CVE Database

11843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22086
9.8 CRITICAL

handle_request in http.c in cherry through 4b877df has an sscanf stack-based buffer overflow via a long URI, leading to remote code execution.

Jan 5, 2024
CVE-2024-22051
9.8 CRITICAL

CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap …

Jan 4, 2024
CVE-2023-51812
9.8 CRITICAL

Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.

Jan 4, 2024
CVE-2023-51154
9.8 CRITICAL

Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php.

Jan 4, 2024
CVE-2023-50867
9.8 CRITICAL

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the signupAction.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-50866
9.8 CRITICAL

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginAction.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-50865
9.8 CRITICAL

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'city' parameter of the hotelSearch.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-50864
9.8 CRITICAL

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelId' parameter of the hotelDetails.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-50863
9.8 CRITICAL

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the generateReceipt.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-50862
9.8 CRITICAL

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the booking.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-50753
9.8 CRITICAL

Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parameter of the user/update_profile.php resource does not validate the characters …

Jan 4, 2024
CVE-2023-50752
9.8 CRITICAL

Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'e' parameter of the login.php resource does not validate the characters …

Jan 4, 2024
CVE-2023-50743
9.8 CRITICAL

Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parameter of the registration.php resource does not validate the characters …

Jan 4, 2024
CVE-2023-49666
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'custmer_details' parameter of the submit_material_list.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49665
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'quantity[]' parameter of the submit_delivery_list.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49658
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'bank_details' parameter of the party_submit.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49639
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'customer_details' parameter of the buyer_invoice_submit.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49633
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'buyer_address' parameter of the buyer_detail_submit.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49625
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the partylist_edit_submit.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49624
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cancelid' parameter of the material_bill.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49622
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'itemnameid' parameter of the material_bill.php?action=itemRelation resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49442
9.8 CRITICAL

Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.

Jan 3, 2024
CVE-2023-50090
9.8 CRITICAL

Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write arbitrary files and run arbitrary commands via crafted …

Jan 3, 2024
CVE-2023-50253
9.6 CRITICAL

Laf is a cloud development platform. In the Laf version design, the log uses communication with k8s to quickly retrieve logs from the container without …

Jan 3, 2024
CVE-2023-39655
9.6 CRITICAL

A host header injection vulnerability exists in the NPM package @perfood/couch-auth versions <= 0.20.0. By sending a specially crafted host header in the forgot password …

Jan 3, 2024
CVE-2023-51784
9.8 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, which could lead to Remote …

Jan 3, 2024
CVE-2023-52314
9.6 CRITICAL

PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. This resulted in the ability to execute arbitrary commands on the operating system.

Jan 3, 2024
CVE-2023-52311
9.6 CRITICAL

PaddlePaddle before 2.6.0 has a command injection in _wget_download. This resulted in the ability to execute arbitrary commands on the operating system.

Jan 3, 2024
CVE-2023-52310
9.6 CRITICAL

PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute arbitrary commands on the operating system.

Jan 3, 2024
CVE-2023-50921
9.8 CRITICAL

An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. This affects …

Jan 3, 2024
CVE-2023-46308
9.8 CRITICAL

In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty.

Jan 3, 2024
CVE-2023-48418
10.0 CRITICAL

In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion due to an insecure default value. This could lead to …

Jan 2, 2024
CVE-2023-6339
10.0 CRITICAL

Google Nest WiFi Pro root code-execution & user-data compromise

Jan 2, 2024
CVE-2024-21623
9.8 CRITICAL

OTCLient is an alternative tibia client for otserv. Prior to commit db560de0b56476c87a2f967466407939196dd254, the /mehah/otclient "`Analysis - SonarCloud`" workflow is vulnerable to an expression injection in …

Jan 2, 2024
CVE-2023-47458
9.8 CRITICAL

An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.

Jan 2, 2024
CVE-2023-48419
10.0 CRITICAL

An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege

Jan 2, 2024
CVE-2023-4280
9.3 CRITICAL

An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of …

Jan 2, 2024
CVE-2023-6436
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ekol Informatics Website Template allows SQL Injection.This issue affects Website Template: …

Jan 2, 2024
CVE-2023-33032
9.3 CRITICAL

Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.

Jan 2, 2024
CVE-2023-33030
9.3 CRITICAL

Memory corruption in HLOS while running playready use-case.

Jan 2, 2024
CVE-2023-33025
9.8 CRITICAL

Memory corruption in Data Modem when a non-standard SDP body, during a VOLTE call.

Jan 2, 2024
CVE-2023-32874
9.8 CRITICAL

In Modem IMS Stack, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution …

Jan 2, 2024
CVE-2023-5877
9.8 CRITICAL

The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, …

Jan 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.