CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-49862
6.5 MEDIUM

An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead …

Jan 10, 2024
CVE-2023-49810
7.3 HIGH

A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead …

Jan 10, 2024
CVE-2023-49738
7.5 HIGH

An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary …

Jan 10, 2024
CVE-2023-49715
4.3 MEDIUM

A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request …

Jan 10, 2024
CVE-2023-49599
9.8 CRITICAL

An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can …

Jan 10, 2024
CVE-2023-49589
8.8 HIGH

An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead …

Jan 10, 2024
CVE-2023-48730
8.5 HIGH

A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can …

Jan 10, 2024
CVE-2023-48728
9.6 CRITICAL

A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff. A specially crafted HTTP request …

Jan 10, 2024
CVE-2023-47862
9.8 CRITICAL

A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to …

Jan 10, 2024
CVE-2023-47861
9.0 CRITICAL

A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP …

Jan 10, 2024
CVE-2023-47171
6.5 MEDIUM

An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request …

Jan 10, 2024
CVE-2023-45139
7.5 HIGH

fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker …

Jan 10, 2024
CVE-2023-41056
8.1 HIGH

Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to …

Jan 10, 2024
CVE-2023-6158
6.5 MEDIUM

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a …

Jan 10, 2024
CVE-2023-51965
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function setIptvInfo.

Jan 10, 2024
CVE-2023-51964
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo.

Jan 10, 2024
CVE-2023-51963
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.

Jan 10, 2024
CVE-2023-51960
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv.

Jan 10, 2024
CVE-2023-51959
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.

Jan 10, 2024
CVE-2023-51958
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.

Jan 10, 2024
CVE-2023-51957
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.

Jan 10, 2024
CVE-2023-51956
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv

Jan 10, 2024
CVE-2023-51955
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.

Jan 10, 2024
CVE-2023-51954
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv.

Jan 10, 2024
CVE-2023-51953
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.

Jan 10, 2024
CVE-2023-51952
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.

Jan 10, 2024
CVE-2024-0395

Rejected reason: NON Security Issue.

Jan 10, 2024
CVE-2024-0389
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Student Attendance System 1.0. Affected is an unknown function of the file attendance_report.php. The …

Jan 10, 2024
CVE-2023-51966
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo.

Jan 10, 2024
CVE-2023-51961
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.

Jan 10, 2024
CVE-2024-20715
5.5 MEDIUM

Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Jan 10, 2024
CVE-2024-20714
5.5 MEDIUM

Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Jan 10, 2024
CVE-2024-20713
5.5 MEDIUM

Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Jan 10, 2024
CVE-2024-20712
5.5 MEDIUM

Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Jan 10, 2024
CVE-2024-20711
5.5 MEDIUM

Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Jan 10, 2024
CVE-2024-20710
5.5 MEDIUM

Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Jan 10, 2024
CVE-2023-5455
6.5 MEDIUM

A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting …

Jan 10, 2024
CVE-2023-51972
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp.

Jan 10, 2024
CVE-2023-51971
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function getIptvInfo.

Jan 10, 2024
CVE-2023-48266
8.1 HIGH

The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

Jan 10, 2024
CVE-2023-48265
8.1 HIGH

The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

Jan 10, 2024
CVE-2023-48264
8.1 HIGH

The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

Jan 10, 2024
CVE-2023-48263
8.1 HIGH

The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

Jan 10, 2024
CVE-2023-48262
8.1 HIGH

The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

Jan 10, 2024
CVE-2023-48261
5.3 MEDIUM

The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.

Jan 10, 2024
CVE-2023-48260
5.3 MEDIUM

The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.

Jan 10, 2024
CVE-2023-48259
5.3 MEDIUM

The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.

Jan 10, 2024
CVE-2023-48258
5.5 MEDIUM

The vulnerability allows a remote attacker to delete arbitrary files on the file system via a crafted URL or HTTP request through a victim’s session.

Jan 10, 2024
CVE-2023-48257
7.8 HIGH

The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) with root privileges on …

Jan 10, 2024
CVE-2023-48256
5.3 MEDIUM

The vulnerability allows a remote attacker to inject arbitrary HTTP response headers or manipulate HTTP response bodies inside a victim’s session via a crafted URL …

Jan 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.