CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0811
4.3 MEDIUM

Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak …

Jan 24, 2024
CVE-2024-0810
4.3 MEDIUM

Insufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak …

Jan 24, 2024
CVE-2024-0809
4.3 MEDIUM

Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security …

Jan 24, 2024
CVE-2024-0805
4.3 MEDIUM

Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security …

Jan 24, 2024
CVE-2023-35836
6.5 MEDIUM

An issue was discovered in SolaX Pocket WiFi 3 through 3.001.02. An attacker within RF range can obtain a cleartext copy of the network configuration …

Jan 23, 2024
CVE-2023-7237
5.7 MEDIUM

Lantronix XPort sends weakly encoded credentials within web request headers.

Jan 23, 2024
CVE-2023-52330
6.1 MEDIUM

A cross-site scripting vulnerability in Trend Micro Apex Central could allow a remote attacker to execute arbitrary code on affected installations of Trend Micro Apex …

Jan 23, 2024
CVE-2023-52329
6.1 MEDIUM

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code …

Jan 23, 2024
CVE-2023-52328
6.1 MEDIUM

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code …

Jan 23, 2024
CVE-2023-52327
6.1 MEDIUM

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code …

Jan 23, 2024
CVE-2023-52326
6.1 MEDIUM

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code …

Jan 23, 2024
CVE-2023-41178
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided …

Jan 23, 2024
CVE-2023-41177
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided …

Jan 23, 2024
CVE-2023-41176
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided …

Jan 23, 2024
CVE-2023-38627
5.4 MEDIUM

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal …

Jan 23, 2024
CVE-2023-38626
5.4 MEDIUM

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal …

Jan 23, 2024
CVE-2023-38625
5.4 MEDIUM

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal …

Jan 23, 2024
CVE-2023-38624
5.4 MEDIUM

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal …

Jan 23, 2024
CVE-2023-46889
5.7 MEDIUM

Meross MSH30Q 4.5.23 is vulnerable to Cleartext Transmission of Sensitive Information. During the device setup phase, the MSH30Q creates an unprotected Wi-Fi access point. In …

Jan 23, 2024
CVE-2023-42144
5.5 MEDIUM

Cleartext Transmission during initial setup in Shelly TRV 20220811-15234 v.2.1.8 allows a local attacker to obtain the Wi-Fi password.

Jan 23, 2024
CVE-2023-42143
5.4 MEDIUM

Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5afc928c allows malicious users to create a backdoor by redirecting the device to an attacker-controlled machine which serves the …

Jan 23, 2024
CVE-2024-22497
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in /admin/login password parameter in JFinalcms 5.0.0 allows attackers to run arbitrary code via crafted URL.

Jan 23, 2024
CVE-2024-23341
6.1 MEDIUM

TuiTse-TsuSin is a package for organizing the comparative corpus of Taiwanese Chinese characters and Roman characters, and extracting sentences of the Taiwanese Chinese characters and …

Jan 23, 2024
CVE-2024-23330
5.3 MEDIUM

Tuta is an encrypted email service. In versions prior to 119.10, an attacker can attach an image in a html mail which is loaded from …

Jan 23, 2024
CVE-2024-22417
6.1 MEDIUM

Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `element` method in `app/routes.py` does not validate the user-controlled `src_type` and `element_url` …

Jan 23, 2024
CVE-2024-22204
5.3 MEDIUM

Whoogle Search is a self-hosted metasearch engine. Versions 0.8.3 and prior have a limited file write vulnerability when the configuration options in Whoogle are enabled. …

Jan 23, 2024
CVE-2023-6573
5.5 MEDIUM

HPE OneView may have a missing passphrase during restore.

Jan 23, 2024
CVE-2023-45889
6.1 MEDIUM

A Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.8 allows remote attackers to inject JavaScript into any webpage. NOTE: this issue …

Jan 23, 2024
CVE-2024-22496
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the /admin/login username parameter.

Jan 23, 2024
CVE-2024-22490
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in beetl-bbs 2.0 allows attackers to run arbitrary code via the /index keyword parameter.

Jan 23, 2024
CVE-2024-0754
6.5 MEDIUM

Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.

Jan 23, 2024
CVE-2024-0753
6.5 MEDIUM

In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird …

Jan 23, 2024
CVE-2024-0752
6.5 MEDIUM

A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted in …

Jan 23, 2024
CVE-2024-0749
4.3 MEDIUM

A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox …

Jan 23, 2024
CVE-2024-0748
4.3 MEDIUM

A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar …

Jan 23, 2024
CVE-2024-0747
6.5 MEDIUM

When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. …

Jan 23, 2024
CVE-2024-0746
6.5 MEDIUM

A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, …

Jan 23, 2024
CVE-2024-0742
4.3 MEDIUM

It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to …

Jan 23, 2024
CVE-2024-0741
6.5 MEDIUM

An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox …

Jan 23, 2024
CVE-2023-49783
4.3 MEDIUM

Silverstripe Admin provides a basic management interface for the Silverstripe Framework. In versions on the 1.x branch prior to 1.13.19 and on the 2.x branch …

Jan 23, 2024
CVE-2023-48714
4.3 MEDIUM

Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to versions 4.13.39 and 5.1.11, if a user should …

Jan 23, 2024
CVE-2023-44401
5.3 MEDIUM

The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `canView` permission checks …

Jan 23, 2024
CVE-2024-0703
4.4 MEDIUM

The Sticky Buttons – floating buttons builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via sticky URLs in all versions up to, and …

Jan 23, 2024
CVE-2024-23183
5.4 MEDIUM

Cross-site scripting vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x …

Jan 23, 2024
CVE-2024-23181
6.1 MEDIUM

Cross-site scripting vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x …

Jan 23, 2024
CVE-2023-46343
5.5 MEDIUM

In the Linux kernel before 6.5.9, there is a NULL pointer dereference in send_acknowledge in net/nfc/nci/spi.c.

Jan 23, 2024
CVE-2024-23851
5.5 MEDIUM

copy_params in drivers/md/dm-ioctl.c in the Linux kernel through 6.7.1 can attempt to allocate more than INT_MAX bytes, and crash, because of a missing param_kernel->data_size check. …

Jan 23, 2024
CVE-2024-23850
5.5 MEDIUM

In btrfs_get_root_ref in fs/btrfs/disk-io.c in the Linux kernel through 6.7.1, there can be an assertion failure and crash because a subvolume can be read out …

Jan 23, 2024
CVE-2024-23849
5.5 MEDIUM

In rds_recv_track_latency in net/rds/af_rds.c in the Linux kernel through 6.7.1, there is an off-by-one error for an RDS_MSG_RX_DGRAM_TRACE_MAX comparison, resulting in out-of-bounds access.

Jan 23, 2024
CVE-2024-23848
5.5 MEDIUM

In the Linux kernel through 6.7.1, there is a use-after-free in cec_queue_msg_fh, related to drivers/media/cec/core/cec-adap.c and drivers/media/cec/core/cec-api.c.

Jan 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.