Vulnerabilities (CVE)

Total 403867 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-49743 1 Plugin-planet 1 Dashboard Widget Suite 2026-06-17 N/A 5.9 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Dashboard Widgets Suite allows Stored XSS.This issue affects Dashboard Widgets Suite: from n/a through 3.4.1.
CVE-2023-49742 2026-06-17 N/A 9.9 CRITICAL
Missing Authorization vulnerability in Support Genix.This issue affects Support Genix: from n/a through 1.2.3.
CVE-2023-49741 2026-06-17 N/A 3.7 LOW
Authentication Bypass by Spoofing vulnerability in wpdevart Coming soon and Maintenance mode allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coming soon and Maintenance mode: from n/a through 3.7.3.
CVE-2023-49740 1 S-sols 1 Seraphinite Accelerator 2026-06-17 N/A 7.1 HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Seraphinite Solutions Seraphinite Accelerator allows Reflected XSS.This issue affects Seraphinite Accelerator: from n/a through 2.20.28.
CVE-2023-49739 1 Ideabox 1 Powerpack Addons For Elementor 2026-06-17 N/A 7.1 HIGH
Vulnerability in IdeaBox Creations PowerPack Pro for Elementor.This issue affects PowerPack Pro for Elementor: from n/a through 2.9.23.
CVE-2023-49738 1 Wwbn 1 Avideo 2026-06-17 N/A 7.5 HIGH
An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.
CVE-2023-49736 1 Apache 1 Superset 2026-06-17 N/A 6.5 MEDIUM
A where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow for SQL injection in Apache Superset.This issue affects Apache Superset: before 2.1.2, from 3.0.0 before 3.0.2. Users are recommended to upgrade to version 3.0.2, which fixes the issue.
CVE-2023-49735 1 Apache 1 Tiles 2026-06-17 N/A 7.5 HIGH
** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML definition files, leading to possible path traversal and eventually SSRF/XXE when passing user-controlled data to this key. Passing user-controlled data to this key may be relatively common, as it was also used like that to set the language in the 'tiles-test' application shipped with Tiles. This issue affects Apache Tiles from version 2 onwards. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2023-49734 1 Apache 1 Superset 2026-06-17 N/A 7.7 HIGH
An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the charts allowing him to incorrectly have write permissions to these charts.This issue affects Apache Superset: before 2.1.2, from 3.0.0 before 3.0.2. Users are recommended to upgrade to version 3.0.2 or 2.1.3, which fixes the issue.
CVE-2023-49733 1 Apache 1 Cocoon 2026-06-17 N/A 9.8 CRITICAL
Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.
CVE-2023-49722 1 Bosch 6 Bcc101, Bcc101 Firmware, Bcc102 and 3 more 2026-06-17 N/A 8.3 HIGH
Network port 8899 open in WiFi firmware of BCC101/BCC102/BCC50 products, that allows an attacker to connect to the device via same WiFi network.
CVE-2023-49721 2 Canonical, Tianocore 2 Lxd, Edk2 2026-06-17 N/A 6.7 MEDIUM
An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.
CVE-2023-49716 1 Emerson 6 Gc1500xa, Gc1500xa Firmware, Gc370xa and 3 more 2026-06-17 N/A 6.9 MEDIUM
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote computer.
CVE-2023-49715 1 Wwbn 1 Avideo 2026-06-17 N/A 4.3 MEDIUM
A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary code execution when chained with an LFI vulnerability. An attacker can send a series of HTTP requests to trigger this vulnerability.
CVE-2023-49713 1 Jtekt 20 Gc-a22w-cw, Gc-a22w-cw Firmware, Gc-a24 and 17 more 2026-06-17 N/A 7.5 HIGH
Denial-of-service (DoS) vulnerability exists in NetBIOS service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.
CVE-2023-49708 1 Joomstar 1 Starshop 2026-06-17 N/A 9.8 CRITICAL
SQLi vulnerability in Starshop component for Joomla.
CVE-2023-49707 1 Joomlart 1 S5 Register 2026-06-17 N/A 9.8 CRITICAL
SQLi vulnerability in S5 Register module for Joomla.
CVE-2023-49706 1 Linotp 2 Linotp, Virtual Appliance 2026-06-17 N/A 6.8 MEDIUM
Defective request context handling in Self Service in LinOTP 3.x before 3.2.5 allows remote unauthenticated attackers to escalate privileges, thereby allowing them to act as and with the permissions of another user. Attackers must generate repeated API requests to trigger a race condition with concurrent user activity in the self-service portal.
CVE-2023-49701 1 Asrmicro 4 Asr1803, Asr1803 Firmware, Asr1806 and 1 more 2026-06-17 N/A 7.2 HIGH
Memory Corruption in SIM management while USIMPhase2init
CVE-2023-49700 1 Asrmicro 4 Asr1803, Asr1803 Firmware, Asr1806 and 1 more 2026-06-17 N/A 6.7 MEDIUM
Security best practices violations, a string operation in Streamingmedia will write past the end of fixed-size destination buffer if the source buffer is too large.