Vulnerabilities (CVE)

Total 401083 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-52076 1 Mate-desktop 1 Atril 2026-06-17 N/A 8.5 HIGH
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril prior to 1.26.2. This vulnerability is capable of writing arbitrary files anywhere on the filesystem to which the user opening a crafted document has access. The only limitation is that this vulnerability cannot be exploited to overwrite existing files, but that doesn't stop an attacker from achieving Remote Command Execution on the target system. Version 1.26.2 of Atril contains a patch for this vulnerability.
CVE-2023-52075 1 Revanced 1 Revanced 2026-06-17 N/A 7.5 HIGH
ReVanced API proxies requests needed to feed the ReVanced Manager and website with data. Up to and including commit 71f81f7f20cd26fd707335bca9838fa3e7df20d2, ReVanced API lacks error caching causing rate limit to be triggered thus increasing server load. This causes a denial of service for all users using the API. It is recommended to implement proper error caching.
CVE-2023-52074 1 Flycms Project 1 Flycms 2026-06-17 N/A 8.8 HIGH
FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component system/site/webconfig_updagte.
CVE-2023-52073 1 Flycms Project 1 Flycms 2026-06-17 N/A 8.8 HIGH
FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/config_footer_updagte.
CVE-2023-52072 1 Flycms Project 1 Flycms 2026-06-17 N/A 8.8 HIGH
FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/userconfig_updagte.
CVE-2023-52069 1 Kodcloud 1 Kodbox 2026-06-17 N/A 5.4 MEDIUM
kodbox v1.49.04 was discovered to contain a cross-site scripting (XSS) vulnerability via the URL parameter.
CVE-2023-52068 1 Kodcloud 1 Kodbox 2026-06-17 N/A 6.1 MEDIUM
kodbox v1.43 was discovered to contain a cross-site scripting (XSS) vulnerability via the operation and login logs.
CVE-2023-52066 2026-06-17 N/A 7.2 HIGH
http.zig commit 76cf5 was discovered to contain a CRLF injection vulnerability via the url parameter.
CVE-2023-52064 1 Wuzhicms 1 Wuzhicms 2026-06-17 N/A 9.8 CRITICAL
Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the $keywords parameter at /core/admin/copyfrom.php.
CVE-2023-52060 1 Gestsup 1 Gestsup 2026-06-17 N/A 4.3 MEDIUM
A Cross-Site Request Forgery (CSRF) in Gestsup v3.2.46 allows attackers to arbitrarily edit user profile information via a crafted request.
CVE-2023-52059 1 Gestsup 1 Gestsup 2026-06-17 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in Gestsup v3.2.46 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description text field.
CVE-2023-52048 1 Ruoyi 1 Ruoyi 2026-06-17 N/A 4.7 MEDIUM
RuoYi v4.7.8 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/notice/.
CVE-2023-52047 1 Dedecms 1 Dedecms 2026-06-17 N/A 8.8 HIGH
Dedecms v5.7.112 was discovered to contain a Cross-Site Request Forgery (CSRF) in the file manager.
CVE-2023-52046 1 Webmin 1 Webmin 2026-06-17 N/A 4.8 MEDIUM
Cross Site Scripting vulnerability (XSS) in webmin v.2.105 and earlier allows a remote attacker to execute arbitrary code via a crafted payload to the "Execute cron job as" tab Input field.
CVE-2023-52045 1 Std42 1 Elfinder 2026-06-17 N/A 6.1 MEDIUM
Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.
CVE-2023-52044 1 Std42 1 Elfinder 2026-06-17 N/A 9.8 CRITICAL
Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.
CVE-2023-52043 2026-06-17 N/A 8.1 HIGH
An issue in D-Link COVR 1100, 1102, 1103 AC1200 Dual-Band Whole-Home Mesh Wi-Fi System (Hardware Rev B1) truncates Wireless Access Point Passwords (WPA-PSK) allowing an attacker to gain unauthorized network access via weak authentication controls.
CVE-2023-52042 1 Totolink 2 X6000r, X6000r Firmware 2026-06-17 N/A 9.8 CRITICAL
An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parameter.
CVE-2023-52041 1 Totolink 2 X6000r, X6000r Firmware 2026-06-17 N/A 9.8 CRITICAL
An issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code via the sub_410118 function of the shttpd program.
CVE-2023-52040 1 Totolink 2 X6000r, X6000r Firmware 2026-06-17 N/A 9.8 CRITICAL
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.