Vulnerabilities (CVE)

Total 402547 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-52290 1 Apache 1 Streampark 2026-06-17 N/A 8.1 HIGH
In streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-end, and the SQL query is generated using this field. However, because this sort field isn't validated, there is a risk of SQL injection vulnerability. The attacker must successfully log into the system to launch an attack, which may cause data leakage. Since no data will be written, so this is a low-impact vulnerability. Mitigation: all users should upgrade to 2.1.4, Such parameters will be blocked.
CVE-2023-52289 1 Sujeetkv 1 Flaskcode 2026-06-17 N/A 7.5 HIGH
An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a POST request to a /update-resource-data/<file_path> URI (from views.py), allows attackers to write to arbitrary files.
CVE-2023-52288 1 Sujeetkv 1 Flaskcode 2026-06-17 N/A 7.5 HIGH
An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a GET request to a /resource-data/<file_path>.txt URI (from views.py), allows attackers to read arbitrary files.
CVE-2023-52286 1 Tencent 1 Tencent Distributed Sql 2026-06-17 N/A 7.5 HIGH
Tencent tdsqlpcloud through 1.8.5 allows unauthenticated remote attackers to discover database credentials via an index.php/api/install/get_db_info request, a related issue to CVE-2023-42387.
CVE-2023-52285 1 Lrx0014 1 Examsys 2026-06-17 N/A 7.5 HIGH
ExamSys 9150244 allows SQL Injection via the /Support/action/Pages.php s_score2 parameter.
CVE-2023-52284 1 Bytecodealliance 1 Webassembly Micro Runtime 2026-06-17 N/A 5.5 MEDIUM
Bytecode Alliance wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) before 1.3.0 can have an "double free or corruption" error for a valid WebAssembly module because push_pop_frame_ref_offset is mishandled.
CVE-2023-52277 1 Royalapps 1 Royaltsx 2026-06-17 N/A 7.8 HIGH
Royal RoyalTSX before 6.0.2.1 allows attackers to cause a denial of service (Heap Memory Corruption and application crash) or possibly have unspecified other impact via a long hostname in an RTSZ file, if the victim clicks on Test Connection. This occurs during SecureGatewayHost object processing in RAPortCheck.createNWConnection.
CVE-2023-52275 1 Tecno-mobile 2 Camon X, Camon X Firmware 2026-06-17 N/A 2.1 LOW
Gallery3d on Tecno Camon X CA7 devices allows attackers to view hidden images by navigating to data/com.android.gallery3d/.privatealbum/.encryptfiles and guessing the correct image file extension.
CVE-2023-52274 1 Yzmcms 1 Yzmcms 2026-06-17 N/A 6.1 MEDIUM
member/index/register.html in YzmCMS 6.5 through 7.0 allows XSS via the Referer HTTP header.
CVE-2023-52271 1 Topazevolution 1 Antifraud 2026-06-17 N/A 6.5 MEDIUM
The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process Light) process via an IOCTL (which will be named at a later time).
CVE-2023-52269 1 Mdaemon 1 Securitygateway 2026-06-17 N/A 4.8 MEDIUM
MDaemon SecurityGateway through 9.0.3 allows XSS via a crafted Message Content Filtering rule. This might allow domain administrators to conduct attacks against global administrators.
CVE-2023-52268 2026-06-17 N/A 9.1 CRITICAL
The End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to authenticate as an arbitrary user because a session token can be sent to the /auth endpoint. NOTE: this module is not part of freescout-helpdesk/freescout on GitHub.
CVE-2023-52267 1 Hongliuliao 1 Ehttp 2026-06-17 N/A 7.5 HIGH
ehttp 1.0.6 before 17405b9 has a simple_log.cpp _log out-of-bounds-read during error logging for long strings.
CVE-2023-52266 1 Hongliuliao 1 Ehttp 2026-06-17 N/A 7.5 HIGH
ehttp 1.0.6 before 17405b9 has an epoll_socket.cpp read_func use-after-free. An attacker can make many connections over a short time to trigger this.
CVE-2023-52265 1 Idurarapp 1 Idurar 2026-06-17 N/A 5.4 MEDIUM
IDURAR (aka idurar-erp-crm) through 2.0.1 allows stored XSS via a PATCH request with a crafted JSON email template in the /api/email/update data.
CVE-2023-52264 1 Thirtybees 1 Bees Blog 2026-06-17 N/A 6.1 MEDIUM
The beesblog (aka Bees Blog) component before 1.6.2 for thirty bees allows Reflected XSS because controllers/front/post.php sharing_url is mishandled.
CVE-2023-52263 1 Brave 1 Browser 2026-06-17 N/A 6.1 MEDIUM
Brave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect. This is related to browser/brave_content_browser_client.cc and browser/ui/webui/brave_web_ui_controller_factory.cc.
CVE-2023-52262 1 Outdoorbits 1 Little Backup Box 2026-06-17 N/A 9.8 CRITICAL
outdoorbits little-backup-box (aka Little Backup Box) before f39f91c allows remote attackers to execute arbitrary code because the PHP extract function is used for untrusted input.
CVE-2023-52257 1 Logobee 1 Logobee 2026-06-17 N/A 6.1 MEDIUM
LogoBee 0.2 allows updates.php?id= XSS.
CVE-2023-52252 1 Unifiedremote 1 Unified Remote 2026-06-17 N/A 9.8 CRITICAL
Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload endpoint.