Total
403248 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-50073 | 1 Leadscloud | 1 Empirecms | 2026-06-17 | N/A | 9.8 CRITICAL |
| EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php. | |||||
| CVE-2023-50072 | 1 Openkm | 1 Openkm | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated user to upload a note on a file which acts as a stored XSS payload. Any user who opens the note of a document file will trigger the XSS. | |||||
| CVE-2023-50071 | 1 Customer Support System Project | 1 Customer Support System | 2026-06-17 | N/A | 8.8 HIGH |
| Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_department via id or name. | |||||
| CVE-2023-50070 | 1 Oretnom23 | 1 Customer Support System | 2026-06-17 | N/A | 8.8 HIGH |
| Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_ticket via department_id, customer_id, and subject. | |||||
| CVE-2023-50069 | 1 Wiremock | 1 Wiremock | 2026-06-17 | N/A | 6.1 MEDIUM |
| WireMock with GUI versions 3.2.0.0 through 3.0.4.0 are vulnerable to stored cross-site scripting (SXSS) through the recording feature. An attacker can host a malicious payload and perform a test mapping pointing to the attacker's file, and the result will render on the Matched page in the Body area, resulting in the execution of the payload. This occurs because the response body is not validated or sanitized. | |||||
| CVE-2023-50061 | 1 Store-opart | 1 Op\'art Easy Redirect | 2026-06-17 | N/A | 9.8 CRITICAL |
| PrestaShop Op'art Easy Redirect >= 1.3.8 and <= 1.3.12 is vulnerable to SQL Injection via Oparteasyredirect::hookActionDispatcher(). | |||||
| CVE-2023-50059 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| An issue ingalxe.com Galxe platform 1.0 allows a remote attacker to obtain sensitive information via the Web3 authentication process of Galxe, the signed message lacks a nonce (random number) | |||||
| CVE-2023-50053 | 2026-06-17 | N/A | 7.6 HIGH | ||
| An issue in Foundation.app Foundation platform 1.0 allows a remote attacker to obtain sensitive information via the Web3 authentication process of Foundation, the signed message lacks a nonce (random number) | |||||
| CVE-2023-50044 | 1 Cesanta | 1 Mjs | 2026-06-17 | N/A | 9.8 CRITICAL |
| Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an input string. | |||||
| CVE-2023-50038 | 1 Textpattern | 1 Textpattern | 2026-06-17 | N/A | 8.8 HIGH |
| There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions. | |||||
| CVE-2023-50035 | 1 Small Crm Project | 1 Small Crm | 2026-06-17 | N/A | 9.8 CRITICAL |
| PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is directly used in the SQL query without any sanitization and the SQL Injection payload being executed. | |||||
| CVE-2023-50030 | 1 Joommasters | 1 Jmssetting | 2026-06-17 | N/A | 9.8 CRITICAL |
| In the module "Jms Setting" (jmssetting) from Joommasters for PrestaShop, a guest can perform SQL injection in versions <= 1.1.0. The method `JmsSetting::getSecondImgs()` has a sensitive SQL call that can be executed with a trivial http call and exploited to forge a blind SQL injection. | |||||
| CVE-2023-50029 | 2026-06-17 | N/A | 10.0 CRITICAL | ||
| PHP Injection vulnerability in the module "M4 PDF Extensions" (m4pdf) up to version 3.3.2 from PrestaAddons for PrestaShop allows attackers to run arbitrary code via the M4PDF::saveTemplate() method. | |||||
| CVE-2023-50028 | 1 Prestashopmodules | 1 Sliding Cart Block | 2026-06-17 | N/A | 9.8 CRITICAL |
| In the module "Sliding cart block" (blockslidingcart) up to version 2.3.8 from PrestashopModules.eu for PrestaShop, a guest can perform SQL injection. | |||||
| CVE-2023-50027 | 1 Buy-addons | 1 Bazoom Magnifier | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in Buy Addons baproductzoommagnifier module for PrestaShop versions 1.0.16 and before, allows remote attackers to escalate privileges and gain sensitive information via BaproductzoommagnifierZoomModuleFrontController::run() method. | |||||
| CVE-2023-50026 | 1 Prestamonster | 1 Multi Accessories Pro | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro) module for PrestaShop versions 5.1.1 and before, allows remote attackers to escalate privileges and obtain sensitive information via the method HsAccessoriesGroupProductAbstract::getAccessoriesByIdProducts(). | |||||
| CVE-2023-50020 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 7.5 HIGH |
| An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF. | |||||
| CVE-2023-50019 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 5.9 MEDIUM |
| An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response. | |||||
| CVE-2023-50017 | 1 Iteachyou | 1 Dreamer Cms | 2026-06-17 | N/A | 8.8 HIGH |
| Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/database/backup | |||||
| CVE-2023-50015 | 2026-06-17 | N/A | 8.8 HIGH | ||
| An issue was discovered in Grandstream GXP14XX 1.0.8.9 and GXP16XX 1.0.7.13, allows remote attackers to escalate privileges via incorrect access control using an end-user session-identity token. | |||||
