Security Vulnerabilities, CVEs
CVE-2023-49229
An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in the administration web service allows read-only, unprivileged users to obtain sensitive information about the device configuration.
Max CVSS
0.0
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-49228
An issue was discovered in Peplink Balance Two before 8.4.0. Console port authentication uses hard-coded credentials, which allows an attacker with physical access and sufficient knowledge to execute arbitrary commands as root.
Max CVSS
0.0
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%
CVE-2023-49226
An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute feature of the administration console allows users with admin privileges to execute arbitrary commands as root.
Max CVSS
0.0
Published
2023-12-25
Updated
2023-12-26
EPSS
0.04%
CVE-2023-49225
A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in the product. As for the affected products/models/versions, see the information provided by the vendor listed under [References] section or the list under [Product Status] section.
Max CVSS
6.1
Published
2023-12-07
Updated
2023-12-12
EPSS
0.05%
CVE-2023-49216
Usedesk before 1.7.57 allows profile stored XSS.
Max CVSS
5.4
Published
2023-11-23
Updated
2023-11-30
EPSS
0.05%
CVE-2023-49215
Usedesk before 1.7.57 allows filter reflected XSS.
Max CVSS
6.1
Published
2023-11-23
Updated
2023-11-30
EPSS
0.05%
CVE-2023-49214
Usedesk before 1.7.57 allows chat template injection.
Max CVSS
9.8
Published
2023-11-23
Updated
2023-11-30
EPSS
0.09%
CVE-2023-49213
The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests if a param block is used, due to invalid sanitization of input strings. The fixed versions are 3.10.2, 4.1.10, and 4.2.1.
Max CVSS
8.8
Published
2023-11-23
Updated
2023-11-30
EPSS
0.15%
CVE-2023-49210
The openssl (aka node-openssl) NPM package through 2.0.0 was characterized as "a nonsense wrapper with no real purpose" by its author, and accepts an opts argument that contains a verb field (used for command execution). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Max CVSS
9.8
Published
2023-11-23
Updated
2023-11-30
EPSS
0.06%
CVE-2023-49208
scheme/webauthn.c in Glewlwyd SSO server before 2.7.6 has a possible buffer overflow during FIDO2 credentials validation in webauthn registration.
Max CVSS
9.8
Published
2023-11-23
Updated
2023-11-30
EPSS
0.08%
CVE-2023-49197
Cross-Site Request Forgery (CSRF) vulnerability in Apasionados, Apasionados del Marketing, NetConsulting DoFollow Case by Case.This issue affects DoFollow Case by Case: from n/a through 3.4.2.
Max CVSS
8.8
Published
2023-12-15
Updated
2023-12-21
EPSS
0.06%
CVE-2023-49195
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Phillips Nested Pages allows Stored XSS.This issue affects Nested Pages: from n/a through 3.2.6.
Max CVSS
5.9
Published
2023-12-14
Updated
2023-12-18
EPSS
0.05%
CVE-2023-49191
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Supsystic GDPR Cookie Consent by Supsystic allows Stored XSS.This issue affects GDPR Cookie Consent by Supsystic: from n/a through 2.1.2.
Max CVSS
5.9
Published
2023-12-15
Updated
2023-12-21
EPSS
0.05%
CVE-2023-49190
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chandra Shekhar Sahu Site Offline Or Coming Soon Or Maintenance Mode allows Stored XSS.This issue affects Site Offline Or Coming Soon Or Maintenance Mode: from n/a through 1.5.6.
Max CVSS
5.9
Published
2023-12-15
Updated
2023-12-21
EPSS
0.05%
CVE-2023-49189
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Getsocial, S.A. Social Share Buttons & Analytics Plugin – GetSocial.Io allows Stored XSS.This issue affects Social Share Buttons & Analytics Plugin – GetSocial.Io: from n/a through 4.3.12.
Max CVSS
5.9
Published
2023-12-15
Updated
2023-12-21
EPSS
0.05%
CVE-2023-49188
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZealousWeb Track Geolocation Of Users Using Contact Form 7 allows Stored XSS.This issue affects Track Geolocation Of Users Using Contact Form 7: from n/a through 1.4.
Max CVSS
5.9
Published
2023-12-15
Updated
2023-12-19
EPSS
0.05%
CVE-2023-49187
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spoonthemes Adifier - Classified Ads WordPress Theme allows Reflected XSS.This issue affects Adifier - Classified Ads WordPress Theme: from n/a before 3.1.4.
Max CVSS
7.1
Published
2023-12-15
Updated
2023-12-19
EPSS
0.05%
CVE-2023-49185
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Doofinder Doofinder WP & WooCommerce Search allows Reflected XSS.This issue affects Doofinder WP & WooCommerce Search: from n/a through 2.1.7.
Max CVSS
7.1
Published
2023-12-15
Updated
2023-12-19
EPSS
0.05%
CVE-2023-49184
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Parallax Slider Block allows Stored XSS.This issue affects Parallax Slider Block: from n/a through 1.2.4.
Max CVSS
5.9
Published
2023-12-15
Updated
2023-12-19
EPSS
0.05%
CVE-2023-49183
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NextScripts NextScripts: Social Networks Auto-Poster allows Reflected XSS.This issue affects NextScripts: Social Networks Auto-Poster: from n/a through 4.4.2.
Max CVSS
7.1
Published
2023-12-15
Updated
2023-12-19
EPSS
0.05%
CVE-2023-49182
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fabio Marzocca List all posts by Authors, nested Categories and Titles allows Reflected XSS.This issue affects List all posts by Authors, nested Categories and Titles: from n/a through 2.7.10.
Max CVSS
7.1
Published
2023-12-15
Updated
2023-12-19
EPSS
0.05%
CVE-2023-49181
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Event Manager WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce allows Stored XSS.This issue affects WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce: from n/a through 3.1.40.
Max CVSS
5.9
Published
2023-12-15
Updated
2023-12-19
EPSS
0.05%
CVE-2023-49180
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ternstyle LLC Automatic Youtube Video Posts Plugin allows Stored XSS.This issue affects Automatic Youtube Video Posts Plugin: from n/a through 5.2.2.
Max CVSS
5.9
Published
2023-12-15
Updated
2023-12-19
EPSS
0.05%
CVE-2023-49179
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N.O.U.S. Open Useful and Simple Event post allows Stored XSS.This issue affects Event post: from n/a through 5.8.6.
Max CVSS
6.5
Published
2023-12-15
Updated
2023-12-20
EPSS
0.05%
CVE-2023-49178
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mr. Hdwplayer HDW Player Plugin (Video Player & Video Gallery) allows Reflected XSS.This issue affects HDW Player Plugin (Video Player & Video Gallery): from n/a through 5.0.
Max CVSS
7.1
Published
2023-12-15
Updated
2023-12-20
EPSS
0.05%