CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23649
7.5 HIGH

Lemmy is a link aggregator and forum for the fediverse. Starting in version 0.17.0 and prior to version 0.19.1, users can report private messages, even …

Jan 24, 2024
CVE-2024-23648
8.8 HIGH

Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The password reset functionality sends to the the user requesting a password change an …

Jan 24, 2024
CVE-2024-22720
4.8 MEDIUM

Kanboard 1.2.34 is vulnerable to Html Injection in the group management feature.

Jan 24, 2024
CVE-2023-52040
9.8 CRITICAL

An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.

Jan 24, 2024
CVE-2023-52039
9.8 CRITICAL

An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.

Jan 24, 2024
CVE-2023-52038
9.8 CRITICAL

An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.

Jan 24, 2024
CVE-2023-51890
7.5 HIGH

An infinite loop issue discovered in Mathtex 1.05 and before allows a remote attackers to consume CPU resources via crafted string in the application URL.

Jan 24, 2024
CVE-2023-51889
9.8 CRITICAL

Stack Overflow vulnerability in the validate() function in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in the …

Jan 24, 2024
CVE-2023-51888
7.5 HIGH

Buffer Overflow vulnerability in the nomath() function in Mathtex v.1.05 and before allows a remote attacker to cause a denial of service via a crafted …

Jan 24, 2024
CVE-2021-42144
9.8 CRITICAL

Buffer over-read vulnerability in Contiki-NG tinyDTLS through master branch 53a0d97 allows attackers obtain sensitive information via crafted input to dtls_ccm_decrypt_message().

Jan 24, 2024
CVE-2021-42143
9.1 CRITICAL

An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. An infinite loop bug exists during the handling of a ClientHello handshake message. This …

Jan 24, 2024
CVE-2024-23641
7.5 HIGH

SvelteKit is a web development kit. In SvelteKit 2, sending a GET request with a body eg `{}` to a built and previewed/hosted sveltekit app …

Jan 24, 2024
CVE-2024-22229
3.1 LOW

Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability …

Jan 24, 2024
CVE-2023-51887
9.8 CRITICAL

Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL.

Jan 24, 2024
CVE-2023-51886
7.5 HIGH

Buffer Overflow vulnerability in the main() function in Mathtex 1.05 and before allows a remote attacker to cause a denial of service when using \convertpath.

Jan 24, 2024
CVE-2023-51885
9.8 CRITICAL

Buffer Overflow vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via the length of the LaTeX string component.

Jan 24, 2024
CVE-2024-22725
6.1 MEDIUM

Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability was present in the server's error reporting.

Jan 24, 2024
CVE-2024-22651
9.8 CRITICAL

There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmware v1.04.

Jan 24, 2024
CVE-2023-44281
6.6 MEDIUM

Dell Pair Installer version prior to 1.2.1 contains an elevation of privilege vulnerability. A low privilege user with local access to the system could potentially …

Jan 24, 2024
CVE-2024-22141
6.5 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: from n/a through 3.10.0.

Jan 24, 2024
CVE-2023-6697
6.1 MEDIUM

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the map id parameter in all versions …

Jan 24, 2024
CVE-2024-22154
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SNP Digital SalesKing.This issue affects SalesKing: from n/a through 1.6.15.

Jan 24, 2024
CVE-2023-51702
6.5 MEDIUM

Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as …

Jan 24, 2024
CVE-2023-50944
6.5 MEDIUM

Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code of a DAG to which they don't …

Jan 24, 2024
CVE-2023-50943
7.5 HIGH

Apache Airflow, versions before 2.8.1, have a vulnerability that allows a potential attacker to poison the XCom data by bypassing the protection of "enable_xcom_pickling=False" configuration …

Jan 24, 2024
CVE-2024-22309
8.7 HIGH

Deserialization of Untrusted Data vulnerability in QuantumCloud ChatBot with AI.This issue affects ChatBot with AI: from n/a through 5.1.0.

Jan 24, 2024
CVE-2024-22308
3.4 LOW

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.4.1.

Jan 24, 2024
CVE-2024-22301
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ignazio Scimone Albo Pretorio On line.This issue affects Albo Pretorio On line: from n/a through …

Jan 24, 2024
CVE-2024-22294
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in IP2Location IP2Location Country Blocker.This issue affects IP2Location Country Blocker: from n/a through 2.33.3.

Jan 24, 2024
CVE-2024-22284
8.7 HIGH

Deserialization of Untrusted Data vulnerability in Thomas Belser Asgaros Forum.This issue affects Asgaros Forum: from n/a through 2.7.2.

Jan 24, 2024
CVE-2024-22152
8.0 HIGH

Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Export for WooCommerce: from n/a through …

Jan 24, 2024
CVE-2024-22135
8.0 HIGH

Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Order Export & Order Import for WooCommerce.This issue affects Order Export & Order Import for …

Jan 24, 2024
CVE-2024-22134
4.9 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Renzo Johnson Contact Form 7 Extension For Mailchimp.This issue affects Contact Form 7 Extension For Mailchimp: from n/a through …

Jan 24, 2024
CVE-2023-52221
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in UkrSolution Barcode Scanner and Inventory manager.This issue affects Barcode Scanner and Inventory manager: from n/a through …

Jan 24, 2024
CVE-2024-0854
5.4 MEDIUM

URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7, 7.1.1-42962-7 and 7.2.1-69057-2 allows remote …

Jan 24, 2024
CVE-2023-44001
5.4 MEDIUM

An issue in Ailand clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-44000
5.4 MEDIUM

An issue in Otakara lapis totuka mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43999
5.4 MEDIUM

An issue in COLORFUL_laundry mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43998
5.4 MEDIUM

An issue in Books-futaba mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43997
5.4 MEDIUM

An issue in Yoruichi hobby base mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43996
5.4 MEDIUM

An issue in Q co ltd mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43995
5.4 MEDIUM

An issue in picot.golf mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43994
5.4 MEDIUM

An issue in Cleaning_makotoya mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43993
5.4 MEDIUM

An issue in smaregi_app_market mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43992
5.4 MEDIUM

An issue in STOCKMAN GROUP mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43991
5.4 MEDIUM

An issue in PRIMA CLINIC mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43990
5.4 MEDIUM

An issue in cherub-hair mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43989
5.4 MEDIUM

An issue in mokumoku chohu mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43988
5.4 MEDIUM

An issue in nature fitness saijo mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2024-0665
6.1 MEDIUM

The WP Customer Area plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 8.2.1 …

Jan 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.