Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6746 1 Github 1 Enterprise Server 2024-01-10 N/A 5.7 MEDIUM
An insertion of sensitive information into log file vulnerability was identified in the log files for a GitHub Enterprise Server back-end service that could permit an `adversary in the middle attack` when combined with other phishing techniques. To exploit this, an attacker would need access to the log files for the GitHub Enterprise Server appliance, a backup archive created with GitHub Enterprise Server Backup Utilities, or a service which received streamed logs. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.7.19, 3.8.12, 3.9.7, 3.10.4, and 3.11.1. 
CVE-2024-20802 1 Samsung 1 Dex 2024-01-10 N/A 5.5 MEDIUM
Improper access control vulnerability in Samsung DeX prior to SMR Jan-2024 Release 1 allows owner to access other users' notification in a multi-user environment.
CVE-2023-6918 3 Fedoraproject, Libssh, Redhat 3 Fedora, Libssh, Enterprise Linux 2024-01-10 N/A 5.3 MEDIUM
A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked, which could cause low-memory situations failures, NULL dereferences, crashes, or usage of the uninitialized memory as an input for the KDF. In this case, non-matching keys will result in decryption/integrity failures, terminating the connection.
CVE-2023-7044 1 Wpdeveloper 1 Essential Addons For Elementor 2024-01-10 N/A 5.4 MEDIUM
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom ID in all versions up to, and including, 5.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access and higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2024-20803 1 Samsung 1 Android 2024-01-10 N/A 6.5 MEDIUM
Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing process without user interaction.
CVE-2024-20804 1 Samsung 2 Android, Myfiles 2024-01-10 N/A 5.5 MEDIUM
Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows attackers to write arbitrary file.
CVE-2024-20806 1 Samsung 1 Android 2024-01-10 N/A 5.5 MEDIUM
Improper access control in Notification service prior to SMR Jan-2024 Release 1 allows local attacker to access notification data.
CVE-2024-21636 1 Viewcomponent 1 View Component 2024-01-10 N/A 6.1 MEDIUM
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. Versions prior to 3.9.0 and 2.83.0 have a cross-site scripting vulnerability that has the potential to impact anyone rendering a component directly from a controller with the view_component gem. Note that only components that define a `#call` method (i.e. instead of using a sidecar template) are affected. The return value of the `#call` method is not sanitized and can include user-defined content. In addition, the return value of the `#output_postamble` methodis not sanitized, which can also lead to cross-site scripting issues. Versions 3.9.0 and 2.83.0 have been released and fully mitigate both the `#call` and the `#output_postamble` vulnerabilities. As a workaround, sanitize the return value of `#call`.
CVE-2024-20805 1 Samsung 2 Android, Myfiles 2024-01-10 N/A 5.5 MEDIUM
Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows attackers to write arbitrary file.
CVE-2023-3019 2 Qemu, Redhat 2 Qemu, Enterprise Linux 2024-01-10 N/A 6.5 MEDIUM
A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue could allow a privileged guest user to crash the QEMU process on the host, resulting in a denial of service.
CVE-2023-6493 1 Averta 1 Depicter Slider 2024-01-10 N/A 4.3 MEDIUM
The Depicter Slider – Responsive Image Slider, Video Slider & Post Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.6. This is due to missing or incorrect nonce validation on the 'save' function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE-2023-51491 appears to be a duplicate of this issue.
CVE-2024-22075 1 Firefly-iii 1 Firefly Iii 2024-01-10 N/A 6.1 MEDIUM
Firefly III (aka firefly-iii) before 6.1.1 allows webhooks HTML Injection.
CVE-2024-20808 1 Samsung 1 Nearby Device Scanning 2024-01-10 N/A 5.5 MEDIUM
Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access data.
CVE-2024-20809 1 Samsung 1 Nearby Device Scanning 2024-01-10 N/A 5.5 MEDIUM
Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access data.
