Vulnerabilities (CVE)

Total 400203 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-5357 1 Ink361 1 Instagram For Wordpress 2026-06-17 N/A 6.4 MEDIUM
The Instagram for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2023-5356 1 Gitlab 1 Gitlab 2026-06-17 N/A 7.3 HIGH
Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user.
CVE-2023-5355 1 Getawesomesupport 1 Awesome Support 2026-06-17 N/A 8.1 HIGH
The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server.
CVE-2023-5354 1 Getawesomesupport 1 Awesome Support 2026-06-17 N/A 6.1 MEDIUM
The Awesome Support WordPress plugin before 6.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2023-5353 1 Salesagility 1 Suitecrm 2026-06-17 N/A 6.5 MEDIUM
Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.
CVE-2023-5352 1 Getawesomesupport 1 Awesome Support 2026-06-17 N/A 4.3 MEDIUM
The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing users to edit posts for which they do not have permission.
CVE-2023-5351 1 Salesagility 1 Suitecrm 2026-06-17 N/A 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1.
CVE-2023-5350 1 Salesagility 1 Suitecrm 2026-06-17 N/A 9.1 CRITICAL
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.
CVE-2023-5349 2 Fedoraproject, Rmagick 2 Fedora, Rmagick 2026-06-17 N/A 5.3 MEDIUM
A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick. This issue can lead to a denial of service (DOS) by memory exhaustion.
CVE-2023-5348 1 Multivendorx 1 Product Catalog Mode For Woocommerce 2026-06-17 N/A 6.1 MEDIUM
The Product Catalog Mode For WooCommerce WordPress plugin before 5.0.3 does not properly authorize settings updates or escape settings values, leading to stored XSS by unauthenticated users.
CVE-2023-5347 1 Korenix 84 Jetnet 4508, Jetnet 4508-w, Jetnet 4508-w Firmware and 81 more 2026-06-17 N/A 9.8 CRITICAL
An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue affects JetNet devices older than firmware version 2024/01.
CVE-2023-5346 2 Fedoraproject, Google 2 Fedora, Chrome 2026-06-17 N/A 8.8 HIGH
Type confusion in V8 in Google Chrome prior to 117.0.5938.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-5345 2 Fedoraproject, Linux 2 Fedora, Linux Kernel 2026-06-17 N/A 7.8 HIGH
A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege escalation. In case of an error in smb3_fs_context_parse_param, ctx->password was freed but the field was not set to NULL which could lead to double free. We recommend upgrading past commit e6e43b8aa7cd3c3af686caf0c2e11819a886d705.
CVE-2023-5344 2 Fedoraproject, Vim 2 Fedora, Vim 2026-06-17 N/A 7.5 HIGH
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.
CVE-2023-5343 1 Ays-pro 1 Popup Box 2026-06-17 N/A 4.8 MEDIUM
The Popup box WordPress plugin before 3.7.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
CVE-2023-5342 2026-06-17 N/A 4.1 MEDIUM
The Fedora Secure Boot CA certificate shipped with shim in Fedora was expired which could lead to old or invalid signed boot components being loaded.
CVE-2023-5341 3 Fedoraproject, Imagemagick, Redhat 4 Extra Packages For Enterprise Linux, Fedora, Imagemagick and 1 more 2026-06-17 N/A 6.2 MEDIUM
A heap use-after-free flaw was found in coders/bmp.c in ImageMagick.
CVE-2023-5340 1 Fivestarplugins 1 Five Star Restaurant Menu 2026-06-17 N/A 9.8 CRITICAL
The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perform PHP Object Injection when a suitable gadget is present on the blog.
CVE-2023-5339 1 Mattermost 1 Mattermost Desktop 2026-06-17 N/A 4.7 MEDIUM
Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged. 
CVE-2023-5338 1 Themeblvd 1 Theme Blvd Shortcodes 2026-06-17 N/A 6.4 MEDIUM
The Theme Blvd Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.