CVE-2023-49742

CRITICAL Year: 2023
CVSS v3 Score
9.9
Critical

Vulnerability Description

Missing Authorization vulnerability in Support Genix.This issue affects Support Genix: from n/a through 1.2.3.

CVSS:9.9(Critical)

Easytime Studio Easy File Manager 1.1 has a HTTP request security bypass

CVSS:9.9(Critical)

An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget wit...

CVSS:9.9(Critical)

The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_actions function in versions 1.3.4 through 1.6.1. This ma...

CVSS:9.9(Critical)

SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate pr...

CVSS:9.9(Critical)

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to escalate...

CVSS:9.8(Critical)

A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2.1.16.