CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2023-44042

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in /settings/index.php of Black Cat CMS 1.4.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website header parameter.

    Published: 26 Sept 2023
    6.1
    Medium

    CVE-2023-44043

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in /install/index.php of Black Cat CMS 1.4.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website title parameter.

    Published: 26 Sept 2023
    7.2
    High

    CVE-2023-44044

    Last Modified: 21 Nov 2024

    Super Store Finder v3.6 and below was discovered to contain a SQL injection vulnerability via the Search parameter at /admin/stores.php.

    Published: 26 Sept 2023
    9.8
    Critical

    CVE-2023-44169

    Last Modified: 21 Nov 2024

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.

    Published: 26 Sept 2023
    9.8
    Critical

    CVE-2023-44170

    Last Modified: 21 Nov 2024

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.

    Published: 26 Sept 2023
    9.8
    Critical

    CVE-2023-44171

    Last Modified: 21 Nov 2024

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.

    Published: 26 Sept 2023
    9.8
    Critical

    CVE-2023-44172

    Last Modified: 21 Nov 2024

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.

    Published: 26 Sept 2023
    6.5
    Medium

    CVE-2023-5169

    Last Modified: 13 Feb 2025

    A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

    Published: 26 Sept 2023
    6.5
    Medium

    CVE-2023-5171

    Last Modified: 13 Feb 2025

    During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

    Published: 26 Sept 2023
    9.8
    Critical

    CVE-2023-5174

    Last Modified: 5 May 2025

    If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash. *This bug only affects Firefox on Windows when run in non-standard configurations (such as using `runas`). Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

    Published: 26 Sept 2023
    7.1
    High

    CVE-2023-5366

    Last Modified: 13 Feb 2025

    A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.

    Published: 26 Sept 2023
    7.5
    High

    CVE-2023-46728

    Last Modified: 3 Nov 2025

    Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1. Responses triggering this bug are possible to be received from any gopher server, even those without malicious intent. Gopher support has been removed in Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should reject all gopher URL requests.

    Published: 26 Sept 2023
    6.5
    Medium

    CVE-2023-43040

    Last Modified: 4 Nov 2025

    IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM X-Force ID: 266807.

    Published: 26 Sept 2023
    7.1
    High

    CVE-2023-4259

    Last Modified: 13 Feb 2025

    Two potential buffer overflow vulnerabilities at the following locations in the Zephyr eS-WiFi driver source code.

    Published: 25 Sept 2023
    8.6
    High

    CVE-2023-4258

    Last Modified: 21 Nov 2024

    In Bluetooth mesh implementation If provisionee has a public key that is sent OOB then during provisioning it can be sent back and will be accepted by provisionee.

    Published: 25 Sept 2023
    9.1
    Critical

    CVE-2023-43644

    Last Modified: 21 Nov 2024

    Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafted requests are sent to sing-box. This affects all SOCKS5 inbounds with user authentication and an attacker may be able to bypass authentication. Users are advised to update to sing-box 1.4.4 or to 1.5.0-rc.4. Users unable to update should not expose the SOCKS5 inbound to insecure environments.

    Published: 25 Sept 2023
    7.5
    High

    CVE-2023-43642

    Last Modified: 21 Nov 2024

    snappy-java is a Java port of the snappy, a fast C++ compresser/decompresser developed by Google. The SnappyInputStream was found to be vulnerable to Denial of Service (DoS) attacks when decompressing data with a too large chunk size. Due to missing upper bound check on chunk length, an unrecoverable fatal error can occur. All versions of snappy-java including the latest released version 1.1.10.3 are vulnerable to this issue. A fix has been introduced in commit `9f8c3cf74` which will be included in the 1.1.10.4 release. Users are advised to upgrade. Users unable to upgrade should only accept compressed data from trusted sources.

    Published: 25 Sept 2023
    5.4
    Medium

    CVE-2023-42817

    Last Modified: 21 Nov 2024

    Pimcore admin-ui-classic-bundle provides a Backend UI for Pimcore. The translation value with text including “%s” (from “%suggest%) is parsed by sprintf() even though it’s supposed to be output literally to the user. The translations may be accessible by a user with comparatively lower overall access (as the translation permission cannot be scoped to certain “modules”) and a skilled attacker might be able to exploit the parsing of the translation string in the dialog box. This issue has been patched in commit `abd77392` which is included in release 1.1.2. Users are advised to update to version 1.1.2 or apply the patch manually.

