CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-24559
5.4 MEDIUM

The Qyrr WordPress plugin before 0.7 does not escape the data-uri of the QR Code when outputting it in a src attribute, allowing for Cross-Site …

Jan 16, 2024
CVE-2021-24433
5.4 MEDIUM

The simple sort&search WordPress plugin through 0.0.3 does not make sure that the indexurl parameter of the shortcodes "category_sims", "order_sims", "orderby_sims", "period_sims", and "tag_sims" use …

Jan 16, 2024
CVE-2021-24432
6.1 MEDIUM

The Advanced AJAX Product Filters WordPress plugin does not sanitise the 'term_id' POST parameter before outputting it in the page, leading to reflected Cross-Site Scripting …

Jan 16, 2024
CVE-2021-24151
7.2 HIGH

The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via …

Jan 16, 2024
CVE-2024-0582
7.8 HIGH

A memory leak flaw was found in the Linux kernel’s io_uring functionality in how a user registers a buffer ring with IORING_REGISTER_PBUF_RING, mmap() it, and …

Jan 16, 2024
CVE-2024-0575
8.8 HIGH

A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been classified as critical. This affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jan 16, 2024
CVE-2024-0574
8.8 HIGH

A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130 and classified as critical. Affected by this issue is the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The …

Jan 16, 2024
CVE-2024-0573
8.8 HIGH

A vulnerability has been found in Totolink LR1200GB 9.1.0u.6619_B20230130 and classified as critical. Affected by this vulnerability is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. …

Jan 16, 2024
CVE-2023-6395
6.7 MEDIUM

The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary code with root user privileges. This …

Jan 16, 2024
CVE-2021-4432
5.3 MEDIUM

A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as problematic. This affects an unknown part of the component USER Command …

Jan 16, 2024
CVE-2024-0584

Rejected reason: Do not use this CVE as it is duplicate of CVE-2023-6932

Jan 16, 2024
CVE-2024-0581
4.0 MEDIUM

An Uncontrolled Resource Consumption vulnerability has been found on Sandsprite Scdbg.exe, affecting version 1.0. This vulnerability allows an attacker to send a specially crafted shellcode …

Jan 16, 2024
CVE-2024-0572
8.8 HIGH

A vulnerability, which was classified as critical, was found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jan 16, 2024
CVE-2024-0571
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. This issue affects the function setSmsCfg of the file /cgi-bin/cstecgi.cgi. The …

Jan 16, 2024
CVE-2024-0570
7.3 HIGH

A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6265. This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. …

Jan 16, 2024
CVE-2024-0567
7.5 HIGH

A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a …

Jan 16, 2024
CVE-2024-0232
4.7 MEDIUM

A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim …

Jan 16, 2024
CVE-2024-0569
4.3 MEDIUM

A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This affects the function getSysStatusCfg of the file /cgi-bin/cstecgi.cgi of the component Setting …

Jan 16, 2024
CVE-2024-0553
7.5 HIGH

A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 …

Jan 16, 2024
CVE-2024-0556
7.1 HIGH

A Weak Cryptography for Passwords vulnerability has been detected on WIC200 affecting version 1.1. This vulnerability allows a remote user to intercept the traffic and …

Jan 16, 2024
CVE-2024-0555
4.6 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated user could lead another user into executing unwanted actions …

Jan 16, 2024
CVE-2024-0554
5.5 MEDIUM

A Cross-site scripting (XSS) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated user could store a malicious javascript payload in the device …

Jan 16, 2024
CVE-2023-52106
4.4 MEDIUM

Vulnerability of permission verification for APIs in the DownloadProviderMain module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.

Jan 16, 2024
CVE-2023-52105
7.5 HIGH

The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability.

Jan 16, 2024
CVE-2023-52104
7.5 HIGH

Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-52103
9.8 CRITICAL

Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds read.

Jan 16, 2024
CVE-2023-52102
7.5 HIGH

Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-52101
9.1 CRITICAL

Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service availability and integrity.

Jan 16, 2024
CVE-2023-52100
7.5 HIGH

The Celia Keyboard module has a vulnerability in access control. Successful exploitation of this vulnerability may affect availability.

Jan 16, 2024
CVE-2023-52099
7.5 HIGH

Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-34063
9.9 CRITICAL

Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability leading to unauthorized access to remote organizations and workflows.

Jan 16, 2024
CVE-2023-52116
7.5 HIGH

Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.

Jan 16, 2024
CVE-2023-52115
7.5 HIGH

The iaware module has a Use-After-Free (UAF) vulnerability. Successful exploitation of this vulnerability may affect the system functions.

Jan 16, 2024
CVE-2023-52114
7.5 HIGH

Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity.

Jan 16, 2024
CVE-2023-52108
7.5 HIGH

Vulnerability of process priorities being raised in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.

Jan 16, 2024
CVE-2023-52107
7.5 HIGH

Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-52098
7.5 HIGH

Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability.

Jan 16, 2024
CVE-2023-52113
7.5 HIGH

launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.

Jan 16, 2024
CVE-2023-52112
5.3 MEDIUM

Unauthorized file access vulnerability in the wallpaper service module. Successful exploitation of this vulnerability may cause features to perform abnormally.

Jan 16, 2024
CVE-2023-52111
7.5 HIGH

Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.

Jan 16, 2024
CVE-2023-52110
7.5 HIGH

The sensor module has an out-of-bounds access vulnerability.Successful exploitation of this vulnerability may affect availability.

Jan 16, 2024
CVE-2023-52109
7.5 HIGH

Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-4566
7.5 HIGH

Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-44117
7.5 HIGH

Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-44112
7.5 HIGH

Out-of-bounds access vulnerability in the device authentication module. Successful exploitation of this vulnerability may affect confidentiality.

Jan 16, 2024
CVE-2011-10005
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in EasyFTP 1.7.0.2. Affected is an unknown function of the component MKD Command Handler. The manipulation …

Jan 16, 2024
CVE-2024-21674
7.5 HIGH

This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with …

Jan 16, 2024
CVE-2024-21673
8.8 HIGH

This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with …

Jan 16, 2024
CVE-2024-21672
8.8 HIGH

This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with …

Jan 16, 2024
CVE-2023-22527
9.8 CRITICAL KEV

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers …

Jan 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.