5.4
    Medium

    CVE-2023-44758

    Last Modified: 21 Nov 2024

    GDidees CMS 3.0 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload to the Page Title.

    Published:6 Oct 2023
    7.5
    High

    CVE-2023-44487

    Last Modified: 16 Sept 2025

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

    Source:Madhusudhan Rajappa
    Published:10 Oct 2023
    7.8
    High

    CVE-2023-44452

    Last Modified: 14 Aug 2025

    Linux Mint Xreader CBT File Parsing Argument Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CBT files. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-22132.

    Published:3 May 2024
    7.8
    High

    CVE-2023-44451

    Last Modified: 14 Aug 2025

    Linux Mint Xreader EPUB File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EPUB files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-21897.

    Published:3 May 2024
    5.9
    Medium

    CVE-2023-44088

    Last Modified: 13 Apr 2025

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to be executed using any account with low privileges. This issue affects Pandora FMS: from 700 through 774.

    Source:Osama Yousef
    Published:29 Dec 2023
    8.8
    High

    CVE-2023-44061

    Last Modified: 21 Nov 2024

    File Upload vulnerability in Simple and Nice Shopping Cart Script v.1.0 allows a remote attacker to execute arbitrary code via the upload function in the edit profile component.

    Published:6 Oct 2023
    9.8
    Critical

    CVE-2023-43955

    Last Modified: 21 Nov 2024

    The com.phlox.tvwebbrowser TV Bro application through 2.0.0 for Android mishandles external intents through WebView. This allows attackers to execute arbitrary code, create arbitrary files. and perform arbitrary downloads via JavaScript that uses takeBlobDownloadData.

    Published:27 Dec 2023
    4.8
    Medium

    CVE-2023-43879

    Last Modified: 21 Nov 2024

    Rite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload into the Global Content Blocks in the Administration Menu.

    Published:28 Sept 2023
    5.4
    Medium

    CVE-2023-43878

    Last Modified: 21 Nov 2024

    Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a crafted payload into the Main Menu Items in the Administration Menu.

    Published:28 Sept 2023
    4.8
    Medium

    CVE-2023-43877

    Last Modified: 21 Nov 2024

    Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a payload crafted in the Home Page fields in the Administration menu.

    Published:4 Oct 2023
    5.4
    Medium

    CVE-2023-43876

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost field.

    Published:28 Sept 2023
    6.1
    Medium

    CVE-2023-43875

    Last Modified: 21 Nov 2024

    Multiple Cross-Site Scripting (XSS) vulnerabilities in installation of Subrion CMS v.4.2.1 allows a local attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost, dbname, dbuser, adminusername and adminemail.

    Published:19 Oct 2023
    5.4
    Medium

    CVE-2023-43874

    Last Modified: 21 Nov 2024

    Multiple Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Copyright and Author fields in the Meta & Custom Tags Menu.

    Published:28 Sept 2023
    5.4
    Medium

    CVE-2023-43873

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Name filed in the Manage Menu.

    Published:28 Sept 2023
    5.4
    Medium

    CVE-2023-43872

    Last Modified: 21 Nov 2024

    A File upload vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).

    Published:28 Sept 2023
    5.4
    Medium

    CVE-2023-43871

    Last Modified: 21 Nov 2024

    A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).

    Published:28 Sept 2023
    7.8
    High

    CVE-2023-43838

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar.

    Published:4 Oct 2023
    5.5
    Medium

    CVE-2023-43786

    Last Modified: 6 Nov 2025

    A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available system resources and cause a denial of service condition.

    Published:4 Oct 2023
    6.1
    Medium

    CVE-2023-43770

    Last Modified: 31 Oct 2025

    Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.

    Published:22 Sept 2023
    6.5
    Medium

    CVE-2023-43757

    Last Modified: 21 Nov 2024

    Inadequate encryption strength vulnerability in multiple routers provided by ELECOM CO.,LTD. and LOGITEC CORPORATION allows a network-adjacent unauthenticated attacker to guess the encryption key used for wireless LAN communication and intercept the communication. As for the affected products/versions, see the information provided by the vendor under [References] section.

    Published:16 Nov 2023
    10
    Critical

    CVE-2023-43654

    Last Modified: 13 Feb 2025

    TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper input validation, enabling third parties to invoke remote HTTP download requests and write files to the disk. This issue could be taken advantage of to compromise the integrity of the system and sensitive data. This issue is present in versions 0.1.0 to 0.8.1. A user is able to load the model of their choice from any URL that they would like to use. The user of TorchServe is responsible for configuring both the allowed_urls and specifying the model URL to be used. A pull request to warn the user when the default value for allowed_urls is used has been merged in PR #2534. TorchServe release 0.8.2 includes this change. Users are advised to upgrade. There are no known workarounds for this issue.

    Published:28 Sept 2023
    8.6
    High

    CVE-2023-43646

    Last Modified: 21 Nov 2024

    get-func-name is a module to retrieve a function's name securely and consistently both in NodeJS and the browser. Versions prior to 2.0.1 are subject to a regular expression denial of service (redos) vulnerability which may lead to a denial of service when parsing malicious input. This vulnerability can be exploited when there is an imbalance in parentheses, which results in excessive backtracking and subsequently increases the CPU load and processing time significantly. This vulnerability can be triggered using the following input: '\t'.repeat(54773) + '\t/function/i'. This issue has been addressed in commit `f934b228b` which has been included in releases from 2.0.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published:26 Sept 2023
    7.5
    High

    CVE-2023-43622

    Last Modified: 13 Feb 2025

    An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, similar to the well known "slow loris" attack pattern. This has been fixed in version 2.4.58, so that such connection are terminated properly after the configured connection timeout. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.57. Users are recommended to upgrade to version 2.4.58, which fixes the issue.

