CVE-2023-49402

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg.
Max CVSS
9.8
Published
2023-12-07
Updated
2023-12-09
EPSS
0.09%

CVE-2023-49398

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/delete.
Max CVSS
8.8
Published
2023-12-05
Updated
2023-12-09
EPSS
0.06%

CVE-2023-49397

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/updateStatus.
Max CVSS
8.8
Published
2023-12-05
Updated
2023-12-09
EPSS
0.06%

CVE-2023-49396

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/save.
Max CVSS
8.8
Published
2023-12-05
Updated
2023-12-09
EPSS
0.06%

CVE-2023-49395

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/update.
Max CVSS
8.8
Published
2023-12-05
Updated
2023-12-09
EPSS
0.06%

CVE-2023-49391

An issue was discovered in free5GC version 3.3.0, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) on AMF component via crafted NGAP message.
Max CVSS
0.0
Published
2023-12-22
Updated
2023-12-22
EPSS
0.05%

CVE-2023-49383

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/save.
Max CVSS
8.8
Published
2023-12-05
Updated
2023-12-09
EPSS
0.06%

CVE-2023-49382

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/delete.
Max CVSS
8.8
Published
2023-12-05
Updated
2023-12-09
EPSS
0.06%

CVE-2023-49381

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/update.
Max CVSS
8.8
Published
2023-12-05
Updated
2023-12-09
EPSS
0.06%

CVE-2023-49380

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/delete.
Max CVSS
8.8
Published
2023-12-05
Updated
2023-12-09
EPSS
0.06%

CVE-2023-49379

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /admin/friend_link/save.
Max CVSS
8.8
Published
2023-12-05
Updated
2023-12-09
EPSS
0.06%

CVE-2023-49378

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/form/save.
Max CVSS
8.8
Published
2023-12-05
Updated
2023-12-09
EPSS
0.06%

CVE-2023-49377

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/update.
Max CVSS
8.8
Published
2023-12-05
Updated
2023-12-09
EPSS
0.06%

CVE-2023-49376

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/delete.
Max CVSS
8.8
Published
2023-12-05
Updated
2023-12-09
EPSS
0.06%

CVE-2023-49375

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/update.
Max CVSS
8.8
Published
2023-12-05
Updated
2023-12-09
EPSS
0.06%

CVE-2023-49374

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/slide/update.
Max CVSS
8.8
Published
2023-12-05
Updated
2023-12-09
EPSS
0.06%

CVE-2023-49373

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/slide/delete.
Max CVSS
8.8
Published
2023-12-05
Updated
2023-12-09
EPSS
0.06%

CVE-2023-49372

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/slide/save.
Max CVSS
8.8
Published
2023-12-05
Updated
2023-12-09
EPSS
0.06%

CVE-2023-49371

RuoYi up to v4.6 was discovered to contain a SQL injection vulnerability via /system/dept/edit.
Max CVSS
9.8
Published
2023-12-01
Updated
2023-12-06
EPSS
0.08%

CVE-2023-49363

Rockoa <2.3.3 is vulnerable to SQL Injection. The problem exists in the indexAction method in reimpAction.php.
Max CVSS
9.8
Published
2023-12-13
Updated
2023-12-18
EPSS
0.08%

CVE-2023-49356

A stack buffer overflow vulnerability in MP3Gain v1.6.2 allows an attacker to cause a denial of service via the WriteMP3GainAPETag function at apetag.c:592.
Max CVSS
7.5
Published
2023-12-22
Updated
2023-12-29
EPSS
0.05%

CVE-2023-49355

decToString in decNumber/decNumber.c in jq 88f01a7 has a one-byte out-of-bounds write via the " []-1.2e-1111111111" input. NOTE: this is not the same as CVE-2023-50246. The CVE-2023-50246 71c2ab5 reference mentions -10E-1000010001, which is not in normalized scientific notation.
Max CVSS
7.5
Published
2023-12-11
Updated
2023-12-20
EPSS
0.05%

CVE-2023-49347

Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may read private information from windows, present false information to users, or deny access to the application.
Max CVSS
7.8
Published
2023-12-14
Updated
2023-12-20
EPSS
0.04%

CVE-2023-49346

Temporary data passed between application components by Budgie Extras WeatherShow applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or deny access to the application and panel.
Max CVSS
7.8
Published
2023-12-14
Updated
2023-12-20
EPSS
0.04%

CVE-2023-49345

Temporary data passed between application components by Budgie Extras Takeabreak applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or deny access to the application and panel.
Max CVSS
7.8
Published
2023-12-14
Updated
2023-12-20
EPSS
0.04%
50 vulnerabilities found
1 2 3 4 5 6 ...... 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 ...... 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50