5.3
    Medium

    CVE-2023-5089

    Last Modified: 23 Apr 2025

    The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.

    Published:16 Oct 2023
    6.5
    Medium

    CVE-2023-5070

    Last Modified: 8 Apr 2026

    The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.8.5 via the sfsi_save_export function. This can allow subscribers to export plugin settings that include social media authentication tokens and secrets as well as app passwords.

    Published:20 Oct 2023
    7.6
    High

    CVE-2023-5044

    Last Modified: 12 Jun 2025

    Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.

    Published:25 Oct 2023
    7.6
    High

    CVE-2023-5043

    Last Modified: 13 Feb 2025

    Ingress nginx annotation injection causes arbitrary command execution.

    Published:25 Oct 2023
    3.5
    Low

    CVE-2023-5024

    Last Modified: 21 Nov 2024

    A vulnerability was found in Planno 23.04.04. It has been classified as problematic. This affects an unknown part of the component Comment Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239865 was assigned to this vulnerability.

    Published:17 Sept 2023
    9.4
    Critical

    CVE-2023-4966

    Last Modified: 24 Oct 2025

    Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

    Published:10 Oct 2023
    7.8
    High

    CVE-2023-4911

    Last Modified: 11 Feb 2026

    A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.

    Source:Beatriz Fresno Naumova
    Published:3 Oct 2023
    8.8
    High

    CVE-2023-4863

    Last Modified: 24 Oct 2025

    Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

    Published:11 Sept 2023
    7.2
    High

    CVE-2023-4861

    Last Modified: 23 Apr 2025

    The File Manager Pro WordPress plugin before 1.8.1 allows admin users to upload arbitrary files, even in environments where such a user should not be able to gain full control of the server, such as a multisite installation. This leads to remote code execution.

    Published:16 Oct 2023
    6.4
    Medium

    CVE-2023-4842

    Last Modified: 8 Apr 2026

    The Social Sharing Plugin - Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'social_warfare' shortcode in versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published:7 Nov 2023
    5.9
    Medium

    CVE-2023-4813

    Last Modified: 11 Nov 2025

    A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.

    Published:1 Mar 2022
    6.5
    Medium

    CVE-2023-4800

    Last Modified: 6 Mar 2025

    The DoLogin Security WordPress plugin before 3.7.1 does not restrict the access of a widget that shows the IPs of failed logins to low privileged users.

    Published:16 Oct 2023
    6.1
    Medium

    CVE-2023-4771

    Last Modified: 21 Nov 2024

    A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /ckeditor/samples/old/ajax.html file and retrieve an authorized user's information.

    Published:16 Nov 2023
    8.8
    High

    CVE-2023-4762

    Last Modified: 24 Oct 2025

    Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

    Published:5 Sept 2023
    6.3
    Medium

    CVE-2023-4741

    Last Modified: 21 Nov 2024

    A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. This vulnerability affects unknown code of the file ?r=diary/default/del of the component Delete Logs Handler. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-238630 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published:3 Sept 2023
    6.3
    Medium

    CVE-2023-4708

    Last Modified: 9 Oct 2023

    A vulnerability was found in Infosoftbd Clcknshop 1.0.0. It has been rated as critical. This issue affects some unknown processing of the file /collection/all of the component GET Parameter Handler. The manipulation of the argument tag leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-238571. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Source:CraCkEr
    Published:1 Sept 2023
    10
    Critical

    CVE-2023-4699

    Last Modified: 16 Dec 2025

    Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC-F Series CPU modules, MELSEC iQ-F Series, MELSEC iQ-R series CPU modules, MELSEC iQ-R series, MELSEC iQ-L series, MELSEC Q series, MELSEC-L series, Mitsubishi Electric CNC M800V/M80V series, Mitsubishi Electric CNC M800/M80/E80 series and Mitsubishi Electric CNC M700V/M70V/E70 series allows a remote unauthenticated attacker to execute arbitrary commands by sending specific packets to the affected products. This could lead to disclose or tamper with information by reading or writing control programs, or cause a denial-of-service (DoS) condition on the products by resetting the memory contents of the products to factory settings or resetting the products remotely.

    Published:6 Nov 2023
    7.5
    High

    CVE-2023-4698

    Last Modified: 21 Nov 2024

    Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.

    Published:1 Sept 2023
    9.8
    Critical

    CVE-2023-4696

    Last Modified: 21 Nov 2024

    Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.

    Published:1 Sept 2023
    5.5
    Medium

    CVE-2023-4683

    Last Modified: 21 Nov 2024

    NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV.

    Published:31 Aug 2023
    4.4
    Medium

    CVE-2023-4636

    Last Modified: 8 Apr 2026

    The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published:5 Sept 2023
    9.8
    Critical

    CVE-2023-4634

    Last Modified: 9 Oct 2023

    The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the ~/includes/mla-stream-image.php file, where images are processed via Imagick(). This makes it possible for unauthenticated attackers to supply files via FTP that will make directory lists, local file inclusion, and remote code execution possible.

    Source:Florent MONTEL
    Published:6 Sept 2023
    5.3
    Medium

    CVE-2023-4631

    Last Modified: 3 Mar 2026

    The DoLogin Security WordPress plugin before 3.7 uses headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing.

    Published:25 Sept 2023
    7.8
    High

    CVE-2023-4622

    Last Modified: 13 Feb 2025

    A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without locking the queue. Thus there is a race where unix_stream_sendpage() could access an skb locklessly that is being released by garbage collection, resulting in use-after-free. We recommend upgrading past commit 790c2f9d15b594350ae9bca7b236f2b1859de02c.

    Published:6 Sept 2023
    9.8
    Critical

    CVE-2023-4596

    Last Modified: 8 Apr 2026

    The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and including, 1.24.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published:30 Aug 2023
    7.3
    High

    CVE-2023-4590

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in Frhed hex editor, affecting version 1.6.0. This vulnerability could allow an attacker to execute arbitrary code via a long filename argument through the Structured Exception Handler (SEH) registers.

    Published:27 Nov 2023
    6.5
    Medium

    CVE-2023-4568

    Last Modified: 21 Nov 2024

    PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to be affected, but later versions may also be affected due to lack of a vendor supplied patch.

    Published:13 Sept 2023
    6.1
    Medium

    CVE-2023-4549

    Last Modified: 3 Mar 2026

    The DoLogin Security WordPress plugin before 3.7 does not properly sanitize IP addresses coming from the X-Forwarded-For header, which can be used by attackers to conduct Stored XSS attacks via WordPress' login form.

    Published:25 Sept 2023
    6.3
    Medium

    CVE-2023-4548

    Last Modified: 8 Sept 2023

    A vulnerability classified as critical has been found in SPA-Cart eCommerce CMS 1.9.0.3. This affects an unknown part of the file /search of the component GET Parameter Handler. The manipulation of the argument filter[brandid] leads to sql injection. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-238059.

    Source:CraCkEr
    Published:26 Aug 2023
    3.5
    Low

    CVE-2023-4547

    Last Modified: 4 Sept 2023

    A vulnerability was found in SPA-Cart eCommerce CMS 1.9.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /search. The manipulation of the argument filter[brandid]/filter[price] leads to cross site scripting. The attack may be launched remotely. VDB-238058 is the identifier assigned to this vulnerability.

    Source:CraCkEr
    Published:26 Aug 2023
    6.3
    Medium

    CVE-2023-4542

    Last Modified: 21 Nov 2024

    A vulnerability was found in D-Link DAR-8000-10 up to 20230809. It has been classified as critical. This affects an unknown part of the file /app/sys1.php. The manipulation of the argument cmd with the input id leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-238047. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published:25 Aug 2023
    7
    High

    CVE-2023-4504

    Last Modified: 4 Nov 2025

    Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.

    Published:20 Sept 2023
    6.1
    Medium

    CVE-2023-4460

    Last Modified: 21 Nov 2024

    The Uploading SVG, WEBP and ICO files WordPress plugin through 1.2.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

    Published:4 Dec 2023
    6.3
    Medium

    CVE-2023-4450

    Last Modified: 2 Jul 2025

    A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-237571.

