CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-7213
6.3 MEDIUM

A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6139_B20201216. Affected by this vulnerability is the function main of the file /cgi-bin/cstecgi.cgi?action=login&flag=1 of the …

Jan 7, 2024
CVE-2023-47145
8.4 HIGH

IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privileges to the SYSTEM user …

Jan 7, 2024
CVE-2024-0286
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file index.php#contact_us of …

Jan 7, 2024
CVE-2024-0284
3.5 LOW

A vulnerability was found in Kashipara Food Management System up to 1.0. It has been rated as problematic. This issue affects some unknown processing of …

Jan 7, 2024
CVE-2023-7212
4.7 MEDIUM

A vulnerability classified as critical has been found in DeDeCMS up to 5.7.112. Affected is an unknown function of the file file_class.php of the component …

Jan 7, 2024
CVE-2024-0283
3.5 LOW

A vulnerability was found in Kashipara Food Management System up to 1.0. It has been declared as problematic. This vulnerability affects unknown code of the …

Jan 7, 2024
CVE-2024-0282
3.5 LOW

A vulnerability was found in Kashipara Food Management System up to 1.0. It has been classified as problematic. This affects an unknown part of the …

Jan 7, 2024
CVE-2024-0281
6.3 MEDIUM

A vulnerability was found in Kashipara Food Management System up to 1.0 and classified as critical. Affected by this issue is some unknown functionality of …

Jan 7, 2024
CVE-2024-0280
6.3 MEDIUM

A vulnerability has been found in Kashipara Food Management System up to 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality …

Jan 7, 2024
CVE-2024-0279
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Kashipara Food Management System up to 1.0. Affected is an unknown function of the file …

Jan 7, 2024
CVE-2024-0278
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Kashipara Food Management System up to 1.0. This issue affects some unknown processing of …

Jan 7, 2024
CVE-2024-0277
6.3 MEDIUM

A vulnerability classified as critical was found in Kashipara Food Management System up to 1.0. This vulnerability affects unknown code of the file party_submit.php. The …

Jan 7, 2024
CVE-2024-0276
6.3 MEDIUM

A vulnerability classified as critical has been found in Kashipara Food Management System up to 1.0. This affects an unknown part of the file rawstock_used_damaged_smt.php. …

Jan 7, 2024
CVE-2024-0275
6.3 MEDIUM

A vulnerability was found in Kashipara Food Management System up to 1.0. It has been rated as critical. Affected by this issue is some unknown …

Jan 7, 2024
CVE-2024-0274
6.3 MEDIUM

A vulnerability was found in Kashipara Food Management System up to 1.0. It has been declared as critical. Affected by this vulnerability is an unknown …

Jan 7, 2024
CVE-2024-0273
6.3 MEDIUM

A vulnerability was found in Kashipara Food Management System up to 1.0. It has been classified as critical. Affected is an unknown function of the …

Jan 7, 2024
CVE-2024-0272
6.3 MEDIUM

A vulnerability was found in Kashipara Food Management System up to 1.0 and classified as critical. This issue affects some unknown processing of the file …

Jan 7, 2024
CVE-2023-7211
5.6 MEDIUM

A vulnerability was found in Uniway Router 2.0. It has been declared as critical. This vulnerability affects unknown code of the component Administrative Web Interface. …

Jan 7, 2024
CVE-2023-7210
7.3 HIGH

A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of the file /index.php?c=api of …

Jan 7, 2024
CVE-2024-0271
6.3 MEDIUM

A vulnerability has been found in Kashipara Food Management System up to 1.0 and classified as critical. This vulnerability affects unknown code of the file …

Jan 7, 2024
CVE-2023-7209
7.5 HIGH

A vulnerability was found in Uniway Router up to 2.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jan 7, 2024
CVE-2024-0270
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Kashipara Food Management System up to 1.0. This affects an unknown part of the file …

Jan 7, 2024
CVE-2024-0268
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Kashipara Hospital Management System up to 1.0. Affected by this issue is some unknown …

Jan 7, 2024
CVE-2023-7208
8.0 HIGH

A vulnerability classified as critical was found in Totolink X2000R_V2 2.0.0-B20230727.10434. This vulnerability affects the function formTmultiAP of the file /bin/boa. The manipulation leads to …

