CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-51741
7.5 HIGH

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could exploit …

Jan 17, 2024
CVE-2023-51740
7.5 HIGH

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could exploit …

Jan 17, 2024
CVE-2023-51739
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Device Name parameter at its web …

Jan 17, 2024
CVE-2023-51738
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Network Name (SSID) parameter at its …

Jan 17, 2024
CVE-2023-51737
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Preshared Phrase parameter at its web …

Jan 17, 2024
CVE-2023-51736
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the L2TP/PPTP Username parameter at its web …

Jan 17, 2024
CVE-2023-51735
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Pre-shared key parameter at its web …

Jan 17, 2024
CVE-2023-51734
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Identity parameter under Remote endpoint settings …

Jan 17, 2024
CVE-2023-51733
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Identity parameter under Local endpoint settings …

Jan 17, 2024
CVE-2023-51732
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the IPsec Tunnel Name parameter at its …

Jan 17, 2024
CVE-2023-51731
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Hostname parameter at its web interface. …

Jan 17, 2024
CVE-2023-51730
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the DDNS Password parameter at its web …

Jan 17, 2024
CVE-2023-51729
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the DDNS Username parameter at its web …

Jan 17, 2024
CVE-2023-51728
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the SMTP Password parameter at its web …

Jan 17, 2024
CVE-2023-51727
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the SMTP Username parameter at its web …

Jan 17, 2024
CVE-2023-51726
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the SMTP Server Name parameter at its …

Jan 17, 2024
CVE-2023-51725
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Contact Email Address parameter at its …

Jan 17, 2024
CVE-2023-51724
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the URL parameter at its web interface. …

Jan 17, 2024
CVE-2023-51723
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Description parameter at its web interface. …

Jan 17, 2024
CVE-2023-51722
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Time Server 3 parameter at its …

Jan 17, 2024
CVE-2023-51721
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Time Server 2 parameter at its …

Jan 17, 2024
CVE-2023-51720
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Time Server 1 parameter at its …

Jan 17, 2024
CVE-2023-51719
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Traceroute parameter at its web interface. …

Jan 17, 2024
CVE-2024-0405
7.2 HIGH

The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin, version 1.5.3, is vulnerable to Post-Authenticated SQL Injection via multiple JSON parameters in the /wp-json/burst/v1/data/compare endpoint. …

Jan 17, 2024
CVE-2023-52069
5.4 MEDIUM

kodbox v1.49.04 was discovered to contain a cross-site scripting (XSS) vulnerability via the URL parameter.

Jan 17, 2024
CVE-2023-46952
6.1 MEDIUM

Cross Site Scripting vulnerability in ABO.CMS v.5.9.3 allows an attacker to execute arbitrary code via a crafted payload to the Referer header.

Jan 17, 2024
CVE-2023-36235
6.5 MEDIUM

An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.

Jan 17, 2024
CVE-2023-25295
6.1 MEDIUM

A Cross Site Scripting (XSS) vulnerability in evewa3ajax.php in GRUEN eVEWA3 Community 31 through 53 allows attackers to obtain escalated privileges via a crafted request …

Jan 17, 2024
CVE-2023-49515
4.6 MEDIUM

Insecure Permissiosn vulnerability in TP Link TC70 and C200 WIFI Camera v.3 firmware v.1.3.4 and fixed in v.1.3.11 allows a physically proximate attacker to obtain …

Jan 17, 2024
CVE-2024-22409
7.5 HIGH

DataHub is an open-source metadata platform. In affected versions a low privileged user could remove a user, edit group members, or edit another user's profile …

Jan 16, 2024
CVE-2024-22408
7.6 HIGH

Shopware is an open headless commerce platform. The implemented Flow Builder functionality in the Shopware application does not adequately validate the URL used when creating …

Jan 16, 2024
CVE-2024-22407
4.9 MEDIUM

Shopware is an open headless commerce platform. In the Shopware CMS, the state handler for orders fails to sufficiently verify user authorizations for actions that …

Jan 16, 2024
CVE-2024-22406
9.3 CRITICAL

Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enables users to search through information stored within their …

Jan 16, 2024
CVE-2023-51807
5.4 MEDIUM

Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a crafted payload to the title addition component.

Jan 16, 2024
CVE-2024-22916
9.8 CRITICAL

In D-LINK Go-RT-AC750 v101b03, the sprintf function in the sub_40E700 function within the cgibin is susceptible to stack overflow.

Jan 16, 2024
CVE-2024-22411
6.5 MEDIUM

Avo is a framework to create admin panels for Ruby on Rails apps. In Avo 3 pre12, any HTML inside text that is passed to …

Jan 16, 2024
CVE-2024-22192
6.5 MEDIUM

Ursa is a cryptographic library for use with blockchains. The revocation scheme that is part of the Ursa CL-Signatures implementations has a flaw that could …

Jan 16, 2024
CVE-2024-22191
7.3 HIGH

Avo is a framework to create admin panels for Ruby on Rails apps. A stored cross-site scripting (XSS) vulnerability was found in the key_value field …

Jan 16, 2024
CVE-2024-21670
6.5 MEDIUM

Ursa is a cryptographic library for use with blockchains. The revocation schema that is part of the Ursa CL-Signatures implementations has a flaw that could …

Jan 16, 2024
CVE-2024-20987
5.4 MEDIUM

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows …

Jan 16, 2024
CVE-2024-20985
6.5 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. …

Jan 16, 2024
CVE-2024-20983
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.34 and prior. Easily exploitable vulnerability allows …

Jan 16, 2024
CVE-2024-20981
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. …

Jan 16, 2024
CVE-2024-20979
5.4 MEDIUM

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 6.4.0.0.0, 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable …

Jan 16, 2024
CVE-2024-20977
6.5 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. …

Jan 16, 2024
CVE-2024-20975
6.5 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.2.0 and prior. Easily exploitable vulnerability allows …

Jan 16, 2024
CVE-2024-20973
6.5 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. …

Jan 16, 2024
CVE-2024-20971
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. …

Jan 16, 2024
CVE-2024-20969
5.5 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. …

Jan 16, 2024
CVE-2024-20967
5.5 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. …

Jan 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.