CVE-2023-48801 |
Description: In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resulting in a command execution vulnerability.
CVSS: CRITICAL (9.8) EPSS Score: 1.31%
November 27th, 2024 (5 months ago)
|
CVE-2023-48656 |
|
CVE-2023-48208 |
Description: A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php.
CVSS: MEDIUM (6.1) EPSS Score: 0.08%
November 27th, 2024 (5 months ago)
|
CVE-2023-48198 |
|
CVE-2023-48176 |
|
CVE-2023-48105 |
Description: An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of service via the wasm_loader_prepare_bytecode function in core/iwasm/interpreter/wasm_loader.c.
CVSS: HIGH (7.5) EPSS Score: 0.1%
November 27th, 2024 (5 months ago)
|
CVE-2023-47573 |
|
CVE-2023-47453 |
|
CVE-2023-47364 |
|
CVE-2023-47350 |
|