    Published: 25 Sept 2023
    8.3
    High

    CVE-2023-40581

    Last Modified: 21 Nov 2024

    yt-dlp is a youtube-dl fork with additional features and fixes. yt-dlp allows the user to provide shell command lines to be executed at various stages in its download steps through the `--exec` flag. This flag allows output template expansion in its argument, so that metadata values may be used in the shell commands. The metadata fields can be combined with the `%q` conversion, which is intended to quote/escape these values so they can be safely passed to the shell. However, the escaping used for `cmd` (the shell used by Python's `subprocess` on Windows) does not properly escape special characters, which can allow for remote code execution if `--exec` is used directly with maliciously crafted remote data. This vulnerability only impacts `yt-dlp` on Windows, and the vulnerability is present regardless of whether `yt-dlp` is run from `cmd` or from `PowerShell`. Support for output template expansion in `--exec`, along with this vulnerable behavior, was added to `yt-dlp` in version 2021.04.11. yt-dlp version 2023.09.24 fixes this issue by properly escaping each special character. `\n` will be replaced by `\r` as no way of escaping it has been found. It is recommended to upgrade yt-dlp to version 2023.09.24 as soon as possible. Also, always be careful when using --exec, because while this specific vulnerability has been patched, using unvalidated input in shell commands is inherently dangerous. For Windows users who are not able to upgrade: 1. Avoid using any output template expansion in --exec other than {} (filepath). 2. If expansion in --exec is needed, verify the fields you are using do not contain ", | or &. 3. Instead of using --exec, write the info json and load the fields from it instead.

    Published: 25 Sept 2023
    7.1
    High

    CVE-2023-41863

    Last Modified: 21 Nov 2024

    Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Pepro Dev. Group PeproDev CF7 Database plugin <= 1.7.0 versions.

    Published: 25 Sept 2023
    7.1
    High

    CVE-2023-41867

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AcyMailing Newsletter Team AcyMailing plugin <= 8.6.2 versions.

    Published: 25 Sept 2023
    7.1
    High

    CVE-2023-41868

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ram Ratan Maurya, Codestag StagTools plugin <= 2.3.7 versions.

    Published: 25 Sept 2023
    7.1
    High

    CVE-2023-41871

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Poll Maker Team Poll Maker plugin <= 4.7.0 versions.

    Published: 25 Sept 2023
    6.1
    Medium

    CVE-2023-4476

    Last Modified: 23 Apr 2025

    The Locatoraid Store Locator WordPress plugin before 3.9.24 does not sanitise and escape the lpr-search parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 25 Sept 2023
    6.1
    Medium

    CVE-2023-4549

    Last Modified: 3 Mar 2026

    The DoLogin Security WordPress plugin before 3.7 does not properly sanitize IP addresses coming from the X-Forwarded-For header, which can be used by attackers to conduct Stored XSS attacks via WordPress' login form.

    Published: 25 Sept 2023
    7.2
    High

    CVE-2023-3664

    Last Modified: 21 Nov 2024

    The FileOrganizer WordPress plugin through 1.0.2 does not restrict functionality on multisite instances, allowing site admins to gain full control over the server.

    Published: 25 Sept 2023
    8.8
    High

    CVE-2023-3547

    Last Modified: 23 Apr 2025

    The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly check nonce values in several actions, allowing an attacker to perform CSRF attacks.

    Published: 25 Sept 2023
    4.8
    Medium

    CVE-2023-4502

    Last Modified: 2 May 2025

    The Translate WordPress with GTranslate WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). This vulnerability affects multiple parameters.

    Published: 25 Sept 2023
    6.1
    Medium

    CVE-2023-4148

    Last Modified: 1 May 2025

    The Ditty WordPress plugin before 3.1.25 does not sanitise and escape some parameters and generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 25 Sept 2023
    5.3
    Medium

    CVE-2023-4631

    Last Modified: 3 Mar 2026

    The DoLogin Security WordPress plugin before 3.7 uses headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing.

    Published: 25 Sept 2023
    9.8
    Critical

    CVE-2023-4521

    Last Modified: 23 Apr 2025

    The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue (https://wpscan.com/vulnerability/d4220025-2272-4d5f-9703-4b2ac4a51c42) and not deleting the created files when releasing the new version.

