CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-7063
7.2 HIGH

The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and including, 1.8.5.3 due …

Jan 20, 2024
CVE-2023-47024
8.8 HIGH

Cross-Site Request Forgery (CSRF) in NCR Terminal Handler v.1.5.1 leads to a one-click account takeover. This is achieved by exploiting multiple vulnerabilities, including an undisclosed …

Jan 20, 2024
CVE-2023-51926
7.5 HIGH

YonBIP v3_23.05 was discovered to contain an arbitrary file read vulnerability via the nc.bs.framework.comn.serv.CommonServletDispatcher component.

Jan 20, 2024
CVE-2024-0739
7.3 HIGH

A vulnerability, which was classified as critical, was found in Hecheng Leadshop up to 1.4.20. Affected is an unknown function of the file /web/leadshop.php. The …

Jan 19, 2024
CVE-2024-23689
8.8 HIGH

Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificate …

Jan 19, 2024
CVE-2024-23684
7.5 HIGH

Inefficient algorithmic complexity in DecodeFromBytes function in com.upokecenter.cbor Java implementation of Concise Binary Object Representation (CBOR) versions 4.0.0 to 4.5.1 allows an attacker to cause …

Jan 19, 2024
CVE-2024-23683
8.2 HIGH

Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker …

Jan 19, 2024
CVE-2024-23682
8.2 HIGH

Artemis Java Test Sandbox versions before 1.8.0 are vulnerable to a sandbox escape when an attacker includes class files in a package that Ares trusts. …

Jan 19, 2024
CVE-2024-23681
8.2 HIGH

Artemis Java Test Sandbox versions before 1.11.2 are vulnerable to a sandbox escape when an attacker loads untrusted libraries using System.load or System.loadLibrary. An attacker …

Jan 19, 2024
CVE-2024-22421
7.6 HIGH

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious …

Jan 19, 2024
CVE-2023-49329
7.2 HIGH

Anomali Match before 4.6.2 allows OS Command Injection. An authenticated admin user can inject and execute operating system commands. This arises from improper handling of …

Jan 19, 2024
CVE-2024-23331
7.5 HIGH

Vite is a frontend tooling framework for javascript. The Vite dev server option `server.fs.deny` can be bypassed on case-insensitive file systems using case-augmented versions of …

Jan 19, 2024
CVE-2023-6043
7.8 HIGH

A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker to bypass integrity checks and execute arbitrary code with elevated …

Jan 19, 2024
CVE-2023-50447
8.1 HIGH

Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).

Jan 19, 2024
CVE-2023-47035
7.5 HIGH

RPTC 0x3b08c was discovered to not conduct status checks on the parameter tradingOpen. This vulnerability can allow attackers to conduct unauthorized transfer operations.

Jan 19, 2024
CVE-2023-42766
7.5 HIGH

Improper input validation in some Intel NUC 8 Compute Element BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local …

Jan 19, 2024
CVE-2023-42429
7.5 HIGH

Improper buffer restrictions in some Intel NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

Jan 19, 2024
CVE-2023-38587
7.5 HIGH

Improper input validation in some Intel NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

Jan 19, 2024
CVE-2023-32544
7.3 HIGH

Improper access control in some Intel HotKey Services for Windows 10 for Intel NUC P14E Laptop Element software installers before version 1.1.45 may allow an …

Jan 19, 2024
CVE-2023-32272
7.9 HIGH

Uncontrolled search path in some Intel NUC Pro Software Suite Configuration Tool software installers before version 3.0.0.6 may allow an authenticated user to potentially enable …

Jan 19, 2024
CVE-2023-29495
7.5 HIGH

Improper input validation for some Intel NUC BIOS firmware before version IN0048 may allow a privileged user to potentially enable escalation of privilege via local …

Jan 19, 2024
CVE-2023-28743
7.5 HIGH

Improper input validation for some Intel NUC BIOS firmware before version QN0073 may allow a privileged user to potentially enable escalation of privilege via local …

Jan 19, 2024
CVE-2023-28738
7.5 HIGH

Improper input validation for some Intel NUC BIOS firmware before version JY0070 may allow a privileged user to potentially enable escalation of privilege via local …

Jan 19, 2024
CVE-2024-22956
7.8 HIGH

swftools 0.9.2 was discovered to contain a heap-use-after-free vulnerability via the function removeFromTo at swftools/src/swfc.c:838

Jan 19, 2024
CVE-2024-22955
7.8 HIGH

swftools 0.9.2 was discovered to contain a stack-buffer-underflow vulnerability via the function parseExpression at swftools/src/swfc.c:2576.