    Published:21 Aug 2023
    8.1
    High

    CVE-2023-4427

    Last Modified: 13 Feb 2025

    Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

    Published:22 Aug 2023
    6.3
    Medium

    CVE-2023-4407

    Last Modified: 4 Sept 2023

    A vulnerability classified as critical was found in Codecanyon Credit Lite 1.5.4. Affected by this vulnerability is an unknown functionality of the file /portal/reports/account_statement of the component POST Request Handler. The manipulation of the argument date1/date2 leads to sql injection. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-237511.

    Source:CraCkEr
    Published:18 Aug 2023
    3.5
    Low

    CVE-2023-4382

    Last Modified: 4 Sept 2023

    A vulnerability, which was classified as problematic, has been found in tdevs Hyip Rio 2.1. Affected by this issue is some unknown functionality of the file /user/settings of the component Profile Settings. The manipulation of the argument avatar leads to cross site scripting. The attack may be launched remotely. VDB-237314 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Source:CraCkEr
    Published:16 Aug 2023
    8.8
    High

    CVE-2023-4357

    Last Modified: 13 Feb 2025

    Insufficient validation of untrusted input in XML in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published:15 Aug 2023
    7.2
    High

    CVE-2023-4300

    Last Modified: 23 Apr 2025

    The Import XML and RSS Feeds WordPress plugin before 2.1.4 does not filter file extensions for uploaded files, allowing an attacker to upload a malicious PHP file, leading to Remote Code Execution.

    Published:25 Sept 2023
    6.1
    Medium

    CVE-2023-4294

    Last Modified: 2 May 2025

    The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing an unauthenticated attacker to inject malicious javascript that will trigger in the plugins admin panel with statistics of the created short link.

    Published:11 Sept 2023
    5.3
    Medium

    CVE-2023-4281

    Last Modified: 23 Apr 2025

    This Activity Log WordPress plugin before 2.8.8 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to hide the source of malicious traffic.

    Published:25 Sept 2023
    7.5
    High

    CVE-2023-4279

    Last Modified: 23 Apr 2025

    This User Activity Log WordPress plugin before 1.6.7 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to hide the source of malicious traffic.

    Published:4 Sept 2023
    7.5
    High

    CVE-2023-4278

    Last Modified: 9 Oct 2023

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instructor. They can then add courses and/or posts.

    Source:Revan Arifio
    Published:11 Sept 2023
    8.8
    High

    CVE-2023-4226

    Last Modified: 21 Nov 2024

    Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.

    Published:28 Nov 2023
    8.1
    High

    CVE-2023-4220

    Last Modified: 18 Mar 2025

    Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.

    Source:Mohamed Kamel BOUZEKRIA
    Published:28 Nov 2023
    7.5
    High

    CVE-2023-4197

    Last Modified: 21 Nov 2024

    Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.

    Published:1 Nov 2023
    3.5
    Low

    CVE-2023-4174

    Last Modified: 8 Aug 2023

    A vulnerability has been found in mooSocial mooStore 3.1.6 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. The identifier VDB-236209 was assigned to this vulnerability.

    Source:CraCkEr
    Published:6 Aug 2023
    3.5
    Low

    CVE-2023-4173

    Last Modified: 8 Aug 2023

    A vulnerability, which was classified as problematic, was found in mooSocial mooStore 3.1.6. Affected is an unknown function of the file /search/index. The manipulation of the argument q leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-236208.

    Source:CraCkEr
    Published:6 Aug 2023
    6.3
    Medium

    CVE-2023-4169

    Last Modified: 21 Nov 2024

    A vulnerability was found in Ruijie RG-EW1200G 1.0(1)B1P5. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /api/sys/set_passwd of the component Administrator Password Handler. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-236185 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published:5 Aug 2023
    4.3
    Medium

    CVE-2023-4168

    Last Modified: 8 Aug 2023

    A vulnerability was found in Templatecookie Adlisting 2.14.0. It has been classified as problematic. Affected is an unknown function of the file /ad-list of the component Redirect Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-236184. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Source:CraCkEr
    Published:5 Aug 2023