CVE-2024-20715 2024-01-10 N/A 5.5 MEDIUM
Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2024-20714 2024-01-10 N/A 5.5 MEDIUM
Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2023-6980 1 Veronalabs 1 Wp Sms 2024-01-10 N/A 4.3 MEDIUM
The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5. This is due to missing or incorrect nonce validation on the 'delete' action of the wp-sms-subscribers page. This makes it possible for unauthenticated attackers to delete subscribers via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-2023-38858 1 Faad2 Project 1 Faad2 2024-01-10 N/A 6.5 MEDIUM
Buffer Overflow vulnerability infaad2 v.2.10.1 allows a remote attacker to execute arbitrary code and cause a denial of service via the mp4info function in mp4read.c:1039.
CVE-2023-38857 1 Faad2 Project 1 Faad2 2024-01-10 N/A 5.5 MEDIUM
Buffer Overflow vulnerability infaad2 v.2.10.1 allows a remote attacker to execute arbitrary code and cause a denial of service via the stcoin function in mp4read.c.
CVE-2023-52148 1 Wpaffiliatemanager 1 Affiliates Manager 2024-01-10 N/A 5.3 MEDIUM
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliates Manager: from n/a through 2.9.30.
CVE-2023-51678 1 Doofinder 1 Doofinder 2024-01-10 N/A 6.5 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Doofinder Doofinder WP & WooCommerce Search.This issue affects Doofinder WP & WooCommerce Search: from n/a through 2.0.33.
CVE-2023-52125 1 Iframe Project 1 Iframe 2024-01-10 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webvitaly iframe allows Stored XSS.This issue affects iframe: from n/a through 4.8.
CVE-2023-52124 1 Shapedplugin 1 Wp Tabs 2024-01-10 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC WP Tabs – Responsive Tabs Plugin for WordPress allows Stored XSS.This issue affects WP Tabs – Responsive Tabs Plugin for WordPress: from n/a through 2.2.0.
CVE-2023-52151 1 Uncannyowl 1 Uncanny Automator 2024-01-10 N/A 5.3 MEDIUM
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Uncanny Automator, Uncanny Owl Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin.This issue affects Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin: from n/a through 5.1.0.2.
CVE-2023-52126 1 Sumanbhattarai 1 Send Users Email 2024-01-10 N/A 5.3 MEDIUM
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Suman Bhattarai Send Users Email.This issue affects Send Users Email: from n/a through 1.4.3.
CVE-2023-49994 1 Espeak-ng 1 Espeak-ng 2024-01-10 N/A 5.5 MEDIUM
Espeak-ng 1.52-dev was discovered to contain a Floating Point Exception via the function PeaksToHarmspect at wavegen.c.
CVE-2023-49993 1 Espeak-ng 1 Espeak-ng 2024-01-10 N/A 5.3 MEDIUM
Espeak-ng 1.52-dev was discovered to contain a Buffer Overflow via the function ReadClause at readclause.c.
CVE-2023-49992 1 Espeak-ng 1 Espeak-ng 2024-01-10 N/A 5.3 MEDIUM
Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Overflow via the function RemoveEnding at dictionary.c.
CVE-2023-49991 1 Espeak-ng 1 Espeak-ng 2024-01-10 N/A 5.3 MEDIUM
Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Underflow via the function CountVowelPosition at synthdata.c.
CVE-2023-49990 1 Espeak-ng 1 Espeak-ng 2024-01-10 N/A 5.3 MEDIUM
Espeak-ng 1.52-dev was discovered to contain a buffer-overflow via the function SetUpPhonemeTable at synthdata.c.
CVE-2023-44796 1 Limesurvey 1 Limesurvey 2024-01-10 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate privileges via a crafted script to the _generaloptions_panel.php component.
