Vulnerabilities (CVE)

Total 403221 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-50110 1 Testlink 1 Testlink 2026-06-17 N/A 7.5 HIGH
TestLink through 1.9.20 allows type juggling for authentication bypass because === is not used.
CVE-2023-50104 1 Zzcms 1 Zzcms 2026-06-17 N/A 9.8 CRITICAL
ZZCMS 2023 has a file upload vulnerability in 3/E_bak5.1/upload/index.php, allowing attackers to exploit this loophole to gain server privileges and execute arbitrary code.
CVE-2023-50102 1 Jfinalcms Project 1 Jfinalcms 2026-06-17 N/A 5.4 MEDIUM
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-50101 1 Jfinalcms Project 1 Jfinalcms 2026-06-17 N/A 5.4 MEDIUM
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via Label management editing.
CVE-2023-50100 1 Jfinalcms Project 1 Jfinalcms 2026-06-17 N/A 5.4 MEDIUM
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via carousel image editing.
CVE-2023-50096 1 St 1 X-cube-safea1 2026-06-17 N/A 7.5 HIGH
STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus. This is caused by an StSafeA_ReceiveBytes buffer overflow in the X-CUBE-SAFEA1 Software Package for STSAFE-A sample applications (1.2.0), and thus can affect user-written code that was derived from a published sample application.
CVE-2023-50094 1 Yogeshojha 1 Rengine 2026-06-17 N/A 8.8 HIGH
reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via subprocess.check_output.
CVE-2023-50093 1 Apiida 1 Api Gateway Manager 2026-06-17 N/A 6.1 MEDIUM
APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection.
CVE-2023-50092 1 Apiida 1 Api Gateway Manager 2026-06-17 N/A 6.1 MEDIUM
APIIDA API Gateway Manager for Broadcom Layer7 v2023.2 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-50090 1 Ureport2 Project 1 Ureport2 2026-06-17 N/A 9.8 CRITICAL
Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write arbitrary files and run arbitrary commands via crafted POST request.
CVE-2023-50089 1 Netgear 2 Wnr2000, Wnr2000 Firmware 2026-06-17 N/A 9.8 CRITICAL
A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication.
CVE-2023-50082 1 Pbootcms 1 Pbootcms 2026-06-17 N/A 7.5 HIGH
Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via session leakage allows a user to avoid logging into the backend management platform.
CVE-2023-50073 1 Leadscloud 1 Empirecms 2026-06-17 N/A 9.8 CRITICAL
EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php.
CVE-2023-50072 1 Openkm 1 Openkm 2026-06-17 N/A 5.4 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated user to upload a note on a file which acts as a stored XSS payload. Any user who opens the note of a document file will trigger the XSS.
CVE-2023-50071 1 Customer Support System Project 1 Customer Support System 2026-06-17 N/A 8.8 HIGH
Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_department via id or name.
CVE-2023-50070 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 8.8 HIGH
Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_ticket via department_id, customer_id, and subject.
CVE-2023-50069 1 Wiremock 1 Wiremock 2026-06-17 N/A 6.1 MEDIUM
WireMock with GUI versions 3.2.0.0 through 3.0.4.0 are vulnerable to stored cross-site scripting (SXSS) through the recording feature. An attacker can host a malicious payload and perform a test mapping pointing to the attacker's file, and the result will render on the Matched page in the Body area, resulting in the execution of the payload. This occurs because the response body is not validated or sanitized.
CVE-2023-50061 1 Store-opart 1 Op\'art Easy Redirect 2026-06-17 N/A 9.8 CRITICAL
PrestaShop Op'art Easy Redirect >= 1.3.8 and <= 1.3.12 is vulnerable to SQL Injection via Oparteasyredirect::hookActionDispatcher().
CVE-2023-50059 2026-06-17 N/A 5.3 MEDIUM
An issue ingalxe.com Galxe platform 1.0 allows a remote attacker to obtain sensitive information via the Web3 authentication process of Galxe, the signed message lacks a nonce (random number)
CVE-2023-50053 2026-06-17 N/A 7.6 HIGH
An issue in Foundation.app Foundation platform 1.0 allows a remote attacker to obtain sensitive information via the Web3 authentication process of Foundation, the signed message lacks a nonce (random number)