Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-46521: Digging/TP-LINK/TL-WR886N/11/1.md at main · XYIYM/Digging

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function RegisterRegister.

CVE
#vulnerability#git
CVE-2023-46525: Digging/TP-LINK/TL-WR886N/12/1.md at main · XYIYM/Digging

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function loginRegister.

CVE-2023-45756: WordPress ApplyOnline – Application Form Builder and Manager plugin <= 2.5.3 - Reflected Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Spider Teams ApplyOnline – Application Form Builder and Manager plugin <= 2.5.2 versions.

CVE-2023-45755: WordPress BuddyPress Global Search plugin <= 1.2.1 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BuddyBoss BuddyPress Global Search plugin <= 1.2.1 versions.

CVE-2023-46560: Digging/TOTOLINK/X2000R/23/1.md at main · XYIYM/Digging

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formTcpipSetup.

CVE-2023-46563: Digging/TOTOLINK/X2000R/7/1.md at main · XYIYM/Digging

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIpQoS.

CVE-2023-45754: WordPress Easy Testimonial Slider and Form plugin <= 1.0.18 - Cross Site Scripting (XSS) - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Easy Testimonial Slider and Form plugin <= 1.0.18 versions.

CVE-2023-45634: WordPress Copy or Move Comments plugin <= 5.0.4 - Reflected Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Biztechc Copy or Move Comments plugin <= 5.0.4 versions.

CVE-2023-46574: repo/totolink A3700R/1/A3700R V9.1.2u.6165_20211012 vuln.md at main · OraclePi/repo

An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.

CVE-2023-46557: Digging/TOTOLINK/X2000R/22/1.md at main · XYIYM/Digging

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMultiAPVLAN.