Vulnerabilities (CVE)

Total 404335 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-48106 1 Zlib-ng 1 Minizip-ng 2026-06-17 N/A 8.8 HIGH
Buffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the mz_path_resolve function in the mz_os.c file.
CVE-2023-48104 1 Alinto 1 Sogo 2026-06-17 N/A 6.1 MEDIUM
Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.
CVE-2023-48094 1 Cesium 1 Cesiumjs 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in CesiumJS v1.111 allows attackers to execute arbitrary code in the context of the victim's browser via sending a crafted payload to /container_files/public_html/doc/index.html. NOTE: the vendor’s position is that Apps/Sandcastle/standalone.html is part of the CesiumGS/cesium GitHub repository, but is demo code that is not part of the CesiumJS JavaScript library product.
CVE-2023-48090 1 Gpac 1 Gpac 2026-06-17 N/A 7.1 HIGH
GPAC 2.3-DEV-rev617-g671976fcc-master is vulnerable to memory leaks in extract_attributes media_tools/m3u8.c:329.
CVE-2023-48089 1 Xuxueli 1 Xxl-job 2026-06-17 N/A 8.8 HIGH
xxl-job-admin 2.4.0 is vulnerable to Remote Code Execution (RCE) via /xxl-job-admin/jobcode/save.
CVE-2023-48088 1 Xuxueli 1 Xxl-job 2026-06-17 N/A 5.4 MEDIUM
xxl-job-admin 2.4.0 is vulnerable to Cross Site Scripting (XSS) via /xxl-job-admin/joblog/logDetailPage.
CVE-2023-48087 1 Xuxueli 1 Xxl-job 2026-06-17 N/A 5.4 MEDIUM
xxl-job-admin 2.4.0 is vulnerable to Insecure Permissions via /xxl-job-admin/joblog/clearLog and /xxl-job-admin/joblog/logDetailCat.
CVE-2023-48085 1 Nagios 1 Nagios Xi 2026-06-17 N/A 9.8 CRITICAL
Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php.
CVE-2023-48084 1 Nagios 1 Nagios Xi 2026-06-17 N/A 9.8 CRITICAL
Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.
CVE-2023-48082 1 Nagios 1 Nagios Xi 2026-06-17 N/A 9.1 CRITICAL
Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers to possibly generate the same set of API keys for all users and utilize them to authenticate.
CVE-2023-48078 1 Code-projects 1 Simple Crud Functionality 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in add.php in Simple CRUD Functionality v1.0 allows attackers to run arbitrary SQL commands via the 'title' parameter.
CVE-2023-48068 1 Dedecms 1 Dedecms 2026-06-17 N/A 5.4 MEDIUM
DedeCMS v6.2 was discovered to contain a Cross-site Scripting (XSS) vulnerability via spec_add.php.
CVE-2023-48063 1 Iteachyou 1 Dreamer Cms 2026-06-17 N/A 4.3 MEDIUM
An issue was discovered in dreamer_cms 4.1.3. There is a CSRF vulnerability that can delete a theme project via /admin/category/delete.
CVE-2023-48060 1 Iteachyou 1 Dreamer Cms 2026-06-17 N/A 8.8 HIGH
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/add
CVE-2023-48058 1 Iteachyou 1 Dreamer Cms 2026-06-17 N/A 8.8 HIGH
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/run
CVE-2023-48055 1 Superagi 1 Superagi 2026-06-17 N/A 7.5 HIGH
SuperAGI v0.0.13 was discovered to use a hardcoded key for encryption operations. This vulnerability can lead to the disclosure of information and communications.
CVE-2023-48054 1 Localstack 1 Localstack 2026-06-17 N/A 7.4 HIGH
Missing SSL certificate validation in localstack v2.3.2 allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack.
CVE-2023-48053 1 Archerydms 1 Archery 2026-06-17 N/A 7.5 HIGH
Archery v1.10.0 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications.
CVE-2023-48052 1 Httpie 1 Httpie 2026-06-17 N/A 7.4 HIGH
Missing SSL certificate validation in HTTPie v3.2.2 allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack.
CVE-2023-48051 1 Carglglz 1 Upydev 2026-06-17 N/A 7.5 HIGH
An issue in /upydev/keygen.py in upydev v0.4.3 allows attackers to decrypt sensitive information via weak encryption padding.