CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-47202
7.8 HIGH

A local file inclusion vulnerability on the Trend Micro Apex One management server could allow a local attacker to escalate privileges on affected installations. Please …

Jan 23, 2024
CVE-2023-47201
7.8 HIGH

A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. …

Jan 23, 2024
CVE-2023-47200
7.8 HIGH

A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. …

Jan 23, 2024
CVE-2023-47199
7.8 HIGH

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: …

Jan 23, 2024
CVE-2023-47198
7.8 HIGH

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: …

Jan 23, 2024
CVE-2023-47197
7.8 HIGH

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: …

Jan 23, 2024
CVE-2023-47196
7.8 HIGH

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: …

Jan 23, 2024
CVE-2023-47195
7.8 HIGH

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: …

Jan 23, 2024
CVE-2023-47194
7.8 HIGH

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: …

Jan 23, 2024
CVE-2023-47193
7.8 HIGH

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: …

Jan 23, 2024
CVE-2023-47192
7.8 HIGH

An agent link vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: …

Jan 23, 2024
CVE-2023-46892
8.8 HIGH

The radio frequency communication protocol being used by Meross MSH30Q 4.5.23 is vulnerable to replay attacks, allowing attackers to record and replay previously captured communication …

Jan 23, 2024
CVE-2023-41178
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided …

Jan 23, 2024
CVE-2023-41177
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided …

Jan 23, 2024
CVE-2023-41176
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided …

Jan 23, 2024
CVE-2023-38627
5.4 MEDIUM

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal …

Jan 23, 2024
CVE-2023-38626
5.4 MEDIUM

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal …

Jan 23, 2024
CVE-2023-38625
5.4 MEDIUM

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal …

Jan 23, 2024
CVE-2023-38624
5.4 MEDIUM

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal …

Jan 23, 2024
CVE-2023-7238
7.1 HIGH

A XSS payload can be uploaded as a DICOM study and when a user tries to view the infected study inside the Osimis WebViewer the …

Jan 23, 2024
CVE-2023-6926
8.4 HIGH

There is an OS command injection vulnerability in Crestron AM-300 firmware version 1.4499.00018 which may enable a user of a limited-access SSH session to escalate …

Jan 23, 2024
CVE-2023-46889
5.7 MEDIUM

Meross MSH30Q 4.5.23 is vulnerable to Cleartext Transmission of Sensitive Information. During the device setup phase, the MSH30Q creates an unprotected Wi-Fi access point. In …

Jan 23, 2024
CVE-2023-42144
5.5 MEDIUM

Cleartext Transmission during initial setup in Shelly TRV 20220811-15234 v.2.1.8 allows a local attacker to obtain the Wi-Fi password.

Jan 23, 2024
CVE-2023-42143
5.4 MEDIUM

Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5afc928c allows malicious users to create a backdoor by redirecting the device to an attacker-controlled machine which serves the …

Jan 23, 2024
CVE-2024-22497
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in /admin/login password parameter in JFinalcms 5.0.0 allows attackers to run arbitrary code via crafted URL.

Jan 23, 2024
CVE-2023-51210
9.8 CRITICAL

SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote attacker to execute arbitrary code via the id_product parameters in the UpdateProductQuantity function.

Jan 23, 2024
CVE-2024-23636
9.8 CRITICAL

SOFARPC is a Java RPC framework. SOFARPC defaults to using the SOFA Hessian protocol to deserialize received data, while the SOFA Hessian protocol uses a …

Jan 23, 2024
CVE-2024-23341
6.1 MEDIUM

TuiTse-TsuSin is a package for organizing the comparative corpus of Taiwanese Chinese characters and Roman characters, and extracting sentences of the Taiwanese Chinese characters and …

Jan 23, 2024
CVE-2024-23330
5.3 MEDIUM

Tuta is an encrypted email service. In versions prior to 119.10, an attacker can attach an image in a html mail which is loaded from …

Jan 23, 2024
CVE-2024-22417
6.1 MEDIUM

Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `element` method in `app/routes.py` does not validate the user-controlled `src_type` and `element_url` …

Jan 23, 2024
CVE-2024-22205
9.1 CRITICAL

Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `window` endpoint does not sanitize user-supplied input from the `location` variable and …

Jan 23, 2024
CVE-2024-22204
5.3 MEDIUM

Whoogle Search is a self-hosted metasearch engine. Versions 0.8.3 and prior have a limited file write vulnerability when the configuration options in Whoogle are enabled. …

Jan 23, 2024
CVE-2024-22203
9.1 CRITICAL

Whoogle Search is a self-hosted metasearch engine. In versions prior to 0.8.4, the `element` method in `app/routes.py` does not validate the user-controlled `src_type` and `element_url` …

Jan 23, 2024
CVE-2023-6573
5.5 MEDIUM

HPE OneView may have a missing passphrase during restore.

Jan 23, 2024
CVE-2023-45889
6.1 MEDIUM

A Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.8 allows remote attackers to inject JavaScript into any webpage. NOTE: this issue …

Jan 23, 2024
CVE-2024-22496
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the /admin/login username parameter.

Jan 23, 2024
CVE-2024-22490
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in beetl-bbs 2.0 allows attackers to run arbitrary code via the /index keyword parameter.

Jan 23, 2024
CVE-2023-50275
7.5 HIGH

HPE OneView may allow clusterService Authentication Bypass resulting in denial of service.

Jan 23, 2024
CVE-2023-50274
7.8 HIGH

HPE OneView may allow command injection with local privilege escalation.

Jan 23, 2024
CVE-2024-23854

Rejected reason: This CVE ID was unused by the CNA.

Jan 23, 2024
CVE-2024-22663
9.8 CRITICAL

TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg

Jan 23, 2024
CVE-2024-22662
9.8 CRITICAL

TOTOLINK A3700R_V9.1.2u.6165_20211012 has a stack overflow vulnerability via setParentalRules

Jan 23, 2024
CVE-2024-22660
9.8 CRITICAL

TOTOLINK_A3700R_V9.1.2u.6165_20211012has a stack overflow vulnerability via setLanguageCfg

Jan 23, 2024
CVE-2023-49657
9.6 CRITICAL

A stored cross-site scripting (XSS) vulnerability exists in Apache Superset before 3.0.3. An authenticated attacker with create/update permissions on charts or dashboards could store a …

Jan 23, 2024
CVE-2024-0755
8.8 HIGH

Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memory corruption and we presume …

Jan 23, 2024
CVE-2024-0754
6.5 MEDIUM

Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.

Jan 23, 2024
CVE-2024-0753
6.5 MEDIUM

In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird …

Jan 23, 2024
CVE-2024-0752
6.5 MEDIUM

A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted in …

Jan 23, 2024
CVE-2024-0751
8.8 HIGH

A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

Jan 23, 2024
CVE-2024-0750
8.8 HIGH

A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects …

Jan 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.