CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2023-40208

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Aleksandar Urošević Stock Ticker plugin <= 3.23.3 versions.

    Published: 4 Sept 2023
    7.5
    High

    CVE-2023-4615

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/download/updateFile endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of the current user.

    Published: 4 Sept 2023
    9.8
    Critical

    CVE-2023-4614

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/installation/setThumbnailRc endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user.

    Published: 4 Sept 2023
    7.1
    High

    CVE-2023-39992

    Last Modified: 10 Jun 2025

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in vCita.Com Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.3.2 versions.

    Published: 4 Sept 2023
    7.1
    High

    CVE-2023-30494

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ImageRecycle ImageRecycle pdf & image compression plugin <= 3.1.10 versions.

    Published: 4 Sept 2023
    7.1
    High

    CVE-2023-31220

    Last Modified: 19 Feb 2025

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP-EXPERTS.IN TEAM WP Categories Widget plugin <= 2.2 versions.

    Published: 4 Sept 2023
    7.1
    High

    CVE-2023-37393

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Atarim Visual Website Collaboration, Feedback & Project Management – Atarim plugin <= 3.9.3 versions.

    Published: 4 Sept 2023
    6.5
    Medium

    CVE-2023-39988

    Last Modified: 21 Nov 2024

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in 标准云(std.Cloud) WxSync plugin <= 2.7.23 versions.

    Published: 4 Sept 2023
    7.1
    High

    CVE-2023-39991

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blindside Networks BigBlueButton plugin <= 3.0.0-beta.4 versions.

    Published: 4 Sept 2023
    5.9
    Medium

    CVE-2023-39987

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ajay Lulia wSecure Lite plugin <= 2.5 versions.

    Published: 4 Sept 2023
    7.1
    High

    CVE-2023-39918

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in SAASPROJECT Booking Package Booking Package plugin <= 1.6.01 versions.

    Published: 4 Sept 2023
    5.9
    Medium

    CVE-2023-39919

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in maennchen1.De wpShopGermany – Protected Shops plugin <= 2.0 versions.

    Published: 4 Sept 2023
    5.9
    Medium

    CVE-2023-25465

    Last Modified: 19 Feb 2025

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy wp tell a friend popup form plugin <= 7.1 versions.

    Published: 4 Sept 2023
    7.1
    High

    CVE-2023-39162

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in XLPlugins User Email Verification for WooCommerce plugin <= 3.5.0 versions.

    Published: 4 Sept 2023
    7.1
    High

    CVE-2023-39164

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Molongui Author Box for Authors, Co-Authors, Multiple Authors and Guest Authors – Molongui plugin <= 4.6.19 versions.

    Published: 4 Sept 2023
    5.9
    Medium

    CVE-2023-36382

    Last Modified: 19 Feb 2025

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jeffrey-WP Media Library Categories plugin <= 2.0.0 versions.

    Published: 4 Sept 2023
    5.5
    Medium

    CVE-2023-4756

    Last Modified: 21 Nov 2024

    Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.

    Published: 4 Sept 2023
    5.5
    Medium

    CVE-2023-4754

    Last Modified: 21 Nov 2024

    Out-of-bounds Write in GitHub repository gpac/gpac prior to 2.3-DEV.

    Published: 4 Sept 2023
    9.8
    Critical

    CVE-2023-4613

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/settings/upload endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user.

    Published: 4 Sept 2023
    —
    Unknown

    CVE-2023-41839

    Last Modified: 28 May 2025

    Not used

    Published: 4 Sept 2023
    4.4
    Medium

    CVE-2023-32817

    Last Modified: 21 Nov 2024

    In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08044040; Issue ID: ALPS08044035.

    Published: 4 Sept 2023
    4.4
    Medium

    CVE-2023-32816

    Last Modified: 21 Nov 2024

    In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08044040; Issue ID: ALPS08044032.

    Published: 4 Sept 2023
    4.4
    Medium

    CVE-2023-32815

    Last Modified: 21 Nov 2024

    In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08037801; Issue ID: ALPS08037801.

    Published: 4 Sept 2023
    4.4
    Medium

    CVE-2023-32814

    Last Modified: 21 Nov 2024

    In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08031947; Issue ID: ALPS08031947.

    Published: 4 Sept 2023
    4.4
    Medium

    CVE-2023-32813

    Last Modified: 21 Nov 2024

    In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017370; Issue ID: ALPS08017370.

    Published: 4 Sept 2023
    6.7
    Medium

    CVE-2023-32812

    Last Modified: 21 Nov 2024

    In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local esclation of privileges with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017365; Issue ID: ALPS08017365.

    Published: 4 Sept 2023
    6.7
    Medium

    CVE-2023-32811

    Last Modified: 21 Nov 2024

    In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929848; Issue ID: ALPS07929848.

