Vulnerabilities (CVE)

Total 403188 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-50124 1 Flient 2 Smart Lock Advanced, Smart Lock Advanced Firmware 2026-06-17 N/A 6.8 MEDIUM
Flient Smart Door Lock v1.0 is vulnerable to Use of Default Credentials. Due to default credentials on a debug interface, in combination with certain design choices, an attacker can unlock the Flient Smart Door Lock by replacing the fingerprint that is stored on the scanner.
CVE-2023-50123 1 Hozard 1 Alarm System 2026-06-17 N/A 8.1 HIGH
The number of attempts to bring the Hozard Alarm system (alarmsystemen) v1.0 to a disarmed state is not limited. This could allow an attacker to perform a brute force on the SMS authentication, to bring the alarm system to a disarmed state.
CVE-2023-50121 1 Autelrobotics 2 Evo Nano Drone, Evo Nano Drone Firmware 2026-06-17 N/A 5.7 MEDIUM
Autel EVO NANO drone flight control firmware version 1.6.5 is vulnerable to denial of service (DoS).
CVE-2023-50120 1 Gpac 1 Gpac 2026-06-17 N/A 5.5 MEDIUM
MP4Box GPAC version 2.3-DEV-rev636-gfbd7e13aa-master was discovered to contain an infinite loop in the function av1_uvlc at media_tools/av_parsers.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
CVE-2023-50110 1 Testlink 1 Testlink 2026-06-17 N/A 7.5 HIGH
TestLink through 1.9.20 allows type juggling for authentication bypass because === is not used.
CVE-2023-50104 1 Zzcms 1 Zzcms 2026-06-17 N/A 9.8 CRITICAL
ZZCMS 2023 has a file upload vulnerability in 3/E_bak5.1/upload/index.php, allowing attackers to exploit this loophole to gain server privileges and execute arbitrary code.
CVE-2023-50102 1 Jfinalcms Project 1 Jfinalcms 2026-06-17 N/A 5.4 MEDIUM
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-50101 1 Jfinalcms Project 1 Jfinalcms 2026-06-17 N/A 5.4 MEDIUM
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via Label management editing.
CVE-2023-50100 1 Jfinalcms Project 1 Jfinalcms 2026-06-17 N/A 5.4 MEDIUM
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via carousel image editing.
CVE-2023-50096 1 St 1 X-cube-safea1 2026-06-17 N/A 7.5 HIGH
STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus. This is caused by an StSafeA_ReceiveBytes buffer overflow in the X-CUBE-SAFEA1 Software Package for STSAFE-A sample applications (1.2.0), and thus can affect user-written code that was derived from a published sample application.
CVE-2023-50094 1 Yogeshojha 1 Rengine 2026-06-17 N/A 8.8 HIGH
reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via subprocess.check_output.
CVE-2023-50093 1 Apiida 1 Api Gateway Manager 2026-06-17 N/A 6.1 MEDIUM
APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection.
CVE-2023-50092 1 Apiida 1 Api Gateway Manager 2026-06-17 N/A 6.1 MEDIUM
APIIDA API Gateway Manager for Broadcom Layer7 v2023.2 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-50090 1 Ureport2 Project 1 Ureport2 2026-06-17 N/A 9.8 CRITICAL
Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write arbitrary files and run arbitrary commands via crafted POST request.
CVE-2023-50089 1 Netgear 2 Wnr2000, Wnr2000 Firmware 2026-06-17 N/A 9.8 CRITICAL
A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication.
CVE-2023-50082 1 Pbootcms 1 Pbootcms 2026-06-17 N/A 7.5 HIGH
Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via session leakage allows a user to avoid logging into the backend management platform.
CVE-2023-50073 1 Leadscloud 1 Empirecms 2026-06-17 N/A 9.8 CRITICAL
EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php.
CVE-2023-50072 1 Openkm 1 Openkm 2026-06-17 N/A 5.4 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated user to upload a note on a file which acts as a stored XSS payload. Any user who opens the note of a document file will trigger the XSS.
CVE-2023-50071 1 Customer Support System Project 1 Customer Support System 2026-06-17 N/A 8.8 HIGH
Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_department via id or name.
CVE-2023-50070 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 8.8 HIGH
Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_ticket via department_id, customer_id, and subject.