Total
403599 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-4667 | 1 Idemia | 12 Morphowave Compact, Morphowave Compact Firmware, Morphowave Sp and 9 more | 2026-06-17 | N/A | 8.1 HIGH |
| The web interface of the PAC Device allows the device administrator user profile to store malicious scripts in some fields. The stored malicious script is then executed when the GUI is opened by any users of the webserver administration interface. The root cause of the vulnerability is inadequate input validation and output encoding in the web administration interface component of the firmware. This could lead to unauthorized access and data leakage | |||||
| CVE-2023-4666 | 1 10web | 1 Form Maker | 2026-06-17 | N/A | 9.8 CRITICAL |
| The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE | |||||
| CVE-2023-4665 | 1 Adobe | 1 Connect | 2026-06-17 | N/A | 8.8 HIGH |
| Incorrect Execution-Assigned Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation. This issue affects Saphira Connect: before 9. | |||||
| CVE-2023-4664 | 1 Adobe | 1 Connect | 2026-06-17 | N/A | 8.8 HIGH |
| Incorrect Default Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation. This issue affects Saphira Connect: before 9. | |||||
| CVE-2023-4663 | 1 Adobe | 1 Connect | 2026-06-17 | N/A | 6.1 MEDIUM |
| Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Saphira Saphira Connect allows Reflected XSS. This issue affects Saphira Connect: before 9. | |||||
| CVE-2023-4662 | 1 Adobe | 1 Connect | 2026-06-17 | N/A | 9.8 CRITICAL |
| Execution with Unnecessary Privileges vulnerability in Saphira Saphira Connect allows Remote Code Inclusion. This issue affects Saphira Connect: before 9. | |||||
| CVE-2023-4661 | 1 Adobe | 1 Connect | 2026-06-17 | N/A | 9.8 CRITICAL |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saphira Saphira Connect allows SQL Injection. This issue affects Saphira Connect: before 9. | |||||
| CVE-2023-4659 | 1 Free5gc | 1 Free5gc | 2026-06-17 | N/A | 9.8 CRITICAL |
| Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the platform as an administrator, simply by changing the token value to "admin". It is also possible to perform POST, GET and DELETE requests without any token value. Therefore, an unprivileged remote user is able to create, delete and modify users within theapplication. | |||||
| CVE-2023-4658 | 1 Gitlab | 1 Gitlab | 2026-06-17 | N/A | 3.1 LOW |
| An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group. | |||||
| CVE-2023-4655 | 1 Instantcms | 1 Instantcms | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1. | |||||
| CVE-2023-4654 | 1 Instantcms | 1 Instantcms | 2026-06-17 | N/A | 3.5 LOW |
| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository instantsoft/icms2 prior to 2.16.1. | |||||
| CVE-2023-4653 | 1 Instantcms | 1 Instantcms | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | |||||
| CVE-2023-4652 | 1 Instantcms | 1 Instantcms | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | |||||
| CVE-2023-4651 | 1 Instantcms | 1 Instantcms | 2026-06-17 | N/A | 5.4 MEDIUM |
| Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1. | |||||
| CVE-2023-4650 | 1 Instantcms | 1 Instantcms | 2026-06-17 | N/A | 4.7 MEDIUM |
| Improper Access Control in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | |||||
| CVE-2023-4649 | 1 Instantcms | 1 Instantcms | 2026-06-17 | N/A | 5.4 MEDIUM |
| Session Fixation in GitHub repository instantsoft/icms2 prior to 2.16.1. | |||||
| CVE-2023-4648 | 1 Gowebsolutions | 1 Wp Customer Reviews | 2026-06-17 | N/A | 4.4 MEDIUM |
| The WP Customer Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. | |||||
| CVE-2023-4647 | 1 Gitlab | 1 Gitlab | 2026-06-17 | N/A | 5.3 MEDIUM |
| An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which the projects API pagination can be skipped, potentially leading to DoS on certain instances. | |||||
| CVE-2023-4646 | 1 Sayandatta | 1 Simple Posts Ticker | 2026-06-17 | N/A | 5.4 MEDIUM |
| The Simple Posts Ticker WordPress plugin before 1.1.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |||||
| CVE-2023-4645 | 1 Igorfuna | 1 Ad Inserter | 2026-06-17 | N/A | 5.3 MEDIUM |
| The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai_ajax function. This can allow unauthenticated attackers to extract sensitive data such as post titles and slugs (including those of protected posts along with their passwords), usernames, available roles, the plugin license key provided the remote debugging option is enabled. In the default state it is disabled. | |||||
