Vulnerabilities (CVE)

Total 404108 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-49228 1 Peplink 2 Balance Two, Balance Two Firmware 2026-06-17 N/A 6.4 MEDIUM
An issue was discovered in Peplink Balance Two before 8.4.0. Console port authentication uses hard-coded credentials, which allows an attacker with physical access and sufficient knowledge to execute arbitrary commands as root.
CVE-2023-49226 1 Peplink 2 Balance Two, Balance Two Firmware 2026-06-17 N/A 7.2 HIGH
An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute feature of the administration console allows users with admin privileges to execute arbitrary commands as root.
CVE-2023-49225 2 Commscope, Ruckuswireless 74 Ruckus Smartzone, C110, C110 Firmware and 71 more 2026-06-17 N/A 6.1 MEDIUM
A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in the product. As for the affected products/models/versions, see the information provided by the vendor listed under [References] section or the list under [Product Status] section.
CVE-2023-49224 2026-06-17 N/A 8.0 HIGH
Precor touchscreen console P62, P80, and P82 contains a default SSH public key in the authorized_keys file. A remote attacker could use this key to gain root privileges.
CVE-2023-49223 2026-06-17 N/A 8.8 HIGH
Precor touchscreen console P62, P80, and P82 could allow a remote attacker to obtain sensitive information because the root password is stored in /etc/passwd. An attacker could exploit this to extract files and obtain sensitive information.
CVE-2023-49222 2026-06-17 N/A 8.8 HIGH
Precor touchscreen console P82 contains a private SSH key that corresponds to a default public key. A remote attacker could exploit this to gain root privileges.
CVE-2023-49221 2026-06-17 N/A 7.8 HIGH
Precor touchscreen console P62, P80, and P82 could allow a remote attacker (within the local network) to bypass security restrictions, and access the service menu, because there is a hard-coded service code.
CVE-2023-49216 1 Usedesk 1 Usedesk 2026-06-17 N/A 5.4 MEDIUM
Usedesk before 1.7.57 allows profile stored XSS.
CVE-2023-49215 1 Usedesk 1 Usedesk 2026-06-17 N/A 6.1 MEDIUM
Usedesk before 1.7.57 allows filter reflected XSS.
CVE-2023-49214 1 Usedesk 1 Usedesk 2026-06-17 N/A 9.8 CRITICAL
Usedesk before 1.7.57 allows chat template injection.
CVE-2023-49213 1 Ironmansoftware 1 Powershell Universal 2026-06-17 N/A 8.8 HIGH
The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests if a param block is used, due to invalid sanitization of input strings. The fixed versions are 3.10.2, 4.1.10, and 4.2.1.
CVE-2023-49210 1 Node-openssl Project 1 Node-openssl 2026-06-17 N/A 9.8 CRITICAL
The openssl (aka node-openssl) NPM package through 2.0.0 was characterized as "a nonsense wrapper with no real purpose" by its author, and accepts an opts argument that contains a verb field (used for command execution). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2023-49208 1 Glewlwyd Sso Server Project 1 Glewlwyd Sso Server 2026-06-17 N/A 9.8 CRITICAL
scheme/webauthn.c in Glewlwyd SSO server before 2.7.6 has a possible buffer overflow during FIDO2 credentials validation in webauthn registration.
CVE-2023-49203 1 Technitium 1 Dnsserver 2026-06-17 N/A 7.5 HIGH
Technitium 11.5.3 allows remote attackers to cause a denial of service (bandwidth amplification) because the DNSBomb manipulation causes accumulation of low-rate DNS queries such that there is a large-sized response in a burst of traffic.
CVE-2023-49198 1 Apache 1 Seatunnel 2026-06-17 N/A 7.5 HIGH
Mysql security vulnerability in Apache SeaTunnel. Attackers can read files on the MySQL server by modifying the information in the MySQL URL allowLoadLocalInfile=true&allowUrlInLocalInfile=true&allowLoadLocalInfileInPath=/&maxAllowedPacket=655360 This issue affects Apache SeaTunnel: 1.0.0. Users are recommended to upgrade to version [1.0.1], which fixes the issue.
CVE-2023-49197 1 Apasionados 1 Dofollow Case By Case 2026-06-17 N/A 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Apasionados, Apasionados del Marketing, NetConsulting DoFollow Case by Case.This issue affects DoFollow Case by Case: from n/a through 3.4.2.
CVE-2023-49196 2026-06-17 N/A 4.3 MEDIUM
Missing Authorization vulnerability in Pagelayer Team PageLayer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PageLayer: from n/a through 1.7.7.
CVE-2023-49195 1 Kylephillips 1 Nested Pages 2026-06-17 N/A 5.9 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Phillips Nested Pages allows Stored XSS.This issue affects Nested Pages: from n/a through 3.2.6.
CVE-2023-49194 2026-06-17 N/A 5.3 MEDIUM
Insertion of Sensitive Information Into Debugging Code vulnerability in importify Importify (Dropshipping WooCommerce) importify allows Retrieve Embedded Sensitive Data.This issue affects Importify (Dropshipping WooCommerce): from n/a through <= 1.0.4.
CVE-2023-49193 2026-06-17 N/A 5.3 MEDIUM
Missing Authorization vulnerability in NerdPress Hubbub Lite social-pug allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hubbub Lite: from n/a through <= 1.30.0.