CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0929
4.7 MEDIUM

A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been rated as critical. Affected by this issue is the function fromNatStaticSetting. The manipulation of …

Jan 26, 2024
CVE-2024-0928
4.7 MEDIUM

A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been declared as critical. Affected by this vulnerability is the function fromDhcpListClient. The manipulation of …

Jan 26, 2024
CVE-2024-22551
6.1 MEDIUM

WhatACart v2.0.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /site/default/search.

Jan 26, 2024
CVE-2024-22550
6.1 MEDIUM

An arbitrary file upload vulnerability in the component /alsdemo/ss/mediam.cgi of ShopSite v14.0 allows attackers to execute arbitrary code via uploading a crafted SVG file.

Jan 26, 2024
CVE-2024-0927
4.7 MEDIUM

A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been classified as critical. Affected is the function fromAddressNat. The manipulation of the argument entrys/mitInterface/page …

Jan 26, 2024
CVE-2024-0926
4.7 MEDIUM

A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01 and classified as critical. This issue affects the function formWifiWpsOOB. The manipulation of the argument index leads …

Jan 26, 2024
CVE-2024-0925
4.7 MEDIUM

A vulnerability has been found in Tenda AC10U 15.03.06.49_multi_TDE01 and classified as critical. This vulnerability affects the function formSetVirtualSer. The manipulation of the argument list …

Jan 26, 2024
CVE-2024-0924
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.49_multi_TDE01. This affects the function formSetPPTPServer. The manipulation of the argument startIp leads …

Jan 26, 2024
CVE-2024-0923
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.49_multi_TDE01. Affected by this issue is the function formSetDeviceName. The manipulation of …

Jan 26, 2024
CVE-2024-0922
4.7 MEDIUM

A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49_multi_TDE01. Affected by this vulnerability is the function formQuickIndex. The manipulation of the argument PPPOEPassword …

Jan 26, 2024
CVE-2024-0921
4.7 MEDIUM

A vulnerability has been found in D-Link DIR-816 A2 1.10CNB04 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Jan 26, 2024
CVE-2024-0727
5.5 MEDIUM

Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading …

Jan 26, 2024
CVE-2023-48129
5.4 MEDIUM

An issue in kimono-oldnew mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2024-23388
6.1 MEDIUM

Improper authorization in handler for custom URL scheme issue in "Mercari" App for Android prior to version 5.78.0 allows a remote attacker to lead a …

Jan 26, 2024
CVE-2023-48135
5.4 MEDIUM

An issue in mimasaka_farm mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-48133
5.4 MEDIUM

An issue in angel coffee mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-48132
5.4 MEDIUM

An issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-48131
5.4 MEDIUM

An issue in CHIGASAKI BAKERY mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-48130
5.4 MEDIUM

An issue in GINZA CAFE mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-48128
5.4 MEDIUM

An issue in UNITED BOXING GYM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-48127
5.4 MEDIUM

An issue in myGAKUYA mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-48126
5.4 MEDIUM

An issue in Luxe Beauty Clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-6159
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 …

Jan 26, 2024
CVE-2023-5612
5.3 MEDIUM

An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to …

Jan 26, 2024
CVE-2024-21387
5.3 MEDIUM

Microsoft Edge for Android Spoofing Vulnerability

Jan 26, 2024
CVE-2024-21382
4.3 MEDIUM

Microsoft Edge for Android Information Disclosure Vulnerability

Jan 26, 2024
CVE-2024-0456
4.3 MEDIUM

An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able …

Jan 26, 2024
CVE-2023-5933
6.4 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper …

Jan 26, 2024
CVE-2024-21619
5.3 MEDIUM

A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS …

Jan 25, 2024
CVE-2024-0890
6.3 MEDIUM

A vulnerability was found in hongmaple octopus 1.0. It has been classified as critical. Affected is an unknown function of the file /system/dept/edit. The manipulation …

Jan 25, 2024
CVE-2024-0889
5.3 MEDIUM

A vulnerability was found in Kmint21 Golden FTP Server 2.02b and classified as problematic. This issue affects some unknown processing of the component PASV Command …

Jan 25, 2024
CVE-2024-23055
6.1 MEDIUM

An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the HOST headers.

Jan 25, 2024
CVE-2024-0888
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in BORGChat 1.0.0 Build 438. This affects an unknown part of the component Service Port 7551. …

Jan 25, 2024
CVE-2024-0887
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Mafiatic Blue Server 1.1. Affected by this issue is some unknown functionality of the …

Jan 25, 2024
CVE-2024-22639
6.1 MEDIUM

iGalerie v3.0.22 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Titre (Title) field in the editing interface.

Jan 25, 2024
CVE-2024-22637
6.1 MEDIUM

Form Tools v3.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /form_builder/preview.php?form_id=2.

Jan 25, 2024
CVE-2024-22635
6.1 MEDIUM

WebCalendar v1.3.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /WebCalendarvqsmnseug2/edit_entry.php.

Jan 25, 2024
CVE-2024-0885
5.3 MEDIUM

A vulnerability classified as problematic has been found in SpyCamLizard 1.230. Affected is an unknown function of the component HTTP GET Request Handler. The manipulation …

Jan 25, 2024
CVE-2024-0884
4.7 MEDIUM

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. This issue affects the function exec …

Jan 25, 2024
CVE-2023-52046
4.8 MEDIUM

Cross Site Scripting vulnerability (XSS) in webmin v.2.105 and earlier allows a remote attacker to execute arbitrary code via a crafted payload to the "Execute …

Jan 25, 2024
CVE-2024-21630
4.3 MEDIUM

Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applies to multi-use invitations, not single-use invitation links …

Jan 25, 2024
CVE-2023-41474
6.5 MEDIUM

Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component.

Jan 25, 2024
CVE-2024-0883
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been declared as critical. This vulnerability affects the function prepare …

Jan 25, 2024
CVE-2024-0882
4.3 MEDIUM

A vulnerability was found in qwdigital LinkWechat 5.1.0. It has been classified as problematic. This affects an unknown part of the file /linkwechat-api/common/download/resource of the …

Jan 25, 2024
CVE-2024-0880
4.3 MEDIUM

A vulnerability was found in Qidianbang qdbcrm 1.1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /user/edit?id=2 of …

Jan 25, 2024
CVE-2024-0879
6.5 MEDIUM

Authentication bypass in vector-admin allows a user to register to a vector-admin server while “domain restriction” is active, even when not owning an authorized email …

Jan 25, 2024
CVE-2023-6282
5.4 MEDIUM

IceHrm 23.0.0.OS does not sufficiently encode user-controlled input, which creates a Cross-Site Scripting (XSS) vulnerability via /icehrm/app/fileupload_page.php, in multiple parameters. An attacker could exploit this …

Jan 25, 2024
CVE-2023-33760
5.3 MEDIUM

SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to eavesdrop on communications via …

Jan 25, 2024
CVE-2023-33758
6.1 MEDIUM

Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the CLIENT_NAME and DEVICE_GUID fields in the login …

Jan 25, 2024
CVE-2023-33757
5.9 MEDIUM

A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Android App) v1.8.5 and before …

Jan 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.