Vulnerabilities (CVE)

Total 402961 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-50706 1 Efacec 2 Uc 500e, Uc 500e Firmware 2026-06-17 N/A 4.1 MEDIUM
A user without administrator permissions with access to the UC500 windows system could perform a memory dump of the running processes and extract clear credentials or valid session tokens.
CVE-2023-50705 1 Efacec 2 Uc 500e, Uc 500e Firmware 2026-06-17 N/A 5.3 MEDIUM
An attacker could create malicious requests to obtain sensitive information about the web server.
CVE-2023-50704 1 Efacec 2 Uc 500e, Uc 500e Firmware 2026-06-17 N/A 4.3 MEDIUM
An attacker could construct a URL within the application that causes a redirection to an arbitrary external domain and could be leveraged to facilitate phishing attacks against application users.
CVE-2023-50703 1 Efacec 2 Uc 500e, Uc 500e Firmware 2026-06-17 N/A 6.3 MEDIUM
An attacker with network access could perform a man-in-the-middle (MitM) attack and capture sensitive information to gain unauthorized access to the application.
CVE-2023-50702 2026-06-17 N/A 8.8 HIGH
Sikka SSCWindowsService 5 2023-09-14 executes a program as LocalSystem but allows full control by low-privileged users (and low-privileged users have write access to %PROGRAMDATA%\SSCService). Consequently, low-privileged users can execute arbitrary code as LocalSystem.
CVE-2023-50700 2026-06-17 N/A 7.8 HIGH
Insecure Permissions vulnerability in Deepin dde-file-manager 6.0.54 and earlier allows privileged operations to be called by unprivileged users via the D-Bus method.
CVE-2023-50694 1 Dom96 1 Httpbeast 2026-06-17 N/A 9.8 CRITICAL
An issue in dom96 HTTPbeast v.0.4.1 and before allows a remote attacker to send a malicious crafted request due to insufficient parsing in the parser.nim component.
CVE-2023-50693 1 Jester Project 1 Jester 2026-06-17 N/A 9.8 CRITICAL
An issue in Jester v.0.6.0 and before allows a remote attacker to send a malicious crafted request.
CVE-2023-50692 1 Jizhicms 1 Jizhicms 2026-06-17 N/A 8.8 HIGH
File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploaded and downloaded to the download_url parameter in the app/admin/exts/ directory.
CVE-2023-50685 2026-06-17 N/A 7.5 HIGH
An issue in Hipcam Cameras RealServer v.1.0 allows a remote attacker to cause a denial of service via a crafted script to the client_port parameter.
CVE-2023-50677 1 Netgear 2 Dgnd4000, Dgnd4000 Firmware 2026-06-17 N/A 8.8 HIGH
An issue in NETGEAR-DGND4000 v.1.1.00.15_1.00.15 allows a remote attacker to escalate privileges via the next_file parameter to the /setup.cgi component.
CVE-2023-50671 1 Aertherwide 1 Exiftags 2026-06-17 N/A 7.8 HIGH
In exiftags 1.01, nikon_prop1 in nikon.c has a heap-based buffer overflow (write of size 28) because snprintf can write to an unexpected address.
CVE-2023-50658 1 Dvsekhvalnov 1 Jose2go 2026-06-17 N/A 7.5 HIGH
The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
CVE-2023-50639 1 Iscute 1 Cute Http File Server 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in CuteHttpFileServer v.1.0 and v.2.0 allows attackers to obtain sensitive information via the file upload function in the home page.
CVE-2023-50630 1 Teamwork Management System Project 1 Teamwork Management System 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in xiweicheng TMS v.2.28.0 allows a remote attacker to execute arbitrary code via a crafted script to the click here function.
CVE-2023-50628 1 Libming 1 Libming 2026-06-17 N/A 9.8 CRITICAL
Buffer Overflow vulnerability in libming version 0.4.8, allows attackers to execute arbitrary code and obtain sensitive information via parser.c component.
CVE-2023-50614 1 Cdebyte 2 E880-ir01, E880-ir01 Firmware 2026-06-17 N/A 7.5 HIGH
An issue discovereed in EBYTE E880-IR01-V1.1 allows an attacker to obtain sensitive information via crafted POST request to /cgi-bin/luci.
CVE-2023-50612 1 Fit2cloud 1 Cloudexplorer Lite 2026-06-17 N/A 7.8 HIGH
Insecure Permissions vulnerability in fit2cloud Cloud Explorer Lite version 1.4.1, allow local attackers to escalate privileges and obtain sensitive information via the cloud accounts parameter.
CVE-2023-50609 1 Ava 1 Teaching Video Application Service Platform 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in AVA teaching video application service platform version 3.1, allows remote attackers to execute arbitrary code via a crafted script to ajax.aspx.
CVE-2023-50589 1 Embras 1 Geosiap Erp 2026-06-17 N/A 9.8 CRITICAL
Grupo Embras GEOSIAP ERP v2.2.167.02 was discovered to contain a SQL injection vulnerability via the codLogin parameter on the login page.