Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-50762 2 Debian, Mozilla 2 Debian Linux, Thunderbird 2023-12-29 N/A 4.3 MEDIUM
When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This is because the text was interpreted as a MIME message and the first paragraph was always treated as an email header section. A digitally signed text from a different context, such as a signed GIT commit, could be used to spoof an email message. This vulnerability affects Thunderbird < 115.6.
CVE-2023-50761 2 Debian, Mozilla 2 Debian Linux, Thunderbird 2023-12-29 N/A 4.3 MEDIUM
The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If present, Thunderbird did not compare the signature creation date with the message date and time, and displayed a valid signature despite a date or time mismatch. This could be used to give recipients the impression that a message was sent at a different date or time. This vulnerability affects Thunderbird < 115.6.
CVE-2023-6228 2 Libtiff, Redhat 2 Libtiff, Enterprise Linux 2023-12-29 N/A 5.5 MEDIUM
An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may cause a heap-based buffer overflow leads to an application crash.
CVE-2023-27990 1 Zyxel 38 Atp100, Atp100 Firmware, Atp100w and 35 more 2023-12-29 N/A 4.8 MEDIUM
The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker with administrator privileges to store malicious scripts in a vulnerable device. A successful XSS attack could then result in the stored malicious scripts being executed when the user visits the Logs page of the GUI on the device.
CVE-2022-45854 1 Zyxel 12 Nwa110ax, Nwa110ax Firmware, Nwa210ax and 9 more 2023-12-29 N/A 4.3 MEDIUM
An improper check for unusual conditions in Zyxel NWA110AX firmware verisons prior to 6.50(ABTG.0)C0, which could allow a LAN attacker to cause a temporary denial-of-service (DoS) by sending crafted VLAN frames if the MAC address of the vulnerable AP were intercepted by the attacker.
CVE-2022-43392 1 Zyxel 96 Ax7501-b0, Ax7501-b0 Firmware, Dx3301-t0 and 93 more 2023-12-29 N/A 6.5 MEDIUM
A buffer overflow vulnerability in the parameter of web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted authorization request.
CVE-2022-43391 1 Zyxel 96 Ax7501-b0, Ax7501-b0 Firmware, Dx3301-t0 and 93 more 2023-12-29 N/A 6.5 MEDIUM
A buffer overflow vulnerability in the parameter of the CGI program in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted HTTP request.
CVE-2023-47527 1 Sajjadhsagor 1 Wp Edit Username 2023-12-29 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sajjad Hossain Sagor WP Edit Username allows Stored XSS.This issue affects WP Edit Username: from n/a through 1.0.5.
CVE-2023-47525 1 Awplife 1 Event Monster 2023-12-29 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Event Monster – Event Management, Tickets Booking, Upcoming Event allows Stored XSS.This issue affects Event Monster – Event Management, Tickets Booking, Upcoming Event: from n/a through 1.3.2.
CVE-2023-50569 1 Cacti 1 Cacti 2023-12-29 N/A 6.1 MEDIUM
Reflected Cross Site Scripting (XSS) vulnerability in Cacti v1.2.25, allows remote attackers to escalate privileges when uploading an xml template file via templates_import.php.
CVE-2023-6744 1 Elegantthemes 1 Divi 2023-12-29 N/A 5.4 MEDIUM
The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'et_pb_text' shortcode in all versions up to, and including, 4.23.1 due to insufficient input sanitization and output escaping on user supplied custom field data. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2020-36769 1 Porternovelli 1 Widget Settings Importer\/exporter 2023-12-29 N/A 5.4 MEDIUM
The Widget Settings Importer/Exporter Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp_ajax_import_widget_dataparameter AJAX action in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber-level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2023-7075 1 Code-projects 1 Point Of Sales And Inventory Management System 2023-12-29 N/A 6.1 MEDIUM
A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /main/checkout.php. The manipulation of the argument pt leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248846 is the identifier assigned to this vulnerability.
CVE-2022-43450 1 Xwp 1 Stream 2023-12-29 N/A 6.5 MEDIUM
Authorization Bypass Through User-Controlled Key vulnerability in XWP Stream.This issue affects Stream: from n/a through 3.9.2.
