CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-2081
7.5 HIGH

A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is enabled and configured, …

Jan 4, 2024
CVE-2023-50630
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in xiweicheng TMS v.2.28.0 allows a remote attacker to execute arbitrary code via a crafted script to the click here …

Jan 4, 2024
CVE-2023-50082
7.5 HIGH

Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via session leakage allows a user to avoid …

Jan 4, 2024
CVE-2023-41784
6.6 MEDIUM

Permissions and Access Control Vulnerability in ZTE Red Magic 8 Pro

Jan 4, 2024
CVE-2023-52322
6.1 MEDIUM

ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as alphanumerics.

Jan 4, 2024
CVE-2022-43375

Rejected reason: This CVE ID was unused by the CNA.

Jan 4, 2024
CVE-2023-29962
6.5 MEDIUM

S-CMS v5.0 was discovered to contain an arbitrary file read vulnerability.

Jan 4, 2024
CVE-2023-6738
5.4 MEDIUM

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_header_code', 'pagelayer_body_open_code', and 'pagelayer_footer_code' …

Jan 4, 2024
CVE-2023-6733
6.5 MEDIUM

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode. …

Jan 4, 2024
CVE-2023-6498
4.4 MEDIUM

The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including …

Jan 4, 2024
CVE-2024-0225
8.8 HIGH

Use after free in WebGPU in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jan 4, 2024
CVE-2024-0224
8.8 HIGH

Use after free in WebAudio in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jan 4, 2024
CVE-2024-0223
8.8 HIGH

Heap buffer overflow in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jan 4, 2024
CVE-2024-0222
8.8 HIGH

Use after free in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap …

Jan 4, 2024
CVE-2024-20809
4.0 MEDIUM

Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access data.

Jan 4, 2024
CVE-2024-20808
4.0 MEDIUM

Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access data.

Jan 4, 2024
CVE-2024-20807
3.3 LOW

Implicit intent hijacking vulnerability in Samsung Email prior to version 6.1.90.16 allows local attacker to get sensitive information.

Jan 4, 2024
CVE-2024-20806
6.2 MEDIUM

Improper access control in Notification service prior to SMR Jan-2024 Release 1 allows local attacker to access notification data.

Jan 4, 2024
CVE-2024-20805
3.3 LOW

Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 …

Jan 4, 2024
CVE-2024-20804
4.0 MEDIUM

Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 …

Jan 4, 2024
CVE-2024-20803
6.8 MEDIUM

Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing process without user interaction.

Jan 4, 2024
CVE-2024-20802
4.6 MEDIUM

Improper access control vulnerability in Samsung DeX prior to SMR Jan-2024 Release 1 allows owner to access other users' notification in a multi-user environment.

Jan 4, 2024
CVE-2024-21634
7.5 HIGH

Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service issue exists in `ion-java` for applications that …

Jan 3, 2024
CVE-2023-5138
6.8 MEDIUM

Glitch detection is not enabled by default for the CortexM33 core in Silicon Labs secure vault high parts EFx32xG2xB, except EFR32xG21B.

Jan 3, 2024
CVE-2023-50256
7.5 HIGH

Froxlor is open source server administration software. Prior to version 2.1.2, it was possible to submit the registration form with the essential fields, such as …

Jan 3, 2024
CVE-2023-6540
6.5 MEDIUM

A vulnerability was reported in the Lenovo Browser Mobile and Lenovo Browser HD Apps for Android that could allow an attacker to craft a payload …

Jan 3, 2024
CVE-2023-6338
7.8 HIGH

Uncontrolled search path vulnerabilities were reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with …

Jan 3, 2024
CVE-2023-49442
9.8 CRITICAL

Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.

Jan 3, 2024
CVE-2023-5881
8.2 HIGH

Unauthenticated access permitted to web interface page The Genie Company Aladdin Connect (Retrofit-Kit Model ALDCM) "Garage Door Control Module Setup" and modify the Garage door's …

Jan 3, 2024
CVE-2023-5880
8.8 HIGH

When the Genie Company Aladdin Connect garage door opener (Retrofit-Kit Model ALDCM) is placed into configuration mode the web servers “Garage Door Control Module Setup” …

Jan 3, 2024
CVE-2023-5879
6.8 MEDIUM

Users’ product account authentication data was stored in clear text in The Genie Company Aladdin Connect Mobile Application Version 5.65 Build 2075 (and below) on …

Jan 3, 2024
CVE-2023-50090
9.8 CRITICAL

Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write arbitrary files and run arbitrary commands via crafted …

Jan 3, 2024
CVE-2023-46929
7.5 HIGH

An issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui /afltest/gpac/src/media_tools/av_parsers.c:6872:55 allows attackers to crash the application.

Jan 3, 2024
CVE-2024-21633
7.8 HIGH

Apktool is a tool for reverse engineering Android APK files. In versions 2.9.1 and prior, Apktool infers resource files' output path according to their resource …

Jan 3, 2024
CVE-2024-21631
6.5 MEDIUM

Vapor is an HTTP web framework for Swift. Prior to version 4.90.0, Vapor's `vapor_urlparser_parse` function uses `uint16_t` indexes when parsing a URI's components, which may …

Jan 3, 2024
CVE-2024-21622
5.4 MEDIUM

Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 …

Jan 3, 2024
CVE-2024-0217
3.3 LOW

A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some …

Jan 3, 2024
CVE-2023-6004
4.8 MEDIUM

A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may …

Jan 3, 2024
CVE-2023-50253
9.6 CRITICAL

Laf is a cloud development platform. In the Laf version design, the log uses communication with k8s to quickly retrieve logs from the container without …

Jan 3, 2024
CVE-2023-46742
4.8 MEDIUM

CubeFS is an open-source cloud-native file storage system. CubeFS prior to version 3.3.1 was found to leak users secret keys and access keys in the …

Jan 3, 2024
CVE-2023-46741
4.8 MEDIUM

CubeFS is an open-source cloud-native file storage system. A vulnerability was found in CubeFS prior to version 3.3.1 that could allow users to read sensitive …

Jan 3, 2024
CVE-2023-46740
6.5 MEDIUM

CubeFS is an open-source cloud-native file storage system. Prior to version 3.3.1, CubeFS used an insecure random string generator to generate user-specific, sensitive keys used …

Jan 3, 2024
CVE-2023-46739
6.5 MEDIUM

CubeFS is an open-source cloud-native file storage system. A vulnerability was found during in the CubeFS master component in versions prior to 3.3.1 that could …

Jan 3, 2024
CVE-2024-21911
6.1 MEDIUM

TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting …

Jan 3, 2024
CVE-2024-21910
6.1 MEDIUM

TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would …

Jan 3, 2024
CVE-2024-21909
7.5 HIGH

PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of service vulnerability. An attacker may trigger the denial of service condition by providing crafted …

Jan 3, 2024
CVE-2024-21908
6.1 MEDIUM

TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting …

Jan 3, 2024
CVE-2024-21907
7.5 HIGH

Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a …

Jan 3, 2024
CVE-2023-46738
6.5 MEDIUM

CubeFS is an open-source cloud-native file storage system. A security vulnerability was found in CubeFS HandlerNode in versions prior to 3.3.1 that could allow authenticated …

Jan 3, 2024
CVE-2023-30617
6.5 MEDIUM

Kruise provides automated management of large-scale applications on Kubernetes. Starting in version 0.8.0 and prior to versions 1.3.1, 1.4.1, and 1.5.2, an attacker who has …

Jan 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.