CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-7192
5.5 MEDIUM

A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink.c in the Linux Kernel. This issue may allow a local attacker with CAP_NET_ADMIN privileges to …

Jan 2, 2024
CVE-2023-48419
10.0 CRITICAL

An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege

Jan 2, 2024
CVE-2022-3010
7.5 HIGH

The Priva TopControl Suite contains predictable credentials for the SSH service, based on the Serial number. Which makes it possible for an attacker to calculate …

Jan 2, 2024
CVE-2024-0193
7.8 HIGH

A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, …

Jan 2, 2024
CVE-2024-0189
3.5 LOW

A vulnerability has been found in RRJ Nueva Ecija Engineer Online Portal 1.0 and classified as problematic. This vulnerability affects unknown code of the file …

Jan 2, 2024
CVE-2023-4280
9.3 CRITICAL

An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of …

Jan 2, 2024
CVE-2023-48721

Rejected reason: Not used

Jan 2, 2024
CVE-2018-25097
3.5 LOW

A vulnerability, which was classified as problematic, was found in Acumos Design Studio up to 2.0.7. Affected is an unknown function. The manipulation leads to …

Jan 2, 2024
CVE-2024-0188
3.1 LOW

A vulnerability, which was classified as problematic, was found in RRJ Nueva Ecija Engineer Online Portal 1.0. This affects an unknown part of the file …

Jan 2, 2024
CVE-2017-20188
2.6 LOW

A vulnerability has been found in Zimbra zm-ajax up to 8.8.1 and classified as problematic. Affected by this vulnerability is the function XFormItem.prototype.setError of the …

Jan 2, 2024
CVE-2015-10128
3.5 LOW

A vulnerability was found in rt-prettyphoto Plugin up to 1.2 on WordPress and classified as problematic. Affected by this issue is the function royal_prettyphoto_plugin_links of …

Jan 2, 2024
CVE-2023-6436
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ekol Informatics Website Template allows SQL Injection.This issue affects Website Template: …

Jan 2, 2024
CVE-2023-6693
4.9 MEDIUM

A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if guest …

Jan 2, 2024
CVE-2023-50333
3.7 LOW

Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change …

Jan 2, 2024
CVE-2023-48732
4.3 MEDIUM

Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSocket broadcasting the information about who was …

Jan 2, 2024
CVE-2023-47858
4.3 MEDIUM

Mattermost fails to properly verify the permissions needed for viewing archived public channels, allowing a member of one team to get details about the archived …

Jan 2, 2024
CVE-2023-49142
4.0 MEDIUM

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia audio crash through modify a released pointer.

Jan 2, 2024
CVE-2023-49135
4.0 MEDIUM

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.

Jan 2, 2024
CVE-2023-48360
4.0 MEDIUM

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.

Jan 2, 2024
CVE-2023-47857
4.0 MEDIUM

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia camera crash through modify a released pointer.

Jan 2, 2024
CVE-2023-47216
2.9 LOW

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through occupy all resources

Jan 2, 2024
CVE-2023-47039
7.8 HIGH

A vulnerability was found in Perl. This security issue occurs while Perl for Windows relies on the system path environment variable to find the shell …

Jan 2, 2024
CVE-2023-43514
8.4 HIGH

Memory corruption while invoking IOCTLs calls from user space for internal mem MAP and internal mem UNMAP.

Jan 2, 2024
CVE-2023-43512
7.5 HIGH

Transient DOS while parsing GATT service data when the total amount of memory that is required by the multiple services is greater than the actual …

Jan 2, 2024
CVE-2023-43511
7.5 HIGH

Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.

Jan 2, 2024
CVE-2023-33120
7.8 HIGH

Memory corruption in Audio when memory map command is executed consecutively in ADSP.

Jan 2, 2024
CVE-2023-33118
7.8 HIGH

Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL.

Jan 2, 2024
CVE-2023-33117
7.8 HIGH

Memory corruption when HLOS allocates the response payload buffer to copy the data received from ADSP in response to AVCS_LOAD_MODULE command.

Jan 2, 2024
CVE-2023-33116
7.5 HIGH

Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver.

Jan 2, 2024
CVE-2023-33114
8.4 HIGH

Memory corruption while running NPU, when NETWORK_UNLOAD and (NETWORK_UNLOAD or NETWORK_EXECUTE_V2) commands are submitted at the same time.

Jan 2, 2024
CVE-2023-33113
8.4 HIGH

Memory corruption when resource manager sends the host kernel a reply message with multiple fragments.

Jan 2, 2024
CVE-2023-33112
7.5 HIGH

Transient DOS when WLAN firmware receives "reassoc response" frame including RIC_DATA element.

Jan 2, 2024
CVE-2023-33110
7.8 HIGH

The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close …

Jan 2, 2024
CVE-2023-33109
7.5 HIGH

Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.

Jan 2, 2024
CVE-2023-33108
8.4 HIGH

Memory corruption in Graphics Driver when destroying a context with KGSL_GPU_AUX_COMMAND_TIMELINE objects queued.

Jan 2, 2024
CVE-2023-33094
8.4 HIGH

Memory corruption while running VK synchronization with KASAN enabled.

Jan 2, 2024
CVE-2023-33085
7.8 HIGH

Memory corruption in wearables while processing data from AON.

Jan 2, 2024
CVE-2023-33062
7.5 HIGH

Transient DOS in WLAN Firmware while parsing a BTM request.

Jan 2, 2024
CVE-2023-33040
7.5 HIGH

Transient DOS in Data Modem during DTLS handshake.

Jan 2, 2024
CVE-2023-33038
6.7 MEDIUM

Memory corruption while receiving a message in Bus Socket Transport Server.

Jan 2, 2024
CVE-2023-33037
7.1 HIGH

Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data.

Jan 2, 2024
CVE-2023-33036
7.1 HIGH

Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call.

Jan 2, 2024
CVE-2023-33033
8.4 HIGH

Memory corruption in Audio during playback with speaker protection.

Jan 2, 2024
CVE-2023-33032
9.3 CRITICAL

Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.

Jan 2, 2024
CVE-2023-33030
9.3 CRITICAL

Memory corruption in HLOS while running playready use-case.

Jan 2, 2024
CVE-2023-33025
9.8 CRITICAL

Memory corruption in Data Modem when a non-standard SDP body, during a VOLTE call.

Jan 2, 2024
CVE-2023-33014
7.6 HIGH

Information disclosure in Core services while processing a Diag command.

Jan 2, 2024
CVE-2023-28583
6.7 MEDIUM

Memory corruption when IPv6 prefix timer object`s lifetime expires which are created while Netmgr daemon gets an IPv6 address.

Jan 2, 2024
CVE-2023-26159
7.3 HIGH

Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When …

Jan 2, 2024
CVE-2023-26157
5.5 MEDIUM

Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c.

Jan 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.