CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2023-40350

    Last Modified: 21 Nov 2024

    Jenkins Docker Swarm Plugin 1.11 and earlier does not escape values returned from Docker before inserting them into the Docker Swarm Dashboard view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control responses from Docker.

    Published: 16 Aug 2023
    5.3
    Medium

    CVE-2023-40349

    Last Modified: 21 Nov 2024

    Jenkins Gogs Plugin 1.0.15 and earlier improperly initializes an option to secure its webhook endpoint, allowing unauthenticated attackers to trigger builds of jobs.

    Published: 16 Aug 2023
    5.3
    Medium

    CVE-2023-40348

    Last Modified: 21 Nov 2024

    The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers information about the existence of jobs in its output.

    Published: 16 Aug 2023
    6.5
    Medium

    CVE-2023-40347

    Last Modified: 21 Nov 2024

    Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.14 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.

    Published: 16 Aug 2023
    5.4
    Medium

    CVE-2023-40346

    Last Modified: 21 Nov 2024

    Jenkins Shortcut Job Plugin 0.4 and earlier does not escape the shortcut redirection URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure shortcut jobs.

    Published: 16 Aug 2023
    6.5
    Medium

    CVE-2023-40345

    Last Modified: 21 Nov 2024

    Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Overall/Read permission to access and capture credentials they are not entitled to.

    Published: 16 Aug 2023
    4.3
    Medium

    CVE-2023-40344

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Delphix Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

    Published: 16 Aug 2023
    5.9
    Medium

    CVE-2023-40343

    Last Modified: 21 Nov 2024

    Jenkins Tuleap Authentication Plugin 1.1.20 and earlier uses a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication token.

    Published: 16 Aug 2023
    5.4
    Medium

    CVE-2023-40342

    Last Modified: 21 Nov 2024

    Jenkins Flaky Test Handler Plugin 1.2.2 and earlier does not escape JUnit test contents when showing them on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control JUnit report file contents.

    Published: 16 Aug 2023
    7.5
    High

    CVE-2023-40340

    Last Modified: 21 Nov 2024

    Jenkins NodeJS Plugin 1.6.0 and earlier does not properly mask (i.e., replace with asterisks) credentials specified in the Npm config file in Pipeline build logs.

    Published: 16 Aug 2023
    7.3
    High

    CVE-2023-32493

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS, 9.5.0.x, contains a protection mechanism bypass vulnerability. An unprivileged, remote attacker could potentially exploit this vulnerability, leading to denial of service, information disclosure and remote execution.

    Published: 16 Aug 2023
    5.3
    Medium

    CVE-2023-32492

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS 9.5.0.x contains an incorrect default permissions vulnerability. A low-privileged local attacker could potentially exploit this vulnerability, leading to information disclosure or allowing to modify files.

    Published: 16 Aug 2023
    6.3
    Medium

    CVE-2023-32491

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS 9.5.0.x, contains an insertion of sensitive information into log file vulnerability in SNMPv3. A low privileges user could potentially exploit this vulnerability, leading to information disclosure.

    Published: 16 Aug 2023
    6.7
    Medium

    CVE-2023-32490

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS 8.2x -9.5x contains an improper privilege management vulnerability. A high privilege local attacker could potentially exploit this vulnerability, leading to system takeover.

    Published: 16 Aug 2023
    6.7
    Medium

    CVE-2023-32489

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS 8.2x -9.5x contains a privilege escalation vulnerability. A local attacker with high privileges could potentially exploit this vulnerability, to bypass mode protections and gain elevated privileges.  

    Published: 16 Aug 2023
    5.3
    Medium

    CVE-2023-32488

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS, 8.2.x-9.5.0.x, contains an information disclosure vulnerability in NFS. A low privileged attacker could potentially exploit this vulnerability, leading to information disclosure.

    Published: 16 Aug 2023
    7.8
    High

    CVE-2023-32487

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS, 8.2.x - 9.5.0.x, contains an elevation of privilege vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to denial of service, code execution and information disclosure.

