Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-29931: Local File Inclusion (LFI) vulnerability · Issue #437 · hhxsv5/laravel-s

laravel-s 3.7.35 is vulnerable to Local File Inclusion via /src/Illuminate/Laravel.php.

CVE
#vulnerability#php
CVE-2023-29709

An issue was discovered in /cgi-bin/login_rj.cgi in Wildix WSG24POE version 103SP7D190822, allows attackers to bypass authentication.

CVE-2023-29708: WAVLINK-Reset/CVE-2023-29708 at main · shellpei/WAVLINK-Reset

An issue was discovered in /cgi-bin/adm.cgi in WavLink WavRouter version RPT70HA1.x, allows attackers to force a factory reset via crafted payload.

CVE-2023-29707

Cross Site Scripting (XSS) vulnerability in GBCOM LAC WEB Control Center version lac-1.3.x, allows attackers to create an arbitrary device.

CVE-2023-28695: WordPress VigilanTor plugin <= 1.3.10 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Drew Phillips VigilanTor plugin <= 1.3.10 versions.

CVE-2023-28534: WordPress WP Job Portal – A Complete Job Board plugin <= 2.0.0 - Cross Site Scripting (XSS) - Patchstack

Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in WP Job Portal WP Job Portal – A Complete Job Board plugin <= 2.0.0 versions.

CVE-2023-28496: WordPress SMTP2GO plugin <= 1.4.2 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SMTP2GO – Email Made Easy plugin <= 1.4.2 versions.

CVE-2023-28423: WordPress Modern Footnotes plugin <= 1.4.15 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Prism Tech Studios Modern Footnotes plugin <= 1.4.15 versions.

CVE-2023-28171: WordPress Brilliance theme <= 1.3.1 - Reflected Cross-Site Scripting (XSS) vulnerability - Patchstack

Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in WP Chill Brilliance theme <= 1.3.1 versions.

CVE-2023-28166: WordPress Tags Cloud Manager plugin <= 1.0.0 - Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Aakif Kadiwala Tags Cloud Manager plugin <= 1.0.0 versions.