CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-31001
5.1 MEDIUM

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) temporarily stores sensitive information in …

Jan 11, 2024
CVE-2022-40361
6.1 MEDIUM

Cross Site Scripting Vulnerability in Elite CRM v1.2.11 allows attacker to execute arbitrary code via the language parameter to the /ngs/login endpoint.

Jan 11, 2024
CVE-2023-45175
6.2 MEDIUM

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a …

Jan 11, 2024
CVE-2023-45173
6.2 MEDIUM

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the NFS kernel extension to cause a …

Jan 11, 2024
CVE-2024-21667
6.5 MEDIUM

pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An authenticated and unauthorized user can access the GDPR data extraction feature …

Jan 11, 2024
CVE-2024-21666
6.5 MEDIUM

The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, personalization and marketing automation. An authenticated and unauthorized user can access …

Jan 11, 2024
CVE-2024-21665
4.3 MEDIUM

ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the …

Jan 11, 2024
CVE-2024-0333
5.3 MEDIUM

Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attacker in a privileged network position to install a malicious extension via …

Jan 10, 2024
CVE-2023-49295
6.4 MEDIUM

quic-go is an implementation of the QUIC protocol (RFC 9000, RFC 9001, RFC 9002) in Go. An attacker can cause its peer to run out …

Jan 10, 2024
CVE-2023-42941
4.8 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker in a privileged network position may …

Jan 10, 2024
CVE-2023-42934
4.2 MEDIUM

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An …

Jan 10, 2024
CVE-2023-42929
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access protected user data.

Jan 10, 2024
CVE-2023-42872
5.5 MEDIUM

The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app may be …

Jan 10, 2024
CVE-2023-42865
6.5 MEDIUM

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, tvOS 16.4, iOS 16.4 and iPadOS 16.4, watchOS …

Jan 10, 2024
CVE-2023-42862
6.5 MEDIUM

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, tvOS 16.4, iOS 16.4 and iPadOS 16.4, watchOS …

Jan 10, 2024
CVE-2023-42831
5.5 MEDIUM

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Monterey …

Jan 10, 2024
CVE-2023-42829
5.5 MEDIUM

The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Big Sur 11.7.9, macOS Monterey 12.6.8, …

Jan 10, 2024
CVE-2023-41994
5.5 MEDIUM

A logic issue was addressed with improved checks This issue is fixed in macOS Sonoma 14. A camera extension may be able to access the …

Jan 10, 2024
CVE-2023-41987
5.5 MEDIUM

This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access sensitive user data.

Jan 10, 2024
CVE-2023-41069
5.5 MEDIUM

This issue was addressed by improving Face ID anti-spoofing models. This issue is fixed in iOS 17 and iPadOS 17. A 3D model constructed to …

Jan 10, 2024
CVE-2023-40438
5.5 MEDIUM

An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14, iOS 16.7 and iPadOS 16.7. An app …

Jan 10, 2024
CVE-2023-40437
5.5 MEDIUM

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS Ventura …

Jan 10, 2024
CVE-2023-40433
5.5 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3. An app may bypass Gatekeeper checks.

Jan 10, 2024
CVE-2023-40430
5.5 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access removable volumes …

Jan 10, 2024
CVE-2023-40411
5.5 MEDIUM

This issue was addressed with improved data protection. This issue is fixed in macOS Sonoma 14. An app may be able to access user-sensitive data.

Jan 10, 2024
CVE-2023-40385
6.5 MEDIUM

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. A …

Jan 10, 2024
CVE-2023-38607
5.5 MEDIUM

The issue was addressed with improved handling of caches. This issue is fixed in macOS Sonoma 14. An app may be able to modify Printer …

Jan 10, 2024
CVE-2023-32424
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.4 and iPadOS 16.4, watchOS 9.4. An attacker that has already …

Jan 10, 2024
CVE-2023-28185
5.5 MEDIUM

An integer overflow was addressed through improved input validation. This issue is fixed in tvOS 16.4, macOS Big Sur 11.7.5, iOS 16.4 and iPadOS 16.4, …

Jan 10, 2024
CVE-2022-48577
5.5 MEDIUM

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive …

Jan 10, 2024
CVE-2022-48504
5.5 MEDIUM

The issue was addressed with improved handling of caches. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive …

Jan 10, 2024
CVE-2022-46710
5.5 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Location data may be …

Jan 10, 2024
CVE-2022-42816
5.5 MEDIUM

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. An app may be able to modify protected …

Jan 10, 2024
CVE-2022-32931
5.5 MEDIUM

This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app with root privileges may be able to …

Jan 10, 2024
CVE-2022-32919
4.7 MEDIUM

The issue was addressed with improved UI handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Visiting a website that …

Jan 10, 2024
CVE-2023-29447
5.7 MEDIUM

An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the web server uses basic authentication.

Jan 10, 2024
CVE-2023-29446
4.7 MEDIUM

An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a malicious project file. This allows …

Jan 10, 2024
CVE-2022-45793
5.5 MEDIUM

Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker to overwrite files which will result in code execution …

Jan 10, 2024
CVE-2023-48783
5.4 MEDIUM

An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, version 6.0.14 and below, version 5.3.8 and …

Jan 10, 2024
CVE-2023-37934
4.3 MEDIUM

An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiPAM 1.0 all versions allows an authenticated attacker to perform a denial of service …

Jan 10, 2024
CVE-2023-37932
6.5 MEDIUM

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authenticated attacker …

Jan 10, 2024
CVE-2023-29444
6.3 MEDIUM

An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM. Alternatively, they …

Jan 10, 2024
CVE-2023-50172
5.3 MEDIUM

A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can …

Jan 10, 2024
CVE-2023-49864
6.5 MEDIUM

An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead …

Jan 10, 2024
CVE-2023-49863
6.5 MEDIUM

An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead …

Jan 10, 2024
CVE-2023-49862
6.5 MEDIUM

An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead …

Jan 10, 2024
CVE-2023-49715
4.3 MEDIUM

A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request …

Jan 10, 2024
CVE-2023-47171
6.5 MEDIUM

An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request …

Jan 10, 2024
CVE-2023-6158
6.5 MEDIUM

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a …

Jan 10, 2024
CVE-2024-0389
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Student Attendance System 1.0. Affected is an unknown function of the file attendance_report.php. The …

Jan 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.