Total
403391 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-50123 | 1 Hozard | 1 Alarm System | 2026-06-17 | N/A | 8.1 HIGH |
| The number of attempts to bring the Hozard Alarm system (alarmsystemen) v1.0 to a disarmed state is not limited. This could allow an attacker to perform a brute force on the SMS authentication, to bring the alarm system to a disarmed state. | |||||
| CVE-2023-50121 | 1 Autelrobotics | 2 Evo Nano Drone, Evo Nano Drone Firmware | 2026-06-17 | N/A | 5.7 MEDIUM |
| Autel EVO NANO drone flight control firmware version 1.6.5 is vulnerable to denial of service (DoS). | |||||
| CVE-2023-50120 | 1 Gpac | 1 Gpac | 2026-06-17 | N/A | 5.5 MEDIUM |
| MP4Box GPAC version 2.3-DEV-rev636-gfbd7e13aa-master was discovered to contain an infinite loop in the function av1_uvlc at media_tools/av_parsers.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file. | |||||
| CVE-2023-50110 | 1 Testlink | 1 Testlink | 2026-06-17 | N/A | 7.5 HIGH |
| TestLink through 1.9.20 allows type juggling for authentication bypass because === is not used. | |||||
| CVE-2023-50104 | 1 Zzcms | 1 Zzcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| ZZCMS 2023 has a file upload vulnerability in 3/E_bak5.1/upload/index.php, allowing attackers to exploit this loophole to gain server privileges and execute arbitrary code. | |||||
| CVE-2023-50102 | 1 Jfinalcms Project | 1 Jfinalcms | 2026-06-17 | N/A | 5.4 MEDIUM |
| JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS). | |||||
| CVE-2023-50101 | 1 Jfinalcms Project | 1 Jfinalcms | 2026-06-17 | N/A | 5.4 MEDIUM |
| JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via Label management editing. | |||||
| CVE-2023-50100 | 1 Jfinalcms Project | 1 Jfinalcms | 2026-06-17 | N/A | 5.4 MEDIUM |
| JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via carousel image editing. | |||||
| CVE-2023-50096 | 1 St | 1 X-cube-safea1 | 2026-06-17 | N/A | 7.5 HIGH |
| STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus. This is caused by an StSafeA_ReceiveBytes buffer overflow in the X-CUBE-SAFEA1 Software Package for STSAFE-A sample applications (1.2.0), and thus can affect user-written code that was derived from a published sample application. | |||||
| CVE-2023-50094 | 1 Yogeshojha | 1 Rengine | 2026-06-17 | N/A | 8.8 HIGH |
| reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via subprocess.check_output. | |||||
| CVE-2023-50093 | 1 Apiida | 1 Api Gateway Manager | 2026-06-17 | N/A | 6.1 MEDIUM |
| APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection. | |||||
| CVE-2023-50092 | 1 Apiida | 1 Api Gateway Manager | 2026-06-17 | N/A | 6.1 MEDIUM |
| APIIDA API Gateway Manager for Broadcom Layer7 v2023.2 is vulnerable to Cross Site Scripting (XSS). | |||||
| CVE-2023-50090 | 1 Ureport2 Project | 1 Ureport2 | 2026-06-17 | N/A | 9.8 CRITICAL |
| Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write arbitrary files and run arbitrary commands via crafted POST request. | |||||
| CVE-2023-50089 | 1 Netgear | 2 Wnr2000, Wnr2000 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication. | |||||
| CVE-2023-50082 | 1 Pbootcms | 1 Pbootcms | 2026-06-17 | N/A | 7.5 HIGH |
| Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via session leakage allows a user to avoid logging into the backend management platform. | |||||
| CVE-2023-50073 | 1 Leadscloud | 1 Empirecms | 2026-06-17 | N/A | 9.8 CRITICAL |
| EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php. | |||||
| CVE-2023-50072 | 1 Openkm | 1 Openkm | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated user to upload a note on a file which acts as a stored XSS payload. Any user who opens the note of a document file will trigger the XSS. | |||||
| CVE-2023-50071 | 1 Customer Support System Project | 1 Customer Support System | 2026-06-17 | N/A | 8.8 HIGH |
| Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_department via id or name. | |||||
| CVE-2023-50070 | 1 Oretnom23 | 1 Customer Support System | 2026-06-17 | N/A | 8.8 HIGH |
| Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_ticket via department_id, customer_id, and subject. | |||||
| CVE-2023-50069 | 1 Wiremock | 1 Wiremock | 2026-06-17 | N/A | 6.1 MEDIUM |
| WireMock with GUI versions 3.2.0.0 through 3.0.4.0 are vulnerable to stored cross-site scripting (SXSS) through the recording feature. An attacker can host a malicious payload and perform a test mapping pointing to the attacker's file, and the result will render on the Matched page in the Body area, resulting in the execution of the payload. This occurs because the response body is not validated or sanitized. | |||||
