CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0755
8.8 HIGH

Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memory corruption and we presume …

Jan 23, 2024
CVE-2024-0751
8.8 HIGH

A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

Jan 23, 2024
CVE-2024-0750
8.8 HIGH

A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects …

Jan 23, 2024
CVE-2024-0745
8.8 HIGH

The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < …

Jan 23, 2024
CVE-2024-0744
7.5 HIGH

In some circumstances, JIT compiled code could have dereferenced a wild pointer value. This could have led to an exploitable crash. This vulnerability affects Firefox …

Jan 23, 2024
CVE-2024-0743
7.5 HIGH

An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.9, …

Jan 23, 2024
CVE-2024-22705
7.8 HIGH

An issue was discovered in ksmbd in the Linux kernel before 6.6.10. smb2_get_data_area_len in fs/smb/server/smb2misc.c can cause an smb_strndup_from_utf16 out-of-bounds access because the relationship between …

Jan 23, 2024
CVE-2023-51043
7.0 HIGH

In the Linux kernel before 6.4.5, drivers/gpu/drm/drm_atomic.c has a use-after-free during a race condition between a nonblocking atomic commit and a driver unload.

Jan 23, 2024
CVE-2023-51042
7.8 HIGH

In the Linux kernel before 6.4.12, amdgpu_cs_wait_all_fences in drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c has a fence use-after-free.

Jan 23, 2024
CVE-2024-23348
8.8 HIGH

Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, …

Jan 23, 2024
CVE-2024-23182
8.1 HIGH

Relative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, …

Jan 23, 2024
CVE-2024-23180
8.8 HIGH

Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, …

Jan 23, 2024
CVE-2024-23842
7.4 HIGH

Improper Input Validation in Hitron Systems DVR LGUVR-16H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Jan 23, 2024
CVE-2024-22772
7.4 HIGH

Improper Input Validation in Hitron Systems DVR LGUVR-8H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Jan 23, 2024
CVE-2024-22771
7.4 HIGH

Improper Input Validation in Hitron Systems DVR LGUVR-4H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Jan 23, 2024
CVE-2024-22770
7.4 HIGH

Improper Input Validation in Hitron Systems DVR HVR-16781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Jan 23, 2024
CVE-2024-22769
7.4 HIGH

Improper Input Validation in Hitron Systems DVR HVR-8781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Jan 23, 2024
CVE-2024-22768
7.4 HIGH

Improper Input Validation in Hitron Systems DVR HVR-4781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Jan 23, 2024
CVE-2024-23222
8.8 HIGH KEV

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS …

Jan 23, 2024
CVE-2024-23214
8.8 HIGH

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, …

Jan 23, 2024
CVE-2024-23213
8.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, …

Jan 23, 2024
CVE-2024-23212
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey …

Jan 23, 2024
CVE-2024-23209
8.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.3. Processing web content may lead to arbitrary code execution.

Jan 23, 2024
CVE-2024-23208
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. …

Jan 23, 2024
CVE-2024-23204
7.5 HIGH

The issue was addressed with additional permissions checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Monterey …

Jan 23, 2024
CVE-2024-23203
7.5 HIGH

The issue was addressed with additional permissions checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Sonoma …

Jan 23, 2024
CVE-2023-42881
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2. Processing a file may lead to unexpected app termination …

Jan 23, 2024
CVE-2024-23345
7.1 HIGH

Nautobot is a Network Source of Truth and Network Automation Platform built as a web application. All users of Nautobot versions earlier than 1.6.10 or …

Jan 23, 2024
CVE-2024-23342
7.4 HIGH

The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve …

Jan 23, 2024
CVE-2024-23678
7.5 HIGH

In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path input data. This results in the unsafe deserialization …

Jan 22, 2024
CVE-2023-24135
7.8 HIGH

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a command injection vulnerability in the function formWriteFacMac. This vulnerability allows attackers to execute arbitrary …

Jan 22, 2024
CVE-2023-7082
7.2 HIGH

The Import any XML or CSV File to WordPress plugin before 3.7.3 accepts all zip files and automatically extracts the zip file into a publicly …

Jan 22, 2024
CVE-2024-0605
7.5 HIGH

Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses security measures, …

Jan 22, 2024
CVE-2022-45792
7.8 HIGH

Project files may contain malicious contents which the software will use to create files on the filesystem. This allows directory traversal and overwriting files with …

Jan 22, 2024
CVE-2022-45790
8.6 HIGH

The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentication is susceptible to bruteforce attack, which may allow an adversary …

Jan 22, 2024
CVE-2024-0778
8.0 HIGH

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in Uniview ISC 2500-S up to 20210930. Affected by this …

Jan 22, 2024
CVE-2024-22895
8.8 HIGH

DedeCMS 5.7.112 has a File Upload vulnerability via uploads/dede/module_upload.php.

Jan 22, 2024
CVE-2020-36771
7.8 HIGH

CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view the authentication …

Jan 22, 2024
CVE-2024-22233
7.5 HIGH

In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) …

Jan 22, 2024
CVE-2023-52354
7.5 HIGH

chasquid before 1.13 allows SMTP smuggling because LF-terminated lines are accepted.

Jan 22, 2024
CVE-2024-21484
7.5 HIGH

Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts …

Jan 22, 2024
CVE-2023-47352
8.8 HIGH

Technicolor TC8715D devices have predictable default WPA2 security passwords. An attacker who scans for SSID and BSSID values may be able to predict these passwords.

Jan 22, 2024
CVE-2024-23768
8.8 HIGH

Dremio before 24.3.1 allows path traversal. An authenticated user who has no privileges on certain folders (and the files and datasets in these folders) can …

Jan 22, 2024
CVE-2024-23750
8.8 HIGH

MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen.

Jan 22, 2024
CVE-2024-23744
7.5 HIGH

An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.

Jan 21, 2024
CVE-2023-52353
7.5 HIGH

An issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is mishandled. For example, if the last connection negotiated …

Jan 21, 2024
CVE-2024-23732
7.5 HIGH

The JSON loader in Embedchain before 0.1.57 allows a ReDoS (regular expression denial of service) via a long string to json.py.

Jan 21, 2024
CVE-2023-6531
7.0 HIGH

A use-after-free flaw was found in the Linux Kernel due to a race problem in the unix garbage collector's deletion of SKB races with unix_stream_read_generic() …

Jan 21, 2024
CVE-2024-23726
8.8 HIGH

Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a Wi-Fi network) …

Jan 21, 2024
CVE-2024-0521
7.8 HIGH

Code Injection in paddlepaddle/paddle

Jan 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.