    Published:10 Oct 2023
    4.3
    Medium

    CVE-2023-43494

    Last Modified: 21 Nov 2024

    Jenkins 2.50 through 2.423 (both inclusive), LTS 2.60.1 through 2.414.1 (both inclusive) does not exclude sensitive build variables (e.g., password parameter values) from the search in the build history widget, allowing attackers with Item/Read permission to obtain values of sensitive variables used in builds by iteratively testing different characters until the correct sequence is discovered.

    Published:20 Sept 2023
    7.2
    High

    CVE-2023-43482

    Last Modified: 4 Nov 2025

    A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published:6 Feb 2024
    9.8
    Critical

    CVE-2023-43481

    Last Modified: 21 Nov 2024

    An issue in Shenzhen TCL Browser TV Web BrowseHere (aka com.tcl.browser) 6.65.022_dab24cc6_231221_gp allows a remote attacker to execute arbitrary JavaScript code via the com.tcl.browser.portal.browse.activity.BrowsePageActivity component.

    Published:27 Dec 2023
    9.8
    Critical

    CVE-2023-43364

    Last Modified: 21 Nov 2024

    main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.

    Published:12 Dec 2023
    5.4
    Medium

    CVE-2023-43360

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Top Directory parameter in the File Picker Menu component.

    Published:24 Oct 2023
    5.4
    Medium

    CVE-2023-43359

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Page Specific Metadata and Smarty data parameters in the Content Manager Menu component.

    Published:19 Oct 2023
    5.4
    Medium

    CVE-2023-43358

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the News Menu component.

    Published:23 Oct 2023
    5.4
    Medium

    CVE-2023-43357

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the Manage Shortcuts component.

    Published:20 Oct 2023
    5.4
    Medium

    CVE-2023-43356

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Global Meatadata parameter in the Global Settings Menu component.

    Published:20 Oct 2023
    5.4
    Medium

    CVE-2023-43355

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the password and password again parameters in the My Preferences - Add user component.

    Published:20 Oct 2023
    5.4
    Medium

    CVE-2023-43354

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Profiles parameter in the Extensions -MicroTiny WYSIWYG editor component.

    Published:20 Oct 2023
    5.4
    Medium

    CVE-2023-43353

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the extra parameter in the news menu component.

    Published:20 Oct 2023
    7.8
    High

    CVE-2023-43352

    Last Modified: 21 Nov 2024

    An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu component.

    Published:26 Oct 2023
    5.4
    Medium

    CVE-2023-43346

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Backend - Dashboard parameter in the Languages Menu component.

    Published:20 Oct 2023
    8.6
    High

    CVE-2023-43345

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Content - Name parameter in the Pages Menu component.

    Published:19 Oct 2023
    5.4
    Medium

    CVE-2023-43344

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the SEO - Meta description parameter in the Pages Menu component.

    Published:19 Oct 2023
    5.4
    Medium

    CVE-2023-43343

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Files - Description parameter in the Pages Menu component.

    Published:5 Oct 2023
    5.4
    Medium

    CVE-2023-43342

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Languages Menu component.

    Published:19 Oct 2023
    6.1
    Medium

    CVE-2023-43341

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in evolution evo v.3.2.3 allows a local attacker to execute arbitrary code via a crafted payload injected uid parameter.

    Published:19 Oct 2023
    5.2
    Medium

    CVE-2023-43340

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in evolution v.3.2.3 allows a local attacker to execute arbitrary code via a crafted payload injected into the cmsadmin, cmsadminemail, cmspassword and cmspasswordconfim parameters

    Published:19 Oct 2023
    6.1
    Medium

    CVE-2023-43339

    Last Modified: 21 Nov 2024

    Cross-Site Scripting (XSS) vulnerability in cmsmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload injected into the Database Name, DataBase User or Database Port components.

    Published:25 Sept 2023
    6.1
    Medium

    CVE-2023-43326

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability exisits in multiple url of mooSocial v3.1.8 allows attackers to steal user's session cookies and impersonate their account via a crafted URL.

    Published:25 Sept 2023
    6.1
    Medium

    CVE-2023-43325

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in the data[redirect_url] parameter of mooSocial v3.1.8 allows attackers to steal user's session cookies and impersonate their account via a crafted URL.

    Published:25 Sept 2023
    6.5
    Medium

    CVE-2023-43323

    Last Modified: 21 Nov 2024

    mooSocial 3.1.8 is vulnerable to external service interaction on post function. When executed, the server sends a HTTP and DNS request to external server. The Parameters effected are multiple - messageText, data[wall_photo], data[userShareVideo] and data[userShareLink].

    Published:28 Sept 2023
    8.8
    High

    CVE-2023-43318

    Last Modified: 4 Nov 2025

    TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of the 'tid' and 'usrlvl' values in GET requests.

    Published:5 Mar 2024
    8.8
    High

    CVE-2023-43317

    Last Modified: 20 Jun 2025

    An issue in Coign CRM Portal v.06.06 allows a remote attacker to escalate privileges via the userPermissionsList parameter in Session Storage component.

    Published:24 Jan 2024
    8.8
    High

    CVE-2023-43284

    Last Modified: 21 Nov 2024

    D-Link Wireless MU-MIMO Gigabit AC1200 Router DIR-846 100A53DBR-Retail devices allow an authenticated remote attacker to execute arbitrary code via an unspecified manipulation of the QoS POST parameter.

    Published:5 Oct 2023