Total
402561 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-52079 | 1 Kriszyp | 1 Msgpackr | 2026-06-17 | N/A | 6.8 MEDIUM |
| msgpackr is a fast MessagePack NodeJS/JavaScript implementation. Prior to 1.10.1, when decoding user supplied MessagePack messages, users can trigger stuck threads by crafting messages that keep the decoder stuck in a loop. The fix is available in v1.10.1. Exploits seem to require structured cloning, replacing the 0x70 extension with your own (that throws an error or does something other than recursive referencing) should mitigate the issue. | |||||
| CVE-2023-52077 | 1 Nexryai | 1 Nexkey | 2026-06-17 | N/A | 8.9 HIGH |
| Nexkey is a lightweight fork of Misskey v12 optimized for small to medium size servers. Prior to 12.23Q4.5, Nexkey allows external apps using tokens issued by administrators and moderators to call admin APIs. This allows malicious third-party apps to perform operations such as updating server settings, as well as compromise object storage and email server credentials. This issue has been patched in 12.23Q4.5. | |||||
| CVE-2023-52076 | 1 Mate-desktop | 1 Atril | 2026-06-17 | N/A | 8.5 HIGH |
| Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril prior to 1.26.2. This vulnerability is capable of writing arbitrary files anywhere on the filesystem to which the user opening a crafted document has access. The only limitation is that this vulnerability cannot be exploited to overwrite existing files, but that doesn't stop an attacker from achieving Remote Command Execution on the target system. Version 1.26.2 of Atril contains a patch for this vulnerability. | |||||
| CVE-2023-52075 | 1 Revanced | 1 Revanced | 2026-06-17 | N/A | 7.5 HIGH |
| ReVanced API proxies requests needed to feed the ReVanced Manager and website with data. Up to and including commit 71f81f7f20cd26fd707335bca9838fa3e7df20d2, ReVanced API lacks error caching causing rate limit to be triggered thus increasing server load. This causes a denial of service for all users using the API. It is recommended to implement proper error caching. | |||||
| CVE-2023-52074 | 1 Flycms Project | 1 Flycms | 2026-06-17 | N/A | 8.8 HIGH |
| FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component system/site/webconfig_updagte. | |||||
| CVE-2023-52073 | 1 Flycms Project | 1 Flycms | 2026-06-17 | N/A | 8.8 HIGH |
| FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/config_footer_updagte. | |||||
| CVE-2023-52072 | 1 Flycms Project | 1 Flycms | 2026-06-17 | N/A | 8.8 HIGH |
| FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/userconfig_updagte. | |||||
| CVE-2023-52069 | 1 Kodcloud | 1 Kodbox | 2026-06-17 | N/A | 5.4 MEDIUM |
| kodbox v1.49.04 was discovered to contain a cross-site scripting (XSS) vulnerability via the URL parameter. | |||||
| CVE-2023-52068 | 1 Kodcloud | 1 Kodbox | 2026-06-17 | N/A | 6.1 MEDIUM |
| kodbox v1.43 was discovered to contain a cross-site scripting (XSS) vulnerability via the operation and login logs. | |||||
| CVE-2023-52066 | 2026-06-17 | N/A | 7.2 HIGH | ||
| http.zig commit 76cf5 was discovered to contain a CRLF injection vulnerability via the url parameter. | |||||
| CVE-2023-52064 | 1 Wuzhicms | 1 Wuzhicms | 2026-06-17 | N/A | 9.8 CRITICAL |
| Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the $keywords parameter at /core/admin/copyfrom.php. | |||||
| CVE-2023-52060 | 1 Gestsup | 1 Gestsup | 2026-06-17 | N/A | 4.3 MEDIUM |
| A Cross-Site Request Forgery (CSRF) in Gestsup v3.2.46 allows attackers to arbitrarily edit user profile information via a crafted request. | |||||
| CVE-2023-52059 | 1 Gestsup | 1 Gestsup | 2026-06-17 | N/A | 5.4 MEDIUM |
| A cross-site scripting (XSS) vulnerability in Gestsup v3.2.46 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description text field. | |||||
| CVE-2023-52048 | 1 Ruoyi | 1 Ruoyi | 2026-06-17 | N/A | 4.7 MEDIUM |
| RuoYi v4.7.8 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/notice/. | |||||
| CVE-2023-52047 | 1 Dedecms | 1 Dedecms | 2026-06-17 | N/A | 8.8 HIGH |
| Dedecms v5.7.112 was discovered to contain a Cross-Site Request Forgery (CSRF) in the file manager. | |||||
| CVE-2023-52046 | 1 Webmin | 1 Webmin | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cross Site Scripting vulnerability (XSS) in webmin v.2.105 and earlier allows a remote attacker to execute arbitrary code via a crafted payload to the "Execute cron job as" tab Input field. | |||||
| CVE-2023-52045 | 1 Std42 | 1 Elfinder | 2026-06-17 | N/A | 6.1 MEDIUM |
| Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability. | |||||
| CVE-2023-52044 | 1 Std42 | 1 Elfinder | 2026-06-17 | N/A | 9.8 CRITICAL |
| Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension. | |||||
| CVE-2023-52043 | 2026-06-17 | N/A | 8.1 HIGH | ||
| An issue in D-Link COVR 1100, 1102, 1103 AC1200 Dual-Band Whole-Home Mesh Wi-Fi System (Hardware Rev B1) truncates Wireless Access Point Passwords (WPA-PSK) allowing an attacker to gain unauthorized network access via weak authentication controls. | |||||
| CVE-2023-52042 | 1 Totolink | 2 X6000r, X6000r Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parameter. | |||||