CVE-2023-6600 1 Daan 1 Omgf 2024-01-10 N/A 5.4 MEDIUM
The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting due to a missing capability check on the update_settings() function hooked via admin_init in all versions up to, and including, 5.7.9. This makes it possible for unauthenticated attackers to update the plugin's settings which can be used to inject Cross-Site Scripting payloads and delete entire directories. PLease note there were several attempted patched, and we consider 5.7.10 to be the most sufficiently patched.
CVE-2023-6992 1 Cloudflare 1 Zlib 2024-01-10 N/A 5.5 MEDIUM
Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c). The issues resulted from improper input validation and heap-based buffer overflow. A local attacker could exploit the problem during compression using a crafted malicious file potentially leading to denial of service of the software. Patches: The issue has been patched in commit 8352d10 https://github.com/cloudflare/zlib/commit/8352d108c05db1bdc5ac3bdf834dad641694c13c . The upstream repository is not affected.
CVE-2023-52263 1 Brave 1 Browser 2024-01-09 N/A 6.1 MEDIUM
Brave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect. This is related to browser/brave_content_browser_client.cc and browser/ui/webui/brave_web_ui_controller_factory.cc.
CVE-2023-6927 1 Redhat 2 Keycloak, Single Sign-on 2024-01-09 N/A 6.1 MEDIUM
A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security patch implemented to address CVE-2023-6134.
CVE-2023-6524 1 Mappresspro 1 Mappress 2024-01-09 N/A 5.4 MEDIUM
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the map title parameter in all versions up to and including 2.88.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2023-6629 1 Wpexperts 1 Post Smtp 2024-01-09 N/A 6.1 MEDIUM
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ parameter in all versions up to, and including, 2.8.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
CVE-2023-6984 1 Ideabox 1 Powerpack Addons For Elementor 2024-01-09 N/A 4.3 MEDIUM
The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.13. This is due to missing or incorrect nonce validation in the powerpack-lite-for-elementor/classes/class-pp-admin-settings.php file. This makes it possible for unauthenticated attackers to modify and reset plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-2023-7068 1 Webtoffee 1 Woocommerce Pdf Invoices\, Packing Slips\, Delivery Notes And Shipping Labels 2024-01-09 N/A 6.5 MEDIUM
The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on theprint_packinglist action in all versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to export orders which can contain sensitive information.
CVE-2024-0201 1 Webcodingplace 1 Product Expiry For Woocommerce 2024-01-09 N/A 4.3 MEDIUM
The Product Expiry for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_settings' function in versions up to, and including, 2.5. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update plugin settings.
CVE-2023-41779 1 Zte 2 Zxcloud Irai, Zxcloud Irai Firmware 2024-01-09 N/A 5.5 MEDIUM
There is an illegal memory access vulnerability of ZTE's ZXCLOUD iRAI product.When the vulnerability is exploited by an attacker with the common user permission, the physical machine will be crashed.
CVE-2024-21319 2024-01-09 N/A 6.8 MEDIUM
Microsoft Identity Denial of service vulnerability
CVE-2024-20699 2024-01-09 N/A 5.5 MEDIUM
Windows Hyper-V Denial of Service Vulnerability
CVE-2024-20691 2024-01-09 N/A 4.7 MEDIUM
Windows Themes Information Disclosure Vulnerability
CVE-2024-20690 2024-01-09 N/A 6.5 MEDIUM
Windows Nearby Sharing Spoofing Vulnerability
CVE-2024-20680 2024-01-09 N/A 6.5 MEDIUM
Windows Message Queuing Client (MSMQC) Information Disclosure
CVE-2024-20666 2024-01-09 N/A 6.6 MEDIUM
BitLocker Security Feature Bypass Vulnerability
CVE-2024-20660 2024-01-09 N/A 6.5 MEDIUM
Microsoft Message Queuing Information Disclosure Vulnerability
CVE-2024-20655 2024-01-09 N/A 6.6 MEDIUM
Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability
CVE-2023-50093 1 Apiida 1 Api Gateway Manager 2024-01-09 N/A 6.1 MEDIUM
APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection.