CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2023-48206

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability in GaatiTrack Courier Management System 1.0 allows a remote attacker to inject JavaScript via the page parameter to login.php or header.php.

    Published: 7 Dec 2023
    8.8
    High

    CVE-2023-48207

    Last Modified: 21 Nov 2024

    Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.

    Published: 7 Dec 2023
    5.4
    Medium

    CVE-2023-48838

    Last Modified: 21 Nov 2024

    Appointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-48823

    Last Modified: 21 Nov 2024

    A Blind SQL injection issue in ajax.php in GaatiTrack Courier Management System 1.0 allows an unauthenticated attacker to inject a payload via the email parameter during login.

    Published: 7 Dec 2023
    5.4
    Medium

    CVE-2023-48824

    Last Modified: 21 Nov 2024

    BoidCMS 2.0.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the title, subtitle, footer, or keywords parameter in a page=create action.

    Published: 7 Dec 2023
    5.4
    Medium

    CVE-2023-48825

    Last Modified: 21 Nov 2024

    Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.

    Published: 7 Dec 2023
    8.8
    High

    CVE-2023-48826

    Last Modified: 21 Nov 2024

    Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.

    Published: 7 Dec 2023
    5.4
    Medium

    CVE-2023-48827

    Last Modified: 21 Nov 2024

    Time Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.

    Published: 7 Dec 2023
    8.8
    High

    CVE-2023-48830

    Last Modified: 21 Nov 2024

    Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export.

    Published: 7 Dec 2023
    7.5
    High

    CVE-2023-48831

    Last Modified: 21 Nov 2024

    A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.

    Published: 7 Dec 2023
    7.5
    High

    CVE-2023-48833

    Last Modified: 21 Nov 2024

    A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion.

    Published: 7 Dec 2023
    7.5
    High

    CVE-2023-48834

    Last Modified: 28 May 2025

    A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.

    Published: 7 Dec 2023
    8.8
    High

    CVE-2023-48835

    Last Modified: 21 Nov 2024

    Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.

    Published: 7 Dec 2023
    5.4
    Medium

    CVE-2023-48836

    Last Modified: 26 Nov 2024

    Car Rental Script 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.

    Published: 7 Dec 2023
    5.4
    Medium

    CVE-2023-48837

    Last Modified: 21 Nov 2024

    Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.

    Published: 7 Dec 2023
    7.5
    High

    CVE-2023-48840

    Last Modified: 21 Nov 2024

    A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.

    Published: 7 Dec 2023
    8.8
    High

    CVE-2023-48841

    Last Modified: 21 Nov 2024

    Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-48860

    Last Modified: 21 Nov 2024

    TOTOLINK N300RT version 3.2.4-B20180730.0906 has a post-authentication RCE due to incorrect access control, allows attackers can bypass front-end security restrictions and execute arbitrary code.

    Published: 7 Dec 2023
    7.8
    High

    CVE-2023-48861

    Last Modified: 26 Nov 2024

    DLL hijacking vulnerability in TTplayer version 7.0.2, allows local attackers to escalate privileges and execute arbitrary code via urlmon.dll.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49426

    Last Modified: 21 Nov 2024

    Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.

    Published: 7 Dec 2023
    5.5
    Medium

    CVE-2023-48958

    Last Modified: 21 Nov 2024

    gpac 2.3-DEV-rev617-g671976fcc-master contains memory leaks in gf_mpd_resolve_url media_tools/mpd.c:4589.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49434

    Last Modified: 21 Nov 2024

    Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetNetControlList.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49435

    Last Modified: 21 Nov 2024

    Tenda AX9 V22.03.01.46 is vulnerable to command injection.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49436

    Last Modified: 21 Nov 2024

    Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49402

    Last Modified: 21 Nov 2024

    Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49403

    Last Modified: 21 Nov 2024

    Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setFixTools.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49404

    Last Modified: 28 May 2025

    Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvancedSetListSet.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49405

    Last Modified: 21 Nov 2024

    Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49406

    Last Modified: 21 Nov 2024

    Tenda W30E V16.01.0.12(4843) was discovered to contain a Command Execution vulnerability via the function /goform/telnet.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49408

    Last Modified: 21 Nov 2024

    Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the function set_device_name.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49409

    Last Modified: 21 Nov 2024

    Tenda AX3 V16.03.12.11 was discovered to contain a Command Execution vulnerability via the function /goform/telnet.

