Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In December 2023
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs allows Reflected XSS.This issue affects WP Pocket URLs: from n/a through 1.0.2.
CVSS Score
7.1
EPSS Score
0.002
Published
2023-12-15
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gilles Dumas which template file allows Reflected XSS.This issue affects which template file: from n/a through 4.9.0.
CVSS Score
7.1
EPSS Score
0.002
Published
2023-12-15
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mr. Hdwplayer HDW Player Plugin (Video Player & Video Gallery) allows Reflected XSS.This issue affects HDW Player Plugin (Video Player & Video Gallery): from n/a through 5.0.
CVSS Score
7.1
EPSS Score
0.002
Published
2023-12-15
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in datafeedr.Com Ads by datafeedr.Com allows Stored XSS.This issue affects Ads by datafeedr.Com: from n/a through 1.2.0.
CVSS Score
6.5
EPSS Score
0.002
Published
2023-12-15
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in captainform Forms by CaptainForm – Form Builder for WordPress allows Reflected XSS.This issue affects Forms by CaptainForm – Form Builder for WordPress: from n/a through 2.5.3.
CVSS Score
7.1
EPSS Score
0.002
Published
2023-12-15
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in formzu Inc. Formzu WP allows Stored XSS.This issue affects Formzu WP: from n/a through 1.6.6.
CVSS Score
6.5
EPSS Score
0.002
Published
2023-12-15
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Real Big Plugins Client Dash allows Stored XSS.This issue affects Client Dash: from n/a through 2.2.1.
CVSS Score
5.9
EPSS Score
0.001
Published
2023-12-15
In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible
CVSS Score
4.3
EPSS Score
0.0
Published
2023-12-15
In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed
CVSS Score
4.3
EPSS Score
0.0
Published
2023-12-15
Tutanota (Tuta Mail) is an encrypted email provider. Tutanota allows users to open links in emails in external applications. Prior to version 3.118.12, it correctly blocks the `file:` URL scheme, which can be used by malicious actors to gain code execution on a victims computer, however fails to check other harmful schemes such as `ftp:`, `smb:`, etc. which can also be used. Successful exploitation of this vulnerability will enable an attacker to gain code execution on a victim's computer. Version 3.118.2 contains a patch for this issue.
CVSS Score
9.3
EPSS Score
0.009
Published
2023-12-15


Contact Us

Shodan ® - All rights reserved