| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-40205 | Hig | 0.46 | 7.1 | 0.00 | Sep 4, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Pixelgrade PixTypes plugin <= 1.4.15 versions. | ||
| CVE-2023-40196 | Hig | 0.46 | 7.1 | 0.00 | Sep 4, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ImageRecycle ImageRecycle pdf & image compression plugin <= 3.1.11 versions. | ||
| CVE-2023-32296 | Hig | 0.46 | 7.1 | 0.00 | Sep 4, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kangu para WooCommerce plugin <= 2.2.9 versions. | ||
| CVE-2023-30485 | Hig | 0.46 | 7.1 | 0.00 | Sep 4, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Solwin Infotech Responsive WordPress Slider – Avartan Slider Lite plugin <= 1.5.3 versions. | ||
| CVE-2023-4616 | Hig | 0.49 | 7.5 | 0.01 | Sep 4, 2023 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/thumbnail endpoint. The issue results from the lack… | ||
| CVE-2023-4615 | Hig | 0.49 | 7.5 | 0.01 | Sep 4, 2023 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/download/updateFile endpoint. The issue results from… | ||
| CVE-2023-40208 | Hig | 0.46 | 7.1 | 0.01 | Sep 4, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Aleksandar Urošević Stock Ticker plugin <= 3.23.3 versions. | ||
| CVE-2023-39992 | Hig | 0.46 | 7.1 | 0.00 | Sep 4, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in vCita.Com Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.3.2 versions. | ||
| CVE-2023-39991 | Hig | 0.46 | 7.1 | 0.00 | Sep 4, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blindside Networks BigBlueButton plugin <= 3.0.0-beta.4 versions. | ||
| CVE-2023-39918 | Hig | 0.46 | 7.1 | 0.00 | Sep 4, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in SAASPROJECT Booking Package Booking Package plugin <= 1.6.01 versions. | ||
| CVE-2023-37393 | Hig | 0.46 | 7.1 | 0.00 | Sep 4, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Atarim Visual Website Collaboration, Feedback & Project Management – Atarim plugin <= 3.9.3 versions. | ||
| CVE-2023-31220 | Hig | 0.46 | 7.1 | 0.00 | Sep 4, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP-EXPERTS.IN TEAM WP Categories Widget plugin <= 2.2 versions. | ||
| CVE-2023-30494 | Hig | 0.46 | 7.1 | 0.00 | Sep 4, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ImageRecycle ImageRecycle pdf & image compression plugin <= 3.1.10 versions. | ||
| CVE-2023-39164 | Hig | 0.46 | 7.1 | 0.00 | Sep 4, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Molongui Author Box for Authors, Co-Authors, Multiple Authors and Guest Authors – Molongui plugin <= 4.6.19 versions. | ||
| CVE-2023-39162 | Hig | 0.46 | 7.1 | 0.00 | Sep 4, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in XLPlugins User Email Verification for WooCommerce plugin <= 3.5.0 versions. | ||
| CVE-2023-20820 | Hig | 0.47 | 7.2 | 0.01 | Sep 4, 2023 | In wlan service, there is a possible command injection due to improper input validation. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00244189; Issue ID: WCNCR00244189. | ||
| CVE-2023-38464 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38460 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38459 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38458 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38456 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38455 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38453 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38452 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38451 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38450 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38449 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38444 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38443 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-33915 | Hig | 0.49 | 7.5 | 0.00 | Sep 4, 2023 | In LTE protocol stack, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed | ||
| CVE-2023-33914 | Hig | 0.49 | 7.5 | 0.00 | Sep 4, 2023 | In NIA0 algorithm in Security Mode Command, there is a possible missing verification incorrect input. This could lead to remote information disclosure no additional execution privileges needed | ||
