Vulnerabilities (CVE)

Total 404335 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-48207 1 Phpjabbers 1 Availability Booking Calendar 2026-06-17 N/A 8.8 HIGH
Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.
CVE-2023-48206 1 Mayurik 1 Courier Management System 2026-06-17 N/A 6.1 MEDIUM
A Cross Site Scripting (XSS) vulnerability in GaatiTrack Courier Management System 1.0 allows a remote attacker to inject JavaScript via the page parameter to login.php or header.php.
CVE-2023-48205 1 Jorani 1 Leave Management System 2026-06-17 N/A 5.3 MEDIUM
Jorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emails.
CVE-2023-48204 1 Publiccms 1 Publiccms 2026-06-17 N/A 6.5 MEDIUM
An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters parameter of the api/method/getHtml component.
CVE-2023-48202 1 Sunlight-cms 1 Sunlight Cms 2026-06-17 N/A 5.4 MEDIUM
Cross-Site Scripting (XSS) vulnerability in Sunlight CMS 8.0.1 allows an authenticated low-privileged user to escalate privileges via a crafted SVG file in the File Manager component.
CVE-2023-48201 1 Sunlight-cms 1 Sunlight Cms 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in Sunlight CMS v.8.0.1, allows remote authenticated attackers to execute arbitrary code and escalate privileges via a crafted script to the Content text editor component.
CVE-2023-48200 1 Grocy Project 1 Grocy 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Grocy v.4.0.3 allows a local attacker to execute arbitrary code and obtain sensitive information via the equipment description component within /equipment/ component.
CVE-2023-48199 1 Grocy Project 1 Grocy 2026-06-17 N/A 7.8 HIGH
HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTML content without script execution. This occurs when user-supplied data is not appropriately sanitized, enabling the injection of HTML tags through parameter values. The attacker can then manipulate page content in the QR code detail popup, often coupled with social engineering tactics, exploiting both the trust of users and the application's lack of proper input handling.
CVE-2023-48198 1 Grocy Project 1 Grocy 2026-06-17 N/A 5.4 MEDIUM
A Cross-Site Scripting (XSS) vulnerability in the 'product description' component within '/api/stock/products' of Grocy version <= 4.0.3 allows attackers to obtain a victim's cookies.
CVE-2023-48197 1 Grocy Project 1 Grocy 2026-06-17 N/A 5.4 MEDIUM
Cross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and earlier allows attackers to obtain victim's cookies when the victim clicks on the "see QR code" function.
CVE-2023-48188 1 Store-opart 1 Op\'art Devis 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in PrestaShop opartdevis v.4.5.18 thru v.4.6.12 allows a remote attacker to execute arbitrary code via a crafted script to the getModuleTranslation function.
CVE-2023-48185 1 Terra-mater 1 Terra-master 2026-06-17 N/A 7.5 HIGH
Directory Traversal vulnerability in TerraMaster v.s1.0 through v.2.295 allows a remote attacker to obtain sensitive information via a crafted GET request.
CVE-2023-48184 1 Quickjs Project 1 Quickjs 2026-06-17 N/A 3.9 LOW
QuickJS before 7414e5f has a quickjs.h JS_FreeValueRT use-after-free because of incorrect garbage collection of async functions with closures.
CVE-2023-48183 1 Quickjs Project 1 Quickjs 2026-06-17 N/A 7.5 HIGH
QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an erroneous lexical scope of "this" with eval.
CVE-2023-48176 1 Mizhexiaoxiao 1 Websiteguide 2026-06-17 N/A 9.8 CRITICAL
An Insecure Permissions issue in WebsiteGuide v.0.2 allows a remote attacker to gain escalated privileges via crafted jwt (JSON web token).
CVE-2023-48172 1 Phpjabbers 1 Shuttle Booking Software 2026-06-17 N/A 5.4 MEDIUM
A Cross Site Scripting (XSS) vulnerability in Shuttle Booking Software 2.0 allows a remote attacker to inject JavaScript via the name, description, title, or address parameter to index.php.
CVE-2023-48171 1 Owasp 1 Defectdojo 2026-06-17 N/A 8.8 HIGH
An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.
CVE-2023-48166 1 Unify 1 Openscape Voice 2026-06-17 N/A 7.5 HIGH
A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attacker to view the contents of arbitrary files in the local file system. An unauthenticated attacker might obtain sensitive files that allow for the compromise of the underlying system.
CVE-2023-48135 1 Linecorp 1 Line 2026-06-17 N/A 5.4 MEDIUM
An issue in mimasaka_farm mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
CVE-2023-48134 1 Linecorp 1 Line 2026-06-17 N/A 7.5 HIGH
nagayama_copabowl Line 13.6.1 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor.