Unknown

    CVE-2023-50596

    https://github.com/chandraprarikraj/CVE-2023-50596

    8.8
    High

    CVE-2023-50564

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary code via uploading a crafted ZIP file.

    Published:14 Dec 2023
    5.4
    Medium

    CVE-2023-50465

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in Monica (aka MonicaHQ) 4.0.0 via an SVG document uploaded by an authenticated user.

    Published:11 Dec 2023
    7.5
    High

    CVE-2023-50387

    Last Modified: 4 Nov 2025

    Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.

    Published:13 Feb 2024
    8.8
    High

    CVE-2023-50386

    Last Modified: 24 Apr 2025

    Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1. In the affected versions, Solr ConfigSets accepted Java jar and class files to be uploaded through the ConfigSets API. When backing up Solr Collections, these configSet files would be saved to disk when using the LocalFileSystemRepository (the default for backups). If the backup was saved to a directory that Solr uses in its ClassPath/ClassLoaders, then the jar and class files would be available to use with any ConfigSet, trusted or untrusted. When Solr is run in a secure way (Authorization enabled), as is strongly suggested, this vulnerability is limited to extending the Backup permissions with the ability to add libraries. Users are recommended to upgrade to version 8.11.3 or 9.4.1, which fix the issue. In these versions, the following protections have been added: * Users are no longer able to upload files to a configSet that could be executed via a Java ClassLoader. * The Backup API restricts saving backups to directories that are used in the ClassLoader.

    Published:9 Feb 2024
    6.5
    Medium

    CVE-2023-50290

    Last Modified: 9 May 2025

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes all unprotected environment variables available to each Apache Solr instance. Users are able to specify which environment variables to hide, however, the default list is designed to work for known secret Java system properties. Environment variables cannot be strictly defined in Solr, like Java system properties can be, and may be set for the entire host, unlike Java system properties which are set per-Java-proccess. The Solr Metrics API is protected by the "metrics-read" permission. Therefore, Solr Clouds with Authorization setup will only be vulnerable via users with the "metrics-read" permission. This issue affects Apache Solr: from 9.0.0 before 9.3.0. Users are recommended to upgrade to version 9.3.0 or later, in which environment variables are not published via the Metrics API.

    Published:12 Jan 2024
    9.7
    Critical

    CVE-2023-50257

    Last Modified: 2 Jan 2026

    eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Even with the application of SROS2, due to the issue where the data (`p[UD]`) and `guid` values used to disconnect between nodes are not encrypted, a vulnerability has been discovered where a malicious attacker can forcibly disconnect a Subscriber and can deny a Subscriber attempting to connect. Afterwards, if the attacker sends the packet for disconnecting, which is data (`p[UD]`), to the Global Data Space (`239.255.0.1:7400`) using the said Publisher ID, all the Subscribers (Listeners) connected to the Publisher (Talker) will not receive any data and their connection will be disconnected. Moreover, if this disconnection packet is sent continuously, the Subscribers (Listeners) trying to connect will not be able to do so. Since the initial commit of the `SecurityManager.cpp` code (`init`, `on_process_handshake`) on Nov 8, 2016, the Disconnect Vulnerability in RTPS Packets Used by SROS2 has been present prior to versions 2.13.0, 2.12.2, 2.11.3, 2.10.3, and 2.6.7.

    Published:19 Feb 2024
    9.3
    Critical

    CVE-2023-50254

    Last Modified: 21 Nov 2024

    Deepin Linux's default document reader `deepin-reader` software suffers from a serious vulnerability in versions prior to 6.0.7 due to a design flaw that leads to remote command execution via crafted docx document. This is a file overwrite vulnerability. Remote code execution (RCE) can be achieved by overwriting files like .bash_rc, .bash_login, etc. RCE will be triggered when the user opens the terminal. Version 6.0.7 contains a patch for the issue.

    Published:22 Dec 2023
    9.8
    Critical

    CVE-2023-50245

    Last Modified: 21 Nov 2024

    OpenEXR-viewer is a viewer for OpenEXR files with detailed metadata probing. Versions prior to 0.6.1 have a memory overflow vulnerability. This issue is fixed in version 0.6.1.

