Vulnerabilities (CVE)

Total 401251 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-51095 1 Tenda 2 M3, M3 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formDelWlRfPolicy.
CVE-2023-51094 1 Tenda 2 M3, M3 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda M3 V1.0.0.12(4856) was discovered to contain a Command Execution vulnerability via the function TendaTelnet.
CVE-2023-51093 1 Tenda 2 M3, M3 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function fromSetLocalVlanInfo.
CVE-2023-51092 1 Tenda 2 M3, M3 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function upgrade.
CVE-2023-51091 1 Tenda 2 M3, M3 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function R7WebsSecurityHandler.
CVE-2023-51090 1 Tenda 2 M3, M3 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formGetWeiXinConfig.
CVE-2023-51084 1 Hyavijava 1 Hyavijava 2026-06-17 N/A 9.8 CRITICAL
hyavijava v6.0.07.1 was discovered to contain a stack overflow via the ResultConverter.convert2Xml method.
CVE-2023-51080 1 Hutool 1 Hutool 2026-06-17 N/A 7.5 HIGH
The NumberUtil.toBigDecimal method in hutool-core v5.8.23 was discovered to contain a stack overflow.
CVE-2023-51079 1 Mvel 1 Mvel 2026-06-17 N/A 5.3 MEDIUM
A long execution time can occur in the ParseTools.subCompileExpression method in MVEL 2.5.0.Final because of many Java class lookups. NOTE: the vendor disputes this because "the only thing that you could expect is that the parser will take a crazy amount of time to complete its task."
CVE-2023-51075 1 Hutool 1 Hutool 2026-06-17 N/A 7.5 HIGH
hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function. This vulnerability allows attackers to cause a Denial of Service (DoS) via manipulation of the first two parameters.
CVE-2023-51074 1 Json-path 1 Jayway Jsonpath 2026-06-17 N/A 5.3 MEDIUM
json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.
CVE-2023-51073 1 Buffalo 2 Ls210d, Ls210d Firmware 2026-06-17 N/A 8.1 HIGH
An issue in Buffalo LS210D v.1.78-0.03 allows a remote attacker to execute arbitrary code via the Firmware Update Script at /etc/init.d/update_notifications.sh.
CVE-2023-51072 1 Nagios 1 Nagios Xi 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 allows low-privileged users to execute malicious HTML or JavaScript code via the audio file upload functionality from the Operation Center section. This allows any authenticated user to execute arbitrary JavaScript code on behalf of other users, including the administrators.
CVE-2023-51071 1 Qstar 1 Archive Storage Manager 2026-06-17 N/A 6.5 MEDIUM
An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily disable the SMB service on a victim's Qstar instance by executing a specific command in a link.
CVE-2023-51070 1 Qstar 1 Archive Storage Manager 2026-06-17 N/A 7.5 HIGH
An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensitive SMB settings on the QStar Server.
CVE-2023-51068 1 Qstar 1 Archive Storage Manager 2026-06-17 N/A 5.4 MEDIUM
An authenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link.
CVE-2023-51067 1 Qstar 1 Archive Storage Manager 2026-06-17 N/A 6.1 MEDIUM
An unauthenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link.
CVE-2023-51066 1 Qstar 1 Archive Storage Manager 2026-06-17 N/A 8.8 HIGH
An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily execute commands.
CVE-2023-51065 1 Qstar 1 Archive Storage Manager 2026-06-17 N/A 7.5 HIGH
Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to obtain system backups and other sensitive information from the QStar Server.
CVE-2023-51064 1 Qstar 1 Archive Storage Manager 2026-06-17 N/A 6.1 MEDIUM
QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based reflected XSS vulnerability within the component qnme-ajax?method=tree_table.