CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-51711
7.8 HIGH

An issue was discovered in Regify Regipay Client for Windows version 4.5.1.0 allows DLL hijacking: a user can trigger the execution of arbitrary code every …

Jan 24, 2024
CVE-2023-43317
8.8 HIGH

An issue in Coign CRM Portal v.06.06 allows a remote attacker to escalate privileges via the userPermissionsList parameter in Session Storage component.

Jan 24, 2024
CVE-2024-22372
6.8 MEDIUM

OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by sending a …

Jan 24, 2024
CVE-2024-22366
6.8 MEDIUM

Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug function accesses the …

Jan 24, 2024
CVE-2023-31037
7.2 HIGH

NVIDIA Bluefield 2 and Bluefield 3 DPU BMC contains a vulnerability in ipmitool, where a root user may cause code injection by a network call. …

Jan 24, 2024
CVE-2024-22380
5.5 MEDIUM

Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development Project Version) March, Heisei 31 era edition Ver.14.0.001.002 and earlier …

Jan 24, 2024
CVE-2024-21796
5.5 MEDIUM

Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4 and Electronic Deliverables Creation Support Tool (Design & Survey Edition) prior to Ver1.0.4 improperly restrict …

Jan 24, 2024
CVE-2024-21765
5.5 MEDIUM

Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 and earlier, Electronic Delivery Check System (Kikai) Ver.10.1.0 and earlier, and …

Jan 24, 2024
CVE-2022-4964
5.5 MEDIUM

Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.

Jan 24, 2024
CVE-2024-23638
6.5 MEDIUM

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial …

Jan 24, 2024
CVE-2024-23633
4.7 MEDIUM

Label Studio, an open source data labeling tool had a remote import feature allowed users to import data from a remote web source, that was …

Jan 24, 2024
CVE-2024-23453
5.5 MEDIUM

Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key when the application …

Jan 24, 2024
CVE-2024-0814
6.5 MEDIUM

Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. …

Jan 24, 2024
CVE-2024-0813
8.8 HIGH

Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to …

Jan 24, 2024
CVE-2024-0812
8.8 HIGH

Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium …

Jan 24, 2024
CVE-2024-0811
4.3 MEDIUM

Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak …

Jan 24, 2024
CVE-2024-0810
4.3 MEDIUM

Insufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak …

Jan 24, 2024
CVE-2024-0809
4.3 MEDIUM

Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security …

Jan 24, 2024
CVE-2024-0808
9.8 CRITICAL

Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security …

Jan 24, 2024
CVE-2024-0807
8.8 HIGH

Use after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Jan 24, 2024
CVE-2024-0806
8.8 HIGH

Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction. (Chromium …

Jan 24, 2024
CVE-2024-0805
4.3 MEDIUM

Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security …

Jan 24, 2024
CVE-2024-0804
7.5 HIGH

Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to leak cross-origin data via a crafted HTML …

Jan 24, 2024
CVE-2023-47115
7.1 HIGH

Label Studio is an a popular open source data labeling tool. Versions prior to 1.9.2 have a cross-site scripting (XSS) vulnerability that could be exploited …

Jan 23, 2024
CVE-2023-35837
9.8 CRITICAL

An issue was discovered in SolaX Pocket WiFi 3 through 3.001.02. Authentication for web interface is completed via an unauthenticated WiFi AP. The administrative password …

Jan 23, 2024
CVE-2023-35836
6.5 MEDIUM

An issue was discovered in SolaX Pocket WiFi 3 through 3.001.02. An attacker within RF range can obtain a cleartext copy of the network configuration …

Jan 23, 2024
CVE-2023-35835
9.8 CRITICAL

An issue was discovered in SolaX Pocket WiFi 3 through 3.001.02. The device provides a WiFi access point for initial configuration. The WiFi network provided …

Jan 23, 2024
CVE-2023-7237
5.7 MEDIUM

Lantronix XPort sends weakly encoded credentials within web request headers.

Jan 23, 2024
CVE-2023-51208

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Jan 23, 2024
CVE-2023-51201

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Jan 23, 2024
CVE-2023-51199

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Jan 23, 2024
CVE-2023-36177
9.8 CRITICAL

An issue was discovered in badaix Snapcast version 0.27.0, allows remote attackers to execute arbitrary code and gain sensitive information via crafted request in JSON-RPC-API.

Jan 23, 2024
CVE-2023-31654
9.8 CRITICAL

Redis raft master-1b8bd86 to master-7b46079 was discovered to contain an ODR violation via the component hiredisAllocFns at /opt/fs/redisraft/deps/hiredis/alloc.c.

Jan 23, 2024
CVE-2021-42142
9.8 CRITICAL

An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers mishandle the early use of a large epoch number. This vulnerability allows …

Jan 23, 2024
CVE-2023-52338
7.8 HIGH

A link following vulnerability in the Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a …

Jan 23, 2024
CVE-2023-52337
7.8 HIGH

An improper access control vulnerability in Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a …

Jan 23, 2024
CVE-2023-52331
7.1 HIGH

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central could allow an attacker to interact with internal or local services directly. Please …

Jan 23, 2024
CVE-2023-52330
6.1 MEDIUM

A cross-site scripting vulnerability in Trend Micro Apex Central could allow a remote attacker to execute arbitrary code on affected installations of Trend Micro Apex …

Jan 23, 2024
CVE-2023-52329
6.1 MEDIUM

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code …

Jan 23, 2024
CVE-2023-52328
6.1 MEDIUM

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code …

Jan 23, 2024
CVE-2023-52327
6.1 MEDIUM

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code …

Jan 23, 2024
CVE-2023-52326
6.1 MEDIUM

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code …

Jan 23, 2024
CVE-2023-52325
7.5 HIGH

A local file inclusion vulnerability in one of Trend Micro Apex Central's widgets could allow a remote attacker to execute arbitrary code on affected installations. …

Jan 23, 2024
CVE-2023-52324
8.8 HIGH

An unrestricted file upload vulnerability in Trend Micro Apex Central could allow a remote attacker to create arbitrary files on affected installations. Please note: although …

Jan 23, 2024
CVE-2023-52094
7.8 HIGH

An updater link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to abuse the updater to delete an arbitrary …

Jan 23, 2024
CVE-2023-52093
7.8 HIGH

An exposed dangerous function vulnerability in the Trend Micro Apex One agent could allow a local attacker to escalate privileges on affected installations. Please note: …

Jan 23, 2024
CVE-2023-52092
7.8 HIGH

A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an …

Jan 23, 2024
CVE-2023-52091
7.8 HIGH

An anti-spyware engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an …

Jan 23, 2024
CVE-2023-52090
7.8 HIGH

A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an …

Jan 23, 2024
CVE-2023-51200

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Jan 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.