    Published:11 Dec 2023
    7.8
    High

    CVE-2023-50226

    Last Modified: 8 Aug 2025

    Parallels Desktop Updater Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability. The specific flaw exists within the Updater service. By creating a symbolic link, an attacker can abuse the service to move arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. . Was ZDI-CAN-21227.

    Published:3 May 2024
    9.8
    Critical

    CVE-2023-50164

    Last Modified: 14 Mar 2025

    An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.

    Published:7 Dec 2023
    Unknown

    CVE-2023-50132

    https://github.com/sajaljat/CVE-2023-50132

    Unknown

    CVE-2023-50131

    https://github.com/sajaljat/CVE-2023-50131

    8.8
    High

    CVE-2023-50094

    Last Modified: 17 Apr 2025

    reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via subprocess.check_output.

    Published:1 Jan 2024
    5.4
    Medium

    CVE-2023-50072

    Last Modified: 3 Jun 2025

    A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated user to upload a note on a file which acts as a stored XSS payload. Any user who opens the note of a document file will trigger the XSS.

    Published:13 Jan 2024
    8.8
    High

    CVE-2023-50071

    Last Modified: 21 Nov 2024

    Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_department via id or name.

    Published:29 Dec 2023
    8.8
    High

    CVE-2023-50070

    Last Modified: 21 Nov 2024

    Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_ticket via department_id, customer_id, and subject.

    Published:29 Dec 2023
    10
    Critical

    CVE-2023-50029

    Last Modified: 15 Apr 2026

    PHP Injection vulnerability in the module "M4 PDF Extensions" (m4pdf) up to version 3.3.2 from PrestaAddons for PrestaShop allows attackers to run arbitrary code via the M4PDF::saveTemplate() method.

    Published:24 Jun 2024
    9.8
    Critical

    CVE-2023-49989

    Last Modified: 14 Apr 2025

    Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at update.php.

    Published:7 Mar 2024
    7.5
    High

    CVE-2023-49988

    Last Modified: 14 Apr 2025

    Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the npss parameter at rooms.php.

    Published:7 Mar 2024
    5.4
    Medium

    CVE-2023-49987

    Last Modified: 16 Apr 2025

    A cross-site scripting (XSS) vulnerability in the component /management/term of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tname parameter.

    Published:7 Mar 2024
    4.7
    Medium

    CVE-2023-49986

    Last Modified: 16 Apr 2025

    A cross-site scripting (XSS) vulnerability in the component /admin/parent of School Fees Management System 1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.

    Published:7 Mar 2024
    6.5
    Medium

    CVE-2023-49985

    Last Modified: 16 Apr 2025

    A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cname parameter.

    Published:6 Mar 2024
    6.1
    Medium

    CVE-2023-49984

    Last Modified: 16 Apr 2025

    A cross-site scripting (XSS) vulnerability in the component /management/settings of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.

    Published:6 Mar 2024
    6.8
    Medium

    CVE-2023-49983

    Last Modified: 16 Apr 2025

    A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.

    Published:6 Mar 2024
    8.8
    High

    CVE-2023-49982

    Last Modified: 16 Apr 2025

    Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and deleting user accounts.

    Published:6 Mar 2024
    7.5
    High

    CVE-2023-49981

    Last Modified: 21 Nov 2024

    A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.

    Published:6 Mar 2024
    7.5
    High

    CVE-2023-49980

    Last Modified: 21 Nov 2024

    A directory listing vulnerability in Best Student Result Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.

    Published:6 Mar 2024
    7.5
    High

    CVE-2023-49979

    Last Modified: 21 Nov 2024

    A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.

    Published:6 Mar 2024
    7.2
    High

    CVE-2023-49978

    Last Modified: 21 Nov 2024

    Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for administrators.

    Published:6 Mar 2024
    5.4
    Medium

    CVE-2023-49977

    Last Modified: 28 Mar 2025

    A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the address parameter at /customer_support/index.php?page=new_customer.

    Published:6 Mar 2024
    5.4
    Medium

    CVE-2023-49976

    Last Modified: 28 Mar 2025

    A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the subject parameter at /customer_support/index.php?page=new_ticket.

    Published:6 Mar 2024
    6.1
    Medium

    CVE-2023-49974

    Last Modified: 28 Mar 2025

    A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the contact parameter at /customer_support/index.php?page=customer_list.

