CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-22526
8.8 HIGH

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center. This RCE (Remote Code Execution) vulnerability, with a …

Jan 16, 2024
CVE-2024-22428
7.0 HIGH

Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user to escalate privileges and …

Jan 16, 2024
CVE-2024-22362
7.5 HIGH

Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a denial-of-service (DoS) …

Jan 16, 2024
CVE-2023-51282
7.5 HIGH

An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.

Jan 16, 2024
CVE-2023-51257
7.8 HIGH

An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code.

Jan 16, 2024
CVE-2023-51059
8.8 HIGH

An issue in MOKO TECHNOLOGY LTD MOKOSmart MKGW1 BLE Gateway v.1.1.1 and before allows a remote attacker to escalate privileges via the session management component …

Jan 16, 2024
CVE-2023-43449
8.8 HIGH

An issue in HummerRisk HummerRisk v.1.10 thru 1.4.1 allows an authenticated attacker to execute arbitrary code via a crafted request to the service/LicenseService component.

Jan 16, 2024
CVE-2023-6457
6.6 MEDIUM

Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Windows (Hitachi Tuning Manager server component) allows local users to read and write specific files.This issue …

Jan 16, 2024
CVE-2023-51810
7.5 HIGH

SQL injection vulnerability in StackIdeas EasyDiscuss v.5.0.5 and fixed in v.5.0.10 allows a remote attacker to obtain sensitive information via a crafted request to the …

Jan 16, 2024
CVE-2023-49107
5.3 MEDIUM

Generation of Error Message Containing Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent modules).This issue affects Hitachi Device Manager: before …

Jan 16, 2024
CVE-2023-49106
4.6 MEDIUM

Missing Password Field Masking vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent component).This issue affects Hitachi Device Manager: before 8.8.5-04.

Jan 16, 2024
CVE-2023-48104
6.1 MEDIUM

Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.

Jan 16, 2024
CVE-2023-47460
8.8 HIGH

SQL injection vulnerability in Knovos Discovery v.22.67.0 allows a remote attacker to execute arbitrary code via the /DiscoveryProcess/Service/Admin.svc/getGridColumnStructure component.

Jan 16, 2024
CVE-2023-47459
6.5 MEDIUM

An issue in Knovos Discovery v.22.67.0 allows a remote attacker to obtain sensitive information via the /DiscoveryReview/Service/CaseManagement.svc/GetProductSiteName component.

Jan 16, 2024
CVE-2023-41619
6.1 MEDIUM

Emlog Pro v2.1.14 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/article.php?action=write.

Jan 16, 2024
CVE-2023-7206
7.8 HIGH

In Horner Automation Cscape versions 9.90 SP10 and prior, local attackers are able to exploit this vulnerability if a user opens a malicious CSP file, …

Jan 15, 2024
CVE-2024-0565
6.8 MEDIUM

An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel. This issue occurs due to …

Jan 15, 2024
CVE-2024-0562
7.8 HIGH

A use-after-free flaw was found in the Linux Kernel. When a disk is removed, bdi_unregister is called to stop further write-back and waits for associated …

Jan 15, 2024
CVE-2024-0558
4.7 MEDIUM

A vulnerability has been found in DedeBIZ 6.3.0 and classified as critical. This vulnerability affects unknown code of the file /admin/makehtml_freelist_action.php. The manipulation of the …

Jan 15, 2024
CVE-2024-0557
2.4 LOW

A vulnerability, which was classified as problematic, was found in DedeBIZ 6.3.0. This affects an unknown part of the component Website Copyright Setting. The manipulation …

Jan 15, 2024
CVE-2024-0320
5.4 MEDIUM

Cross-Site Scripting in FireEye Malware Analysis (AX) affecting version 9.0.3.936530. This vulnerability allows an attacker to send a specially crafted JavaScript payload in the application …

Jan 15, 2024
CVE-2024-0319
5.4 MEDIUM

Open Redirect vulnerability in FireEye HXTool affecting version 4.6, the exploitation of which could allow an attacker to redirect a legitimate user to a malicious …

Jan 15, 2024
CVE-2024-0318
5.4 MEDIUM

Cross-Site Scripting in FireEye HXTool affecting version 4.6. This vulnerability allows an attacker to store a specially crafted JavaScript payload in the 'Profile Name' and …

