Vulnerabilities (CVE)

Total 403884 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-49546 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 8.8 HIGH
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php.
CVE-2023-49545 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 7.5 HIGH
A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.
CVE-2023-49544 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 4.9 MEDIUM
A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php.
CVE-2023-49543 1 Book Store Management System Project 1 Book Store Management System 2026-06-17 N/A 9.8 CRITICAL
Incorrect access control in Book Store Management System v1 allows attackers to access unauthorized pages and execute administrative functions without authenticating.
CVE-2023-49540 1 Oretnom23 1 Book Store Management System 2026-06-17 N/A 6.1 MEDIUM
Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/history. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the history parameter.
CVE-2023-49539 1 Oretnom23 1 Book Store Management System 2026-06-17 N/A 6.1 MEDIUM
Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/category. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the category parameter.
CVE-2023-49528 2 Fedoraproject, Ffmpeg 2 Fedora, Ffmpeg 2026-06-17 N/A 8.0 HIGH
Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.
CVE-2023-49515 1 Tp-link 4 Tapo C200, Tapo C200 Firmware, Tapo Tc70 and 1 more 2026-06-17 N/A 4.6 MEDIUM
Insecure Permissiosn vulnerability in TP Link TC70 and C200 WIFI Camera v.3 firmware v.1.3.4 and fixed in v.1.3.11 allows a physically proximate attacker to obtain sensitive information via a connection to the UART pin components.
CVE-2023-49508 1 Yetiforce 1 Yetiforce Customer Relationship Management 2026-06-17 N/A 6.5 MEDIUM
Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license parameter in the LibraryLicense.php component.
CVE-2023-49502 2 Fedoraproject, Ffmpeg 2 Fedora, Ffmpeg 2026-06-17 N/A 8.8 HIGH
Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the ff_bwdif_filter_intra_c function in the libavfilter/bwdifdsp.c:125:5 component.
CVE-2023-49501 2 Fedoraproject, Ffmpeg 2 Fedora, Ffmpeg 2026-06-17 N/A 8.0 HIGH
Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component.
CVE-2023-49493 1 Dedecms 1 Dedecms 2026-06-17 N/A 6.1 MEDIUM
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the v parameter at selectimages.php.
CVE-2023-49492 1 Dedecms 1 Dedecms 2026-06-17 N/A 6.1 MEDIUM
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the imgstick parameter at selectimages.php.
CVE-2023-49490 1 Xunruicms 1 Xunruicms 2026-06-17 N/A 6.1 MEDIUM
XunRuiCMS v4.5.5 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /admin.php.
CVE-2023-49489 1 Kodcloud 1 Kodexplorer 2026-06-17 N/A 6.1 MEDIUM
Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive information and escalate privileges via the APP_HOST parameter at config/i18n/en/main.php.
CVE-2023-49488 1 Openfiler 1 Openfiler 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Openfiler ESA v2.99.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the nic parameter.
CVE-2023-49487 1 Jfinalcms Project 1 Jfinalcms 2026-06-17 N/A 5.4 MEDIUM
JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the navigation management department.
CVE-2023-49486 1 Jfinalcms Project 1 Jfinalcms 2026-06-17 N/A 5.4 MEDIUM
JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the model management department.
CVE-2023-49485 1 Jfinalcms Project 1 Jfinalcms 2026-06-17 N/A 5.4 MEDIUM
JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the column management department.
CVE-2023-49484 1 Iteachyou 1 Dreamer Cms 2026-06-17 N/A 5.4 MEDIUM
Dreamer CMS v4.1.3 was discovered to contain a cross-site scripting (XSS) vulnerability in the article management department.