Vulnerabilities (CVE)

Total 403621 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-4669 1 Exagate 2 Sysguard 3001, Sysguard 3001 Firmware 2026-06-17 N/A 9.8 CRITICAL
Authentication Bypass by Assumed-Immutable Data vulnerability in Exagate SYSGuard 3001 allows Authentication Bypass. This issue affects SYSGuard 3001: before 3.2.20.0.
CVE-2023-4668 1 Ad Inserter Project 1 Ad Inserter 2026-06-17 N/A 5.3 MEDIUM
The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai-debug-processing-fe URL parameter. This can allow unauthenticated attackers to extract sensitive data including installed plugins (present and active), active theme, various plugin settings, WordPress version, as well as some server settings such as memory limit, installation paths.
CVE-2023-4667 1 Idemia 12 Morphowave Compact, Morphowave Compact Firmware, Morphowave Sp and 9 more 2026-06-17 N/A 8.1 HIGH
The web interface of the PAC Device allows the device administrator user profile to store malicious scripts in some fields. The stored malicious script is then executed when the GUI is opened by any users of the webserver administration interface.  The root cause of the vulnerability is inadequate input validation and output encoding in the web administration interface component of the firmware. This could lead to  unauthorized access and data leakage
CVE-2023-4666 1 10web 1 Form Maker 2026-06-17 N/A 9.8 CRITICAL
The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE
CVE-2023-4665 1 Adobe 1 Connect 2026-06-17 N/A 8.8 HIGH
Incorrect Execution-Assigned Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation. This issue affects Saphira Connect: before 9.
CVE-2023-4664 1 Adobe 1 Connect 2026-06-17 N/A 8.8 HIGH
Incorrect Default Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation. This issue affects Saphira Connect: before 9.
CVE-2023-4663 1 Adobe 1 Connect 2026-06-17 N/A 6.1 MEDIUM
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Saphira Saphira Connect allows Reflected XSS. This issue affects Saphira Connect: before 9.
CVE-2023-4662 1 Adobe 1 Connect 2026-06-17 N/A 9.8 CRITICAL
Execution with Unnecessary Privileges vulnerability in Saphira Saphira Connect allows Remote Code Inclusion. This issue affects Saphira Connect: before 9.
CVE-2023-4661 1 Adobe 1 Connect 2026-06-17 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saphira Saphira Connect allows SQL Injection. This issue affects Saphira Connect: before 9.
CVE-2023-4659 1 Free5gc 1 Free5gc 2026-06-17 N/A 9.8 CRITICAL
Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the platform as an administrator, simply by changing the token value to "admin". It is also possible to perform POST, GET and DELETE requests without any token value. Therefore, an unprivileged remote user is able to create, delete and modify users within theapplication.
CVE-2023-4658 1 Gitlab 1 Gitlab 2026-06-17 N/A 3.1 LOW
An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group.
CVE-2023-4655 1 Instantcms 1 Instantcms 2026-06-17 N/A 6.1 MEDIUM
Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1.
CVE-2023-4654 1 Instantcms 1 Instantcms 2026-06-17 N/A 3.5 LOW
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository instantsoft/icms2 prior to 2.16.1.
CVE-2023-4653 1 Instantcms 1 Instantcms 2026-06-17 N/A 4.8 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
CVE-2023-4652 1 Instantcms 1 Instantcms 2026-06-17 N/A 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
CVE-2023-4651 1 Instantcms 1 Instantcms 2026-06-17 N/A 5.4 MEDIUM
Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1.
CVE-2023-4650 1 Instantcms 1 Instantcms 2026-06-17 N/A 4.7 MEDIUM
Improper Access Control in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
CVE-2023-4649 1 Instantcms 1 Instantcms 2026-06-17 N/A 5.4 MEDIUM
Session Fixation in GitHub repository instantsoft/icms2 prior to 2.16.1.
CVE-2023-4648 1 Gowebsolutions 1 Wp Customer Reviews 2026-06-17 N/A 4.4 MEDIUM
The WP Customer Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
CVE-2023-4647 1 Gitlab 1 Gitlab 2026-06-17 N/A 5.3 MEDIUM
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which the projects API pagination can be skipped, potentially leading to DoS on certain instances.