CVE Database

11843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-27168
9.8 CRITICAL

An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.

Jan 19, 2024
CVE-2024-0705
9.8 CRITICAL

The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, …

Jan 19, 2024
CVE-2023-5716
9.8 CRITICAL

ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary files by sending specific HTTP requests …

Jan 19, 2024
CVE-2024-22212
9.6 CRITICAL

Nextcloud Global Site Selector is a tool which allows you to run multiple small Nextcloud instances and redirect users to the right server. A problem …

Jan 18, 2024
CVE-2023-40051
9.1 CRITICAL

This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0. …

Jan 18, 2024
CVE-2024-22317
9.1 CRITICAL

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.24 and 12.0.1.0 through 12.0.11.0 could allow a remote attacker to obtain sensitive information or cause a denial of …

Jan 18, 2024
CVE-2023-5806
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mergen Software Quality Management System allows SQL Injection.This issue affects Quality …

Jan 18, 2024
CVE-2023-6816
9.8 CRITICAL

A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be …

Jan 18, 2024
CVE-2024-22416
9.6 CRITICAL

pyLoad is a free and open-source Download Manager written in pure Python. The `pyload` API allows any API call to be made using GET requests. …

Jan 18, 2024
CVE-2023-44077
9.8 CRITICAL

Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636.

Jan 17, 2024
CVE-2024-0643
10.0 CRITICAL

Unrestricted upload of dangerous file types in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to upload …

Jan 17, 2024
CVE-2024-0642
9.8 CRITICAL

Inadequate access control in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to access the application as …

Jan 17, 2024
CVE-2021-4434
10.0 CRITICAL

The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. This allows …

Jan 17, 2024
CVE-2024-22406
9.3 CRITICAL

Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enables users to search through information stored within their …

Jan 16, 2024
CVE-2024-22916
9.8 CRITICAL

In D-LINK Go-RT-AC750 v101b03, the sprintf function in the sub_40E700 function within the cgibin is susceptible to stack overflow.

Jan 16, 2024
CVE-2023-52042
9.8 CRITICAL

An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parameter.

Jan 16, 2024
CVE-2023-39691
9.8 CRITICAL

An issue discovered in kodbox through 1.43 allows attackers to arbitrarily add Administrator accounts via crafted GET request.

Jan 16, 2024
CVE-2023-52041
9.8 CRITICAL

An issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code via the sub_410118 function of the shttpd program.

Jan 16, 2024
CVE-2023-49351
9.8 CRITICAL

A stack-based buffer overflow vulnerability in /bin/webs binary in Edimax BR6478AC V2 firmware veraion v1.23 allows attackers to overwrite other values located on the stack …

Jan 16, 2024
CVE-2023-3211
9.8 CRITICAL

The WordPress Database Administrator WordPress plugin through 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an …

Jan 16, 2024
CVE-2023-0224
9.8 CRITICAL

The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could let unauthenticated attackers perform SQL Injection …

Jan 16, 2024
CVE-2022-1609
9.8 CRITICAL

The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an …

Jan 16, 2024
CVE-2023-52103
9.8 CRITICAL

Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds read.

Jan 16, 2024
CVE-2023-52101
9.1 CRITICAL

Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service availability and integrity.

Jan 16, 2024
CVE-2023-34063
9.9 CRITICAL

Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability leading to unauthorized access to remote organizations and workflows.

Jan 16, 2024
CVE-2023-22527
9.8 CRITICAL KEV

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers …

Jan 16, 2024
CVE-2023-6623
9.8 CRITICAL

The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may …

Jan 15, 2024
CVE-2023-6049
9.8 CRITICAL

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users to perform PHP …

Jan 15, 2024
CVE-2023-46226
9.8 CRITICAL

Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2. Users are recommended to upgrade to version 1.3.0, which fixes …

Jan 15, 2024
CVE-2020-36770
9.8 CRITICAL

pkg_postinst in the Gentoo ebuild for Slurm through 22.05.3 unnecessarily calls chown to assign root's ownership on files in the live root filesystem. This could …

Jan 15, 2024
CVE-2024-0552
9.8 CRITICAL

Intumit inc. SmartRobot's web framwork has a remote code execution vulnerability. An unauthorized remote attacker can exploit this vulnerability to execute arbitrary commands on the …

Jan 15, 2024
CVE-2023-46943
9.1 CRITICAL

An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generating tokens is hardcoded as "secret". A weak HMAC …

Jan 13, 2024
CVE-2023-51698
9.6 CRITICAL

Atril is a simple multi-page document viewer. Atril is vulnerable to a critical Command Injection Vulnerability. This vulnerability gives the attacker immediate access to the …

Jan 12, 2024
CVE-2024-22206
9.0 CRITICAL

Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in …

Jan 12, 2024
CVE-2023-31030
9.3 CRITICAL

NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially …

Jan 12, 2024
CVE-2023-31029
9.3 CRITICAL

NVIDIA DGX A100 baseboard management controller (BMC) contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by …

Jan 12, 2024
CVE-2023-31024
9.0 CRITICAL

NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause stack memory corruption by sending a specially …

Jan 12, 2024
CVE-2024-21887
9.1 CRITICAL KEV

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send …

Jan 12, 2024
CVE-2023-49262
9.8 CRITICAL

The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided there is an active user session.

Jan 12, 2024
CVE-2023-49255
9.8 CRITICAL

The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order to modify the configuration, …

Jan 12, 2024
CVE-2023-49253
9.8 CRITICAL

Root user password is hardcoded into the device and cannot be changed in the user interface.

Jan 12, 2024
CVE-2023-7028
10.0 CRITICAL KEV

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 …

Jan 12, 2024
CVE-2023-52026
9.8 CRITICAL

TOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via the telnet_enabled parameter of the setTelnetCfg interface

Jan 12, 2024
CVE-2023-49569
9.8 CRITICAL

A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. …

Jan 12, 2024
CVE-2023-30016
9.8 CRITICAL

SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via sub_event_id parameter in sub_event_details_edit.php.

Jan 12, 2024
CVE-2023-30015
9.8 CRITICAL

SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via txtsearch parameter in review_search.php.

Jan 12, 2024
CVE-2023-30014
9.8 CRITICAL

SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via sub_event_id parameter in sub_event_stat_update.php.

Jan 12, 2024
CVE-2023-50919
9.8 CRITICAL

An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, …

Jan 12, 2024
CVE-2023-37117
9.8 CRITICAL

A heap-use-after-free vulnerability was found in live555 version 2023.05.10 while handling the SETUP.

Jan 12, 2024
CVE-2022-48620
9.8 CRITICAL

uev (aka libuev) before 2.4.1 has a buffer overflow in epoll_wait if maxevents is a large number.

Jan 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.