CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23688
5.3 MEDIUM

Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's …

Jan 19, 2024
CVE-2024-23687
9.1 CRITICAL

Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify configurations …

Jan 19, 2024
CVE-2024-23686
5.3 MEDIUM

DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows …

Jan 19, 2024
CVE-2024-0739
7.3 HIGH

A vulnerability, which was classified as critical, was found in Hecheng Leadshop up to 1.4.20. Affected is an unknown function of the file /web/leadshop.php. The …

Jan 19, 2024
CVE-2024-0738
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in 个人开源 mldong 1.0. This issue affects the function ExpressionEngine of the file com/mldong/modules/wf/engine/model/DecisionModel.java. The …

Jan 19, 2024
CVE-2024-0737
5.3 MEDIUM

A vulnerability classified as problematic was found in Xlightftpd Xlight FTP Server 1.1. This vulnerability affects unknown code of the component Login. The manipulation of …

Jan 19, 2024
CVE-2024-23689
8.8 HIGH

Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificate …

Jan 19, 2024
CVE-2024-23685
5.3 MEDIUM

Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, …

Jan 19, 2024
CVE-2024-23684
7.5 HIGH

Inefficient algorithmic complexity in DecodeFromBytes function in com.upokecenter.cbor Java implementation of Concise Binary Object Representation (CBOR) versions 4.0.0 to 4.5.1 allows an attacker to cause …

Jan 19, 2024
CVE-2024-23683
8.2 HIGH

Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker …

Jan 19, 2024
CVE-2024-23682
8.2 HIGH

Artemis Java Test Sandbox versions before 1.8.0 are vulnerable to a sandbox escape when an attacker includes class files in a package that Ares trusts. …

Jan 19, 2024
CVE-2024-23681
8.2 HIGH

Artemis Java Test Sandbox versions before 1.11.2 are vulnerable to a sandbox escape when an attacker loads untrusted libraries using System.load or System.loadLibrary. An attacker …

Jan 19, 2024
CVE-2024-23680
5.3 MEDIUM

AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.

Jan 19, 2024
CVE-2024-23679
9.8 CRITICAL

Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the …

Jan 19, 2024
CVE-2024-22421
7.6 HIGH

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious …

Jan 19, 2024
CVE-2024-22420
6.5 MEDIUM

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. This vulnerability depends on user interaction by opening …

Jan 19, 2024
CVE-2024-0758
6.1 MEDIUM

MolecularFaces before 0.3.0 is vulnerable to cross site scripting. A remote attacker can execute arbitrary JavaScript in the context of a victim browser via crafted …

Jan 19, 2024
CVE-2024-0736
5.3 MEDIUM

A vulnerability classified as problematic has been found in EFS Easy File Sharing FTP 3.6. This affects an unknown part of the component Login. The …

Jan 19, 2024
CVE-2024-0735
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. Affected by this issue is the …

Jan 19, 2024
CVE-2024-0734
6.3 MEDIUM

A vulnerability was found in Smsot up to 2.12. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Jan 19, 2024
CVE-2024-0733
6.3 MEDIUM

A vulnerability was found in Smsot up to 2.12. It has been classified as critical. Affected is an unknown function of the file /api.php of …

Jan 19, 2024
CVE-2023-49329
7.2 HIGH

Anomali Match before 4.6.2 allows OS Command Injection. An authenticated admin user can inject and execute operating system commands. This arises from improper handling of …

Jan 19, 2024
CVE-2024-23331
7.5 HIGH

Vite is a frontend tooling framework for javascript. The Vite dev server option `server.fs.deny` can be bypassed on case-insensitive file systems using case-augmented versions of …

Jan 19, 2024
CVE-2024-23329
3.7 LOW

changedetection.io is an open source tool designed to monitor websites for content changes. In affected versions the API endpoint `/api/v1/watch/<uuid>/history` can be accessed by any …

Jan 19, 2024
CVE-2024-22211
3.7 LOW

FreeRDP is a set of free and open source remote desktop protocol library and clients. In affected versions an integer overflow in `freerdp_bitmap_planar_context_reset` leads to …

Jan 19, 2024
CVE-2024-0732
5.3 MEDIUM

A vulnerability was found in PCMan FTP Server 2.0.7 and classified as problematic. This issue affects some unknown processing of the component STOR Command Handler. …

Jan 19, 2024
CVE-2024-0731
5.3 MEDIUM

A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as problematic. This vulnerability affects unknown code of the component PUT Command Handler. …

Jan 19, 2024
CVE-2024-0663

Rejected reason: REJECT: This is a false positive report.