    Published: 16 Aug 2023
    6.7
    Medium

    CVE-2023-32486

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS 9.5.x version contain a privilege escalation vulnerability. A low privilege local attacker could potentially exploit this vulnerability, leading to escalation of privileges.

    Published: 16 Aug 2023
    7.8
    High

    CVE-2023-32495

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS, 8.2.x-9.5.x, contains a exposure of sensitive information to an unauthorized Actor vulnerability. An authorized local attacker could potentially exploit this vulnerability, leading to escalation of privileges.

    Published: 16 Aug 2023
    6.7
    Medium

    CVE-2023-32494

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS, 8.0.x-9.5.x, contains an improper handling of insufficient privileges vulnerability. A local privileged attacker could potentially exploit this vulnerability, leading to elevation of privilege and affect in compliance mode also.

    Published: 16 Aug 2023
    5.4
    Medium

    CVE-2023-0551

    Last Modified: 21 Nov 2024

    The REST API TO MiniProgram WordPress plugin through 4.6.1 does not have authorisation and CSRF checks in an AJAX action, allowing ay authenticated users, such as subscriber to call and delete arbitrary attachments

    Published: 16 Aug 2023
    4.8
    Medium

    CVE-2023-2254

    Last Modified: 21 Nov 2024

    The Ko-fi Button WordPress plugin before 1.3.3 does not properly some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup), and we consider it a low risk.

    Published: 16 Aug 2023
    8.8
    High

    CVE-2023-1977

    Last Modified: 21 Nov 2024

    The Booking Manager WordPress plugin before 2.0.29 does not validate URLs input in it's admin panel or in shortcodes for showing events from a remote .ics file, allowing an attacker with privileges as low as Subscriber to perform SSRF attacks on the sites internal network.

    Published: 16 Aug 2023
    6.1
    Medium

    CVE-2023-1465

    Last Modified: 5 May 2025

    The WP EasyPay WordPress plugin before 4.1 does not escape some generated URLs before outputting them back in pages, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as admin

    Published: 16 Aug 2023
    5.4
    Medium

    CVE-2023-0274

    Last Modified: 14 Jan 2026

    The URL Params WordPress plugin before 2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 16 Aug 2023
    5.4
    Medium

    CVE-2023-1110

    Last Modified: 21 Nov 2024

    The Yellow Yard Searchbar WordPress plugin before 2.8.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

    Published: 16 Aug 2023
    4.8
    Medium

    CVE-2023-2225

    Last Modified: 21 Nov 2024

    The SEO ALert WordPress plugin through 1.59 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 16 Aug 2023
    6.1
    Medium

    CVE-2023-2272

    Last Modified: 21 Nov 2024

    The Tiempo.com WordPress plugin through 0.1.2 does not sanitise and escape the page parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 16 Aug 2023
    6.1
    Medium

    CVE-2023-0058

    Last Modified: 21 Nov 2024

    The Tiempo.com WordPress plugin through 0.1.2 does not have CSRF check when creating and editing its shortcode, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

    Published: 16 Aug 2023
    4.3
    Medium

    CVE-2023-2271

    Last Modified: 21 Nov 2024

    The Tiempo.com WordPress plugin through 0.1.2 does not have CSRF check when deleting its shortcode, which could allow attackers to make logged in admins delete arbitrary shortcode via a CSRF attack

    Published: 16 Aug 2023
    6.1
    Medium

    CVE-2023-2123

    Last Modified: 21 Nov 2024

    The WP Inventory Manager WordPress plugin before 2.1.0.13 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

    Published: 16 Aug 2023
    8.8
    High

    CVE-2023-0579

    Last Modified: 24 Mar 2026

    The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscribers to perform SQL Injection attacks.

    Published: 16 Aug 2023
    6.1
    Medium

    CVE-2023-2122

    Last Modified: 21 Nov 2024

    The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter before rendering it in the plugin admin panel, leading to a reflected Cross-Site Scripting vulnerability, allowing an attacker to trick a logged in admin to execute arbitrary javascript by clicking a link.