| CVE-2023-4746 | Hig | 0.57 | 8.8 | 0.03 | Sep 4, 2023 | A vulnerability classified as critical has been found in TOTOLINK N200RE V5 9.3.5u.6437_B20230519. This affects the function Validity_check. The manipulation leads to format string. It is possible to initiate the attack remotely. The root-cause of the vulnerability is a format… | ||
| CVE-2023-4751 | Hig | 0.00 | 7.8 | 0.01 | Sep 3, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331. | ||
| CVE-2023-39374 | Hig | 0.51 | 7.8 | 0.00 | Sep 3, 2023 | ForeScout NAC SecureConnector version 11.2 - CWE-427: Uncontrolled Search Path Element | ||
| CVE-2023-39373 | Hig | 0.48 | 7.4 | 0.00 | Sep 3, 2023 | A Hyundai model (2017) - CWE-294: Authentication Bypass by Capture-replay. | ||
| CVE-2023-39372 | Hig | 0.53 | 8.1 | 0.00 | Sep 3, 2023 | StarTrinity Softswitch version 2023-02-16 - Multiple CSRF (CWE-352) | ||
| CVE-2023-39371 | Hig | 0.57 | 8.8 | 0.00 | Sep 3, 2023 | StarTrinity Softswitch version 2023-02-16 - Open Redirect (CWE-601) | ||
| CVE-2023-39370 | Hig | 0.57 | 8.8 | 0.00 | Sep 3, 2023 | StarTrinity Softswitch version 2023-02-16 - Persistent XSS (CWE-79) | ||
| CVE-2023-39369 | Hig | 0.57 | 8.8 | 0.00 | Sep 3, 2023 | StarTrinity Softswitch version 2023-02-16 - Multiple Reflected XSS (CWE-79) | ||
| CVE-2023-37221 | Hig | 0.57 | 8.8 | 0.00 | Sep 3, 2023 | 7Twenty BOT - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). | ||
| CVE-2023-37220 | Hig | 0.47 | 7.2 | 0.00 | Sep 3, 2023 | Synel Terminals - CWE-494: Download of Code Without Integrity Check | ||
| CVE-2023-4738 | Hig | 0.00 | 7.8 | 0.01 | Sep 2, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848. | ||
| CVE-2023-4736 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2023 | Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833. | ||
| CVE-2023-4735 | Hig | 0.51 | 7.8 | 0.01 | Sep 2, 2023 | Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847. | ||
| CVE-2023-4734 | Hig | 0.51 | 7.8 | 0.01 | Sep 2, 2023 | Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846. | ||
| CVE-2023-39982 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2023 | A vulnerability has been identified in MXsecurity versions prior to v1.0.1. The vulnerability may put the confidentiality and integrity of SSH communications at risk on the affected device. This vulnerability is attributed to a hard-coded SSH host key, which might facilitate… | ||
| CVE-2023-39981 | Hig | 0.49 | 7.5 | 0.01 | Sep 2, 2023 | A vulnerability that allows for unauthorized access has been discovered in MXsecurity versions prior to v1.0.1. This vulnerability arises from inadequate authentication measures, potentially leading to the disclosure of device information by a remote attacker. | ||
| CVE-2023-39980 | Hig | 0.46 | 7.1 | 0.01 | Sep 2, 2023 | A vulnerability that allows the unauthorized disclosure of authenticated information has been identified in MXsecurity versions prior to v1.0.1. This vulnerability arises when special elements are not neutralized correctly, allowing remote attackers to alter SQL commands. | ||
| CVE-2023-3297 | Hig | 0.53 | 8.1 | 0.00 | Sep 1, 2023 | In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process. | ||
| CVE-2023-41049 | Hig | 0.42 | 7.5 | 0.00 | Sep 1, 2023 | @dcl/single-sign-on-client is an open source npm library which deals with single sign on authentication flows. Improper input validation in the `init` function allows arbitrary javascript to be executed using the `javascript:` prefix. This vulnerability has been patched on… |
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Pixelgrade PixTypes plugin <= 1.4.15 versions.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ImageRecycle ImageRecycle pdf & image compression plugin <= 3.1.11 versions.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kangu para WooCommerce plugin <= 2.2.9 versions.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Solwin Infotech Responsive WordPress Slider – Avartan Slider Lite plugin <= 1.5.3 versions.
- risk 0.49cvss 7.5epss 0.01
This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/thumbnail endpoint. The issue results from the lack…
- risk 0.49cvss 7.5epss 0.01
This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/download/updateFile endpoint. The issue results from…
- risk 0.46cvss 7.1epss 0.01
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Aleksandar Urošević Stock Ticker plugin <= 3.23.3 versions.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in vCita.Com Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.3.2 versions.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blindside Networks BigBlueButton plugin <= 3.0.0-beta.4 versions.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in SAASPROJECT Booking Package Booking Package plugin <= 1.6.01 versions.
- risk 0.46cvss 7.1epss 0.00
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Atarim Visual Website Collaboration, Feedback & Project Management – Atarim plugin <= 3.9.3 versions.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP-EXPERTS.IN TEAM WP Categories Widget plugin <= 2.2 versions.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ImageRecycle ImageRecycle pdf & image compression plugin <= 3.1.10 versions.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Molongui Author Box for Authors, Co-Authors, Multiple Authors and Guest Authors – Molongui plugin <= 4.6.19 versions.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in XLPlugins User Email Verification for WooCommerce plugin <= 3.5.0 versions.
- risk 0.47cvss 7.2epss 0.01
In wlan service, there is a possible command injection due to improper input validation. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00244189; Issue ID: WCNCR00244189.
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.49cvss 7.5epss 0.00
In LTE protocol stack, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed
- risk 0.49cvss 7.5epss 0.00
In NIA0 algorithm in Security Mode Command, there is a possible missing verification incorrect input. This could lead to remote information disclosure no additional execution privileges needed
- risk 0.57cvss 8.8epss 0.03
A vulnerability classified as critical has been found in TOTOLINK N200RE V5 9.3.5u.6437_B20230519. This affects the function Validity_check. The manipulation leads to format string. It is possible to initiate the attack remotely. The root-cause of the vulnerability is a format…
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.
- risk 0.51cvss 7.8epss 0.00
ForeScout NAC SecureConnector version 11.2 - CWE-427: Uncontrolled Search Path Element
- risk 0.48cvss 7.4epss 0.00
A Hyundai model (2017) - CWE-294: Authentication Bypass by Capture-replay.
- risk 0.53cvss 8.1epss 0.00
StarTrinity Softswitch version 2023-02-16 - Multiple CSRF (CWE-352)
- risk 0.57cvss 8.8epss 0.00
StarTrinity Softswitch version 2023-02-16 - Open Redirect (CWE-601)
- risk 0.57cvss 8.8epss 0.00
StarTrinity Softswitch version 2023-02-16 - Persistent XSS (CWE-79)
- risk 0.57cvss 8.8epss 0.00
StarTrinity Softswitch version 2023-02-16 - Multiple Reflected XSS (CWE-79)
- risk 0.57cvss 8.8epss 0.00
7Twenty BOT - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
- risk 0.47cvss 7.2epss 0.00
Synel Terminals - CWE-494: Download of Code Without Integrity Check
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.
- risk 0.51cvss 7.8epss 0.00
Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.
- risk 0.51cvss 7.8epss 0.01
Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.
- risk 0.51cvss 7.8epss 0.01
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.
- risk 0.49cvss 7.5epss 0.00
A vulnerability has been identified in MXsecurity versions prior to v1.0.1. The vulnerability may put the confidentiality and integrity of SSH communications at risk on the affected device. This vulnerability is attributed to a hard-coded SSH host key, which might facilitate…
- risk 0.49cvss 7.5epss 0.01
A vulnerability that allows for unauthorized access has been discovered in MXsecurity versions prior to v1.0.1. This vulnerability arises from inadequate authentication measures, potentially leading to the disclosure of device information by a remote attacker.
- risk 0.46cvss 7.1epss 0.01
A vulnerability that allows the unauthorized disclosure of authenticated information has been identified in MXsecurity versions prior to v1.0.1. This vulnerability arises when special elements are not neutralized correctly, allowing remote attackers to alter SQL commands.
- risk 0.53cvss 8.1epss 0.00
In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process.
- risk 0.42cvss 7.5epss 0.00
@dcl/single-sign-on-client is an open source npm library which deals with single sign on authentication flows. Improper input validation in the `init` function allows arbitrary javascript to be executed using the `javascript:` prefix. This vulnerability has been patched on…