Jan 15, 2024
CVE-2024-0317
5.4 MEDIUM

Cross-Site Scripting in FireEye EX, affecting version 9.0.3.936727. Exploitation of this vulnerability allows an attacker to send a specially crafted JavaScript payload via the 'type' …

Jan 15, 2024
CVE-2024-22207
5.3 MEDIUM

fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files …

Jan 15, 2024
CVE-2024-0316
6.8 MEDIUM

Improper cleanup vulnerability in exceptions thrown in FireEye Endpoint Security, affecting version 5.2.0.958244. This vulnerability could allow an attacker to send multiple request packets to …

Jan 15, 2024
CVE-2024-0315
6.6 MEDIUM

Remote file inclusion vulnerability in FireEye Central Management affecting version 9.1.1.956704. This vulnerability allows an attacker to upload a malicious PDF file to the system …

Jan 15, 2024
CVE-2024-0314
5.4 MEDIUM

XSS vulnerability in FireEye Central Management affecting version 9.1.1.956704, which could allow an attacker to modify special HTML elements in the application and cause a …

Jan 15, 2024
CVE-2023-6991
8.8 HIGH

The JSM file_get_contents() Shortcode WordPress plugin before 2.7.1 does not validate one of its shortcode's parameters before making a request to it, which could allow …

Jan 15, 2024
CVE-2023-6941
4.8 MEDIUM

The Keap Official Opt-in Forms WordPress plugin through 1.0.11 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 15, 2024
CVE-2023-6843
4.3 MEDIUM

The easy.jobs- Best Recruitment Plugin for Job Board Listing, Manager, Career Page for Elementor & Gutenberg WordPress plugin before 2.4.7 does not properly secure some …

Jan 15, 2024
CVE-2023-6623
9.8 CRITICAL

The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may …

Jan 15, 2024
CVE-2023-6620
7.2 HIGH

The POST SMTP Mailer WordPress plugin before 2.8.7 does not properly sanitise and escape several parameters before using them in SQL statements, leading to a …

Jan 15, 2024
CVE-2023-6163
4.8 MEDIUM

The WP Crowdfunding WordPress plugin before 2.1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jan 15, 2024
CVE-2023-6066
4.3 MEDIUM

The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of its AJAX action callback functions, …

Jan 15, 2024
CVE-2023-6050
6.1 MEDIUM

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not sanitise and escape various parameters and generated URLs before outputting them back in attributes, …

Jan 15, 2024
CVE-2023-6049
9.8 CRITICAL

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users to perform PHP …

Jan 15, 2024
CVE-2023-6048
6.5 MEDIUM

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not prevent user with low privileges on the site, like subscribers, from setting any of …

Jan 15, 2024
CVE-2023-6029
7.5 HIGH

The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from …

Jan 15, 2024
CVE-2023-5905
8.1 HIGH

The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of requests to export the blog data, allowing any logged …

Jan 15, 2024
CVE-2023-50729
8.4 HIGH

Traccar is an open source GPS tracking system. Prior to 5.11, Traccar is affected by an unrestricted file upload vulnerability in File feature allows attackers …

Jan 15, 2024
CVE-2023-4925
4.8 MEDIUM

The Easy Forms for Mailchimp WordPress plugin through 6.8.10 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 15, 2024
CVE-2023-4818
7.6 HIGH

PAX A920 device allows to downgrade bootloader due to a bug in its version check. The signature is correctly checked and only bootloader signed by …

Jan 15, 2024
CVE-2023-42137
7.8 HIGH

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by using malicious symlinks. The attacker must have …

Jan 15, 2024
CVE-2023-42136
7.8 HIGH

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands with system account privilege by shell injection starting with …

Jan 15, 2024
CVE-2023-42135
6.8 MEDIUM

PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection by bypassing the input validation when flashing a specific partition. …

Jan 15, 2024
CVE-2023-42134
6.8 MEDIUM

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partition overwrite and subsequently local code execution via hidden command. The attacker …

Jan 15, 2024
CVE-2024-20721
5.5 MEDIUM

Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to …

Jan 15, 2024
CVE-2024-20709
5.5 MEDIUM

Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to …

Jan 15, 2024
CVE-2023-5253
5.3 MEDIUM

A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guardian and CMC, may allow an unauthenticated …

Jan 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.