Jan 19, 2024
CVE-2024-22919
7.8 HIGH

swftools0.9.2 was discovered to contain a global-buffer-overflow vulnerability via the function parseExpression at swftools/src/swfc.c:2587.

Jan 19, 2024
CVE-2024-22915
7.8 HIGH

A heap-use-after-free was found in SWFTools v0.9.2, in the function swf_DeleteTag at rfxswf.c:1193. It allows an attacker to cause code execution.

Jan 19, 2024
CVE-2024-22913
7.8 HIGH

A heap-buffer-overflow was found in SWFTools v0.9.2, in the function swf5lex at lex.swf5.c:1321. It allows an attacker to cause code execution.

Jan 19, 2024
CVE-2024-22912
7.8 HIGH

A global-buffer-overflow was found in SWFTools v0.9.2, in the function countline at swf5compiler.flex:327. It allows an attacker to cause code execution.

Jan 19, 2024
CVE-2024-22911
7.8 HIGH

A stack-buffer-underflow vulnerability was found in SWFTools v0.9.2, in the function parseExpression at src/swfc.c:2602.

Jan 19, 2024
CVE-2023-47034
7.5 HIGH

A vulnerability in UniswapFrontRunBot 0xdB94c allows attackers to cause financial losses via unspecified vectors.

Jan 19, 2024
CVE-2023-47033
7.5 HIGH

MultiSigWallet 0xF0C99 was discovered to contain a reentrancy vulnerability via the function executeTransaction.

Jan 19, 2024
CVE-2024-22920
7.8 HIGH

swftools 0.9.2 was discovered to contain a heap-use-after-free via the function bufferWriteData in swftools/lib/action/compile.c.

Jan 19, 2024
CVE-2024-22563
7.5 HIGH

openvswitch 2.17.8 was discovered to contain a memory leak via the function xmalloc__ in openvswitch-2.17.8/lib/util.c.

Jan 19, 2024
CVE-2024-22562
7.8 HIGH

swftools 0.9.2 was discovered to contain a Stack Buffer Underflow via the function dict_foreach_keyvalue at swftools/lib/q.c.

Jan 19, 2024
CVE-2022-40700
8.2 HIGH

Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio …

Jan 19, 2024
CVE-2024-0712
7.3 HIGH

A vulnerability was found in Byzoro Smart S150 Management Platform V31R02B15. It has been classified as critical. Affected is an unknown function of the file …

Jan 19, 2024
CVE-2023-51948
7.5 HIGH

A Site-wide directory listing vulnerability in /fm in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to list the files hosted by the web …

Jan 19, 2024
CVE-2024-22424
8.3 HIGH

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.15 are vulnerable …

Jan 19, 2024
CVE-2024-22422
7.5 HIGH

AnythingLLM is an application that turns any document, resource, or piece of content into context that any LLM can use as references during chatting. In …

Jan 19, 2024
CVE-2023-40683
8.8 HIGH

IBM OpenPages with Watson 8.3 and 9.0 could allow remote attacker to bypass security restrictions, caused by insufficient authorization checks. By authenticating as an OpenPages …

Jan 19, 2024
CVE-2023-5131
8.2 HIGH

A heap buffer-overflow exists in Delta Electronics ISPSoft. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DVP …

Jan 18, 2024
CVE-2023-5130
8.2 HIGH

A buffer overflow vulnerability exists in Delta Electronics WPLSoft. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted …

Jan 18, 2024
CVE-2023-50614
7.5 HIGH

An issue discovereed in EBYTE E880-IR01-V1.1 allows an attacker to obtain sensitive information via crafted POST request to /cgi-bin/luci.

Jan 18, 2024
CVE-2023-43824
8.8 HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wTitleTextLen field of a DPS file. A remote, unauthenticated …

Jan 18, 2024
CVE-2023-43823
8.8 HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wTTitleLen field of a DPS file. A remote, unauthenticated …

Jan 18, 2024
CVE-2023-43822
8.8 HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesTimeLen field of a DPS file. A remote, unauthenticated …

Jan 18, 2024
CVE-2023-43821
8.8 HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesActionLen field of a DPS file. A remote, unauthenticated …

Jan 18, 2024
CVE-2023-43820
8.8 HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesPrevValueLen field of a DPS file. A remote, unauthenticated …

Jan 18, 2024
CVE-2023-43819
8.8 HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the InitialMacroLen field of a DPS file. A remote, unauthenticated …

Jan 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.