Total
403188 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-50124 | 1 Flient | 2 Smart Lock Advanced, Smart Lock Advanced Firmware | 2026-06-17 | N/A | 6.8 MEDIUM |
| Flient Smart Door Lock v1.0 is vulnerable to Use of Default Credentials. Due to default credentials on a debug interface, in combination with certain design choices, an attacker can unlock the Flient Smart Door Lock by replacing the fingerprint that is stored on the scanner. | |||||
| CVE-2023-50123 | 1 Hozard | 1 Alarm System | 2026-06-17 | N/A | 8.1 HIGH |
| The number of attempts to bring the Hozard Alarm system (alarmsystemen) v1.0 to a disarmed state is not limited. This could allow an attacker to perform a brute force on the SMS authentication, to bring the alarm system to a disarmed state. | |||||
| CVE-2023-50121 | 1 Autelrobotics | 2 Evo Nano Drone, Evo Nano Drone Firmware | 2026-06-17 | N/A | 5.7 MEDIUM |
| Autel EVO NANO drone flight control firmware version 1.6.5 is vulnerable to denial of service (DoS). | |||||
| CVE-2023-50120 | 1 Gpac | 1 Gpac | 2026-06-17 | N/A | 5.5 MEDIUM |
| MP4Box GPAC version 2.3-DEV-rev636-gfbd7e13aa-master was discovered to contain an infinite loop in the function av1_uvlc at media_tools/av_parsers.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file. | |||||
| CVE-2023-50110 | 1 Testlink | 1 Testlink | 2026-06-17 | N/A | 7.5 HIGH |
| TestLink through 1.9.20 allows type juggling for authentication bypass because === is not used. | |||||
| CVE-2023-50104 | 1 Zzcms | 1 Zzcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| ZZCMS 2023 has a file upload vulnerability in 3/E_bak5.1/upload/index.php, allowing attackers to exploit this loophole to gain server privileges and execute arbitrary code. | |||||
| CVE-2023-50102 | 1 Jfinalcms Project | 1 Jfinalcms | 2026-06-17 | N/A | 5.4 MEDIUM |
| JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS). | |||||
| CVE-2023-50101 | 1 Jfinalcms Project | 1 Jfinalcms | 2026-06-17 | N/A | 5.4 MEDIUM |
| JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via Label management editing. | |||||
| CVE-2023-50100 | 1 Jfinalcms Project | 1 Jfinalcms | 2026-06-17 | N/A | 5.4 MEDIUM |
| JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via carousel image editing. | |||||
| CVE-2023-50096 | 1 St | 1 X-cube-safea1 | 2026-06-17 | N/A | 7.5 HIGH |
| STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus. This is caused by an StSafeA_ReceiveBytes buffer overflow in the X-CUBE-SAFEA1 Software Package for STSAFE-A sample applications (1.2.0), and thus can affect user-written code that was derived from a published sample application. | |||||
| CVE-2023-50094 | 1 Yogeshojha | 1 Rengine | 2026-06-17 | N/A | 8.8 HIGH |
| reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via subprocess.check_output. | |||||
| CVE-2023-50093 | 1 Apiida | 1 Api Gateway Manager | 2026-06-17 | N/A | 6.1 MEDIUM |
| APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection. | |||||
| CVE-2023-50092 | 1 Apiida | 1 Api Gateway Manager | 2026-06-17 | N/A | 6.1 MEDIUM |
| APIIDA API Gateway Manager for Broadcom Layer7 v2023.2 is vulnerable to Cross Site Scripting (XSS). | |||||
| CVE-2023-50090 | 1 Ureport2 Project | 1 Ureport2 | 2026-06-17 | N/A | 9.8 CRITICAL |
| Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write arbitrary files and run arbitrary commands via crafted POST request. | |||||
| CVE-2023-50089 | 1 Netgear | 2 Wnr2000, Wnr2000 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication. | |||||
| CVE-2023-50082 | 1 Pbootcms | 1 Pbootcms | 2026-06-17 | N/A | 7.5 HIGH |
| Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via session leakage allows a user to avoid logging into the backend management platform. | |||||
| CVE-2023-50073 | 1 Leadscloud | 1 Empirecms | 2026-06-17 | N/A | 9.8 CRITICAL |
| EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php. | |||||
| CVE-2023-50072 | 1 Openkm | 1 Openkm | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated user to upload a note on a file which acts as a stored XSS payload. Any user who opens the note of a document file will trigger the XSS. | |||||
| CVE-2023-50071 | 1 Customer Support System Project | 1 Customer Support System | 2026-06-17 | N/A | 8.8 HIGH |
| Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_department via id or name. | |||||
| CVE-2023-50070 | 1 Oretnom23 | 1 Customer Support System | 2026-06-17 | N/A | 8.8 HIGH |
| Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_ticket via department_id, customer_id, and subject. | |||||
