CVE Database

9974+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-3211
9.8 CRITICAL

The WordPress Database Administrator WordPress plugin through 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an …

Jan 16, 2024
CVE-2023-0224
9.8 CRITICAL

The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could let unauthenticated attackers perform SQL Injection …

Jan 16, 2024
CVE-2022-1609
9.8 CRITICAL

The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an …

Jan 16, 2024
CVE-2023-52103
9.8 CRITICAL

Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds read.

Jan 16, 2024
CVE-2023-52101
9.1 CRITICAL

Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service availability and integrity.

Jan 16, 2024
CVE-2023-34063
9.9 CRITICAL

Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability leading to unauthorized access to remote organizations and workflows.

Jan 16, 2024
CVE-2023-22527
9.8 CRITICAL KEV

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers …

Jan 16, 2024
CVE-2023-6623
9.8 CRITICAL

The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may …

Jan 15, 2024
CVE-2023-6049
9.8 CRITICAL

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users to perform PHP …

Jan 15, 2024
CVE-2023-46226
9.8 CRITICAL

Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2. Users are recommended to upgrade to version 1.3.0, which fixes …

Jan 15, 2024
CVE-2020-36770
9.8 CRITICAL

pkg_postinst in the Gentoo ebuild for Slurm through 22.05.3 unnecessarily calls chown to assign root's ownership on files in the live root filesystem. This could …

Jan 15, 2024
CVE-2024-0552
9.8 CRITICAL

Intumit inc. SmartRobot's web framwork has a remote code execution vulnerability. An unauthorized remote attacker can exploit this vulnerability to execute arbitrary commands on the …

Jan 15, 2024
CVE-2023-46943
9.1 CRITICAL

An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generating tokens is hardcoded as "secret". A weak HMAC …

Jan 13, 2024
CVE-2023-51698
9.6 CRITICAL

Atril is a simple multi-page document viewer. Atril is vulnerable to a critical Command Injection Vulnerability. This vulnerability gives the attacker immediate access to the …

Jan 12, 2024
CVE-2024-22206
9.0 CRITICAL

Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in …

Jan 12, 2024
CVE-2023-31030
9.3 CRITICAL

NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially …

Jan 12, 2024
CVE-2023-31029
9.3 CRITICAL

NVIDIA DGX A100 baseboard management controller (BMC) contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by …

Jan 12, 2024
CVE-2023-31024
9.0 CRITICAL

NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause stack memory corruption by sending a specially …

Jan 12, 2024
CVE-2024-21887
9.1 CRITICAL KEV

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send …

Jan 12, 2024
CVE-2023-49262
9.8 CRITICAL

The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided there is an active user session.

Jan 12, 2024
CVE-2023-49255
9.8 CRITICAL

The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order to modify the configuration, …

Jan 12, 2024
CVE-2023-49253
9.8 CRITICAL

Root user password is hardcoded into the device and cannot be changed in the user interface.

Jan 12, 2024
CVE-2023-7028
10.0 CRITICAL KEV

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 …

Jan 12, 2024
CVE-2023-52026
9.8 CRITICAL

TOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via the telnet_enabled parameter of the setTelnetCfg interface

Jan 12, 2024
CVE-2023-49569
9.8 CRITICAL

A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. …

Jan 12, 2024
CVE-2023-30016
9.8 CRITICAL

SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via sub_event_id parameter in sub_event_details_edit.php.

Jan 12, 2024
CVE-2023-30015
9.8 CRITICAL

SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via txtsearch parameter in review_search.php.

Jan 12, 2024
CVE-2023-30014
9.8 CRITICAL

SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via sub_event_id parameter in sub_event_stat_update.php.

Jan 12, 2024
CVE-2023-50919
9.8 CRITICAL

An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, …

Jan 12, 2024
CVE-2023-37117
9.8 CRITICAL

A heap-use-after-free vulnerability was found in live555 version 2023.05.10 while handling the SETUP.

Jan 12, 2024
CVE-2022-48620
9.8 CRITICAL

uev (aka libuev) before 2.4.1 has a buffer overflow in epoll_wait if maxevents is a large number.

Jan 12, 2024
CVE-2016-20021
9.8 CRITICAL

In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature …

Jan 12, 2024
CVE-2024-21591
9.8 CRITICAL

An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a …

Jan 12, 2024
CVE-2023-51350
9.8 CRITICAL

A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the X-Forwarded-For …

Jan 11, 2024
CVE-2024-22199
9.3 CRITICAL

This package provides universal methods to use multiple template engines with the Fiber web framework using the Views interface. This vulnerability specifically impacts web applications …

Jan 11, 2024
CVE-2024-23061
9.8 CRITICAL

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the minute parameter in the setScheduleCfg function.

Jan 11, 2024
CVE-2024-23060
9.8 CRITICAL

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the setDmzCfg function.

Jan 11, 2024
CVE-2024-23059
9.8 CRITICAL

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the username parameter in the setDdnsCfg function.

Jan 11, 2024
CVE-2024-23058
9.8 CRITICAL

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pass parameter in the setTr069Cfg function.

Jan 11, 2024
CVE-2024-23057
9.8 CRITICAL

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the tz parameter in the setNtpCfg function.

Jan 11, 2024
CVE-2024-22942
9.8 CRITICAL

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the hostName parameter in the setWanCfg function.

Jan 11, 2024
CVE-2023-51987
9.8 CRITICAL

D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator accounts with empty passwords.

Jan 11, 2024
CVE-2023-51984
9.8 CRITICAL

D-Link DIR-822+ V1.0.2 was found to contain a command injection in SetStaticRouteSettings function. allows remote attackers to execute arbitrary commands via shell.

Jan 11, 2024
CVE-2023-6875
9.8 CRITICAL

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of …

Jan 11, 2024
CVE-2023-6567
9.8 CRITICAL

The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 4.2.5.7 due to …

Jan 11, 2024
CVE-2023-6316
9.8 CRITICAL

The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the '_single_file_upload' function in versions …

Jan 11, 2024
CVE-2023-52032
9.8 CRITICAL

TOTOlink EX1200T V4.1.2cu.5232_B20210713 was discovered to contain a remote command execution (RCE) vulnerability via the "main" function.

Jan 11, 2024
CVE-2023-52031
9.8 CRITICAL

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the UploadFirmwareFile function.

Jan 11, 2024
CVE-2023-52030
9.8 CRITICAL

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setOpModeCfg function.

Jan 11, 2024
CVE-2023-52029
9.8 CRITICAL

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setDiagnosisCfg function.

Jan 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.