    Published: 4 Sept 2023
    4.4
    Medium

    CVE-2023-32810

    Last Modified: 21 Nov 2024

    In bluetooth driver, there is a possible out of bounds read due to improper input validation. This could lead to local information leak with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07867212; Issue ID: ALPS07867212.

    Published: 4 Sept 2023
    4.4
    Medium

    CVE-2023-32809

    Last Modified: 21 Nov 2024

    In bluetooth driver, there is a possible read and write access to registers due to improper access control of register interface. This could lead to local leak of sensitive information with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07849753; Issue ID: ALPS07849753.

    Published: 4 Sept 2023
    4.4
    Medium

    CVE-2023-32808

    Last Modified: 21 Nov 2024

    In bluetooth driver, there is a possible read and write access to registers due to improper access control of register interface. This could lead to local leak of sensitive information with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07849751; Issue ID: ALPS07849751.

    Published: 4 Sept 2023
    4.4
    Medium

    CVE-2023-32807

    Last Modified: 21 Nov 2024

    In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588360; Issue ID: ALPS07588360.

    Published: 4 Sept 2023
    6.7
    Medium

    CVE-2023-32806

    Last Modified: 21 Nov 2024

    In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441589; Issue ID: ALPS07441589.

    Published: 4 Sept 2023
    6.5
    Medium

    CVE-2023-32805

    Last Modified: 21 Nov 2024

    In power, there is a possible out of bounds write due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08102892; Issue ID: ALPS08102892.

    Published: 4 Sept 2023
    6.3
    Medium

    CVE-2023-20851

    Last Modified: 21 Nov 2024

    In stc, there is a possible out of bounds read due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08048635; Issue ID: ALPS08048635.

    Published: 4 Sept 2023
    6.5
    Medium

    CVE-2023-20850

    Last Modified: 21 Nov 2024

    In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340381.

    Published: 4 Sept 2023
    6.5
    Medium

    CVE-2023-20849

    Last Modified: 21 Nov 2024

    In imgsys_cmdq, there is a possible use after free due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340350.

    Published: 4 Sept 2023
    6.5
    Medium

    CVE-2023-20848

    Last Modified: 21 Nov 2024

    In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340433.

    Published: 4 Sept 2023
    4.2
    Medium

    CVE-2023-20847

    Last Modified: 21 Nov 2024

    In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354025; Issue ID: ALPS07340108.

    Published: 4 Sept 2023
    4.2
    Medium

    CVE-2023-20846

    Last Modified: 21 Nov 2024

    In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354023; Issue ID: ALPS07340098.

    Published: 4 Sept 2023
    4.2
    Medium

    CVE-2023-20845

    Last Modified: 21 Nov 2024

    In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07197795; Issue ID: ALPS07340357.

    Published: 4 Sept 2023
    4.2
    Medium

    CVE-2023-20844

    Last Modified: 21 Nov 2024

    In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354058; Issue ID: ALPS07340121.

    Published: 4 Sept 2023
    4.2
    Medium

    CVE-2023-20843

    Last Modified: 21 Nov 2024

    In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340119; Issue ID: ALPS07340119.

    Published: 4 Sept 2023
    6.5
    Medium

    CVE-2023-20842

    Last Modified: 21 Nov 2024

    In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354259; Issue ID: ALPS07340477.

    Published: 4 Sept 2023
    6.5
    Medium

    CVE-2023-20841

    Last Modified: 21 Nov 2024

    In imgsys, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326441.

    Published: 4 Sept 2023
    6.5
    Medium

    CVE-2023-20840

    Last Modified: 21 Nov 2024

    In imgsys, there is a possible out of bounds read and write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326430; Issue ID: ALPS07326430.

    Published: 4 Sept 2023
    4.2
    Medium

    CVE-2023-20839

    Last Modified: 21 Nov 2024

    In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326409.

    Published: 4 Sept 2023
    4
    Medium

    CVE-2023-20838

    Last Modified: 21 Nov 2024

    In imgsys, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326418.

    Published: 4 Sept 2023
    6.7
    Medium

    CVE-2023-20837

    Last Modified: 21 Nov 2024

    In seninf, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07992786; Issue ID: ALPS07992786.

    Published: 4 Sept 2023
    4.4
    Medium

    CVE-2023-20836

    Last Modified: 21 Nov 2024

    In camsys, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07505629; Issue ID: ALPS07505629.

    Published: 4 Sept 2023
    6.4
    Medium

    CVE-2023-20835

    Last Modified: 21 Nov 2024

    In camsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07341261; Issue ID: ALPS07326570.

    Published: 4 Sept 2023