    Published: 25 Sept 2023
    5.3
    Medium

    CVE-2023-4281

    Last Modified: 23 Apr 2025

    This Activity Log WordPress plugin before 2.8.8 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to hide the source of malicious traffic.

    Published: 25 Sept 2023
    7.2
    High

    CVE-2023-4238

    Last Modified: 22 Apr 2025

    The Prevent files / folders access WordPress plugin before 2.5.2 does not validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.

    Published: 25 Sept 2023
    9.8
    Critical

    CVE-2023-4490

    Last Modified: 23 Apr 2025

    The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

    Published: 25 Sept 2023
    4.8
    Medium

    CVE-2023-3226

    Last Modified: 21 Nov 2024

    The Popup Builder WordPress plugin before 4.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 25 Sept 2023
    7.2
    High

    CVE-2023-4300

    Last Modified: 23 Apr 2025

    The Import XML and RSS Feeds WordPress plugin before 2.1.4 does not filter file extensions for uploaded files, allowing an attacker to upload a malicious PHP file, leading to Remote Code Execution.

    Published: 25 Sept 2023
    5.7
    Medium

    CVE-2023-4892

    Last Modified: 21 Nov 2024

    Teedy v1.11 has a vulnerability in its text editor that allows events to be executed in HTML tags that an attacker could manipulate. Thanks to this, it is possible to execute malicious JavaScript in the webapp.

    Published: 25 Sept 2023
    7.2
    High

    CVE-2023-0633

    Last Modified: 21 Nov 2024

    In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in local privilege escalation (LPE).This issue affects Docker Desktop: before 4.12.0.

    Published: 25 Sept 2023
    6.7
    Medium

    CVE-2023-0627

    Last Modified: 21 Nov 2024

    Docker Desktop 4.11.x allows --no-windows-containers flag bypass via IPC response spoofing which may lead to Local Privilege Escalation (LPE).This issue affects Docker Desktop: 4.11.X.

    Published: 25 Sept 2023
    8
    High

    CVE-2023-0626

    Last Modified: 21 Nov 2024

    Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route. This issue affects Docker Desktop: before 4.12.0.

    Published: 25 Sept 2023
    8
    High

    CVE-2023-0625

    Last Modified: 21 Nov 2024

    Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0.

    Published: 25 Sept 2023
    8
    High

    CVE-2023-5166

    Last Modified: 21 Nov 2024

    Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desktop: before 4.23.0.

    Published: 25 Sept 2023
    7.1
    High

    CVE-2023-5165

    Last Modified: 21 Nov 2024

    Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell which remains accessible for a short time window after launching Docker Desktop. The affected functionality is available for Docker Business customers only and assumes an environment where users are not granted local root or Administrator privileges. This issue has been fixed in Docker Desktop 4.23.0. Affected Docker Desktop versions: from 4.13.0 before 4.23.0.

    Published: 25 Sept 2023
    8.1
    High

    CVE-2023-23567

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow vulnerability exists in the CreateDIBfromPict functionality of Accusoft ImageGear 20.1. A specially crafted file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 25 Sept 2023
    5.6
    Medium

    CVE-2023-28393

    Last Modified: 4 Nov 2025

    A stack-based buffer overflow vulnerability exists in the tif_processing_dng_channel_count functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 25 Sept 2023
    7
    High

    CVE-2023-32614

    Last Modified: 4 Nov 2025

    A heap-based buffer overflow vulnerability exists in the create_png_object functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 25 Sept 2023
    8.1
    High

    CVE-2023-32284

    Last Modified: 4 Nov 2025

    An out-of-bounds write vulnerability exists in the tiff_planar_adobe functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 25 Sept 2023
    9.8
    Critical

    CVE-2023-35002

    Last Modified: 4 Nov 2025

    A heap-based buffer overflow vulnerability exists in the pictwread functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 25 Sept 2023
    9.8
    Critical

    CVE-2023-32653

    Last Modified: 4 Nov 2025

    An out-of-bounds write vulnerability exists in the dcm_pixel_data_decode functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

    Published: 25 Sept 2023
    9.8
    Critical

    CVE-2023-39453

    Last Modified: 4 Nov 2025

    A use-after-free vulnerability exists in the tif_parse_sub_IFD functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can deliver this file to trigger this vulnerability.

    Published: 25 Sept 2023