CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23304
7.5 HIGH

Cybozu KUNAI for Android 3.0.20 to 3.0.21 allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by performing certain operations.

Feb 6, 2024
CVE-2024-20816
8.0 HIGH

Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.

Feb 6, 2024
CVE-2024-20815
8.0 HIGH

Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.

Feb 6, 2024
CVE-2024-20813
8.4 HIGH

Out-of-bounds Write in padmd_vld_qtbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

Feb 6, 2024
CVE-2024-20812
8.4 HIGH

Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

Feb 6, 2024
CVE-2024-22773
8.1 HIGH

Intelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in Cookie resulting in Login Bypass.

Feb 6, 2024
CVE-2023-47889
7.8 HIGH

The Android application BINHDRM26 com.bdrm.superreboot 1.0.3, exposes several critical actions through its exported broadcast receivers. These exposed actions can allow any app on the device …

Feb 6, 2024
CVE-2023-47353
8.8 HIGH

An issue in the com.oneed.dvr.service.DownloadFirmwareService component of IMOU GO v1.0.11 allows attackers to force the download of arbitrary files.

Feb 6, 2024
CVE-2023-46360
8.8 HIGH

Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier is vulnerable to Execution with Unnecessary Privileges.

Feb 6, 2024
CVE-2023-47354
7.8 HIGH

An issue in the PowerOffWidgetReceiver function of Super Reboot (Root) Recovery v1.0.3 allows attackers to arbitrarily reset or power off the device via a crafted …

Feb 6, 2024
CVE-2024-1072
8.2 HIGH

The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized modification of …

Feb 5, 2024
CVE-2024-0869
8.8 HIGH

The Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels plugin for WordPress is vulnerable to unauthorized arbitrary options update due …

Feb 5, 2024
CVE-2024-0761
8.1 HIGH

The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient randomness in …

Feb 5, 2024
CVE-2024-0428
7.1 HIGH

The Index Now plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.3. This is due to missing …

Feb 5, 2024
CVE-2024-0324
8.2 HIGH

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized modification of data …

Feb 5, 2024
CVE-2023-6996
8.8 HIGH

The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Code Injection via the plugin's vg_display_data …

Feb 5, 2024
CVE-2023-6933
8.8 HIGH

The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization of untrusted …

Feb 5, 2024
CVE-2023-6925
7.2 HIGH

The Unlimited Addons for WPBakery Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'importZipFile' …

Feb 5, 2024
CVE-2023-6846
8.8 HIGH

The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.3.4 via the mk_check_filemanager_php_syntax AJAX …

Feb 5, 2024
CVE-2023-6700
8.8 HIGH

The Cookie Information | Free GDPR Consent Solution plugin for WordPress is vulnerable to arbitrary option updates due to a missing capability check on its …

Feb 5, 2024
CVE-2023-6635
7.2 HIGH

The EditorsKit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the 'import_styles' function in versions up to, …

Feb 5, 2024
CVE-2024-1052
8.0 HIGH

Boundary and Boundary Enterprise (“Boundary”) is vulnerable to session hijacking through TLS certificate tampering. An attacker with privileges to enumerate active or pending sessions, obtain …

Feb 5, 2024
CVE-2023-50782
7.5 HIGH

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA …

Feb 5, 2024
CVE-2023-50781
7.5 HIGH

A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, …

Feb 5, 2024
CVE-2024-22567
8.8 HIGH

File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.

Feb 5, 2024
CVE-2024-24267
7.5 HIGH

gpac v2.2.1 (fixed in v2.4.0) was discovered to contain a memory leak via the gfio_blob variable in the gf_fileio_from_blob function.

Feb 5, 2024
CVE-2024-24266
7.5 HIGH

gpac v2.2.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the dasher_configure_pid function at /src/filters/dasher.c.

Feb 5, 2024
CVE-2024-24265
7.5 HIGH

gpac v2.2.1 was discovered to contain a memory leak via the dst_props variable in the gf_filter_pid_merge_properties_internal function.

Feb 5, 2024
CVE-2024-24263
7.5 HIGH

Lotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_line function at /lotos/src/response.c.

Feb 5, 2024
CVE-2024-24262
7.5 HIGH

media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_uac_stop_timer function at /uac/sip-uac-transaction.c.

Feb 5, 2024
CVE-2024-24260
7.5 HIGH

media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_subscribe_remove function at /uac/sip-uac-subscribe.c.

Feb 5, 2024
CVE-2024-24259
7.5 HIGH

freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function.

Feb 5, 2024
CVE-2024-24258
7.5 HIGH

freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function.

Feb 5, 2024
CVE-2023-6874
7.5 HIGH

Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number

Feb 5, 2024
CVE-2024-24469
8.8 HIGH

Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the delete_post .php.

Feb 5, 2024
CVE-2024-24468
8.8 HIGH

Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_customblock.php.

Feb 5, 2024
CVE-2023-47355
7.5 HIGH

The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers for PowerOff, Reboot, and Recovery (e.g., com.eypcnnapps.quickreboot.widget.PowerOff) that …

Feb 5, 2024
CVE-2024-24762
7.5 HIGH

`python-multipart` is a streaming multipart parser for Python. When using form data, `python-multipart` uses a Regular Expression to parse the HTTP `Content-Type` header, including options. …

Feb 5, 2024
CVE-2023-52138
8.2 HIGH

Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerability that can be leveraged to …

Feb 5, 2024
CVE-2024-1225
7.3 HIGH

A vulnerability classified as critical was found in QiboSoft QiboCMS X1 up to 1.0.6. Affected by this vulnerability is the function rmb_pay of the file …

Feb 5, 2024
CVE-2023-5643
7.8 HIGH

Out-of-bounds Write vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver …

Feb 5, 2024
CVE-2023-5249
7.0 HIGH

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper …

Feb 5, 2024
CVE-2024-22667
7.8 HIGH

Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to …

Feb 5, 2024
CVE-2024-24848
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MJS Software PT Sign Ups – Beautiful volunteer sign ups and management made …

Feb 5, 2024
CVE-2024-24847
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgadbois CalculatorPro Calculators allows Reflected XSS.This issue affects CalculatorPro Calculators: from n/a through …

Feb 5, 2024
CVE-2024-24846
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MightyThemes Mighty Addons for Elementor allows Reflected XSS.This issue affects Mighty Addons for …

Feb 5, 2024
CVE-2024-24866
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Biteship Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo allows Reflected XSS.This issue …

Feb 5, 2024
CVE-2024-20015
7.8 HIGH

In telephony, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege with no additional …

Feb 5, 2024
CVE-2024-20009
8.8 HIGH

In alac decoder, there is a possible out of bounds write due to an incorrect error handling. This could lead to remote escalation of privilege …

Feb 5, 2024
CVE-2024-20007
7.5 HIGH

In mp3 decoder, there is a possible out of bounds write due to a race condition. This could lead to remote escalation of privilege with …

Feb 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.