CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23206
6.5 MEDIUM

An access issue was addressed with improved access restrictions. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS …

Jan 23, 2024
CVE-2024-23204
7.5 HIGH

The issue was addressed with additional permissions checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Monterey …

Jan 23, 2024
CVE-2024-23203
7.5 HIGH

The issue was addressed with additional permissions checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Sonoma …

Jan 23, 2024
CVE-2023-42937
5.5 MEDIUM

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, …

Jan 23, 2024
CVE-2023-42935
5.5 MEDIUM

An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be able to view …

Jan 23, 2024
CVE-2023-42915

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jan 23, 2024
CVE-2023-42888
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS Ventura 13.6.4, macOS Sonoma 14.2, …

Jan 23, 2024
CVE-2023-42887
6.3 MEDIUM

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.6.4, macOS Sonoma 14.2. An app may be able …

Jan 23, 2024
CVE-2023-42881
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2. Processing a file may lead to unexpected app termination …

Jan 23, 2024
CVE-2023-40528
5.5 MEDIUM

This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 17, watchOS 10, macOS Sonoma 14, iOS 17 and iPadOS …

Jan 23, 2024
CVE-2024-23345
7.1 HIGH

Nautobot is a Network Source of Truth and Network Automation Platform built as a web application. All users of Nautobot versions earlier than 1.6.10 or …

Jan 23, 2024
CVE-2024-23342
7.4 HIGH

The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve …

Jan 23, 2024
CVE-2024-23340
5.3 MEDIUM

@hono/node-server is an adapter that allows users to run Hono applications on Node.js. Since v1.3.0, @hono/node-server has used its own Request object with `url` behavior …

Jan 22, 2024
CVE-2024-23339
6.3 MEDIUM

hoolock is a suite of lightweight utilities designed to maintain a small footprint when bundled. Starting in version 2.0.0 and prior to version 2.2.1, utility …

Jan 22, 2024
CVE-2021-42141
9.8 CRITICAL

An issue was discovered in Contiki-NG tinyDTLS through 2018-08-30. One incorrect handshake could complete with different epoch numbers in the packets Client_Hello, Client_key_exchange, and Change_cipher_spec, …

Jan 22, 2024
CVE-2024-23678
7.5 HIGH

In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path input data. This results in the unsafe deserialization …

Jan 22, 2024
CVE-2024-23677
4.3 MEDIUM

In Splunk Enterprise versions below 9.0.8, the Splunk RapidDiag utility discloses server responses from external applications in a log file.

Jan 22, 2024
CVE-2024-23676
4.6 MEDIUM

In Splunk versions below 9.0.8 and 9.1.3, the “mrollup” SPL command lets a low-privileged user view metrics on an index that they do not have …

Jan 22, 2024
CVE-2024-23675
6.5 MEDIUM

In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST application …

Jan 22, 2024
CVE-2023-47141
5.3 MEDIUM

IIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user with CONNECT privileges to cause a denial of …

Jan 22, 2024
CVE-2023-24135
7.8 HIGH

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a command injection vulnerability in the function formWriteFacMac. This vulnerability allows attackers to execute arbitrary …

Jan 22, 2024
CVE-2023-7194
6.1 MEDIUM

The Meris WordPress theme through 1.1.2 does not sanitise and escape some parameters before outputting them back in the page, leading to Reflected Cross-Site Scripting …

Jan 22, 2024
CVE-2023-7170
6.1 MEDIUM

The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in the page, leading to a Reflected Cross-Site …

Jan 22, 2024
CVE-2023-7082
7.2 HIGH

The Import any XML or CSV File to WordPress plugin before 3.7.3 accepts all zip files and automatically extracts the zip file into a publicly …

Jan 22, 2024
CVE-2023-6626
4.8 MEDIUM

The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 22, 2024
CVE-2023-6625
4.3 MEDIUM

The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to …

Jan 22, 2024
CVE-2023-6456
4.8 MEDIUM

The WP Review Slider WordPress plugin before 13.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jan 22, 2024
CVE-2023-6447
5.3 MEDIUM

The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id/event …

Jan 22, 2024
CVE-2023-6384
4.3 MEDIUM

The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar

Jan 22, 2024
CVE-2023-6290
4.8 MEDIUM

The SEOPress WordPress plugin before 7.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jan 22, 2024
CVE-2023-47747
5.3 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated user with CONNECT privileges to cause …

Jan 22, 2024
CVE-2023-47158
5.3 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1 and 11.5 could allow an authenticated user with CONNECT privileges to cause …

Jan 22, 2024
CVE-2023-47152
5.9 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an insecure cryptographic algorithm and to information disclosure in stack …

Jan 22, 2024
CVE-2023-27859
6.5 MEDIUM

IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar files across multiple databases. …

Jan 22, 2024
CVE-2024-0606
6.1 MEDIUM

An attacker could execute unauthorized script on a legitimate site through UXSS using window.open() by opening a javascript URI leading to unauthorized actions within the …

Jan 22, 2024
CVE-2024-0605
7.5 HIGH

Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses security measures, …

Jan 22, 2024
CVE-2024-0430
5.5 MEDIUM

IObit Malware Fighter v11.0.0.1274 is vulnerable to a Denial of Service vulnerability by triggering the 0x8001E00C IOCTL code of the ImfHpRegFilter.sys driver.

Jan 22, 2024
CVE-2023-50308
6.5 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 under certain circumstances could allow an authenticated user to the database to cause …

Jan 22, 2024
CVE-2023-48118
9.8 CRITICAL

SQL Injection vulnerability in Quest Analytics LLC IQCRM v.2023.9.5 allows a remote attacker to execute arbitrary code via a crafted request to the Common.svc WSDL …

Jan 22, 2024
CVE-2023-47746
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user with CONNECT privileges to cause …

Jan 22, 2024
CVE-2023-45193
5.9 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of service when a specially crafted …

Jan 22, 2024
CVE-2024-0784
6.3 MEDIUM

A vulnerability was found in hongmaple octopus 1.0. It has been classified as critical. Affected is an unknown function of the file /system/role/list. The manipulation …

Jan 22, 2024
CVE-2024-0783
6.3 MEDIUM

A vulnerability was found in Project Worlds Online Admission System 1.0 and classified as critical. This issue affects some unknown processing of the file documents.php. …

Jan 22, 2024
CVE-2024-0204
9.8 CRITICAL

Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.

Jan 22, 2024
CVE-2022-45795

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jan 22, 2024
CVE-2022-45792
7.8 HIGH

Project files may contain malicious contents which the software will use to create files on the filesystem. This allows directory traversal and overwriting files with …

Jan 22, 2024
CVE-2022-45791

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jan 22, 2024
CVE-2022-45790
8.6 HIGH

The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentication is susceptible to bruteforce attack, which may allow an adversary …

Jan 22, 2024
CVE-2024-0782
3.5 LOW

A vulnerability has been found in CodeAstro Online Railway Reservation System 1.0 and classified as problematic. This vulnerability affects unknown code of the file pass-profile.php. …

Jan 22, 2024
CVE-2024-0781
3.5 LOW

A vulnerability, which was classified as problematic, was found in CodeAstro Internet Banking System 1.0. This affects an unknown part of the file pages_client_signup.php. The …

Jan 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.