CVE-2023-7036 1 Automad 1 Automad 2023-12-29 N/A 5.4 MEDIUM
A vulnerability was found in automad up to 1.10.9. It has been classified as problematic. This affects the function upload of the file FileCollectionController.php of the component Content Type Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248685 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2023-7035 1 Automad 1 Automad 2023-12-29 N/A 5.4 MEDIUM
A vulnerability was found in automad up to 1.10.9 and classified as problematic. Affected by this issue is some unknown functionality of the file packages\standard\templates\post.php of the component Setting Handler. The manipulation of the argument sitename leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-248684. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2023-7038 1 Automad 1 Automad 2023-12-29 N/A 6.5 MEDIUM
A vulnerability was found in automad up to 1.10.9. It has been rated as problematic. This issue affects some unknown processing of the file /dashboard?controller=UserCollection::createUser of the component User Creation Handler. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248687. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2023-48652 1 Concretecms 1 Concrete Cms 2023-12-29 N/A 4.3 MEDIUM
Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) via /ccm/system/dialogs/logs/delete_all/submit. An attacker can force an admin user to delete server report logs on a web application to which they are currently authenticated.
CVE-2023-45165 1 Ibm 1 Aix 2023-12-29 N/A 5.5 MEDIUM
IBM AIX 7.2 and 7.3 could allow a non-privileged local user to exploit a vulnerability in the AIX SMB client to cause a denial of service. IBM X-Force ID: 267963.
CVE-2023-50833 1 Extendthemes 1 Colibri Page Builder 2023-12-29 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExtendThemes Colibri Page Builder allows Stored XSS.This issue affects Colibri Page Builder: from n/a through 1.0.239.
CVE-2023-6134 1 Redhat 2 Keycloak, Single Sign-on 2023-12-29 N/A 5.4 MEDIUM
A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could allow an attacker to submit a specially crafted request leading to cross-site scripting (XSS) or further attacks. This flaw is the result of an incomplete fix for CVE-2020-10748.
CVE-2023-4154 1 Samba 1 Samba 2023-12-29 N/A 6.5 MEDIUM
A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to privileged users and Read-Only Domain Controllers (RODCs). This flaw allows RODCs and users possessing the GET_CHANGES right to access all attributes, including sensitive secrets and passwords. Even in a default setup, RODC DC accounts, which should only replicate some passwords, can gain access to all domain secrets, including the vital krbtgt, effectively eliminating the RODC / DC distinction. Furthermore, the vulnerability fails to account for error conditions (fail open), like out-of-memory situations, potentially granting access to secret attributes, even under low-privileged attacker influence.
CVE-2023-50828 1 Davidvongries 1 Ultimate Dashboard 2023-12-29 N/A 4.8 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Vongries Ultimate Dashboard – Custom WordPress Dashboard allows Stored XSS.This issue affects Ultimate Dashboard – Custom WordPress Dashboard: from n/a through 3.7.11.
CVE-2023-50824 1 Elearningfreak 1 Insert Or Embed Articulate Content 2023-12-29 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Batt Insert or Embed Articulate Content into WordPress allows Stored XSS.This issue affects Insert or Embed Articulate Content into WordPress: from n/a through 4.3000000021.
CVE-2023-50823 1 Wipeoutmedia 1 Css \& Javascript Toolbox 2023-12-29 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wipeout Media CSS & JavaScript Toolbox allows Stored XSS.This issue affects CSS & JavaScript Toolbox: from n/a through 11.7.
CVE-2023-50831 1 Villatheme 1 Curcy 2023-12-29 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme CURCY – Multi Currency for WooCommerce allows Stored XSS.This issue affects CURCY – Multi Currency for WooCommerce: from n/a through 2.2.0.
CVE-2023-50830 1 Seosthemes 1 Seos Contact Form 2023-12-29 N/A 4.8 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Seosbg Seos Contact Form allows Stored XSS.This issue affects Seos Contact Form: from n/a through 1.8.0.
CVE-2023-50829 1 Quick-plugins 1 Loan Repayment Calculator And Application Form 2023-12-29 N/A 4.8 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aerin Loan Repayment Calculator and Application Form allows Stored XSS.This issue affects Loan Repayment Calculator and Application Form: from n/a through 2.9.3.
CVE-2023-50473 1 Billahmed 1 Qbit Matui 2023-12-29 N/A 5.4 MEDIUM
Cross-Site Scripting (XSS) vulnerability in bill-ahmed qbit-matUI version 1.16.4, allows remote attackers to obtain sensitive information via fixed session identifiers (SID) in index.js file.
