CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-33472
8.8 HIGH

An issue was discovered in Scada-LTS v2.7.5.2 build 4551883606 and before, allows remote attackers with low-level authentication to escalate privileges, execute arbitrary code, and obtain …

Jan 13, 2024
CVE-2024-22142
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs Profile Builder Pro allows Reflected XSS.This issue affects Profile Builder Pro: from …

Jan 13, 2024
CVE-2024-0474
7.3 HIGH

A vulnerability classified as critical was found in code-projects Dormitory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php. …

Jan 12, 2024
CVE-2023-48166
7.5 HIGH

A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attacker to view the contents …

Jan 12, 2024
CVE-2023-49647
8.8 HIGH

Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an …

Jan 12, 2024
CVE-2023-48297
8.6 HIGH

Discourse is a platform for community discussion. The message serializer uses the full list of expanded chat mentions (@all and @here) which can lead to …

Jan 12, 2024
CVE-2023-42463
7.4 HIGH

Wazuh is a free and open source platform used for threat prevention, detection, and response. This bug introduced a stack overflow hazard that could allow …

Jan 12, 2024
CVE-2023-31035
7.5 HIGH

NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that could be used to execute arbitrary code at …

Jan 12, 2024
CVE-2023-31032
7.5 HIGH

NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a dynamic variable evaluation by local access. A successful exploit of this vulnerability …

Jan 12, 2024
CVE-2023-46805
8.2 HIGH KEV

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources …

Jan 12, 2024
CVE-2023-31036
7.5 HIGH

NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where, when it is launched with the non-default command line option --model-control explicit, an …

Jan 12, 2024
CVE-2023-51949
8.8 HIGH

Verydows v2.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /protected/controller/backend/role_controller

Jan 12, 2024
CVE-2023-49261
7.5 HIGH

The "tokenKey" value used in user authorization is visible in the HTML source of the login page.

Jan 12, 2024
CVE-2023-49259
7.5 HIGH

The authentication cookies are generated using an algorithm based on the username, hardcoded secret and the up-time, and can be guessed in a reasonable time.

Jan 12, 2024
CVE-2023-49257
8.8 HIGH

An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execute it with the root user privileges.

Jan 12, 2024
CVE-2023-49256
7.5 HIGH

It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded static key.

Jan 12, 2024
CVE-2023-49254
8.8 HIGH

Authenticated user can execute arbitrary commands in the context of the root user by providing payload in the "destination" field of the network test tools. …

Jan 12, 2024
CVE-2023-5356
7.3 HIGH

Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from …

Jan 12, 2024
CVE-2023-4812
7.6 HIGH

An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions …

Jan 12, 2024
CVE-2023-49568
7.5 HIGH

A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks …

Jan 12, 2024
CVE-2023-48909
8.8 HIGH

An issue was discovered in Jave2 version 3.3.1, allows attackers to execute arbitrary code via the FFmpeg function.

Jan 12, 2024
CVE-2023-6740
8.8 HIGH

Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges

Jan 12, 2024
CVE-2023-6735
8.8 HIGH

Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges

Jan 12, 2024
CVE-2023-31211
8.8 HIGH

Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials

Jan 12, 2024
CVE-2023-34061
7.5 HIGH

Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route …

Jan 12, 2024
CVE-2023-6040
7.8 HIGH

An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family); While creating a new netfilter table, …

Jan 12, 2024
CVE-2023-40250
8.8 HIGH

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Hancom HCell on Windows allows Overflow Buffers.This issue affects HCell: 12.0.0.893.

Jan 12, 2024
CVE-2024-21616
7.5 HIGH

An Improper Validation of Syntactic Correctness of Input vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to …

Jan 12, 2024
CVE-2024-21614
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a …

Jan 12, 2024
CVE-2024-21612
7.5 HIGH

An Improper Handling of Syntactically Invalid Structure vulnerability in Object Flooding Protocol (OFP) service of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker …

Jan 12, 2024
CVE-2024-21611
7.5 HIGH

A Missing Release of Memory after Effective Lifetime vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows …

Jan 12, 2024
CVE-2024-21606
7.5 HIGH

A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series allows a network-based, unauthenticated attacker to cause …

Jan 12, 2024
CVE-2024-21604
7.5 HIGH

An Allocation of Resources Without Limits or Throttling vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause …

Jan 12, 2024
CVE-2024-21602
7.5 HIGH

A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS Evolved on ACX7024, ACX7100-32C and ACX7100-48L allows an unauthenticated, network-based attacker to cause a Denial …

Jan 12, 2024
CVE-2024-21595
7.5 HIGH

An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker …

Jan 12, 2024
CVE-2024-21589
7.4 HIGH

An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated network-based attacker to access reports without authenticating, potentially …

Jan 12, 2024
CVE-2023-46474
7.2 HIGH

File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted PHP file uploaded to the start_import.php …

Jan 11, 2024
CVE-2023-50123
8.1 HIGH

The number of attempts to bring the Hozard Alarm system (alarmsystemen) v1.0 to a disarmed state is not limited. This could allow an attacker to …

Jan 11, 2024
CVE-2024-22198
7.1 HIGH

Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. The `Home > Preference` …

Jan 11, 2024
CVE-2024-22196
7.0 HIGH

Nginx-UI is an online statistics for Server Indicators​​ Monitor CPU usage, memory usage, load average, and disk usage in real-time. This issue may lead to …

Jan 11, 2024
CVE-2023-51782
7.0 HIGH

An issue was discovered in the Linux kernel before 6.6.8. rose_ioctl in net/rose/af_rose.c has a use-after-free because of a rose_accept race condition.

Jan 11, 2024
CVE-2023-51781
7.0 HIGH

An issue was discovered in the Linux kernel before 6.6.8. atalk_ioctl in net/appletalk/ddp.c has a use-after-free because of an atalk_recvmsg race condition.

Jan 11, 2024
CVE-2023-51780
7.0 HIGH

An issue was discovered in the Linux kernel before 6.6.8. do_vcc_ioctl in net/atm/ioctl.c has a use-after-free because of a vcc_recvmsg race condition.

Jan 11, 2024
CVE-2024-22197
7.7 HIGH

Nginx-ui is online statistics for Server Indicators​​ Monitor CPU usage, memory usage, load average, and disk usage in real-time. The `Home > Preference` page exposes …

Jan 11, 2024
CVE-2023-50671
7.8 HIGH

In exiftags 1.01, nikon_prop1 in nikon.c has a heap-based buffer overflow (write of size 28) because snprintf can write to an unexpected address.

Jan 11, 2024
CVE-2024-0429
7.3 HIGH

A denial service vulnerability has been found on Hex Workshop affecting version 6.7, an attacker could send a command line file arguments and control the …

Jan 11, 2024
CVE-2023-51749
8.8 HIGH

ScaleFusion 10.5.2 does not properly limit users to the Edge application because a search can be made from a tooltip. NOTE: the vendor's position is …

Jan 11, 2024
CVE-2023-51748
8.8 HIGH

ScaleFusion 10.5.2 does not properly limit users to the Edge application because Ctrl-O and Ctrl-S can be used. This is fixed in 10.5.7 by preventing …

Jan 11, 2024
CVE-2023-50159
8.8 HIGH

In ScaleFusion (Windows Desktop App) agent 10.5.2, Kiosk mode application restrictions can be bypassed allowing arbitrary code to be executed. This is fixed in 10.5.7 …

Jan 11, 2024
CVE-2023-6979
8.8 HIGH

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ivole_import_upload_csv AJAX action …

Jan 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.