Latest CVE Feed
-
6.1
MEDIUMCVE-2023-7194
The Meris WordPress theme through 1.1.2 does not sanitise and escape some parameters before outputting them back in the page, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : meris_wp_theme- EPSS Score: %0.12
- Published: Jan. 22, 2024
- Modified: May. 30, 2025
-
6.1
MEDIUMCVE-2023-7170
The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : rsvp_events- EPSS Score: %0.12
- Published: Jan. 22, 2024
- Modified: May. 30, 2025
-
7.2
HIGHCVE-2023-7063
The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and including, 1.8.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthent... Read more
Affected Products : wpforms- EPSS Score: %1.27
- Published: Jan. 20, 2024
- Modified: May. 30, 2025
-
4.8
MEDIUMCVE-2023-6626
The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability... Read more
- EPSS Score: %0.07
- Published: Jan. 22, 2024
- Modified: May. 30, 2025
-
7.5
HIGHCVE-2023-52353
An issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is mishandled. For example, if the last connection negotiated TLS 1.2, then 1.2 becomes the new maximum.... Read more
Affected Products : mbed_tls- EPSS Score: %0.06
- Published: Jan. 21, 2024
- Modified: May. 30, 2025
-
6.1
MEDIUMCVE-2023-52328
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not ... Read more
Affected Products : apex_central- EPSS Score: %0.58
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2023-52324
An unrestricted file upload vulnerability in Trend Micro Apex Central could allow a remote attacker to create arbitrary files on affected installations. Please note: although authentication is required to exploit this vulnerability, this vulnerability ... Read more
Affected Products : apex_central- EPSS Score: %3.86
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
4.8
MEDIUMCVE-2023-52046
Cross Site Scripting vulnerability (XSS) in webmin v.2.105 and earlier allows a remote attacker to execute arbitrary code via a crafted payload to the "Execute cron job as" tab Input field.... Read more
- EPSS Score: %0.04
- Published: Jan. 25, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2023-52039
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.... Read more
- EPSS Score: %0.12
- Published: Jan. 24, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2023-52038
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.... Read more
- EPSS Score: %0.12
- Published: Jan. 24, 2024
- Modified: May. 30, 2025
-
7.5
HIGHCVE-2023-51926
YonBIP v3_23.05 was discovered to contain an arbitrary file read vulnerability via the nc.bs.framework.comn.serv.CommonServletDispatcher component.... Read more
Affected Products : yonbip- EPSS Score: %0.25
- Published: Jan. 20, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2023-51892
An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to the FrameworkShellController component.... Read more
Affected Products : e-cology- EPSS Score: %2.87
- Published: Jan. 20, 2024
- Modified: May. 30, 2025
-
7.5
HIGHCVE-2023-51886
Buffer Overflow vulnerability in the main() function in Mathtex 1.05 and before allows a remote attacker to cause a denial of service when using \convertpath.... Read more
Affected Products : mathtex- EPSS Score: %0.67
- Published: Jan. 24, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2023-51885
Buffer Overflow vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via the length of the LaTeX string component.... Read more
Affected Products : mathtex- EPSS Score: %2.95
- Published: Jan. 24, 2024
- Modified: May. 30, 2025
-
7.5
HIGHCVE-2023-50943
Apache Airflow, versions before 2.8.1, have a vulnerability that allows a potential attacker to poison the XCom data by bypassing the protection of "enable_xcom_pickling=False" configuration setting resulting in poisoned data after XCom deserialization. T... Read more
Affected Products : airflow- EPSS Score: %0.19
- Published: Jan. 24, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2023-50693
An issue in Jester v.0.6.0 and before allows a remote attacker to send a malicious crafted request.... Read more
Affected Products : jester- EPSS Score: %1.17
- Published: Jan. 19, 2024
- Modified: May. 30, 2025
-
7.8
HIGHCVE-2023-50274
HPE OneView may allow command injection with local privilege escalation.... Read more
Affected Products : oneview- EPSS Score: %0.28
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2023-47352
Technicolor TC8715D devices have predictable default WPA2 security passwords. An attacker who scans for SSID and BSSID values may be able to predict these passwords.... Read more
- EPSS Score: %0.05
- Published: Jan. 22, 2024
- Modified: May. 30, 2025
-
7.8
HIGHCVE-2023-47200
A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged... Read more
Affected Products : apex_one- EPSS Score: %0.03
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
7.8
HIGHCVE-2023-47199
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the ta... Read more
Affected Products : apex_one- EPSS Score: %0.03
- Published: Jan. 23, 2024
- Modified: May. 30, 2025