Vulnerabilities (CVE)

Total 404131 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-48930 1 Rockoa 1 Xinhu 2026-06-17 N/A 9.8 CRITICAL
xinhu xinhuoa 2.2.1 contains a File upload vulnerability.
CVE-2023-48929 1 Franklin-electric 1 System Sentinel Anyware 2026-06-17 N/A 9.8 CRITICAL
Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Session Fixation. The 'sid' parameter in the group_status.asp resource allows an attacker to escalate privileges and obtain sensitive information.
CVE-2023-48928 1 Franklin-electric 1 System Sentinel Anyware 2026-06-17 N/A 6.1 MEDIUM
Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Open Redirect. The 'path' parameter of the prefs.asp resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.
CVE-2023-48926 1 Prestashop 1 Advanced Loyalty Program 2026-06-17 N/A 5.3 MEDIUM
An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated attackers to arbitrarily change an order status.
CVE-2023-48925 1 Buy-addons 1 Bavideotab 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in Buy Addons bavideotab before version 1.0.6, allows attackers to escalate privileges and obtain sensitive information via the component BaVideoTabSaveVideoModuleFrontController::run().
CVE-2023-48914 1 Iteachyou 1 Dreamer Cms 2026-06-17 N/A 8.8 HIGH
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/archives/add.
CVE-2023-48913 1 Iteachyou 1 Dreamer Cms 2026-06-17 N/A 8.8 HIGH
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/archives/delete.
CVE-2023-48912 1 Iteachyou 1 Dreamer Cms 2026-06-17 N/A 8.8 HIGH
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/archives/edit.
CVE-2023-48910 1 Microcks 1 Microcks 2026-06-17 N/A 9.8 CRITICAL
Microcks up to 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.
CVE-2023-48909 1 Aarboard 1 Jave2 2026-06-17 N/A 8.8 HIGH
An issue was discovered in Jave2 version 3.3.1, allows attackers to execute arbitrary code via the FFmpeg function.
CVE-2023-48906 2026-06-17 N/A 4.3 MEDIUM
Stack Overflow vulnerability in Btstack 1.6 and earlier allows attackers to cause a denial of service via crafted input to the char_for_nibble function.
CVE-2023-48903 1 Tramyardg 1 Autoexpress 2026-06-17 N/A 6.1 MEDIUM
Stored Cross-Site Scripting (XSS) vulnerability in tramyardg autoexpress 1.3.0, allows remote unauthenticated attackers to inject arbitrary web script or HTML within parameter "imgType" via in uploadCarImages.php.
CVE-2023-48902 1 Tramyardg 1 Autoexpress 2026-06-17 N/A 9.8 CRITICAL
An issue was discovered in tramyardg autoexpress version 1.3.0, allows unauthenticated remote attackers to escalate privileges, update car data, delete vehicles, and upload car images via authentication bypass in uploadCarImages.php.
CVE-2023-48901 1 Tramyardg 1 Autoexpress 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated attackers to execute arbitrary SQL commands via the parameter "id" within the getPhotosByCarId function call in details.php.
CVE-2023-48894 1 Huaxiaerp 1 Jsherp 2026-06-17 N/A 6.5 MEDIUM
Incorrect Access Control vulnerability in jshERP V3.3 allows attackers to obtain sensitive information via the doFilter function.
CVE-2023-48893 1 Slims 1 Senayan Library Management System Bulian 2026-06-17 N/A 8.8 HIGH
SLiMS (aka SENAYAN Library Management System) through 9.6.1 allows admin/modules/reporting/customs/staff_act.php SQL Injection via startDate or untilDate.
CVE-2023-48887 1 Fengjiachun 1 Jupiter 2026-06-17 N/A 9.8 CRITICAL
A deserialization vulnerability in Jupiter v1.3.1 allows attackers to execute arbitrary commands via sending a crafted RPC request.
CVE-2023-48886 1 Luxiaoxun 1 Nettyrpc 2026-06-17 N/A 9.8 CRITICAL
A deserialization vulnerability in NettyRpc v1.2 allows attackers to execute arbitrary commands via sending a crafted RPC request.
CVE-2023-48882 1 Eyoucms 1 Eyoucms 2026-06-17 N/A 4.8 MEDIUM
A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Document Properties field at /login.php m=admin&c=Index&a=changeTableVal&_ajax=1&lang=cn.
CVE-2023-48881 1 Eyoucms 1 Eyoucms 2026-06-17 N/A 4.8 MEDIUM
A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Field Title field at /login.php?m=admin&c=Field&a=arctype_add&_ajax=1&lang=cn.