Jan 7, 2024
CVE-2024-0267
7.3 HIGH

A vulnerability classified as critical was found in Kashipara Hospital Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the …

Jan 7, 2024
CVE-2024-0266
4.3 MEDIUM

A vulnerability classified as problematic has been found in Project Worlds Online Lawyer Management System 1.0. Affected is an unknown function of the component User …

Jan 7, 2024
CVE-2024-0265
6.3 MEDIUM

A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jan 7, 2024
CVE-2024-0264
7.3 HIGH

A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /LoginRegistration.php. …

Jan 7, 2024
CVE-2024-0263
5.3 MEDIUM

A vulnerability was found in ACME Ultra Mini HTTPd 1.21. It has been classified as problematic. This affects an unknown part of the component HTTP …

Jan 7, 2024
CVE-2024-0262
2.4 LOW

A vulnerability was found in Online Job Portal 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /Admin/News.php …

Jan 7, 2024
CVE-2024-0261
5.3 MEDIUM

A vulnerability has been found in Sentex FTPDMIN 0.96 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component RNFR …

Jan 7, 2024
CVE-2024-0260
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in SourceCodester Engineers Online Portal 1.0. Affected is an unknown function of the file change_password_teacher.php of …

Jan 7, 2024
CVE-2023-51441
7.2 HIGH

** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the admin service to perform possible SSRF This …

Jan 6, 2024
CVE-2023-6801
6.4 MEDIUM

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jan 6, 2024
CVE-2023-6798
5.4 MEDIUM

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized settings update …

Jan 6, 2024
CVE-2023-50121
5.7 MEDIUM

Autel EVO NANO drone flight control firmware version 1.6.5 is vulnerable to denial of service (DoS).

Jan 6, 2024
CVE-2023-46953
9.8 CRITICAL

SQL Injection vulnerability in ABO.CMS v.5.9.3, allows remote attackers to execute arbitrary code via the d parameter in the Documents module.

Jan 6, 2024
CVE-2023-50609
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in AVA teaching video application service platform version 3.1, allows remote attackers to execute arbitrary code via a crafted script …

Jan 6, 2024
CVE-2023-39853
6.5 MEDIUM

SQL Injection vulnerability in Dzzoffice version 2.01, allows remote attackers to obtain sensitive information via the doobj and doevent parameters in the Network Disk backend …

Jan 6, 2024
CVE-2023-50612
7.8 HIGH

Insecure Permissions vulnerability in fit2cloud Cloud Explorer Lite version 1.4.1, allow local attackers to escalate privileges and obtain sensitive information via the cloud accounts parameter.

Jan 6, 2024
CVE-2024-21642
7.5 HIGH

D-Tale is a visualizer for Pandas data structures. Users hosting versions D-Tale prior to 3.9.0 publicly can be vulnerable to server-side request forgery (SSRF), allowing …

Jan 5, 2024
CVE-2024-21641
6.5 MEDIUM

Flarum is open source discussion platform software. Prior to version 1.8.5, the Flarum `/logout` route includes a redirect parameter that allows any third party to …

Jan 5, 2024
CVE-2024-0247
7.3 HIGH

A vulnerability classified as critical was found in CodeAstro Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /admin/ of the …

Jan 5, 2024
CVE-2023-47560
7.4 HIGH

An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute commands via a network. …

Jan 5, 2024
CVE-2023-47559
5.5 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a …

Jan 5, 2024
CVE-2023-47219
3.5 LOW

A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. …

Jan 5, 2024
CVE-2023-46837
3.3 LOW

Arm provides multiple helpers to clean & invalidate the cache for a given region. This is, for instance, used when allocating guest memory to ensure …

Jan 5, 2024
CVE-2023-46836
4.7 MEDIUM

The fixes for XSA-422 (Branch Type Confusion) and XSA-434 (Speculative Return Stack Overflow) are not IRQ-safe. It was believed that the mitigations always operated in …

Jan 5, 2024
CVE-2023-46835
5.5 MEDIUM

The current setup of the quarantine page tables assumes that the quarantine domain (dom_io) has been initialized with an address width of DEFAULT_DOMAIN_ADDRESS_WIDTH (48) and …

Jan 5, 2024
CVE-2023-45044
3.8 LOW

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Jan 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.