Vulnerabilities (CVE)

Total 298254 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-40383 1 Apple 1 Macos 2025-06-17 N/A 3.3 LOW
A path handling issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3. An app may be able to access user-sensitive data.
CVE-2023-40355 1 Axigen 1 Axigen Mobile Webmail 2025-06-17 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authenticated attackers to execute arbitrary code and obtain sensitive information via the logic for switching between the Standard and Ajax versions.
CVE-2023-40262 1 Unify 1 Openscape Voice Trace Manager V8 2025-06-17 N/A 6.1 MEDIUM
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows unauthenticated Stored Cross-Site Scripting (XSS) in the administration component via Access Request.
CVE-2024-34471 1 Hsclabs 1 Mailinspector 2025-06-17 N/A 5.4 MEDIUM
An issue was discovered in HSC Mailinspector 5.2.17-3. A Path Traversal vulnerability (resulting in file deletion) exists in the mliRealtimeEmails.php file. The filename parameter in the export HTML functionality does not properly validate the file location, allowing an attacker to read and delete arbitrary files on the server. This was observed when the mliRealtimeEmails.php file itself was read and subsequently deleted, resulting in a 404 error for the file and disruption of email information loading.
CVE-2024-28345 1 Sipwise 1 Next Generation Communication Platform 2025-06-17 N/A 5.5 MEDIUM
An issue discovered in Sipwise C5 NGCP Dashboard below mr11.5.1 allows a low privileged user to access the Journal endpoint by directly visit the URL.
CVE-2024-29269 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2025-06-17 N/A 8.8 HIGH
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter.
CVE-2024-33820 1 Totolink 2 A3002r, A3002r Firmware 2025-06-17 N/A 7.5 HIGH
Totolink AC1200 Wireless Dual Band Gigabit Router A3002R_V4 Firmware V4.0.0-B20230531.1404 is vulnerable to Buffer Overflow via the formWlEncrypt function of the boa server. Specifically, they exploit the length of the wlan_ssid field triggers the overflow.
CVE-2024-34506 2 Fedoraproject, Mediawiki 2 Fedora, Mediawiki 2025-06-17 N/A 7.5 HIGH
An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a user with the necessary rights to move the page opens Special:MovePage for a page with tens of thousands of subpages, then the page will exceed the maximum request time, leading to a denial of service.
CVE-2024-34507 2 Fedoraproject, Mediawiki 2 Fedora, Mediawiki 2025-06-17 N/A 7.4 HIGH
An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the 0x1b character, as demonstrated by Special:RecentChanges#%1b0000000.
CVE-2024-34510 1 Gradio Project 1 Gradio 2025-06-17 N/A 7.5 HIGH
Gradio before 4.20 allows credential leakage on Windows.
CVE-2024-4549 1 Deltaww 1 Diaenergie 2025-06-17 N/A 7.5 HIGH
A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.
CVE-2024-34470 1 Hsclabs 1 Mailinspector 2025-06-17 N/A 8.6 HIGH
An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability exists in the /public/loader.php file. The path parameter does not properly filter whether the file and directory passed are part of the webroot, allowing an attacker to read arbitrary files on the server.
CVE-2024-34472 1 Hsclabs 1 Mailinspector 2025-06-17 N/A 5.9 MEDIUM
An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An authenticated blind SQL injection vulnerability exists in the mliRealtimeEmails.php file. The ordemGrid parameter in a POST request to /mailinspector/mliRealtimeEmails.php does not properly sanitize input, allowing an authenticated attacker to execute arbitrary SQL commands, leading to the potential disclosure of the entire application database.
CVE-2025-46399 2025-06-17 N/A 4.7 MEDIUM
A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline function.
CVE-2023-52426 1 Libexpat Project 1 Libexpat 2025-06-17 N/A 5.5 MEDIUM
libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.
CVE-2023-52354 1 Blitiri 1 Chasquid 2025-06-17 N/A 7.5 HIGH
chasquid before 1.13 allows SMTP smuggling because LF-terminated lines are accepted.
CVE-2023-52329 1 Trendmicro 1 Apex Central 2025-06-17 N/A 6.1 MEDIUM
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to CVE-2023-52326.
CVE-2023-52289 1 Sujeetkv 1 Flaskcode 2025-06-17 N/A 7.5 HIGH
An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a POST request to a /update-resource-data/<file_path> URI (from views.py), allows attackers to write to arbitrary files.
CVE-2023-52274 1 Yzmcms 1 Yzmcms 2025-06-17 N/A 6.1 MEDIUM
member/index/register.html in YzmCMS 6.5 through 7.0 allows XSS via the Referer HTTP header.
CVE-2023-52251 1 Provectus 1 Ui 2025-06-17 N/A 8.8 HIGH
An issue discovered in provectus kafka-ui 0.4.0 through 0.7.1 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages.