Security Vulnerabilities, CVEs
CVE-2023-48387
TAIWAN-CA(TWCA) JCICSecurityTool's Registry-related functions have insufficient filtering for special characters. An unauthenticated remote attacker can inject malicious script into a webpage to perform XSS (Stored Cross-Site Scripting) attack.
Max CVSS
6.1
Published
2023-12-15
Updated
2023-12-22
EPSS
0.06%
CVE-2023-48384
ArmorX Global Technology Corporation ArmorX Spam has insufficient validation for user input within a special function. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.
Max CVSS
9.8
Published
2023-12-15
Updated
2023-12-22
EPSS
0.16%
CVE-2023-48382
Softnext Mail SQR Expert is an email management platform, it has a Local File Inclusion (LFI) vulnerability in a mail deliver-related URL. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary PHP file with .asp file extension under specific system paths, to access and modify partial system information but does not affect service availability.
Max CVSS
6.5
Published
2023-12-15
Updated
2023-12-21
EPSS
0.07%
CVE-2023-48381
Softnext Mail SQR Expert is an email management platform, it has a Local File Inclusion (LFI) vulnerability in a special URL. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary PHP file with .asp file extension under specific system paths, to access and modify partial system information but does not affect service availability.
Max CVSS
6.5
Published
2023-12-15
Updated
2023-12-20
EPSS
0.07%
CVE-2023-48380
Softnext Mail SQR Expert is an email management platform, it has insufficient filtering for a special character within a spcific function. A remote attacker authenticated as a localhost can exploit this vulnerability to perform command injection attacks, to execute arbitrary system command, manipulate system or disrupt service.
Max CVSS
8.0
Published
2023-12-15
Updated
2023-12-21
EPSS
0.07%
CVE-2023-48379
Softnext Mail SQR Expert is an email management platform, it has inadequate filtering for a specific URL parameter within a specific function. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response.
Max CVSS
5.3
Published
2023-12-15
Updated
2023-12-21
EPSS
0.08%
CVE-2023-48378
Softnext Mail SQR Expert has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
Max CVSS
7.5
Published
2023-12-15
Updated
2023-12-21
EPSS
0.11%
CVE-2023-48376
SmartStar Software CWS is a web-based integration platform, its file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.
Max CVSS
9.8
Published
2023-12-15
Updated
2023-12-20
EPSS
0.27%
CVE-2023-48375
SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users are able to access data or perform actions that they should not be allowed to perform via commands. An authenticated with normal user privilege can execute administrator privilege, resulting in performing arbitrary system operations or disrupting service.
Max CVSS
8.8
Published
2023-12-15
Updated
2023-12-20
EPSS
0.05%
CVE-2023-48374
SmartStar Software CWS is a web-base integration platform, it has a vulnerability of using a hard-coded for a specific account with low privilege. An unauthenticated remote attacker can exploit this vulnerability to run partial processes and obtain partial information, but can't disrupt service or obtain sensitive information.
Max CVSS
6.5
Published
2023-12-15
Updated
2023-12-21
EPSS
0.08%
CVE-2023-48373
ITPison OMICARD EDM has a path traversal vulnerability within its parameter “FileName” in a specific function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
Max CVSS
7.5
Published
2023-12-15
Updated
2023-12-22
EPSS
0.11%
CVE-2023-48372
ITPison OMICARD EDM 's SMS-related function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.
Max CVSS
9.8
Published
2023-12-15
Updated
2023-12-22
EPSS
0.16%
CVE-2023-48371
ITPison OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service.
Max CVSS
9.8
Published
2023-12-15
Updated
2023-12-22
EPSS
0.27%
CVE-2023-48369
Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to different endpoints to potentially overflow the log.
Max CVSS
5.3
Published
2023-11-27
Updated
2023-12-01
EPSS
0.05%
CVE-2023-48365
Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attacker is able to elevate their privilege by tunneling HTTP requests, allowing them to execute HTTP requests on the backend server that hosts the repository application. The fixed versions are August 2023 Patch 2, May 2023 Patch 6, February 2023 Patch 10, November 2022 Patch 12, August 2022 Patch 14, May 2022 Patch 16, February 2022 Patch 15, and November 2021 Patch 17. NOTE: this issue exists because of an incomplete fix for CVE-2023-41265.
Max CVSS
9.9
Published
2023-11-15
Updated
2023-11-29
EPSS
0.08%
CVE-2023-48360
in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.
Max CVSS
4.0
Published
2024-01-02
Updated
2024-01-02
CVE-2023-48336
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cybernetikz Easy Social Icons allows Stored XSS.This issue affects Easy Social Icons: from n/a through 3.2.4.
Max CVSS
6.5
Published
2023-11-30
Updated
2023-12-05
EPSS
0.05%
CVE-2023-48334
Cross-Site Request Forgery (CSRF) vulnerability in DAEXT League Table allows Cross Site Request Forgery.This issue affects League Table: from n/a through 1.13.
Max CVSS
8.8
Published
2023-11-30
Updated
2023-12-05
EPSS
0.06%
CVE-2023-48333
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pluggabl LLC Booster for WooCommerce.This issue affects Booster for WooCommerce: from n/a through 7.1.1.
Max CVSS
6.5
Published
2023-11-30
Updated
2023-12-06
EPSS
0.05%
CVE-2023-48331
Cross-Site Request Forgery (CSRF) vulnerability in Stormhill Media MyBookTable Bookstore by Stormhill Media allows Cross Site Request Forgery.This issue affects MyBookTable Bookstore by Stormhill Media: from n/a through 3.3.4.
Max CVSS
8.8
Published
2023-11-30
Updated
2023-12-05
EPSS
0.06%
CVE-2023-48330
Cross-Site Request Forgery (CSRF) vulnerability in Mike Strand Bulk Comment Remove allows Cross Site Request Forgery.This issue affects Bulk Comment Remove: from n/a through 2.
Max CVSS
8.8
Published
2023-11-30
Updated
2023-12-05
EPSS
0.06%
CVE-2023-48329
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard Fast Custom Social Share by CodeBard allows Stored XSS.This issue affects Fast Custom Social Share by CodeBard: from n/a through 1.1.1.
Max CVSS
5.9
Published
2023-11-30
Updated
2023-12-05
EPSS
0.05%
CVE-2023-48328
Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin – NextGEN Gallery: from n/a through 3.37.
Max CVSS
8.8
Published
2023-11-30
Updated
2023-12-06
EPSS
0.06%
CVE-2023-48327
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Vendors WC Vendors – WooCommerce Multi-Vendor, WooCommerce Marketplace, Product Vendors.This issue affects WC Vendors – WooCommerce Multi-Vendor, WooCommerce Marketplace, Product Vendors: from n/a through 2.4.7.
Max CVSS
7.6
Published
2023-12-19
Updated
2023-12-29
EPSS
0.05%
CVE-2023-48326
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager allows Reflected XSS.This issue affects Events Manager: from n/a through 6.4.5.
Max CVSS
7.1
Published
2023-11-30
Updated
2023-12-05
EPSS
0.05%