41911

    Last Modified: 21 Nov 2024

    Samsung Mobile Processor Exynos 2200 allows a GPU Double Free (issue 1 of 2).

    Published: 28 Sept 2023
    8.8
    High

    CVE-2023-42222

    Last Modified: 21 Nov 2024

    WebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.

    Published: 28 Sept 2023
    8.8
    High

    CVE-2023-43226

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.

    Published: 28 Sept 2023
    7.5
    High

    CVE-2023-43860

    Last Modified: 21 Nov 2024

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanNonLogin function.

    Published: 28 Sept 2023
    7.5
    High

    CVE-2023-43861

    Last Modified: 21 Nov 2024

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanPPPoE function.

    Published: 28 Sept 2023
    7.5
    High

    CVE-2023-43862

    Last Modified: 21 Nov 2024

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formLanguageChange function.

    Published: 28 Sept 2023
    7.5
    High

    CVE-2023-43864

    Last Modified: 21 Nov 2024

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard55 function.

    Published: 28 Sept 2023
    7.5
    High

    CVE-2023-43865

    Last Modified: 21 Nov 2024

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanPPTP function.

    Published: 28 Sept 2023
    7.5
    High

    CVE-2023-43866

    Last Modified: 21 Nov 2024

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard7 function.

    Published: 28 Sept 2023
    7.5
    High

    CVE-2023-43867

    Last Modified: 21 Nov 2024

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanL2TP function.

    Published: 28 Sept 2023
    7.5
    High

    CVE-2023-43868

    Last Modified: 21 Nov 2024

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via websGetVar function.

    Published: 28 Sept 2023
    9.8
    Critical

    CVE-2023-43869

    Last Modified: 21 Nov 2024

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard56 function.

    Published: 28 Sept 2023
    5.4
    Medium

    CVE-2023-43871

    Last Modified: 21 Nov 2024

    A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).

    Published: 28 Sept 2023
    5.4
    Medium

    CVE-2023-43872

    Last Modified: 21 Nov 2024

    A File upload vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).

    Published: 28 Sept 2023
    5.4
    Medium

    CVE-2023-43873

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Name filed in the Manage Menu.

    Published: 28 Sept 2023
    5.4
    Medium

    CVE-2023-43874

    Last Modified: 21 Nov 2024

    Multiple Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Copyright and Author fields in the Meta & Custom Tags Menu.

    Published: 28 Sept 2023
    5.4
    Medium

    CVE-2023-43876

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost field.

    Published: 28 Sept 2023
    5.4
    Medium

    CVE-2023-43878

    Last Modified: 21 Nov 2024

    Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a crafted payload into the Main Menu Items in the Administration Menu.

    Published: 28 Sept 2023