CVE-2023-50100

JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via carousel image editing.
Max CVSS
5.4
Published
2023-12-14
Updated
2023-12-16
EPSS
0.05%

CVE-2023-50096

STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus. This is caused by an StSafeA_ReceiveBytes buffer overflow in the X-CUBE-SAFEA1 Software Package for STSAFE-A sample applications (1.2.0), and thus can affect user-written code that was derived from a published sample application.
Max CVSS
0.0
Published
2024-01-01
Updated
2024-01-01

CVE-2023-50094

reNgine through 2.0.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via subprocess.check_output.
Max CVSS
0.0
Published
2024-01-01
Updated
2024-01-01

CVE-2023-50089

A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication.
Max CVSS
9.8
Published
2023-12-15
Updated
2023-12-19
EPSS
0.17%

CVE-2023-50073

EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php.
Max CVSS
9.8
Published
2023-12-14
Updated
2023-12-18
EPSS
0.08%

CVE-2023-50071

Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_department via id or name.
Max CVSS
0.0
Published
2023-12-29
Updated
2024-01-01
EPSS
0.04%

CVE-2023-50070

Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_ticket via department_id, customer_id, and subject.
Max CVSS
0.0
Published
2023-12-29
Updated
2024-01-01
EPSS
0.04%

CVE-2023-50069

WireMock with GUI versions 3.2.0.0 through 3.0.4.0 are vulnerable to stored cross-site scripting (SXSS) through the recording feature. An attacker can host a malicious payload and perform a test mapping pointing to the attacker's file, and the result will render on the Matched page in the Body area, resulting in the execution of the payload. This occurs because the response body is not validated or sanitized.
Max CVSS
0.0
Published
2023-12-29
Updated
2024-01-01
EPSS
0.04%

CVE-2023-50044

Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an input string.
Max CVSS
9.8
Published
2023-12-20
Updated
2023-12-29
EPSS
0.09%

CVE-2023-50038

There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions.
Max CVSS
0.0
Published
2023-12-28
Updated
2023-12-28
EPSS
0.04%

CVE-2023-50035

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is directly used in the SQL query without any sanitization and the SQL Injection payload being executed.
Max CVSS
0.0
Published
2023-12-29
Updated
2024-01-01
EPSS
0.04%

CVE-2023-50017

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/database/backup
Max CVSS
8.8
Published
2023-12-14
Updated
2023-12-19
EPSS
0.06%

CVE-2023-50011

PopojiCMS version 2.0.1 is vulnerable to remote command execution in the Meta Social field.
Max CVSS
7.2
Published
2023-12-14
Updated
2023-12-19
EPSS
0.31%

CVE-2023-50002

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formRebootMeshNode.
Max CVSS
9.8
Published
2023-12-07
Updated
2023-12-09
EPSS
0.09%

CVE-2023-50001

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formUpgradeMeshOnline.
Max CVSS
9.8
Published
2023-12-07
Updated
2023-12-09
EPSS
0.09%

CVE-2023-50000

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formResetMeshNode.
Max CVSS
9.8
Published
2023-12-07
Updated
2023-12-09
EPSS
0.09%

CVE-2023-49999

Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setUmountUSBPartition.
Max CVSS
9.8
Published
2023-12-07
Updated
2023-12-09
EPSS
0.11%

CVE-2023-49994

Espeak-ng 1.52-dev was discovered to contain a Floating Point Exception via the function PeaksToHarmspect at wavegen.c.
Max CVSS
5.5
Published
2023-12-12
Updated
2023-12-14
EPSS
0.06%

CVE-2023-49993

Espeak-ng 1.52-dev was discovered to contain a Buffer Overflow via the function ReadClause at readclause.c.
Max CVSS
5.3
Published
2023-12-12
Updated
2023-12-18
EPSS
0.04%

CVE-2023-49992

Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Overflow via the function RemoveEnding at dictionary.c.
Max CVSS
5.3
Published
2023-12-12
Updated
2023-12-18
EPSS
0.04%

CVE-2023-49991

Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Underflow via the function CountVowelPosition at synthdata.c.
Max CVSS
5.3
Published
2023-12-12
Updated
2023-12-18
EPSS
0.04%

CVE-2023-49990

Espeak-ng 1.52-dev was discovered to contain a buffer-overflow via the function SetUpPhonemeTable at synthdata.c.
Max CVSS
5.3
Published
2023-12-12
Updated
2023-12-18
EPSS
0.04%

CVE-2023-49967

Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc.
Max CVSS
7.5
Published
2023-12-07
Updated
2023-12-09
EPSS
0.05%

CVE-2023-49964

An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restrictions and achieve RCE (Remote Code Execution). NOTE: this issue exists because of an incomplete fix for CVE-2020-12873.
Max CVSS
0.0
Published
2023-12-11
Updated
2023-12-11
EPSS
0.10%

CVE-2023-49958

An issue was discovered in Dalmann OCPP.Core through 1.2.0 for OCPP (Open Charge Point Protocol) for electric vehicles. The server processes mishandle StartTransaction messages containing additional, arbitrary properties, or duplicate properties. The last occurrence of a duplicate property is accepted. This could be exploited to alter transaction records or impact system integrity.
Max CVSS
7.5
Published
2023-12-07
Updated
2023-12-13
EPSS
0.05%
50 vulnerabilities found
1 2 3 4 5 6 ...... 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 ...... 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50