CVE-2023-49229

An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in the administration web service allows read-only, unprivileged users to obtain sensitive information about the device configuration.
Max CVSS
0.0
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%

CVE-2023-49228

An issue was discovered in Peplink Balance Two before 8.4.0. Console port authentication uses hard-coded credentials, which allows an attacker with physical access and sufficient knowledge to execute arbitrary commands as root.
Max CVSS
0.0
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%

CVE-2023-49226

An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute feature of the administration console allows users with admin privileges to execute arbitrary commands as root.
Max CVSS
0.0
Published
2023-12-25
Updated
2023-12-26
EPSS
0.04%

CVE-2023-49225

A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in the product. As for the affected products/models/versions, see the information provided by the vendor listed under [References] section or the list under [Product Status] section.
Max CVSS
6.1
Published
2023-12-07
Updated
2023-12-12
EPSS
0.05%

CVE-2023-49216

Usedesk before 1.7.57 allows profile stored XSS.
Max CVSS
5.4
Published
2023-11-23
Updated
2023-11-30
EPSS
0.05%

CVE-2023-49215

Usedesk before 1.7.57 allows filter reflected XSS.
Max CVSS
6.1
Published
2023-11-23
Updated
2023-11-30
EPSS
0.05%

CVE-2023-49214

Usedesk before 1.7.57 allows chat template injection.
Max CVSS
9.8
Published
2023-11-23
Updated
2023-11-30
EPSS
0.09%

CVE-2023-49213

The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests if a param block is used, due to invalid sanitization of input strings. The fixed versions are 3.10.2, 4.1.10, and 4.2.1.
Max CVSS
8.8
Published
2023-11-23
Updated
2023-11-30
EPSS
0.15%

CVE-2023-49210

The openssl (aka node-openssl) NPM package through 2.0.0 was characterized as "a nonsense wrapper with no real purpose" by its author, and accepts an opts argument that contains a verb field (used for command execution). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Max CVSS
9.8
Published
2023-11-23
Updated
2023-11-30
EPSS
0.06%

CVE-2023-49208

scheme/webauthn.c in Glewlwyd SSO server before 2.7.6 has a possible buffer overflow during FIDO2 credentials validation in webauthn registration.
Max CVSS
9.8
Published
2023-11-23
Updated
2023-11-30
EPSS
0.08%

CVE-2023-49197

Cross-Site Request Forgery (CSRF) vulnerability in Apasionados, Apasionados del Marketing, NetConsulting DoFollow Case by Case.This issue affects DoFollow Case by Case: from n/a through 3.4.2.
Max CVSS
8.8
Published
2023-12-15
Updated
2023-12-21
EPSS
0.06%

CVE-2023-49195

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Phillips Nested Pages allows Stored XSS.This issue affects Nested Pages: from n/a through 3.2.6.
Max CVSS
5.9
Published
2023-12-14
Updated
2023-12-18
EPSS
0.05%

CVE-2023-49191

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Supsystic GDPR Cookie Consent by Supsystic allows Stored XSS.This issue affects GDPR Cookie Consent by Supsystic: from n/a through 2.1.2.
Max CVSS
5.9
Published
2023-12-15
Updated
2023-12-21
EPSS
0.05%

CVE-2023-49190

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chandra Shekhar Sahu Site Offline Or Coming Soon Or Maintenance Mode allows Stored XSS.This issue affects Site Offline Or Coming Soon Or Maintenance Mode: from n/a through 1.5.6.
Max CVSS
5.9
Published
2023-12-15
Updated
2023-12-21
EPSS
0.05%

CVE-2023-49189

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Getsocial, S.A. Social Share Buttons & Analytics Plugin – GetSocial.Io allows Stored XSS.This issue affects Social Share Buttons & Analytics Plugin – GetSocial.Io: from n/a through 4.3.12.
Max CVSS
5.9
Published
2023-12-15
Updated
2023-12-21
EPSS
0.05%

CVE-2023-49188

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZealousWeb Track Geolocation Of Users Using Contact Form 7 allows Stored XSS.This issue affects Track Geolocation Of Users Using Contact Form 7: from n/a through 1.4.
Max CVSS
5.9
Published
2023-12-15
Updated
2023-12-19
EPSS
0.05%

CVE-2023-49187

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spoonthemes Adifier - Classified Ads WordPress Theme allows Reflected XSS.This issue affects Adifier - Classified Ads WordPress Theme: from n/a before 3.1.4.
Max CVSS
7.1
Published
2023-12-15
Updated
2023-12-19
EPSS
0.05%

CVE-2023-49185

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Doofinder Doofinder WP & WooCommerce Search allows Reflected XSS.This issue affects Doofinder WP & WooCommerce Search: from n/a through 2.1.7.
Max CVSS
7.1
Published
2023-12-15
Updated
2023-12-19
EPSS
0.05%

CVE-2023-49184

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Parallax Slider Block allows Stored XSS.This issue affects Parallax Slider Block: from n/a through 1.2.4.
Max CVSS
5.9
Published
2023-12-15
Updated
2023-12-19
EPSS
0.05%

CVE-2023-49183

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NextScripts NextScripts: Social Networks Auto-Poster allows Reflected XSS.This issue affects NextScripts: Social Networks Auto-Poster: from n/a through 4.4.2.
Max CVSS
7.1
Published
2023-12-15
Updated
2023-12-19
EPSS
0.05%

CVE-2023-49182

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fabio Marzocca List all posts by Authors, nested Categories and Titles allows Reflected XSS.This issue affects List all posts by Authors, nested Categories and Titles: from n/a through 2.7.10.
Max CVSS
7.1
Published
2023-12-15
Updated
2023-12-19
EPSS
0.05%

CVE-2023-49181

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Event Manager WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce allows Stored XSS.This issue affects WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce: from n/a through 3.1.40.
Max CVSS
5.9
Published
2023-12-15
Updated
2023-12-19
EPSS
0.05%

CVE-2023-49180

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ternstyle LLC Automatic Youtube Video Posts Plugin allows Stored XSS.This issue affects Automatic Youtube Video Posts Plugin: from n/a through 5.2.2.
Max CVSS
5.9
Published
2023-12-15
Updated
2023-12-19
EPSS
0.05%

CVE-2023-49179

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N.O.U.S. Open Useful and Simple Event post allows Stored XSS.This issue affects Event post: from n/a through 5.8.6.
Max CVSS
6.5
Published
2023-12-15
Updated
2023-12-20
EPSS
0.05%

CVE-2023-49178

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mr. Hdwplayer HDW Player Plugin (Video Player & Video Gallery) allows Reflected XSS.This issue affects HDW Player Plugin (Video Player & Video Gallery): from n/a through 5.0.
Max CVSS
7.1
Published
2023-12-15
Updated
2023-12-20
EPSS
0.05%
50 vulnerabilities found
1 2 3 4 5 6 ...... 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 ...... 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50