Jan 19, 2024
CVE-2023-6450
5.5 MEDIUM

An incorrect permissions vulnerability was reported in the Lenovo App Store app that could allow an attacker to use system resources, resulting in a denial …

Jan 19, 2024
CVE-2023-6044
6.3 MEDIUM

A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker with physical access to impersonate Lenovo Vantage Service and execute …

Jan 19, 2024
CVE-2023-6043
7.8 HIGH

A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker to bypass integrity checks and execute arbitrary code with elevated …

Jan 19, 2024
CVE-2023-5081
3.3 LOW

An information disclosure vulnerability was reported in the Lenovo Tab M8 HD that could allow a local application to gather a non-resettable device identifier.

Jan 19, 2024
CVE-2023-5080
6.8 MEDIUM

A privilege escalation vulnerability was reported in some Lenovo tablet products that could allow local applications access to device identifiers and system commands.

Jan 19, 2024
CVE-2023-50694
9.8 CRITICAL

An issue in dom96 HTTPbeast v.0.4.1 and before allows a remote attacker to send a malicious crafted request due to insufficient parsing in the parser.nim …

Jan 19, 2024
CVE-2023-50693
9.8 CRITICAL

An issue in Jester v.0.6.0 and before allows a remote attacker to send a malicious crafted request.

Jan 19, 2024
CVE-2023-50447
8.1 HIGH

Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).

Jan 19, 2024
CVE-2023-47035
7.5 HIGH

RPTC 0x3b08c was discovered to not conduct status checks on the parameter tradingOpen. This vulnerability can allow attackers to conduct unauthorized transfer operations.

Jan 19, 2024
CVE-2023-45485

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not …

Jan 19, 2024
CVE-2023-43956

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-36263. Reason: This record is a duplicate of CVE-2023-36263. Notes: All CVE users should reference CVE-2023-36263 …

Jan 19, 2024
CVE-2023-42766
7.5 HIGH

Improper input validation in some Intel NUC 8 Compute Element BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local …

Jan 19, 2024
CVE-2023-42429
7.5 HIGH

Improper buffer restrictions in some Intel NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

Jan 19, 2024
CVE-2023-38587
7.5 HIGH

Improper input validation in some Intel NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

Jan 19, 2024
CVE-2023-38541
6.7 MEDIUM

Insecure inherited permissions in some Intel HID Event Filter drivers for Windows 10 for some Intel NUC laptop software installers before version 2.2.2.1 may allow …

Jan 19, 2024
CVE-2023-33295
6.5 MEDIUM

Cohesity DataProtect prior to 6.8.1_u5 or 7.1 was discovered to have a incorrect access control vulnerability due to a lack of TLS Certificate Validation.

Jan 19, 2024
CVE-2023-32544
7.3 HIGH

Improper access control in some Intel HotKey Services for Windows 10 for Intel NUC P14E Laptop Element software installers before version 1.1.45 may allow an …

Jan 19, 2024
CVE-2023-32272
7.9 HIGH

Uncontrolled search path in some Intel NUC Pro Software Suite Configuration Tool software installers before version 3.0.0.6 may allow an authenticated user to potentially enable …

Jan 19, 2024
CVE-2023-29495
7.5 HIGH

Improper input validation for some Intel NUC BIOS firmware before version IN0048 may allow a privileged user to potentially enable escalation of privilege via local …

Jan 19, 2024
CVE-2023-29244
6.7 MEDIUM

Incorrect default permissions in some Intel Integrated Sensor Hub (ISH) driver for Windows 10 for Intel NUC P14E Laptop Element software installers before version 5.4.1.4479 …

Jan 19, 2024
CVE-2023-28743
7.5 HIGH

Improper input validation for some Intel NUC BIOS firmware before version QN0073 may allow a privileged user to potentially enable escalation of privilege via local …

Jan 19, 2024
CVE-2023-28738
7.5 HIGH

Improper input validation for some Intel NUC BIOS firmware before version JY0070 may allow a privileged user to potentially enable escalation of privilege via local …

Jan 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.