Vulnerabilities (CVE)

Total 399121 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6029 1 Spider-themes 1 Eazydocs 2026-06-17 N/A 7.5 HIGH
The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing unauthenticated users to delete arbitrary posts, as well as add and delete documents/sections.
CVE-2023-6028 1 Br-automation 1 Automation Runtime 2026-06-17 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics Manager of B&R Automation Runtime versions <= G4.93 that enables a remote attacker to execute arbitrary JavaScript code in the context of the attacked user’s browser session.
CVE-2023-6027 1 Elijaa 1 Phpmemcachedadmin 2026-06-17 N/A 6.1 MEDIUM
A critical flaw has been identified in elijaa/phpmemcachedadmin affecting version 1.3.0, specifically related to a stored XSS vulnerability. This vulnerability allows malicious actors to insert a carefully crafted JavaScript payload. The issue arises from improper encoding of user-controlled entries in the "/pmcadmin/configure.php" parameter.
CVE-2023-6026 1 Elijaa 1 Phpmemcachedadmin 2026-06-17 N/A 9.8 CRITICAL
A Path traversal vulnerability has been reported in elijaa/phpmemcachedadmin affecting version 1.3.0. This vulnerability allows an attacker to delete files stored on the server due to lack of proper verification of user-supplied input.
CVE-2023-6023 1 Vertaai 1 Modeldb 2026-06-17 N/A 7.5 HIGH
An attacker can read any file on the filesystem on the server hosting ModelDB through an LFI in the artifact_path URL parameter.
CVE-2023-6022 1 Prefect 1 Prefect 2026-06-17 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) in GitHub repository prefecthq/prefect prior to 2.16.5.
CVE-2023-6021 1 Ray Project 1 Ray 2026-06-17 N/A 7.5 HIGH
LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-2023-48022-cve-2023-48023
CVE-2023-6020 1 Ray Project 1 Ray 2026-06-17 N/A 7.5 HIGH
LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication.
CVE-2023-6019 1 Ray Project 1 Ray 2026-06-17 N/A 9.8 CRITICAL
A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remotely without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-2023-48022-cve-2023-48023
CVE-2023-6018 1 Lfprojects 1 Mlflow 2026-06-17 N/A 9.8 CRITICAL
An attacker can overwrite any file on the server hosting MLflow without any authentication.
CVE-2023-6017 1 H2o 1 H2o 2026-06-17 N/A 7.1 HIGH
H2O included a reference to an S3 bucket that no longer existed allowing an attacker to take over the S3 bucket URL.
CVE-2023-6016 1 H2o 1 H2o 2026-06-17 N/A 9.8 CRITICAL
An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature.
CVE-2023-6015 1 Lfprojects 1 Mlflow 2026-06-17 N/A 7.5 HIGH
MLflow allowed arbitrary files to be PUT onto the server.
CVE-2023-6014 1 Lfprojects 1 Mlflow 2026-06-17 N/A 9.8 CRITICAL
An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.
CVE-2023-6013 1 H2o 1 H2o 2026-06-17 N/A 5.4 MEDIUM
H2O is vulnerable to stored XSS vulnerability which can lead to a Local File Include attack.
CVE-2023-6012 1 Lanaccess 1 Onsafe Monitorhm 2026-06-17 N/A 8.3 HIGH
An improper input validation vulnerability has been found in Lanaccess ONSAFE MonitorHM affecting version 3.7.0. This vulnerability could lead a remote attacker to exploit the checkbox element and perform remote code execution, compromising the entire infrastructure.
CVE-2023-6011 1 Dece 1 Geodi 2026-06-17 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DECE Software Geodi allows Stored XSS. This issue affects Geodi: before 8.0.0.27396.
CVE-2023-6009 1 Userproplugin 1 Userpro 2026-06-17 N/A 8.8 HIGH
The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to insufficient restriction on the 'userpro_update_user_profile' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_capabilities' parameter during a profile update.
CVE-2023-6008 1 Userproplugin 1 Userpro 2026-06-17 N/A 6.3 MEDIUM
The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to add, modify, or delete user meta and plugin options.
CVE-2023-6007 1 Userproplugin 1 Userpro 2026-06-17 N/A 7.3 HIGH
The UserPro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 5.1.1. This makes it possible for unauthenticated attackers to add, modify, or delete user meta and plugin options.