NA - CVE-2023-39331 - A previously disclosed vulnerability...
A previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently in commit 205f1e6. The new path traversal vulnerability arises because the implementation does not protect itself...
NA - CVE-2023-39332 - Various `node:fs` functions allow specifying...
Various `node:fs` functions allow specifying paths as either strings or `Uint8Array` objects. In Node.js environments, the `Buffer` class extends the `Uint8Array` class. Node.js prevents path...
NA - CVE-2023-3254 - The Widgets for Google Reviews plugin for...
The Widgets for Google Reviews plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.9. This is due to missing or incorrect nonce validation within...
NA - CVE-2023-5538 - The MpOperationLogs plugin for WordPress is...
The MpOperationLogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the IP Request Headers in versions up to, and including, 1.0.1 due to insufficient input sanitization and...
NA - CVE-2023-42319 - Geth (aka go-ethereum) through 1.13.4, when...
Geth (aka go-ethereum) through 1.13.4, when --http --graphql is used, allows remote attackers to cause a denial of service (memory consumption and daemon hang) via a crafted GraphQL query. NOTE:...
NA - CVE-2023-4938 - The BEAR for WordPress is vulnerable to Missing...
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the...
NA - CVE-2023-5621 - The Thumbnail Slider With Lightbox plugin for...
The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Title field in versions up to, and including, 1.0 due to insufficient input...