CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-6159
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 …

Jan 26, 2024
CVE-2023-5612
5.3 MEDIUM

An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to …

Jan 26, 2024
CVE-2024-21387
5.3 MEDIUM

Microsoft Edge for Android Spoofing Vulnerability

Jan 26, 2024
CVE-2024-21385
8.3 HIGH

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Jan 26, 2024
CVE-2024-21383
3.3 LOW

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Jan 26, 2024
CVE-2024-21382
4.3 MEDIUM

Microsoft Edge for Android Information Disclosure Vulnerability

Jan 26, 2024
CVE-2024-21326
9.6 CRITICAL

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Jan 26, 2024
CVE-2024-0456
4.3 MEDIUM

An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able …

Jan 26, 2024
CVE-2024-0402
9.9 CRITICAL

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 …

Jan 26, 2024
CVE-2023-5933
6.4 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper …

Jan 26, 2024
CVE-2024-23630
9.0 CRITICAL

An arbitrary firmware upload vulnerability exists in the Motorola MR2600. An attacker can exploit this vulnerability to achieve code execution on the device. Authentication is …

Jan 26, 2024
CVE-2024-23629
9.6 CRITICAL

An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access protected URLs and retrieve …

Jan 26, 2024
CVE-2024-23628
9.0 CRITICAL

A command injection vulnerability exists in the 'SaveStaticRouteIPv6Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication …

Jan 26, 2024
CVE-2024-23627
9.0 CRITICAL

A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication …

Jan 26, 2024
CVE-2024-23626
9.0 CRITICAL

A command injection vulnerability exists in the ‘SaveSysLogParams’ parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication …

Jan 26, 2024
CVE-2024-23625
9.6 CRITICAL

A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenticated attacker can exploit this vulnerability to gain command execution …

Jan 26, 2024
CVE-2024-23624
9.6 CRITICAL

A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerability to gain command execution on …

Jan 26, 2024
CVE-2024-23622
10.0 CRITICAL

A stack-based buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vulnerability to achieve remote code …

Jan 26, 2024
CVE-2024-23621
10.0 CRITICAL

A buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vulnerability to achieve remote code execution.

Jan 26, 2024
CVE-2024-23620
8.8 HIGH

An improper privilege management vulnerability exists in IBM Merge Healthcare eFilm Workstation. A local, authenticated attacker can exploit this vulnerability to escalate privileges to SYSTEM.

Jan 26, 2024
CVE-2024-23619
9.8 CRITICAL

A hardcoded credential vulnerability exists in IBM Merge Healthcare eFilm Workstation. A remote, unauthenticated attacker can exploit this vulnerability to achieve information disclosure or remote …

Jan 26, 2024
CVE-2024-23618
9.6 CRITICAL

An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can exploit this vulnerability to achieve code execution as root.

Jan 26, 2024
CVE-2024-23617
9.6 CRITICAL

A buffer overflow vulnerability exists in Symantec Data Loss Prevention version 14.0.2 and before. A remote, unauthenticated attacker can exploit this vulnerability by enticing a …

Jan 26, 2024
CVE-2024-23616
10.0 CRITICAL

A buffer overflow vulnerability exists in Symantec Server Management Suite version 7.9 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote …

Jan 26, 2024
CVE-2024-23615
10.0 CRITICAL

A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code …

Jan 26, 2024
CVE-2024-23614
10.0 CRITICAL

A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code …

Jan 26, 2024
CVE-2024-23613
10.0 CRITICAL

A buffer overflow vulnerability exists in Symantec Deployment Solution version 7.9 when parsing UpdateComputer tokens. A remote, anonymous attacker can exploit this vulnerability to achieve …

Jan 26, 2024
CVE-2024-21620
8.8 HIGH

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series …

Jan 25, 2024
CVE-2024-21619
5.3 MEDIUM

A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS …

Jan 25, 2024
CVE-2024-0891
3.5 LOW

A vulnerability was found in hongmaple octopus 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of …

Jan 25, 2024
CVE-2024-0890
6.3 MEDIUM

A vulnerability was found in hongmaple octopus 1.0. It has been classified as critical. Affected is an unknown function of the file /system/dept/edit. The manipulation …

Jan 25, 2024
CVE-2024-0889
5.3 MEDIUM

A vulnerability was found in Kmint21 Golden FTP Server 2.02b and classified as problematic. This issue affects some unknown processing of the component PASV Command …

Jan 25, 2024
CVE-2024-23055
6.1 MEDIUM

An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the HOST headers.

Jan 25, 2024
CVE-2024-22922
9.8 CRITICAL

An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page in …

Jan 25, 2024
CVE-2024-0888
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in BORGChat 1.0.0 Build 438. This affects an unknown part of the component Service Port 7551. …

Jan 25, 2024
CVE-2024-0887
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Mafiatic Blue Server 1.1. Affected by this issue is some unknown functionality of the …

Jan 25, 2024
CVE-2024-0886
3.3 LOW

A vulnerability classified as problematic was found in Poikosoft EZ CD Audio Converter 8.0.7. Affected by this vulnerability is an unknown functionality of the component …

Jan 25, 2024
CVE-2023-51833
8.1 HIGH

A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to execute arbitrary code via the data1 parameter in the debug.cgi page.

Jan 25, 2024
CVE-2024-24399
7.2 HIGH

An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code to the backend/languages/index.php languages area.

Jan 25, 2024
CVE-2024-22639
6.1 MEDIUM

iGalerie v3.0.22 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Titre (Title) field in the editing interface.

Jan 25, 2024
CVE-2024-22638
9.8 CRITICAL

liveSite v2019.1 was discovered to contain a remote code execution (RCE) vulenrabiity via the component /livesite/edit_designer_region.php or /livesite/add_email_campaign.php.

Jan 25, 2024
CVE-2024-22637
6.1 MEDIUM

Form Tools v3.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /form_builder/preview.php?form_id=2.

Jan 25, 2024
CVE-2024-22636
8.8 HIGH

PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. This vulnerability is exploited via injecting a …

Jan 25, 2024
CVE-2024-22635
6.1 MEDIUM

WebCalendar v1.3.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /WebCalendarvqsmnseug2/edit_entry.php.

Jan 25, 2024
CVE-2024-0885
5.3 MEDIUM

A vulnerability classified as problematic has been found in SpyCamLizard 1.230. Affected is an unknown function of the component HTTP GET Request Handler. The manipulation …

Jan 25, 2024
CVE-2024-0884
4.7 MEDIUM

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. This issue affects the function exec …

Jan 25, 2024
CVE-2023-52251
8.8 HIGH

An issue discovered in provectus kafka-ui 0.4.0 through 0.7.1 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages.

Jan 25, 2024
CVE-2023-52046
4.8 MEDIUM

Cross Site Scripting vulnerability (XSS) in webmin v.2.105 and earlier allows a remote attacker to execute arbitrary code via a crafted payload to the "Execute …

Jan 25, 2024
CVE-2024-23817
7.1 HIGH

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 18.0.4 has a HTML Injection vulnerability in the Home page …

Jan 25, 2024
CVE-2024-23656
7.5 HIGH

Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves HTTPS with insecure TLS 1.0 and TLS …

Jan 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.