Vulnerabilities (CVE)

Filtered by vendor Xxyopen Subscribe
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-41443 1 Xxyopen 1 Novel-plus 2024-11-21 N/A 7.2 HIGH
SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list.
CVE-2023-30058 1 Xxyopen 1 Novel-plus 2024-11-21 N/A 9.8 CRITICAL
novel-plus 3.6.2 is vulnerable to SQL Injection.