CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-52110
7.5 HIGH

The sensor module has an out-of-bounds access vulnerability.Successful exploitation of this vulnerability may affect availability.

Jan 16, 2024
CVE-2023-52109
7.5 HIGH

Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-4566
7.5 HIGH

Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-44117
7.5 HIGH

Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-44112
7.5 HIGH

Out-of-bounds access vulnerability in the device authentication module. Successful exploitation of this vulnerability may affect confidentiality.

Jan 16, 2024
CVE-2024-21674
7.5 HIGH

This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with …

Jan 16, 2024
CVE-2024-21673
8.8 HIGH

This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with …

Jan 16, 2024
CVE-2024-21672
8.8 HIGH

This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with …

Jan 16, 2024
CVE-2023-22526
8.8 HIGH

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center. This RCE (Remote Code Execution) vulnerability, with a …

Jan 16, 2024
CVE-2024-22428
7.0 HIGH

Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user to escalate privileges and …

Jan 16, 2024
CVE-2024-22362
7.5 HIGH

Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a denial-of-service (DoS) …

Jan 16, 2024
CVE-2023-51282
7.5 HIGH

An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.

Jan 16, 2024
CVE-2023-51257
7.8 HIGH

An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code.

Jan 16, 2024
CVE-2023-51059
8.8 HIGH

An issue in MOKO TECHNOLOGY LTD MOKOSmart MKGW1 BLE Gateway v.1.1.1 and before allows a remote attacker to escalate privileges via the session management component …

Jan 16, 2024
CVE-2023-43449
8.8 HIGH

An issue in HummerRisk HummerRisk v.1.10 thru 1.4.1 allows an authenticated attacker to execute arbitrary code via a crafted request to the service/LicenseService component.

Jan 16, 2024
CVE-2023-51810
7.5 HIGH

SQL injection vulnerability in StackIdeas EasyDiscuss v.5.0.5 and fixed in v.5.0.10 allows a remote attacker to obtain sensitive information via a crafted request to the …

Jan 16, 2024
CVE-2023-47460
8.8 HIGH

SQL injection vulnerability in Knovos Discovery v.22.67.0 allows a remote attacker to execute arbitrary code via the /DiscoveryProcess/Service/Admin.svc/getGridColumnStructure component.

Jan 16, 2024
CVE-2023-7206
7.8 HIGH

In Horner Automation Cscape versions 9.90 SP10 and prior, local attackers are able to exploit this vulnerability if a user opens a malicious CSP file, …

Jan 15, 2024
CVE-2024-0562
7.8 HIGH

A use-after-free flaw was found in the Linux Kernel. When a disk is removed, bdi_unregister is called to stop further write-back and waits for associated …

Jan 15, 2024
CVE-2023-6991
8.8 HIGH

The JSM file_get_contents() Shortcode WordPress plugin before 2.7.1 does not validate one of its shortcode's parameters before making a request to it, which could allow …

Jan 15, 2024
CVE-2023-6620
7.2 HIGH

The POST SMTP Mailer WordPress plugin before 2.8.7 does not properly sanitise and escape several parameters before using them in SQL statements, leading to a …

Jan 15, 2024
CVE-2023-6029
7.5 HIGH

The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from …

Jan 15, 2024
CVE-2023-5905
8.1 HIGH

The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of requests to export the blog data, allowing any logged …

Jan 15, 2024
CVE-2023-50729
8.4 HIGH

Traccar is an open source GPS tracking system. Prior to 5.11, Traccar is affected by an unrestricted file upload vulnerability in File feature allows attackers …

Jan 15, 2024
CVE-2023-4818
7.6 HIGH

PAX A920 device allows to downgrade bootloader due to a bug in its version check. The signature is correctly checked and only bootloader signed by …

Jan 15, 2024
CVE-2023-42137
7.8 HIGH

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by using malicious symlinks. The attacker must have …

Jan 15, 2024
CVE-2023-42136
7.8 HIGH

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands with system account privilege by shell injection starting with …

Jan 15, 2024
CVE-2024-0542
8.8 HIGH

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been rated as critical. Affected by this issue is the function formWifiMacFilterGet of the component …

