CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-49251
8.8 HIGH

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application allows an attacker …

Jan 9, 2024
CVE-2023-49132
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to uninitialized pointer access while …

Jan 9, 2024
CVE-2023-49131
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to uninitialized pointer access while …

Jan 9, 2024
CVE-2023-49130
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to uninitialized pointer access while …

Jan 9, 2024
CVE-2023-49129
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected applications contain a stack overflow vulnerability while parsing …

Jan 9, 2024
CVE-2023-49128
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application contains an out of bounds write past …

Jan 9, 2024
CVE-2023-49127
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected applications contain an out of bounds read past …

Jan 9, 2024
CVE-2023-49126
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected applications contain an out of bounds read past …

Jan 9, 2024
CVE-2023-49124
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected applications contain an out of bounds read past …

Jan 9, 2024
CVE-2023-49123
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to heap-based buffer overflow while …

Jan 9, 2024
CVE-2023-49122
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to heap-based buffer overflow while …

Jan 9, 2024
CVE-2023-49121
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to heap-based buffer overflow while …

Jan 9, 2024
CVE-2023-44120
7.8 HIGH

A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q4). The affected product's sudo configuration permits the local administrative account to execute …

Jan 9, 2024
CVE-2023-42797
6.6 MEDIUM

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.20), CP-8050 MASTER MODULE (All versions < CPCI85 V05.20). The network configuration …

Jan 9, 2024
CVE-2024-22368
5.5 MEDIUM

The Spreadsheet::ParseXLSX package before 0.28 for Perl can encounter an out-of-memory condition during parsing of a crafted XLSX document. This occurs because the memoize implementation …

Jan 9, 2024
CVE-2023-6149
5.7 MEDIUM

Qualys Jenkins Plugin for WAS prior to version and including 2.0.11 was identified to be affected by a security flaw, which was missing a permission …

Jan 9, 2024
CVE-2023-6148
5.7 MEDIUM

Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a …

Jan 9, 2024
CVE-2023-50974
5.5 MEDIUM

In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as …

Jan 9, 2024
CVE-2023-50585
9.8 CRITICAL

Tenda A18 v15.13.07.09 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.

Jan 9, 2024
CVE-2023-49237
9.8 CRITICAL

An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language …

Jan 9, 2024
CVE-2023-49236
9.8 CRITICAL

A stack-based buffer overflow was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices, leading to arbitrary command execution. This occurs because of lack of length validation …

Jan 9, 2024
CVE-2023-49235
9.8 CRITICAL

An issue was discovered in libremote_dbg.so on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Filtering of debug information is mishandled during use of popen. Consequently, an attacker …

Jan 9, 2024
CVE-2023-7220
9.8 CRITICAL

A vulnerability was found in Totolink NR1800X 9.1.0u.6279_B20210910 and classified as critical. Affected by this issue is the function loginAuth of the file /cgi-bin/cstecgi.cgi. The …

Jan 9, 2024
CVE-2023-6147
5.7 MEDIUM

Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a …

Jan 9, 2024
CVE-2023-6842
4.4 MEDIUM

The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jan 9, 2024
CVE-2023-6830
6.5 MEDIUM

The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vulnerability allows unauthenticated users to inject …

Jan 9, 2024
CVE-2023-50932
8.3 HIGH

An issue was discovered in savignano S/Notify before 4.0.2 for Confluence. While an administrative user is logged on, the configuration settings of S/Notify can be …

Jan 9, 2024
CVE-2023-50931
8.3 HIGH

An issue was discovered in savignano S/Notify before 2.0.1 for Bitbucket. While an administrative user is logged on, the configuration settings of S/Notify can be …

Jan 9, 2024
CVE-2023-50930
8.3 HIGH

An issue was discovered in savignano S/Notify before 4.0.2 for Jira. While an administrative user is logged on, the configuration settings of S/Notify can be …

Jan 9, 2024
CVE-2023-7219
7.2 HIGH

A vulnerability has been found in Totolink N350RT 9.3.5u.6139_B202012 and classified as critical. Affected by this vulnerability is the function loginAuth of the file /cgi-bin/cstecgi.cgi. …

Jan 9, 2024
CVE-2023-6788
5.4 MEDIUM

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.1. This is …

Jan 9, 2024
CVE-2023-6594
4.4 MEDIUM

The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 9.7.4 …

Jan 9, 2024
CVE-2024-22125
7.4 HIGH

Under certain conditions the Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge) - version 1.0, allows an attacker to access highly sensitive information …

Jan 9, 2024
CVE-2024-22124
4.1 MEDIUM

Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, …

Jan 9, 2024
CVE-2024-21738
4.1 MEDIUM

SAP NetWeaver ABAP Application Server and ABAP Platform do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker with low privileges …

Jan 9, 2024
CVE-2024-21737
8.4 HIGH

In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to traverse through various layers and …

Jan 9, 2024
CVE-2024-21736
6.4 MEDIUM

SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary authorization checks. A function import could be triggered …

Jan 9, 2024
CVE-2023-51717
9.8 CRITICAL

Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.

Jan 9, 2024
CVE-2023-49238
9.8 CRITICAL

In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a …

Jan 9, 2024
CVE-2023-39336
8.8 HIGH

An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal network to …

Jan 9, 2024
CVE-2023-36629
5.5 MEDIUM

The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.

Jan 9, 2024
CVE-2023-27098
7.5 HIGH

TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.

Jan 9, 2024
CVE-2023-27000
6.1 MEDIUM

Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the name parameter of the Profile and Exclusion …

Jan 9, 2024
CVE-2023-26999
9.8 CRITICAL

An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file.

Jan 9, 2024
CVE-2023-26998
5.4 MEDIUM

Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the creator parameter of the Alert Configuration page.

Jan 9, 2024
CVE-2024-21735
7.3 HIGH

SAP LT Replication Server - version S4CORE 103, S4CORE 104, S4CORE 105, S4CORE 106, S4CORE 107, S4CORE 108, does not perform necessary authorization checks. This …

Jan 9, 2024
CVE-2024-21734
3.7 LOW

SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious page which could lead to …

Jan 9, 2024
CVE-2024-21646
9.8 CRITICAL

Azure uAMQP is a general purpose C library for AMQP 1.0. The UAMQP library is used by several clients to implement AMQP protocol communication. When …

Jan 9, 2024
CVE-2023-50643
9.8 CRITICAL

An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.

Jan 9, 2024
CVE-2023-46906
4.9 MEDIUM

juzaweb <= 3.4 is vulnerable to Incorrect Access Control, resulting in an application outage after a 500 HTTP status code. The payload in the timezone …

Jan 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.