Vulnerabilities (CVE)

Total 403849 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-49982 1 Oretnom23 1 School Fees Management System 2026-06-17 N/A 8.8 HIGH
Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and deleting user accounts.
CVE-2023-49981 1 Oretnom23 1 School Fees Management System 2026-06-17 N/A 7.5 HIGH
A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.
CVE-2023-49980 1 Mayurik 1 Best Student Result Management System 2026-06-17 N/A 7.5 HIGH
A directory listing vulnerability in Best Student Result Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.
CVE-2023-49979 1 Mayurik 1 Best Student Management System 2026-06-17 N/A 7.5 HIGH
A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.
CVE-2023-49978 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 8.8 HIGH
Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for administrators.
CVE-2023-49977 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the address parameter at /customer_support/index.php?page=new_customer.
CVE-2023-49976 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the subject parameter at /customer_support/index.php?page=new_ticket.
CVE-2023-49974 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the contact parameter at /customer_support/index.php?page=customer_list.
CVE-2023-49973 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter at /customer_support/index.php?page=customer_list.
CVE-2023-49971 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter at /customer_support/index.php?page=customer_list.
CVE-2023-49970 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 9.8 CRITICAL
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/ajax.php?action=save_ticket.
CVE-2023-49969 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 4.3 MEDIUM
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer.
CVE-2023-49968 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 7.3 HIGH
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/manage_department.php.
CVE-2023-49967 1 Typecho 1 Typecho 2026-06-17 N/A 7.5 HIGH
Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc.
CVE-2023-49965 2026-06-17 N/A 6.8 MEDIUM
SpaceX Starlink Wi-Fi router Gen 2 before 2023.48.0 allows XSS via the ssid and password parameters on the Setup Page.
CVE-2023-49964 1 Hyland 1 Alfresco Content Services 2026-06-17 N/A 8.8 HIGH
An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restrictions and achieve RCE (Remote Code Execution). NOTE: this issue exists because of an incomplete fix for CVE-2020-12873.
CVE-2023-49963 2026-06-17 N/A 8.8 HIGH
DYMO LabelWriter Print Server through 2.366 contains a backdoor hard-coded password that could allow an attacker to take control.
CVE-2023-49961 1 Wallix 2 Bastion, Bastion Access Manager 2026-06-17 N/A 7.5 HIGH
WALLIX Bastion 7.x, 8.x, 9.x and 10.x and WALLIX Access Manager 3.x and 4.x have Incorrect Access Control which can lead to sensitive data exposure.
CVE-2023-49960 1 Indu-sol 2 Profinet-inspektor Nt, Profinet-inspektor Nt Firmware 2026-06-17 N/A 7.5 HIGH
In Indo-Sol PROFINET-INspektor NT through 2.4.0, a path traversal vulnerability in the httpuploadd service of the firmware allows remote attackers to write to arbitrary files via a crafted filename parameter in requests to the /upload endpoint.
CVE-2023-49959 1 Indu-sol 1 Profinet-inspektor Nt 2026-06-17 N/A 9.8 CRITICAL
In Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the gedtupdater service of the firmware allows remote attackers to execute arbitrary system commands with root privileges via a crafted filename parameter in POST requests to the /api/updater/ctrl/start_update endpoint.