Security Vulnerabilities, CVEs
CVE-2023-48881
A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Field Title field at /login.php?m=admin&c=Field&a=arctype_add&_ajax=1&lang=cn.
Max CVSS
4.8
Published
2023-11-29
Updated
2023-12-05
EPSS
0.05%
CVE-2023-48880
A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Menu Name field at /login.php?m=admin&c=Index&a=changeTableVal&_ajax=1&lang=cn.
Max CVSS
4.8
Published
2023-11-29
Updated
2023-12-05
EPSS
0.05%
CVE-2023-48866
A Cross-Site Scripting (XSS) vulnerability in the recipe preparation component within /api/objects/recipes and note component within /api/objects/shopping_lists/ of Grocy <= 4.0.3 allows attackers to obtain the victim's cookies.
Max CVSS
5.4
Published
2023-12-04
Updated
2023-12-07
EPSS
0.05%
CVE-2023-48863
SEMCMS 3.9 is vulnerable to SQL Injection. Due to the lack of security checks on the input of the application, the attacker uses the existing application to inject malicious SQL commands into the background database engine for execution, and sends some attack codes as commands or query statements to the interpreter. These malicious data can deceive the interpreter, so as to execute unplanned commands or unauthorized access to data.
Max CVSS
7.5
Published
2023-12-04
Updated
2023-12-07
EPSS
0.10%
CVE-2023-48861
DLL hijacking vulnerability in TTplayer version 7.0.2, allows local attackers to escalate privileges and execute arbitrary code via urlmon.dll.
Max CVSS
7.8
Published
2023-12-07
Updated
2023-12-11
EPSS
0.04%
CVE-2023-48860
TOTOLINK N300RT version 3.2.4-B20180730.0906 has a post-authentication RCE due to incorrect access control, allows attackers can bypass front-end security restrictions and execute arbitrary code.
Max CVSS
9.8
Published
2023-12-07
Updated
2023-12-12
EPSS
0.32%
CVE-2023-48859
TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows attackers to bypass front-end security restrictions and execute arbitrary code.
Max CVSS
8.8
Published
2023-12-06
Updated
2023-12-12
EPSS
0.12%
CVE-2023-48849
Ruijie EG Series Routers version EG_3.0(1)B11P216 and before allows unauthenticated attackers to remotely execute arbitrary code due to incorrect filtering.
Max CVSS
9.8
Published
2023-12-06
Updated
2023-12-11
EPSS
0.21%
CVE-2023-48848
An arbitrary file read vulnerability in ureport v2.2.9 allows a remote attacker to arbitrarily read files on the server by inserting a crafted path.
Max CVSS
7.5
Published
2023-11-28
Updated
2023-12-04
EPSS
0.09%
CVE-2023-48842
D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi.
Max CVSS
9.8
Published
2023-12-01
Updated
2023-12-06
EPSS
0.10%
CVE-2023-48841
Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
Max CVSS
8.8
Published
2023-12-07
Updated
2023-12-09
EPSS
0.06%
CVE-2023-48840
A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.
Max CVSS
7.5
Published
2023-12-07
Updated
2023-12-09
EPSS
0.05%
CVE-2023-48839
Appointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
Max CVSS
5.4
Published
2023-12-07
Updated
2023-12-09
EPSS
0.04%
CVE-2023-48838
Appointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code.
Max CVSS
5.4
Published
2023-12-07
Updated
2023-12-09
EPSS
0.04%
CVE-2023-48837
Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
Max CVSS
5.4
Published
2023-12-07
Updated
2023-12-09
EPSS
0.04%
CVE-2023-48836
Car Rental Script 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
Max CVSS
5.4
Published
2023-12-07
Updated
2023-12-09
EPSS
0.04%
CVE-2023-48835
Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
Max CVSS
8.8
Published
2023-12-07
Updated
2023-12-09
EPSS
0.06%
CVE-2023-48834
A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.
Max CVSS
7.5
Published
2023-12-07
Updated
2023-12-09
EPSS
0.05%
CVE-2023-48833
A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion.
Max CVSS
7.5
Published
2023-12-07
Updated
2023-12-09
EPSS
0.05%
CVE-2023-48831
A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.
Max CVSS
7.5
Published
2023-12-07
Updated
2023-12-09
EPSS
0.05%
CVE-2023-48830
Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export.
Max CVSS
8.8
Published
2023-12-07
Updated
2023-12-09
EPSS
0.06%
CVE-2023-48828
Time Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
Max CVSS
5.4
Published
2023-12-07
Updated
2023-12-09
EPSS
0.04%
CVE-2023-48827
Time Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
Max CVSS
5.4
Published
2023-12-07
Updated
2023-12-09
EPSS
0.04%
CVE-2023-48826
Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.
Max CVSS
8.8
Published
2023-12-07
Updated
2023-12-09
EPSS
0.06%
CVE-2023-48825
Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
Max CVSS
5.4
Published
2023-12-07
Updated
2023-12-09
EPSS
0.04%