    Published: 16 Aug 2023
    5.4
    Medium

    CVE-2022-4782

    Last Modified: 21 Nov 2024

    The ClickFunnels WordPress plugin through 3.1.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

    Published: 16 Aug 2023
    4.3
    Medium

    CVE-2023-4381

    Last Modified: 21 Nov 2024

    Unverified Password Change in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

    Published: 16 Aug 2023
    7.5
    High

    CVE-2023-4241

    Last Modified: 21 Nov 2024

    lol-html can cause panics on certain HTML inputs. Anyone processing arbitrary 3rd party HTML with the library is affected.

    Published: 16 Aug 2023
    7.1
    High

    CVE-2023-30871

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PT Woo Plugins (by Webdados) Stock Exporter for WooCommerce plugin <= 1.1.0 versions.

    Published: 16 Aug 2023
    7.1
    High

    CVE-2023-30779

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jonathan Daggerhart Query Wrangler plugin <= 1.5.51 versions.

    Published: 16 Aug 2023
    6.3
    Medium

    CVE-2023-4380

    Last Modified: 20 Nov 2025

    A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting in the loss of confidentiality, integrity, and availability.

    Published: 16 Aug 2023
    6.5
    Medium

    CVE-2023-30784

    Last Modified: 21 Nov 2024

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Kaya Studio Kaya QR Code Generator plugin <= 1.5.2 versions.

    Published: 16 Aug 2023
    7.1
    High

    CVE-2023-30473

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maxim Glazunov YML for Yandex Market plugin <= 3.10.7 versions.

    Published: 16 Aug 2023
    7.1
    High

    CVE-2023-30785

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Video Grid plugin <= 1.21 versions.

    Published: 16 Aug 2023
    7.1
    High

    CVE-2023-30782

    Last Modified: 21 Nov 2024

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Andy Moyle Church Admin plugin <= 3.7.5 versions.

    Published: 16 Aug 2023
    5.9
    Medium

    CVE-2023-30786

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Benjamin Guy Captcha Them All plugin <= 1.3.3 versions.

    Published: 16 Aug 2023
    6.1
    Medium

    CVE-2023-39507

    Last Modified: 21 Nov 2024

    Improper authorization in the custom URL scheme handler in "Rikunabi NEXT" App for Android prior to ver. 11.5.0 allows a malicious intent to lead the vulnerable App to access an arbitrary website.

    Published: 16 Aug 2023
    6.1
    Medium

    CVE-2023-26140

    Last Modified: 21 Nov 2024

    Versions of the package @excalidraw/excalidraw from 0.0.0 are vulnerable to Cross-site Scripting (XSS) via embedded links in whiteboard objects due to improper input sanitization.

    Published: 16 Aug 2023
    4.3
    Medium

    CVE-2023-4374

    Last Modified: 8 Apr 2026

    The WP Remote Users Sync plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'refresh_logs_async' functions in versions up to, and including, 1.2.11. This makes it possible for authenticated attackers with subscriber privileges or above, to view logs.

    Published: 16 Aug 2023
    8.5
    High

    CVE-2023-3958

    Last Modified: 8 Apr 2026

    The WP Remote Users Sync plugin for WordPress is vulnerable to Server Side Request Forgery via the 'notify_ping_remote' AJAX function in versions up to, and including, 1.2.12. This can allow authenticated attackers with subscriber-level permissions or above to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. This was partially patched in version 1.2.12 and fully patched in version 1.2.13.

    Published: 16 Aug 2023
    9.8
    Critical

    CVE-2020-26037

    Last Modified: 5 Jul 2026

    Directory Traversal vulnerability in Server functionalty in Even Balance Punkbuster version 1.902 before 1.905 allows remote attackers to execute arbitrary code.

    Published: 16 Aug 2023
    8.8
    High

    CVE-2023-39975

    Last Modified: 25 Feb 2026

    kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.

    Published: 16 Aug 2023