CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-35702
7.8 HIGH

Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code …

Jan 8, 2024
CVE-2023-35128
7.0 HIGH

An integer overflow vulnerability exists in the fstReaderIterBlocks2 time_table tsec_nitems functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to memory corruption. A …

Jan 8, 2024
CVE-2023-35057
7.8 HIGH

An integer overflow vulnerability exists in the LXT2 lxt2_rd_trace value elements allocation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to memory …

Jan 8, 2024
CVE-2023-35004
7.8 HIGH

An integer overflow vulnerability exists in the VZT longest_len value allocation functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code …

Jan 8, 2024
CVE-2023-34436
7.8 HIGH

An out-of-bounds write vulnerability exists in the LXT2 num_time_table_entries functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A …

Jan 8, 2024
CVE-2023-34087
7.8 HIGH

An improper array index validation vulnerability exists in the EVCD var len parsing functionality of GTKWave 3.3.115. A specially crafted .evcd file can lead to …

Jan 8, 2024
CVE-2023-32650
7.0 HIGH

An integer overflow vulnerability exists in the FST_BL_GEOM parsing maxhandle functionality of GTKWave 3.3.115, when compiled as a 32-bit binary. A specially crafted .fst file …

Jan 8, 2024
CVE-2024-21647
5.9 MEDIUM

Puma is a web server for Ruby/Rack applications built for parallelism. Prior to version 6.4.2, puma exhibited incorrect behavior when parsing chunked transfer encoding bodies …

Jan 8, 2024
CVE-2024-21645
5.3 MEDIUM

pyLoad is the free and open-source Download Manager written in pure Python. A log injection vulnerability was identified in `pyload` allowing any unauthenticated actor to …

Jan 8, 2024
CVE-2024-21644
7.5 HIGH

pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask …

Jan 8, 2024
CVE-2023-7224
7.8 HIGH

OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party libraries using the DYLD_INSERT_LIBRARIES environment variable

Jan 8, 2024
CVE-2023-51701
5.3 MEDIUM

fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. A reverse proxy server built with `@fastify/reply-from` could misinterpret the incoming …

Jan 8, 2024
CVE-2024-0322
9.1 CRITICAL

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

Jan 8, 2024
CVE-2024-0321
9.8 CRITICAL

Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.

Jan 8, 2024
CVE-2023-6552
6.1 MEDIUM

Lack of "current" GET parameter validation during the action of changing a language leads to an open redirect vulnerability.

Jan 8, 2024
CVE-2023-6921
9.8 CRITICAL

Blind SQL Injection vulnerability in PrestaShow Google Integrator (PrestaShop addon) allows for data extraction and modification. This attack is possible via command insertion in one …

Jan 8, 2024
CVE-2024-0308
6.3 MEDIUM

A vulnerability was found in Inis up to 2.0.1. It has been rated as critical. This issue affects some unknown processing of the file app/api/controller/default/Proxy.php. …

Jan 8, 2024
CVE-2024-0307
7.3 HIGH

A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been declared as critical. This vulnerability affects unknown code of …

Jan 8, 2024
CVE-2023-5091
5.5 MEDIUM

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU processing operations to gain access …

Jan 8, 2024
CVE-2024-0306
7.3 HIGH

A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been classified as critical. This affects an unknown part of …

Jan 8, 2024
CVE-2024-0305
5.3 MEDIUM

A vulnerability was found in Guangzhou Yingke Electronic Technology Ncast up to 2017 and classified as problematic. Affected by this issue is some unknown functionality …

Jan 8, 2024
CVE-2023-41710
5.4 MEDIUM

User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could …

Jan 8, 2024
CVE-2023-29052
5.4 MEDIUM

Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could lure …

Jan 8, 2024
CVE-2023-29051
8.1 HIGH

User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the …

Jan 8, 2024
CVE-2023-29050
7.6 HIGH

The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the intended …

Jan 8, 2024
CVE-2023-29049
5.4 MEDIUM

The "upsell" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure users to a compromised account, …

Jan 8, 2024
CVE-2023-29048
8.8 HIGH

A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user. Users and …

Jan 8, 2024
CVE-2024-0304
6.3 MEDIUM

A vulnerability has been found in Youke365 up to 1.5.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Jan 8, 2024
CVE-2024-0303
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Youke365 up to 1.5.3. Affected is an unknown function of the file /app/api/controller/caiji.php of the …

Jan 8, 2024
CVE-2024-22216
10.0 CRITICAL

In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured for remote system management, unauthorized access can …

Jan 8, 2024
CVE-2024-0302
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in fhs-opensource iparking 1.5.22.RELEASE. This issue affects some unknown processing of the file /vueLogin. The …

Jan 8, 2024
CVE-2024-0301
6.3 MEDIUM

A vulnerability classified as critical was found in fhs-opensource iparking 1.5.22.RELEASE. This vulnerability affects the function getData of the file src/main/java/com/xhb/pay/action/PayTempOrderAction.java. The manipulation leads to …

Jan 8, 2024
CVE-2024-0300
6.3 MEDIUM

A vulnerability was found in Byzoro Smart S150 Management Platform up to 20240101. It has been rated as critical. Affected by this issue is some …

Jan 8, 2024
CVE-2024-0299
7.3 HIGH

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been declared as critical. Affected by this vulnerability is the function setTracerouteCfg of the file …

Jan 8, 2024
CVE-2024-0298
7.3 HIGH

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been classified as critical. Affected is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jan 8, 2024
CVE-2024-0297
7.3 HIGH

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. This issue affects the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jan 8, 2024
CVE-2024-0296
7.3 HIGH

A vulnerability has been found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. This vulnerability affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jan 8, 2024
CVE-2024-0295
7.3 HIGH

A vulnerability, which was classified as critical, was found in Totolink LR1200GB 9.1.0u.6619_B20230130. This affects the function setWanCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jan 8, 2024
CVE-2024-0294
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected by this issue is the function setUssd of the file …

Jan 8, 2024
CVE-2024-0293
6.3 MEDIUM

A vulnerability classified as critical was found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected by this vulnerability is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jan 8, 2024
CVE-2023-47140
4.0 MEDIUM

IBM CICS Transaction Gateway 9.3 could allow a user to transfer or view files due to improper access controls.

Jan 8, 2024
CVE-2024-0292
6.3 MEDIUM

A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Jan 8, 2024
CVE-2023-7215
3.5 LOW

A vulnerability, which was classified as problematic, has been found in Chanzhaoyu chatgpt-web 2.11.1. This issue affects some unknown processing. The manipulation of the argument …

Jan 8, 2024
CVE-2023-50948
6.5 MEDIUM

IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, …

Jan 8, 2024
CVE-2024-0291
6.3 MEDIUM

A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been rated as critical. This issue affects the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi. The …

Jan 8, 2024
CVE-2024-0290
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Kashipara Food Management System 1.0. This issue affects some unknown processing of the file …

Jan 8, 2024
CVE-2024-0289
6.3 MEDIUM

A vulnerability classified as critical was found in Kashipara Food Management System 1.0. This vulnerability affects unknown code of the file stock_entry_submit.php. The manipulation of …

Jan 8, 2024
CVE-2024-0288
6.3 MEDIUM

A vulnerability classified as critical has been found in Kashipara Food Management System 1.0. This affects an unknown part of the file rawstock_used_damaged_submit.php. The manipulation …

Jan 8, 2024
CVE-2024-0287
6.3 MEDIUM

A vulnerability was found in Kashipara Food Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jan 7, 2024
CVE-2023-7214
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Totolink N350RT 9.3.5u.6139_B20201216. Affected by this issue is the function main of the file …

Jan 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.