CVE Database

59927+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-52328
6.1 MEDIUM

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code …

Jan 23, 2024
CVE-2023-52327
6.1 MEDIUM

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code …

Jan 23, 2024
CVE-2023-52326
6.1 MEDIUM

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code …

Jan 23, 2024
CVE-2023-41178
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided …

Jan 23, 2024
CVE-2023-41177
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided …

Jan 23, 2024
CVE-2023-41176
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided …

Jan 23, 2024
CVE-2023-38627
5.4 MEDIUM

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal …

Jan 23, 2024
CVE-2023-38626
5.4 MEDIUM

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal …

Jan 23, 2024
CVE-2023-38625
5.4 MEDIUM

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal …

Jan 23, 2024
CVE-2023-38624
5.4 MEDIUM

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal …

Jan 23, 2024
CVE-2023-46889
5.7 MEDIUM

Meross MSH30Q 4.5.23 is vulnerable to Cleartext Transmission of Sensitive Information. During the device setup phase, the MSH30Q creates an unprotected Wi-Fi access point. In …

Jan 23, 2024
CVE-2023-42144
5.5 MEDIUM

Cleartext Transmission during initial setup in Shelly TRV 20220811-15234 v.2.1.8 allows a local attacker to obtain the Wi-Fi password.

Jan 23, 2024
CVE-2023-42143
5.4 MEDIUM

Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5afc928c allows malicious users to create a backdoor by redirecting the device to an attacker-controlled machine which serves the …

Jan 23, 2024
CVE-2024-22497
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in /admin/login password parameter in JFinalcms 5.0.0 allows attackers to run arbitrary code via crafted URL.

Jan 23, 2024
CVE-2024-23341
6.1 MEDIUM

TuiTse-TsuSin is a package for organizing the comparative corpus of Taiwanese Chinese characters and Roman characters, and extracting sentences of the Taiwanese Chinese characters and …

Jan 23, 2024
CVE-2024-23330
5.3 MEDIUM

Tuta is an encrypted email service. In versions prior to 119.10, an attacker can attach an image in a html mail which is loaded from …

Jan 23, 2024
CVE-2024-22417
6.1 MEDIUM

Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `element` method in `app/routes.py` does not validate the user-controlled `src_type` and `element_url` …

Jan 23, 2024
CVE-2024-22204
5.3 MEDIUM

Whoogle Search is a self-hosted metasearch engine. Versions 0.8.3 and prior have a limited file write vulnerability when the configuration options in Whoogle are enabled. …

Jan 23, 2024
CVE-2023-6573
5.5 MEDIUM

HPE OneView may have a missing passphrase during restore.

Jan 23, 2024
CVE-2023-45889
6.1 MEDIUM

A Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.8 allows remote attackers to inject JavaScript into any webpage. NOTE: this issue …

Jan 23, 2024
CVE-2024-22496
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the /admin/login username parameter.

Jan 23, 2024
CVE-2024-22490
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in beetl-bbs 2.0 allows attackers to run arbitrary code via the /index keyword parameter.

Jan 23, 2024
CVE-2024-0754
6.5 MEDIUM

Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.

Jan 23, 2024
CVE-2024-0753
6.5 MEDIUM

In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird …

Jan 23, 2024
CVE-2024-0752
6.5 MEDIUM

A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted in …

Jan 23, 2024
CVE-2024-0749
4.3 MEDIUM

A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox …

Jan 23, 2024
CVE-2024-0748
4.3 MEDIUM

A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar …

Jan 23, 2024
CVE-2024-0747
6.5 MEDIUM

When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. …

Jan 23, 2024
CVE-2024-0746
6.5 MEDIUM

A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, …

Jan 23, 2024
CVE-2024-0742
4.3 MEDIUM

It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to …

Jan 23, 2024
CVE-2024-0741
6.5 MEDIUM

An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox …

Jan 23, 2024
CVE-2023-49783
4.3 MEDIUM

Silverstripe Admin provides a basic management interface for the Silverstripe Framework. In versions on the 1.x branch prior to 1.13.19 and on the 2.x branch …

Jan 23, 2024
CVE-2023-48714
4.3 MEDIUM

Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to versions 4.13.39 and 5.1.11, if a user should …

Jan 23, 2024
CVE-2023-44401
5.3 MEDIUM

The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `canView` permission checks …

Jan 23, 2024
CVE-2024-0703
4.4 MEDIUM

The Sticky Buttons – floating buttons builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via sticky URLs in all versions up to, and …

Jan 23, 2024
CVE-2024-23183
5.4 MEDIUM

Cross-site scripting vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x …

Jan 23, 2024
CVE-2024-23181
6.1 MEDIUM

Cross-site scripting vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x …

Jan 23, 2024
CVE-2023-46343
5.5 MEDIUM

In the Linux kernel before 6.5.9, there is a NULL pointer dereference in send_acknowledge in net/nfc/nci/spi.c.

Jan 23, 2024
CVE-2024-23851
5.5 MEDIUM

copy_params in drivers/md/dm-ioctl.c in the Linux kernel through 6.7.1 can attempt to allocate more than INT_MAX bytes, and crash, because of a missing param_kernel->data_size check. …

Jan 23, 2024
CVE-2024-23850
5.5 MEDIUM

In btrfs_get_root_ref in fs/btrfs/disk-io.c in the Linux kernel through 6.7.1, there can be an assertion failure and crash because a subvolume can be read out …

Jan 23, 2024
CVE-2024-23849
5.5 MEDIUM

In rds_recv_track_latency in net/rds/af_rds.c in the Linux kernel through 6.7.1, there is an off-by-one error for an RDS_MSG_RX_DGRAM_TRACE_MAX comparison, resulting in out-of-bounds access.

Jan 23, 2024
CVE-2024-23848
5.5 MEDIUM

In the Linux kernel through 6.7.1, there is a use-after-free in cec_queue_msg_fh, related to drivers/media/cec/core/cec-adap.c and drivers/media/cec/core/cec-api.c.

Jan 23, 2024
CVE-2024-0587
6.1 MEDIUM

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'disqus_name' parameter in all versions up …

Jan 23, 2024
CVE-2023-39197
4.0 MEDIUM

An out-of-bounds read vulnerability was found in Netfilter Connection Tracking (conntrack) in the Linux kernel. This flaw allows a remote user to disclose sensitive information …

Jan 23, 2024
CVE-2024-23224
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.3, macOS Ventura 13.6.4. An app may be able to access …

Jan 23, 2024
CVE-2024-23223
6.2 MEDIUM

A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, …

Jan 23, 2024
CVE-2024-23219
6.2 MEDIUM

The issue was addressed with improved authentication. This issue is fixed in iOS 17.3 and iPadOS 17.3. Stolen Device Protection may be unexpectedly disabled.

Jan 23, 2024
CVE-2024-23218
5.9 MEDIUM

A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS …

Jan 23, 2024
CVE-2024-23215
5.5 MEDIUM

An issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, …

Jan 23, 2024
CVE-2024-23207
5.5 MEDIUM

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma …

Jan 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.