Jan 15, 2024
CVE-2024-0541
8.8 HIGH

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been declared as critical. Affected by this vulnerability is the function formAddSysLogRule of the component …

Jan 15, 2024
CVE-2024-0539
8.8 HIGH

A vulnerability was found in Tenda W9 1.0.0.7(4456) and classified as critical. This issue affects the function formQosManage_user of the component httpd. The manipulation of …

Jan 15, 2024
CVE-2024-0538
8.8 HIGH

A vulnerability has been found in Tenda W9 1.0.0.7(4456) and classified as critical. This vulnerability affects the function formQosManage_auto of the component httpd. The manipulation …

Jan 15, 2024
CVE-2024-0537
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda W9 1.0.0.7(4456). This affects the function setWrlBasicInfo of the component httpd. The manipulation of …

Jan 15, 2024
CVE-2024-0536
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda W9 1.0.0.7(4456). Affected by this issue is the function setWrlAccessList of the component …

Jan 15, 2024
CVE-2024-0535
8.8 HIGH

A vulnerability classified as critical was found in Tenda PA6 1.0.1.21. Affected by this vulnerability is the function cgiPortMapAdd of the file /portmap of the …

Jan 15, 2024
CVE-2024-0534
7.2 HIGH

A vulnerability classified as critical has been found in Tenda A15 15.13.07.13. Affected is an unknown function of the file /goform/SetOnlineDevName of the component Web-based …

Jan 15, 2024
CVE-2024-0533
7.2 HIGH

A vulnerability was found in Tenda A15 15.13.07.13. It has been rated as critical. This issue affects some unknown processing of the file /goform/SetOnlineDevName of …

Jan 15, 2024
CVE-2023-48383
7.5 HIGH

NetVision Information airPASS has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit this vulnerability to bypass …

Jan 15, 2024
CVE-2024-0532
7.2 HIGH

A vulnerability was found in Tenda A15 15.13.07.13. It has been declared as critical. This vulnerability affects the function set_repeat5 of the file /goform/WifiExtraSet of …

Jan 15, 2024
CVE-2024-0531
7.2 HIGH

A vulnerability was found in Tenda A15 15.13.07.13. It has been classified as critical. This affects an unknown part of the file /goform/setBlackRule of the …

Jan 15, 2024
CVE-2024-0510
7.3 HIGH

A vulnerability, which was classified as critical, has been found in HaoKeKeJi YiQiNiu up to 3.1. Affected by this issue is the function http_post of …

Jan 13, 2024
CVE-2024-0480
7.3 HIGH

A vulnerability was found in Taokeyun up to 1.0.5. It has been declared as critical. Affected by this vulnerability is the function index of the …

Jan 13, 2024
CVE-2024-0479
7.3 HIGH

A vulnerability was found in Taokeyun up to 1.0.5. It has been classified as critical. Affected is the function login of the file application/index/controller/m/User.php of …

Jan 13, 2024
CVE-2023-52289
7.5 HIGH

An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a POST request to a /update-resource-data/<file_path> URI …

Jan 13, 2024
CVE-2023-52288
7.5 HIGH

An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a GET request to a /resource-data/<file_path>.txt URI …

Jan 13, 2024
CVE-2023-51070
7.5 HIGH

An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensitive SMB settings on the …

Jan 13, 2024
CVE-2023-51066
8.8 HIGH

An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily execute commands.

Jan 13, 2024
CVE-2023-51065
7.5 HIGH

Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to obtain system backups and other sensitive information from …

Jan 13, 2024
CVE-2023-51063
8.8 HIGH

QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based Reflected Cross Site Scripting (XSS) vulnerability within the component …

Jan 13, 2024
CVE-2023-51804
7.5 HIGH

An issue in rymcu forest v.0.02 allows a remote attacker to obtain sensitive information via manipulation of the HTTP body URL in the com.rymcu.forest.web.api.common.UploadController file.

Jan 13, 2024
CVE-2023-46942
7.5 HIGH

Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.

Jan 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.