Vulnerabilities (CVE)

Total 400295 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-5114 1 Dbbee 1 Idbbee 2026-06-17 N/A 5.4 MEDIUM
The idbbee plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idbbee' shortcode in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2023-5113 1 Hp 1133 Color Laserjet Enterprise 5700 49k98a, Color Laserjet Enterprise 5700 6qn28a, Color Laserjet Enterprise 6700 49l00a and 1130 more 2026-06-17 N/A 6.1 MEDIUM
Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to denial of service due to WS-Print request and potential injections of Cross Site Scripting via jQuery-UI.
CVE-2023-5112 1 Oscommerce 1 Oscommerce 2026-06-17 N/A 5.4 MEDIUM
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "specials_type_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
CVE-2023-5111 1 Oscommerce 1 Oscommerce 2026-06-17 N/A 5.4 MEDIUM
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "featured_type_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
CVE-2023-5110 1 Bannersky 1 Bsk Pdf Manager 2026-06-17 N/A 6.4 MEDIUM
The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'bsk-pdfm-category-dropdown' shortcode in versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2023-5109 1 Ironikus 1 Wp Mailto Links 2026-06-17 N/A 6.4 MEDIUM
The WP Mailto Links – Protect Email Addresses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wpml_mailto' shortcode in versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This was partially patched in version 3.1.3 and fully patched in version 3.1.4.
CVE-2023-5108 1 Alphabpo 1 Easy Newsletter Signups 2026-06-17 N/A 7.2 HIGH
The Easy Newsletter Signups WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
CVE-2023-5106 1 Gitlab 1 Gitlab 2026-06-17 N/A 8.2 HIGH
An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.
CVE-2023-5105 1 Najeebmedia 1 Frontend File Manager Plugin 2026-06-17 N/A 6.5 MEDIUM
The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass the file download logic and download files such as `wp-config.php`
CVE-2023-5104 1 Nocodb 1 Nocodb 2026-06-17 N/A 6.5 MEDIUM
Improper Input Validation in GitHub repository nocodb/nocodb prior to 0.96.0.
CVE-2023-5103 1 Sick 2 Apu0200, Apu0200 Firmware 2026-06-17 N/A 4.3 MEDIUM
Improper Restriction of Rendered UI Layers or Frames in RDT400 in SICK APU allows an unprivileged remote attacker to potentially reveal sensitive information via tricking a user into clicking on an actionable item using an iframe.
CVE-2023-5102 1 Sick 2 Apu0200, Apu0200 Firmware 2026-06-17 N/A 5.3 MEDIUM
Insufficient Control Flow Management in RDT400 in SICK APU allows an unprivileged remote attacker to potentially enable hidden functionality via HTTP requests.
CVE-2023-5101 1 Sick 2 Apu0200, Apu0200 Firmware 2026-06-17 N/A 5.3 MEDIUM
Files or Directories Accessible to External Parties in RDT400 in SICK APU allows an unprivileged remote attacker to download various files from the server via HTTP requests.
CVE-2023-5100 1 Sick 2 Apu0200, Apu0200 Firmware 2026-06-17 N/A 5.9 MEDIUM
Cleartext Transmission of Sensitive Information in RDT400 in SICK APU allows an unprivileged remote attacker to retrieve potentially sensitive information via intercepting network traffic that is not encrypted.
CVE-2023-5099 1 Jonashjalmarsson 1 Html Filter And Csv-file Search 2026-06-17 N/A 8.8 HIGH
The HTML filter and csv-file search plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7 via the 'src' attribute of the 'csvsearch' shortcode. This allows authenticated attackers, with contributor-level permissions and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
CVE-2023-5098 1 Fatcatapps 1 Campaign Monitor Optin Cat 2026-06-17 N/A 8.1 HIGH
The Campaign Monitor Forms by Optin Cat WordPress plugin before 2.5.6 does not prevent users with low privileges (like subscribers) from overwriting any options on a site with the string "true", which could lead to a variety of outcomes, including DoS.
CVE-2023-5097 2 Hypr, Microsoft 2 Workforce Access, Windows 2026-06-17 N/A 7.0 HIGH
Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: before 8.7.
CVE-2023-5096 1 Jonashjalmarsson 1 Html Filter And Csv-file Search 2026-06-17 N/A 6.4 MEDIUM
The HTML filter and csv-file search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'csvsearch' shortcode in versions up to, and including, 2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2023-5091 1 Arm 1 Valhall Gpu Kernel Driver 2026-06-17 N/A 5.5 MEDIUM
Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU processing operations to gain access to already freed memory. This issue affects Valhall GPU Kernel Driver: from r37p0 through r40p0.
CVE-2023-5089 1 Wpmudev 1 Defender Security 2026-06-17 N/A 5.3 MEDIUM
The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.