CVE-2023-51386

Sandbox Accounts for Events provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Authenticated users could potentially read data from the events table by sending request payloads to the events API, collecting information on planned events, timeframes, budgets and owner email addresses. This data access may allow users to get insights into upcoming events and join events which they have not been invited to. This issue has been patched in version 1.10.0.
Max CVSS
7.8
Published
2023-12-22
Updated
2023-12-25
EPSS
0.04%

CVE-2023-51385

In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.
Max CVSS
9.8
Published
2023-12-18
Updated
2023-12-28
EPSS
0.16%

CVE-2023-51384

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.
Max CVSS
5.5
Published
2023-12-18
Updated
2023-12-22
EPSS
0.05%

CVE-2023-51380

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed issue comments to be read with an improperly scoped token. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.17.19, 3.8.12, 3.9.7, 3.10.4, and 3.11.1.
Max CVSS
4.3
Published
2023-12-21
Updated
2023-12-29
EPSS
0.06%

CVE-2023-51379

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed issue comments to be updated with an improperly scoped token. This vulnerability did not allow unauthorized access to any repository content as it also required contents:write and issues:read permissions. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.17.19, 3.8.12, 3.9.7, 3.10.4, and 3.11.1.
Max CVSS
4.9
Published
2023-12-21
Updated
2023-12-29
EPSS
0.06%

CVE-2023-51378

Cross-Site Request Forgery (CSRF) vulnerability in Rise Themes Rise Blocks – A Complete Gutenberg Page Builder.This issue affects Rise Blocks – A Complete Gutenberg Page Builder: from n/a through 3.1.
Max CVSS
5.4
Published
2023-12-29
Updated
2023-12-29
EPSS
0.04%

CVE-2023-51374

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZeroBounce ZeroBounce Email Verification & Validation allows Stored XSS.This issue affects ZeroBounce Email Verification & Validation: from n/a through 1.0.11.
Max CVSS
5.9
Published
2023-12-29
Updated
2023-12-29
EPSS
0.04%

CVE-2023-51373

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ian Kennerley Google Photos Gallery with Shortcodes allows Reflected XSS.This issue affects Google Photos Gallery with Shortcodes: from n/a through 4.0.2.
Max CVSS
7.1
Published
2023-12-29
Updated
2023-12-29
EPSS
0.04%

CVE-2023-51372

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HashBar – WordPress Notification Bar allows Stored XSS.This issue affects HashBar – WordPress Notification Bar: from n/a through 1.4.1.
Max CVSS
5.9
Published
2023-12-29
Updated
2023-12-29
EPSS
0.04%

CVE-2023-51371

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bit Assist Chat Widget: WhatsApp Chat, Facebook Messenger Chat, Telegram Chat Bubble, Line Messenger, Live Chat Support Chat Button, WeChat, SMS, Call Button, Customer Support Button with floating Chat Widget allows Stored XSS.This issue affects Chat Widget: WhatsApp Chat, Facebook Messenger Chat, Telegram Chat Bubble, Line Messenger, Live Chat Support Chat Button, WeChat, SMS, Call Button, Customer Support Button with floating Chat Widget: from n/a through 1.1.9.
Max CVSS
5.9
Published
2023-12-29
Updated
2023-12-29
EPSS
0.04%

CVE-2023-51363

VR-S1000 firmware Ver. 2.37 and earlier allows a network-adjacent unauthenticated attacker who can access the product's web management page to obtain sensitive information.
Max CVSS
0.0
Published
2023-12-26
Updated
2023-12-26
EPSS
0.04%

CVE-2023-51361

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ginger Plugins Sticky Chat Widget: Click to chat, SMS, Email, Messages, Call Button, Live Chat and Live Support Button allows Stored XSS.This issue affects Sticky Chat Widget: Click to chat, SMS, Email, Messages, Call Button, Live Chat and Live Support Button: from n/a through 1.1.8.
Max CVSS
5.9
Published
2023-12-29
Updated
2023-12-29
EPSS
0.04%

CVE-2023-51358

Cross-Site Request Forgery (CSRF) vulnerability in Bright Plugins Block IPs for Gravity Forms.This issue affects Block IPs for Gravity Forms: from n/a through 1.0.1.
Max CVSS
5.4
Published
2023-12-29
Updated
2023-12-29
EPSS
0.04%

CVE-2023-51354

Cross-Site Request Forgery (CSRF) vulnerability in WebbaPlugins Appointment & Event Booking Calendar Plugin – Webba Booking.This issue affects Appointment & Event Booking Calendar Plugin – Webba Booking: from n/a through 4.5.33.
Max CVSS
4.3
Published
2023-12-29
Updated
2023-12-29
EPSS
0.04%

CVE-2023-51136

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formRebootSchedule.
Max CVSS
0.0
Published
2023-12-30
Updated
2024-01-01
EPSS
0.06%

CVE-2023-51135

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formPasswordSetup.
Max CVSS
0.0
Published
2023-12-30
Updated
2024-01-01
EPSS
0.06%

CVE-2023-51133

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formRoute.
Max CVSS
0.0
Published
2023-12-30
Updated
2024-01-01
EPSS
0.06%

CVE-2023-51107

A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in functon compute_color() of jquant2.c.
Max CVSS
0.0
Published
2023-12-26
Updated
2023-12-26
EPSS
0.04%

CVE-2023-51106

A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in functon pnm_binary_read_image() of load-pnm.c.
Max CVSS
0.0
Published
2023-12-26
Updated
2023-12-26
EPSS
0.04%

CVE-2023-51105

A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in function bmp_decompress_rle4() of load-bmp.c.
Max CVSS
0.0
Published
2023-12-26
Updated
2023-12-26
EPSS
0.04%

CVE-2023-51104

A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in functon pnm_binary_read_image() of load-pnm.c line 527.
Max CVSS
0.0
Published
2023-12-26
Updated
2023-12-26
EPSS
0.04%

CVE-2023-51103

A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in functon fz_new_pixmap_from_float_data() of pixmap.c.
Max CVSS
0.0
Published
2023-12-26
Updated
2023-12-26
EPSS
0.04%

CVE-2023-51102

Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formWifiMacFilterSet.
Max CVSS
9.8
Published
2023-12-26
Updated
2023-12-30
EPSS
0.09%

CVE-2023-51101

Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formSetUplinkInfo.
Max CVSS
9.8
Published
2023-12-26
Updated
2023-12-30
EPSS
0.09%

CVE-2023-51100

Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formGetDiagnoseInfo .
Max CVSS
9.8
Published
2023-12-26
Updated
2023-12-30
EPSS
0.13%
50 vulnerabilities found
1 2 3 4 5 6 7 8 9 10 11 ...... 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50