CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22627
7.2 HIGH

Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_distributor.php?id=.

Jan 16, 2024
CVE-2024-22626
7.2 HIGH

Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_retailer.php?id=.

Jan 16, 2024
CVE-2024-22625
7.2 HIGH

Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_category.php?id=.

Jan 16, 2024
CVE-2023-22514
7.8 HIGH

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code …

Jan 16, 2024
CVE-2023-22512
7.5 HIGH

This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7.5, …

Jan 16, 2024
CVE-2024-0578
8.8 HIGH

A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Jan 16, 2024
CVE-2024-0577
8.8 HIGH

A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been rated as critical. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The …

Jan 16, 2024
CVE-2024-0576
8.8 HIGH

A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been declared as critical. This vulnerability affects the function setIpPortFilterRules of the file /cgi-bin/cstecgi.cgi. The …

Jan 16, 2024
CVE-2023-6373
8.8 HIGH

The ArtPlacer Widget WordPress plugin before 2.20.7 does not sanitize and escape the "id" parameter before submitting the query, leading to a SQLI exploitable by …

Jan 16, 2024
CVE-2023-5922
7.5 HIGH

The Royal Elementor Addons and Templates WordPress plugin before 1.3.81 does not ensure that users accessing posts via an AJAX action (and REST endpoint, currently …

Jan 16, 2024
CVE-2023-4797
7.2 HIGH

The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable …

Jan 16, 2024
CVE-2023-4703
7.5 HIGH

The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating user details, allowing an unauthenticated attacker to …

Jan 16, 2024
CVE-2023-4536
8.8 HIGH

The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber …

Jan 16, 2024
CVE-2023-45235
8.3 HIGH

EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be …

Jan 16, 2024
CVE-2023-45234
8.3 HIGH

EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited …

Jan 16, 2024
CVE-2023-45233
7.5 HIGH

EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can …

Jan 16, 2024
CVE-2023-45232
7.5 HIGH

EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be …

Jan 16, 2024
CVE-2023-45230
8.3 HIGH

EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by …

Jan 16, 2024
CVE-2023-2655
7.2 HIGH

The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using it in a SQL statement, leading …

Jan 16, 2024
CVE-2023-1405
7.5 HIGH

The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is …

Jan 16, 2024
CVE-2022-3899
8.1 HIGH

The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing …

Jan 16, 2024
CVE-2022-3764
7.2 HIGH

The plugin does not filter the "delete_entries" parameter from user requests, leading to an SQL Injection vulnerability.

Jan 16, 2024
CVE-2022-3604
7.8 HIGH

The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.

Jan 16, 2024
CVE-2022-1538
7.2 HIGH

Theme Demo Import WordPress plugin before 1.1.1 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as …

Jan 16, 2024
CVE-2021-24869
8.8 HIGH

The WP Fastest Cache WordPress plugin before 0.9.5 does not escape user input in the set_urls_with_terms method before using it in a SQL statement, leading …

Jan 16, 2024
CVE-2021-24566
8.8 HIGH

The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.

Jan 16, 2024
CVE-2021-24151
7.2 HIGH

The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via …

Jan 16, 2024
CVE-2024-0582
7.8 HIGH

A memory leak flaw was found in the Linux kernel’s io_uring functionality in how a user registers a buffer ring with IORING_REGISTER_PBUF_RING, mmap() it, and …

Jan 16, 2024
CVE-2024-0575
8.8 HIGH

A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been classified as critical. This affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jan 16, 2024
CVE-2024-0574
8.8 HIGH

A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130 and classified as critical. Affected by this issue is the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The …

Jan 16, 2024
CVE-2024-0573
8.8 HIGH

A vulnerability has been found in Totolink LR1200GB 9.1.0u.6619_B20230130 and classified as critical. Affected by this vulnerability is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. …

Jan 16, 2024
CVE-2024-0572
8.8 HIGH

A vulnerability, which was classified as critical, was found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jan 16, 2024
CVE-2024-0571
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. This issue affects the function setSmsCfg of the file /cgi-bin/cstecgi.cgi. The …

Jan 16, 2024
CVE-2024-0570
7.3 HIGH

A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6265. This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. …

Jan 16, 2024
CVE-2024-0567
7.5 HIGH

A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a …

Jan 16, 2024
CVE-2024-0553
7.5 HIGH

A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 …

Jan 16, 2024
CVE-2024-0556
7.1 HIGH

A Weak Cryptography for Passwords vulnerability has been detected on WIC200 affecting version 1.1. This vulnerability allows a remote user to intercept the traffic and …

Jan 16, 2024
CVE-2023-52105
7.5 HIGH

The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability.

Jan 16, 2024
CVE-2023-52104
7.5 HIGH

Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-52102
7.5 HIGH

Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-52100
7.5 HIGH

The Celia Keyboard module has a vulnerability in access control. Successful exploitation of this vulnerability may affect availability.

Jan 16, 2024
CVE-2023-52099
7.5 HIGH

Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-52116
7.5 HIGH

Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.

Jan 16, 2024
CVE-2023-52115
7.5 HIGH

The iaware module has a Use-After-Free (UAF) vulnerability. Successful exploitation of this vulnerability may affect the system functions.

Jan 16, 2024
CVE-2023-52114
7.5 HIGH

Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity.

Jan 16, 2024
CVE-2023-52108
7.5 HIGH

Vulnerability of process priorities being raised in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.

Jan 16, 2024
CVE-2023-52107
7.5 HIGH

Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-52098
7.5 HIGH

Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability.

Jan 16, 2024
CVE-2023-52113
7.5 HIGH

launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.

Jan 16, 2024
CVE-2023-52111
7.5 HIGH

Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.

Jan 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.