CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-46742
4.8 MEDIUM

CubeFS is an open-source cloud-native file storage system. CubeFS prior to version 3.3.1 was found to leak users secret keys and access keys in the …

Jan 3, 2024
CVE-2023-46741
4.8 MEDIUM

CubeFS is an open-source cloud-native file storage system. A vulnerability was found in CubeFS prior to version 3.3.1 that could allow users to read sensitive …

Jan 3, 2024
CVE-2023-46740
6.5 MEDIUM

CubeFS is an open-source cloud-native file storage system. Prior to version 3.3.1, CubeFS used an insecure random string generator to generate user-specific, sensitive keys used …

Jan 3, 2024
CVE-2023-46739
6.5 MEDIUM

CubeFS is an open-source cloud-native file storage system. A vulnerability was found during in the CubeFS master component in versions prior to 3.3.1 that could …

Jan 3, 2024
CVE-2024-21911
6.1 MEDIUM

TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting …

Jan 3, 2024
CVE-2024-21910
6.1 MEDIUM

TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would …

Jan 3, 2024
CVE-2024-21908
6.1 MEDIUM

TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting …

Jan 3, 2024
CVE-2023-46738
6.5 MEDIUM

CubeFS is an open-source cloud-native file storage system. A security vulnerability was found in CubeFS HandlerNode in versions prior to 3.3.1 that could allow authenticated …

Jan 3, 2024
CVE-2023-30617
6.5 MEDIUM

Kruise provides automated management of large-scale applications on Kubernetes. Starting in version 0.8.0 and prior to versions 1.3.1, 1.4.1, and 1.5.2, an attacker who has …

Jan 3, 2024
CVE-2023-50093
6.1 MEDIUM

APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection.

Jan 3, 2024
CVE-2023-50092
6.1 MEDIUM

APIIDA API Gateway Manager for Broadcom Layer7 v2023.2 is vulnerable to Cross Site Scripting (XSS).

Jan 3, 2024
CVE-2024-0201
5.4 MEDIUM

The Product Expiry for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_settings' function …

Jan 3, 2024
CVE-2023-7068
4.3 MEDIUM

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized access of data due to a missing …

Jan 3, 2024
CVE-2023-6984
5.3 MEDIUM

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Jan 3, 2024
CVE-2023-6747
6.4 MEDIUM

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attributes in all versions up to, …

Jan 3, 2024
CVE-2023-6621
6.1 MEDIUM

The POST SMTP WordPress plugin before 2.8.7 does not sanitise and escape the msg parameter before outputting it back in the page, leading to a …

Jan 3, 2024
CVE-2023-52313
4.7 MEDIUM

FPE in paddle.argmin and paddle.argmax in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-52312
4.7 MEDIUM

Nullptr dereference in paddle.crop in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-52308
4.7 MEDIUM

FPE in paddle.amin in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-52306
4.7 MEDIUM

FPE in paddle.lerp in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-52305
4.7 MEDIUM

FPE in paddle.topk in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-52303
4.7 MEDIUM

Nullptr in paddle.put_along_axis in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-52302
4.7 MEDIUM

Nullptr in paddle.nextafter in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-38678
4.7 MEDIUM

OOB access in paddle.mode in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-38677
4.7 MEDIUM

FPE in paddle.linalg.eig in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-38676
4.7 MEDIUM

Nullptr in paddle.dot in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-38675
4.7 MEDIUM

FPE in paddle.linalg.matrix_rank in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-38674
4.7 MEDIUM

FPE in paddle.nanmedian in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-6986
6.4 MEDIUM

The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable …

Jan 3, 2024
CVE-2023-6981
6.1 MEDIUM

The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to SQL Injection via the 'group_id' parameter …

Jan 3, 2024
CVE-2023-6980
4.3 MEDIUM

The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …

Jan 3, 2024
CVE-2023-6524
6.4 MEDIUM

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the map title parameter in all versions up to and …

Jan 3, 2024
CVE-2023-6629
6.1 MEDIUM

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting …

Jan 3, 2024
CVE-2023-50344
5.4 MEDIUM

HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthenticated user can download certain files.

Jan 3, 2024
CVE-2023-41783
4.3 MEDIUM

There is a command injection vulnerability of ZTE's ZXCLOUD iRAI. Due to the program failed to adequately validate the user's input, an attacker could exploit …

Jan 3, 2024
CVE-2023-41780
6.4 MEDIUM

There is an unsafe DLL loading vulnerability in ZTE ZXCLOUD iRAI. Due to the program failed to adequately validate the user's input, an attacker could …

Jan 3, 2024
CVE-2023-41779
4.4 MEDIUM

There is an illegal memory access vulnerability of ZTE's ZXCLOUD iRAI product.When the vulnerability is exploited by an attacker with the common user permission, the …

Jan 3, 2024
CVE-2023-41776
6.7 MEDIUM

There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to escalate local privileges.

Jan 3, 2024
CVE-2023-49558
5.5 MEDIUM

An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the modules/preprocs/nasm/nasm-pp.c component.

Jan 3, 2024
CVE-2023-49557
5.5 MEDIUM

An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasm/section.c component.

Jan 3, 2024
CVE-2023-49556
5.5 MEDIUM

Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_delete_term function in the libyasm/expr.c component.

Jan 3, 2024
CVE-2023-49555
5.5 MEDIUM

An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the modules/preprocs/nasm/nasm-pp.c component.

Jan 3, 2024
CVE-2023-49554
5.5 MEDIUM

Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_directive function in the modules/preprocs/nasm/nasm-pp.c component.

Jan 3, 2024
CVE-2024-21629
5.9 MEDIUM

Rust EVM is an Ethereum Virtual Machine interpreter. In `rust-evm`, a feature called `record_external_operation` was introduced, allowing library users to record custom gas changes. This …

Jan 2, 2024
CVE-2024-21628
5.4 MEDIUM

PrestaShop is an open-source e-commerce platform. Prior to version 8.1.3, the isCleanHtml method is not used on this this form, which makes it possible to …

Jan 2, 2024
CVE-2024-0196
6.3 MEDIUM

A vulnerability has been found in Magic-Api up to 2.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Jan 2, 2024
CVE-2023-50019
5.9 MEDIUM

An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration …

Jan 2, 2024
CVE-2024-0195
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in spider-flow 0.4.3. Affected is the function FunctionService.saveFunction of the file src/main/java/org/spiderflow/controller/FunctionController.java. The manipulation leads to …

Jan 2, 2024
CVE-2024-0194
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in CodeAstro Internet Banking System up to 1.0. This issue affects some unknown processing of …

Jan 2, 2024
CVE-2023-45561
5.3 MEDIUM

An issue in A-WORLD OIRASE BEER_waiting Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.

Jan 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.