Vulnerabilities (CVE)

Total 400121 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6082 1 Chartjs Project 1 Chartjs 2026-06-17 N/A 5.4 MEDIUM
The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2023-6081 1 Chartjs Project 1 Chartjs 2026-06-17 N/A 5.4 MEDIUM
The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2023-6080 1 Lakesidesoftware 1 Systrack Lsiagent 2026-06-17 N/A 7.8 HIGH
Lakeside Software’s SysTrack LsiAgent Installer version 10.7.8 for Windows contains a local privilege escalation vulnerability which allows attackers SYSTEM level access.
CVE-2023-6078 1 3ds 1 Biovia Materials Studio 2026-06-17 N/A 8.8 HIGH
An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl script can lead to arbitrary command execution.
CVE-2023-6077 1 Wpfrank 1 Slider Factory Pro 2026-06-17 N/A 6.5 MEDIUM
The Slider WordPress plugin before 3.5.12 does not ensure that posts to be accessed via an AJAX action are slides and can be viewed by the user making the request, allowing any authenticated users, such as subscriber to access the content arbitrary post such as private, draft and password protected
CVE-2023-6076 1 Phpgurukul 1 Restaurant Table Booking System 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
A vulnerability classified as problematic was found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file booking-details.php of the component Reservation Status Handler. The manipulation of the argument bid leads to information disclosure. The attack can be launched remotely. The identifier VDB-244945 was assigned to this vulnerability.
CVE-2023-6075 1 Phpgurukul 1 Restaurant Table Booking System 2026-06-17 4.0 MEDIUM 3.5 LOW
A vulnerability classified as problematic has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file index.php of the component Reservation Request Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-244944.
CVE-2023-6074 1 Phpgurukul 1 Restaurant Table Booking System 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file check-status.php of the component Booking Reservation Handler. The manipulation leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-244943.
CVE-2023-6073 1 Volkswagen 2 Id.3, Id.3 Firmware 2026-06-17 N/A 5.7 MEDIUM
Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls.
CVE-2023-6072 1 Trellix 1 Central Management System 2026-06-17 N/A 4.6 MEDIUM
A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authenticated attacker to craft CM dashboard internal requests causing arbitrary content to be injected into the response when accessing the CM dashboard.
CVE-2023-6071 1 Trellix 1 Enterprise Security Manager 2026-06-17 N/A 8.4 HIGH
An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administrator to execute arbitrary code as root on the ESM. This is possible as the input isn't correctly sanitized when adding a new data source.
CVE-2023-6070 1 Trellix 1 Enterprise Security Manager 2026-06-17 N/A 4.3 MEDIUM
A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where the API accepts uploaded content and doesn't parse for invalid data
CVE-2023-6069 1 Froxlor 1 Froxlor 2026-06-17 N/A 9.9 CRITICAL
Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0.
CVE-2023-6068 1 Arista 12 7130-32lb, 7130-32lba, 7130-48eh and 9 more 2026-06-17 N/A 3.1 LOW
On affected 7130 Series FPGA platforms running MOS and recent versions of the MultiAccess FPGA, application of ACL’s may result in incorrect operation of the configured ACL for a port resulting in some packets that should be denied being permitted and some
CVE-2023-6067 1 Wpeventsmanager 1 User Profile Avatar 2026-06-17 N/A 5.4 MEDIUM
The WP User Profile Avatar WordPress plugin through 1.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
CVE-2023-6066 1 Kishorkhambu 1 Wp Custom Widget Area 2026-06-17 N/A 4.3 MEDIUM
The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of its AJAX action callback functions, which could allow attackers with subscriber+ privilege to create, delete or modify menus on the site.
CVE-2023-6065 1 Quttera 1 Quttera Web Malware Scanner 2026-06-17 N/A 5.3 MEDIUM
The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which allows a malicious actor to discover local paths and portions of the site's code
CVE-2023-6064 1 Payhere 1 Payhere Payment Gateway 2026-06-17 N/A 7.5 HIGH
The PayHere Payment Gateway WordPress plugin before 2.2.12 automatically creates publicly-accessible log files containing sensitive information when transactions occur.
CVE-2023-6063 1 Wpfastestcache 1 Wp Fastest Cache 2026-06-17 N/A 7.5 HIGH
The WP Fastest Cache WordPress plugin before 1.2.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
CVE-2023-6062 1 Tenable 1 Nessus 2026-06-17 N/A 6.8 MEDIUM
An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus Rules variables to overwrite arbitrary files on the remote host, which could lead to a denial of service condition.