    Published:6 Mar 2024
    6.1
    Medium

    CVE-2023-49973

    Last Modified: 15 Jan 2025

    A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter at /customer_support/index.php?page=customer_list.

    Published:6 Mar 2024
    6.1
    Medium

    CVE-2023-49971

    Last Modified: 15 Jan 2025

    A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter at /customer_support/index.php?page=customer_list.

    Published:6 Mar 2024
    9.8
    Critical

    CVE-2023-49970

    Last Modified: 28 Mar 2025

    Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/ajax.php?action=save_ticket.

    Published:4 Mar 2024
    4.3
    Medium

    CVE-2023-49969

    Last Modified: 28 Mar 2025

    Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer.

    Published:4 Mar 2024
    7.3
    High

    CVE-2023-49968

    Last Modified: 28 Mar 2025

    Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/manage_department.php.

    Published:4 Mar 2024
    6.8
    Medium

    CVE-2023-49965

    Last Modified: 15 Apr 2026

    SpaceX Starlink Wi-Fi router Gen 2 before 2023.48.0 allows XSS via the ssid and password parameters on the Setup Page.

    Published:5 Apr 2024
    8.8
    High

    CVE-2023-49964

    Last Modified: 21 Nov 2024

    An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restrictions and achieve RCE (Remote Code Execution). NOTE: this issue exists because of an incomplete fix for CVE-2020-12873.

    Published:11 Dec 2023
    9.8
    Critical

    CVE-2023-49954

    Last Modified: 23 Apr 2025

    The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search string, or email address.

    Published:25 Dec 2023
    5.4
    Medium

    CVE-2023-49950

    Last Modified: 17 Jun 2025

    The Jinja templating in Logpoint SIEM 6.10.0 through 7.x before 7.3.0 does not correctly sanitize log data being displayed when using a custom Jinja template in the Alert view. A remote attacker can craft a cross-site scripting (XSS) payload and send it to any system or device that sends logs to the SIEM. If an alert is created, the payload will execute upon the alert data being viewed with that template, which can lead to sensitive data disclosure.

    Published:3 Feb 2024
    5.3
    Medium

    CVE-2023-49792

    Last Modified: 21 Nov 2024

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well as Nextcloud Enterprise Server prior to versions 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9, and 27.1.4; when a (reverse) proxy is configured as trusted proxy the server could be tricked into reading a wrong remote address for an attacker, allowing them executing authentication attempts than intended. Nextcloud Server versions 26.0.9 and 27.1.4 and Nextcloud Enterprise Server versions 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9, and 27.1.4 contain a patch for this issue. No known workarounds are available.

    Published:22 Dec 2023
    9.1
    Critical

    CVE-2023-49785

    Last Modified: 10 Apr 2025

    NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 and prior are vulnerable to server-side request forgery and cross-site scripting. This vulnerability enables read access to internal HTTP endpoints but also write access using HTTP POST, PUT, and other methods. Attackers can also use this vulnerability to mask their source IP by forwarding malicious traffic intended for other Internet targets through these open proxies. As of time of publication, no patch is available, but other mitigation strategies are available. Users may avoid exposing the application to the public internet or, if exposing the application to the internet, ensure it is an isolated network with no access to any other internal resources.

    Published:11 Mar 2024
    9.8
    Critical

    CVE-2023-49606

    Last Modified: 4 Nov 2025

    A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previously freed memory, which leads to memory corruption and could lead to remote code execution. An attacker needs to make an unauthenticated HTTP request to trigger this vulnerability.

    Published:1 May 2024
    8.8
    High

    CVE-2023-49548

    Last Modified: 28 Mar 2025

    Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user.

    Published:4 Mar 2024
    9.8
    Critical

    CVE-2023-49547

    Last Modified: 28 Mar 2025

    Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login.

    Published:4 Mar 2024
    8.8
    High

    CVE-2023-49546

    Last Modified: 28 Mar 2025

    Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php.

    Published:4 Mar 2024
    7.5
    High

    CVE-2023-49545

    Last Modified: 28 Mar 2025

    A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.

    Published:1 Mar 2024
    4.9
    Medium

    CVE-2023-49544

    Last Modified: 28 Mar 2025

    A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php.

    Published:1 Mar 2024