CVE-2023-46624 1 Parcelpro 1 Parcel Pro 2023-12-29 N/A 6.1 MEDIUM
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Parcel Pro.This issue affects Parcel Pro: from n/a through 1.6.11.
CVE-2021-28459 1 Microsoft 1 Azure Devops Server 2023-12-29 4.3 MEDIUM 6.1 MEDIUM
Azure DevOps Server Spoofing Vulnerability
CVE-2021-28456 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2023-12-29 4.3 MEDIUM 5.5 MEDIUM
Microsoft Excel Information Disclosure Vulnerability
CVE-2021-28450 1 Microsoft 2 Sharepoint Foundation, Sharepoint Server 2023-12-29 4.0 MEDIUM 5.0 MEDIUM
Microsoft SharePoint Denial of Service Vulnerability
CVE-2021-27067 1 Microsoft 2 Azure Devops Server, Team Foundation Server 2023-12-29 4.0 MEDIUM 6.5 MEDIUM
Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability
CVE-2023-49786 2 Digium, Sangoma 2 Asterisk, Certified Asterisk 2023-12-29 N/A 5.9 MEDIUM
Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1; as well as certified-asterisk prior to 18.9-cert6; Asterisk is susceptible to a DoS due to a race condition in the hello handshake phase of the DTLS protocol when handling DTLS-SRTP for media setup. This attack can be done continuously, thus denying new DTLS-SRTP encrypted calls during the attack. Abuse of this vulnerability may lead to a massive Denial of Service on vulnerable Asterisk servers for calls that rely on DTLS-SRTP. Commit d7d7764cb07c8a1872804321302ef93bf62cba05 contains a fix, which is part of versions 18.20.1, 20.5.1, 21.0.1, amd 18.9-cert6.
CVE-2021-36931 1 Microsoft 1 Edge Chromium 2023-12-28 6.8 MEDIUM 4.4 MEDIUM
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2021-36929 1 Microsoft 1 Edge Chromium 2023-12-28 4.3 MEDIUM 6.3 MEDIUM
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2021-36928 1 Microsoft 1 Edge Chromium 2023-12-28 7.2 HIGH 6.0 MEDIUM
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2021-34466 1 Microsoft 1 Windows 10 2023-12-28 3.6 LOW 5.7 MEDIUM
Windows Hello Security Feature Bypass Vulnerability
CVE-2021-34457 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2023-12-28 2.1 LOW 5.5 MEDIUM
Windows Remote Access Connection Manager Information Disclosure Vulnerability
CVE-2021-34454 1 Microsoft 6 Windows 10, Windows 8.1, Windows Rt 8.1 and 3 more 2023-12-28 2.1 LOW 5.5 MEDIUM
Windows Remote Access Connection Manager Information Disclosure Vulnerability
CVE-2021-34451 1 Microsoft 1 Office Online Server 2023-12-28 5.0 MEDIUM 5.3 MEDIUM
Microsoft Office Online Server Spoofing Vulnerability
CVE-2021-34448 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2023-12-28 9.3 HIGH 6.8 MEDIUM
Scripting Engine Memory Corruption Vulnerability
CVE-2021-34447 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2023-12-28 6.8 MEDIUM 6.8 MEDIUM
Windows MSHTML Platform Remote Code Execution Vulnerability
CVE-2021-34444 1 Microsoft 4 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 1 more 2023-12-28 4.0 MEDIUM 6.5 MEDIUM
Windows DNS Server Denial of Service Vulnerability
CVE-2021-34440 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2023-12-28 2.1 LOW 5.5 MEDIUM
GDI+ Information Disclosure Vulnerability
CVE-2021-34519 1 Microsoft 2 Sharepoint Foundation, Sharepoint Server 2023-12-28 2.3 LOW 5.3 MEDIUM
Microsoft SharePoint Server Information Disclosure Vulnerability
CVE-2021-34517 1 Microsoft 2 Sharepoint Foundation, Sharepoint Server 2023-12-28 5.0 MEDIUM 5.3 MEDIUM
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2021-34509 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2023-12-28 2.1 LOW 5.5 MEDIUM
Storage Spaces Controller Information Disclosure Vulnerability
CVE-2021-34507 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2023-12-28 4.3 MEDIUM 6.5 MEDIUM
Windows Remote Assistance Information Disclosure Vulnerability