CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-52150
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Ovation S.R.L. Dynamic Content for Elementor.This issue affects Dynamic Content for Elementor: from n/a before 2.12.5.

Jan 5, 2024
CVE-2023-51502
7.5 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.6.1.

Jan 5, 2024
CVE-2020-13879
9.8 CRITICAL

IrfanView B3D PlugIns before version 4.56 has a B3d.dll!+214f heap-based out-of-bounds write.

Jan 5, 2024
CVE-2020-13878
9.8 CRITICAL

IrfanView B3D PlugIns before version 4.56 has a B3d.dll!+27ef heap-based out-of-bounds write.

Jan 5, 2024
CVE-2023-51277
9.8 CRITICAL

nbviewer-app (aka Jupyter Notebook Viewer) before 0.1.6 has the get-task-allow entitlement for release builds.

Jan 5, 2024
CVE-2024-22088
9.8 CRITICAL

Lotos WebServer through 0.1.1 (commit 3eb36cc) has a use-after-free in buffer_avail() at buffer.h via a long URI, because realloc is mishandled.

Jan 5, 2024
CVE-2024-22087
9.8 CRITICAL

route in main.c in Pico HTTP Server in C through f3b69a6 has an sprintf stack-based buffer overflow via a long URI, leading to remote code …

Jan 5, 2024
CVE-2024-22086
9.8 CRITICAL

handle_request in http.c in cherry through 4b877df has an sscanf stack-based buffer overflow via a long URI, leading to remote code execution.

Jan 5, 2024
CVE-2023-52323
5.9 MEDIUM

PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.

Jan 5, 2024
CVE-2024-22075
6.1 MEDIUM

Firefly III (aka firefly-iii) before 6.1.1 allows webhooks HTML Injection.

Jan 5, 2024
CVE-2023-6493
4.3 MEDIUM

The Depicter Slider – Responsive Image Slider, Video Slider & Post Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Jan 5, 2024
CVE-2023-41782
3.9 LOW

There is a DLL hijacking vulnerability in ZTE ZXCLOUD iRAI, an attacker could place a fake DLL file in a specific directory and successfully exploit …

Jan 5, 2024
CVE-2024-22051
9.8 CRITICAL

CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap …

Jan 4, 2024
CVE-2024-22050
7.5 HIGH

Path traversal in the static file service in Iodine less than 0.7.33 allows an unauthenticated, remote attacker to read files outside the public folder via …

Jan 4, 2024
CVE-2024-22049
5.3 MEDIUM

httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads …

Jan 4, 2024
CVE-2024-22048
6.1 MEDIUM

govuk_tech_docs versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability. Malicious JavaScript may be executed in the user's browser if a …

Jan 4, 2024
CVE-2024-22047
3.1 LOW

A race condition exists in Audited 4.0.0 to 5.3.3 that can result in an authenticated user to cause audit log entries to be attributed to …

Jan 4, 2024
CVE-2024-0241
7.5 HIGH

encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacker might cause a denial of service condition by …

Jan 4, 2024
CVE-2024-21636
6.1 MEDIUM

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. Versions prior to 3.9.0 and 2.83.0 have a cross-site …

Jan 4, 2024
CVE-2023-51812
9.8 CRITICAL

Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.

Jan 4, 2024
CVE-2023-51154
9.8 CRITICAL

Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php.

Jan 4, 2024
CVE-2023-6270
7.0 HIGH

A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, …

Jan 4, 2024
CVE-2023-6551
5.4 MEDIUM

As a simple library, class.upload.php does not perform an in-depth check on uploaded files, allowing a stored XSS vulnerability when the default configuration is used. …

Jan 4, 2024
CVE-2024-21625
8.8 HIGH

SideQuest is a place to get virtual reality applications for Oculus Quest. The SideQuest desktop application uses deep links with a custom protocol (`sidequest://`) to …

Jan 4, 2024
CVE-2023-50867
9.8 CRITICAL

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the signupAction.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-50866
9.8 CRITICAL

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginAction.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-50865
9.8 CRITICAL

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'city' parameter of the hotelSearch.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-50864
9.8 CRITICAL

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelId' parameter of the hotelDetails.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-50863
9.8 CRITICAL

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the generateReceipt.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-50862
9.8 CRITICAL

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the booking.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-50760
8.8 HIGH

Online Notice Board System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'f' parameter of user/update_profile_pic.php page, allowing an authenticated attacker to …

Jan 4, 2024
CVE-2023-3726
6.9 MEDIUM

OCSInventory allow stored email template with special characters that lead to a Stored cross-site Scripting.

Jan 4, 2024
CVE-2023-50753
9.8 CRITICAL

Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parameter of the user/update_profile.php resource does not validate the characters …

Jan 4, 2024
CVE-2023-50752
9.8 CRITICAL

Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'e' parameter of the login.php resource does not validate the characters …

Jan 4, 2024
CVE-2023-50743
9.8 CRITICAL

Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parameter of the registration.php resource does not validate the characters …

Jan 4, 2024
CVE-2023-49666
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'custmer_details' parameter of the submit_material_list.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49665
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'quantity[]' parameter of the submit_delivery_list.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49658
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'bank_details' parameter of the party_submit.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49639
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'customer_details' parameter of the buyer_invoice_submit.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49633
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'buyer_address' parameter of the buyer_detail_submit.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49625
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the partylist_edit_submit.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49624
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cancelid' parameter of the material_bill.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49622
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'itemnameid' parameter of the material_bill.php?action=itemRelation resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-6992
4.0 MEDIUM

Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c). The issues resulted from improper …

Jan 4, 2024
CVE-2021-45465
7.8 HIGH

A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied data when parsing BMP files. This could …

Jan 4, 2024
CVE-2021-42028
7.8 HIGH

A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied data when parsing BMP files. This could …

Jan 4, 2024
CVE-2021-40367
7.8 HIGH

A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied data when parsing DICOM files. This could …

Jan 4, 2024
CVE-2023-7044
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom …

Jan 4, 2024
CVE-2023-6944
5.7 MEDIUM

A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded …

Jan 4, 2024
CVE-2022-3864
4.5 MEDIUM

A vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED to restart. After restart the device is …

Jan 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.