    Published: 7 Dec 2023
    8.8
    High

    CVE-2023-49468

    Last Modified: 21 Nov 2024

    Libde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding_unit function at slice.cc.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49410

    Last Modified: 21 Nov 2024

    Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function via the function set_wan_status.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49411

    Last Modified: 21 Nov 2024

    Tenda W30E V16.01.0.12(4843) contains a stack overflow vulnerability via the function formDeleteMeshNode.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49424

    Last Modified: 21 Nov 2024

    Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49425

    Last Modified: 21 Nov 2024

    Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCfg .

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49428

    Last Modified: 21 Nov 2024

    Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49430

    Last Modified: 21 Nov 2024

    Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetStaticRouteCfg.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49431

    Last Modified: 21 Nov 2024

    Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.

    Published: 7 Dec 2023
    9.8
    Critical

    CVE-2023-49433

    Last Modified: 21 Nov 2024

    Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetVirtualServerCfg.

    Published: 7 Dec 2023
    8.8
    High

    CVE-2023-49462

    Last Modified: 26 Nov 2024

    libheif v1.17.5 was discovered to contain a segmentation violation via the component /libheif/exif.cc.

    Published: 7 Dec 2023
    8.8
    High

    CVE-2023-49463

    Last Modified: 21 Nov 2024

    libheif v1.17.5 was discovered to contain a segmentation violation via the function find_exif_tag at /libheif/exif.cc.

    Published: 7 Dec 2023
    8.8
    High

    CVE-2023-49464

    Last Modified: 21 Nov 2024

    libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::get_luma_bits_per_pixel_from_configuration_unci.

    Published: 7 Dec 2023
    8.8
    High

    CVE-2023-49465

    Last Modified: 21 Nov 2024

    Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function at motion.cc.

    Published: 7 Dec 2023
    8.8
    High

    CVE-2023-49467

    Last Modified: 21 Nov 2024

    Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_combined_bipredictive_merging_candidates function at motion.cc.

    Published: 7 Dec 2023
    6.1
    Medium

    CVE-2023-49492

    Last Modified: 21 Nov 2024

    DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the imgstick parameter at selectimages.php.

    Published: 7 Dec 2023
    6.1
    Medium

    CVE-2023-49493

    Last Modified: 28 May 2025

    DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the v parameter at selectimages.php.

    Published: 7 Dec 2023
    7.5
    High

    CVE-2023-49955

    Last Modified: 21 Nov 2024

    An issue was discovered in Dalmann OCPP.Core before 1.2.0 for OCPP (Open Charge Point Protocol) for electric vehicles. It does not validate the length of the chargePointVendor field in a BootNotification message, potentially leading to server instability and a denial of service when processing excessively large inputs. NOTE: the vendor's perspective is "OCPP.Core is intended for use in a protected environment/network."

    Published: 7 Dec 2023
    7.5
    High

    CVE-2023-49956

    Last Modified: 21 Nov 2024

    An issue was discovered in Dalmann OCPP.Core before 1.3.0 for OCPP (Open Charge Point Protocol) for electric vehicles. A StopTransaction message with any random transactionId terminates active transactions.

    Published: 7 Dec 2023
    7.5
    High

    CVE-2023-49957

    Last Modified: 21 Nov 2024

    An issue was discovered in Dalmann OCPP.Core before 1.3.0 for OCPP (Open Charge Point Protocol) for electric vehicles. It permits multiple transactions with the same connectorId and idTag, contrary to the expected ConcurrentTx status. This could result in critical transaction management and billing errors. NOTE: the vendor's perspective is "Imagine you've got two cars in your family and want to charge both in parallel on the same account/token? Why should that be rejected?"

    Published: 7 Dec 2023