CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-49254
8.8 HIGH

Authenticated user can execute arbitrary commands in the context of the root user by providing payload in the "destination" field of the network test tools. …

Jan 12, 2024
CVE-2023-49253
9.8 CRITICAL

Root user password is hardcoded into the device and cannot be changed in the user interface.

Jan 12, 2024
CVE-2023-7028
10.0 CRITICAL KEV

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 …

Jan 12, 2024
CVE-2023-6955
6.6 MEDIUM

A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. …

Jan 12, 2024
CVE-2023-5356
7.3 HIGH

Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from …

Jan 12, 2024
CVE-2023-4812
7.6 HIGH

An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions …

Jan 12, 2024
CVE-2023-2030
3.5 LOW

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 …

Jan 12, 2024
CVE-2023-0437
5.3 MEDIUM

When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This issue affects …

Jan 12, 2024
CVE-2023-52026
9.8 CRITICAL

TOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via the telnet_enabled parameter of the setTelnetCfg interface

Jan 12, 2024
CVE-2023-51806
5.4 MEDIUM

File Upload vulnerability in Ujcms v.8.0.2 allows a local attacker to execute arbitrary code via a crafted file.

Jan 12, 2024
CVE-2023-51790
6.1 MEDIUM

Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in the Admin Tools plug-in component.

Jan 12, 2024
CVE-2023-49569
9.8 CRITICAL

A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. …

Jan 12, 2024
CVE-2023-49568
7.5 HIGH

A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks …

Jan 12, 2024
CVE-2023-48909
8.8 HIGH

An issue was discovered in Jave2 version 3.3.1, allows attackers to execute arbitrary code via the FFmpeg function.

Jan 12, 2024
CVE-2023-30016
9.8 CRITICAL

SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via sub_event_id parameter in sub_event_details_edit.php.

Jan 12, 2024
CVE-2023-30015
9.8 CRITICAL

SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via txtsearch parameter in review_search.php.

Jan 12, 2024
CVE-2023-30014
9.8 CRITICAL

SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via sub_event_id parameter in sub_event_stat_update.php.

Jan 12, 2024
CVE-2023-6740
8.8 HIGH

Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges

Jan 12, 2024
CVE-2023-6735
8.8 HIGH

Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges

Jan 12, 2024
CVE-2023-50920
5.5 MEDIUM

An issue was discovered on GL.iNet devices before version 4.5.0. They assign the same session ID after each user reboot, allowing attackers to share session …

Jan 12, 2024
CVE-2023-50919
9.8 CRITICAL

An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, …

Jan 12, 2024
CVE-2023-40362
4.3 MEDIUM

An issue was discovered in CentralSquare Click2Gov Building Permit before October 2023. Lack of access control protections allows remote attackers to arbitrarily delete the contractors …

Jan 12, 2024
CVE-2023-31211
8.8 HIGH

Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials

Jan 12, 2024
CVE-2024-22027
6.5 MEDIUM

Improper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a remote authenticated attacker to perform a Denial of Service (DoS) attack …

Jan 12, 2024
CVE-2023-37117
9.8 CRITICAL

A heap-use-after-free vulnerability was found in live555 version 2023.05.10 while handling the SETUP.

Jan 12, 2024
CVE-2023-34061
7.5 HIGH

Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route …

Jan 12, 2024
CVE-2024-23179
6.1 MEDIUM

An issue was discovered in the GlobalBlocking extension in MediaWiki before 1.40.2. For a Special:GlobalBlock?uselang=x-xss URI, i18n-based XSS can occur via the parentheses message. This …

Jan 12, 2024
CVE-2024-23178
5.4 MEDIUM

An issue was discovered in the Phonos extension in MediaWiki before 1.40.2. PhonosButton.js allows i18n-based XSS via the phonos-purge-needed-error message.

Jan 12, 2024
CVE-2024-23177
6.1 MEDIUM

An issue was discovered in the WatchAnalytics extension in MediaWiki before 1.40.2. XSS can occur via the Special:PageStatistics page parameter.

Jan 12, 2024
CVE-2024-0393

Rejected reason: This CVE ID was unused by the CNA.

Jan 12, 2024
CVE-2024-23174
5.4 MEDIUM

An issue was discovered in the PageTriage extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via …

Jan 12, 2024
CVE-2024-23173
6.1 MEDIUM

An issue was discovered in the Cargo extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. The Special:Drilldown page allows …

Jan 12, 2024
CVE-2024-23172
5.4 MEDIUM

An issue was discovered in the CheckUser extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via …

Jan 12, 2024
CVE-2024-23171
5.4 MEDIUM

An issue was discovered in the CampaignEvents extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. The Special:EventDetails page allows …

Jan 12, 2024
CVE-2022-4961
5.5 MEDIUM

A vulnerability was found in Weitong Mall 1.0.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file …

Jan 12, 2024
CVE-2022-48620
9.8 CRITICAL

uev (aka libuev) before 2.4.1 has a buffer overflow in epoll_wait if maxevents is a large number.

Jan 12, 2024
CVE-2022-4960
3.5 LOW

A vulnerability, which was classified as problematic, has been found in cloudfavorites favorites-web 1.3.0. Affected by this issue is some unknown functionality of the component …

Jan 12, 2024
CVE-2022-48619
5.5 MEDIUM

An issue was discovered in drivers/input/input.c in the Linux kernel before 5.17.10. An attacker can cause a denial of service (panic) because input_set_capability mishandles the …

Jan 12, 2024
CVE-2016-20021
9.8 CRITICAL

In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature …

Jan 12, 2024
CVE-2024-0454
6.0 MEDIUM

ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and enumeration with spoof sensor. This fault leads to that Windows …

Jan 12, 2024
CVE-2023-6040
7.8 HIGH

An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family); While creating a new netfilter table, …

Jan 12, 2024
CVE-2023-52339
6.5 MEDIUM

In libebml before 1.4.5, an integer overflow in MemIOCallback.cpp can occur when reading or writing. It may result in buffer overflows.

Jan 12, 2024
CVE-2023-40250
8.8 HIGH

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Hancom HCell on Windows allows Overflow Buffers.This issue affects HCell: 12.0.0.893.

Jan 12, 2024
CVE-2024-21617
6.5 MEDIUM

An Incomplete Cleanup vulnerability in Nonstop active routing (NSR) component of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause memory leak leading …

Jan 12, 2024
CVE-2024-21616
7.5 HIGH

An Improper Validation of Syntactic Correctness of Input vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to …

Jan 12, 2024
CVE-2024-21614
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a …

Jan 12, 2024
CVE-2024-21613
6.5 MEDIUM

A Missing Release of Memory after Effective Lifetime vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an …

Jan 12, 2024
CVE-2024-21612
7.5 HIGH

An Improper Handling of Syntactically Invalid Structure vulnerability in Object Flooding Protocol (OFP) service of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker …

Jan 12, 2024
CVE-2024-21611
7.5 HIGH

A Missing Release of Memory after Effective Lifetime vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows …

Jan 12, 2024
CVE-2024-21607
5.3 MEDIUM

An Unsupported Feature in the UI vulnerability in Juniper Networks Junos OS on MX Series and EX9200 Series allows an unauthenticated, network-based attacker to cause …

Jan 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.