CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-6878
8.8 HIGH

The Slick Social Share Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'dcssb_ajax_update' function …

Jan 11, 2024
CVE-2023-6828
7.2 HIGH

The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Jan 11, 2024
CVE-2023-6751
7.3 HIGH

The Hostinger plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the function publish_website in all versions …

Jan 11, 2024
CVE-2023-6636
7.2 HIGH

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the …

Jan 11, 2024
CVE-2023-6634
8.1 HIGH

The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due …

Jan 11, 2024
CVE-2023-6558
7.2 HIGH

The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'upload_import_file' …

Jan 11, 2024
CVE-2023-6266
7.5 HIGH

The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP case of …

Jan 11, 2024
CVE-2023-6220
8.1 HIGH

The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'piotnetforms_ajax_form_builder' function in versions up …

Jan 11, 2024
CVE-2023-5504
8.7 HIGH

The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the Log File Folder. This allows authenticated …

Jan 11, 2024
CVE-2024-0252
8.8 HIGH

ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication …

Jan 11, 2024
CVE-2024-21637
7.6 HIGH

Authentik is an open-source Identity Provider. Authentik is a vulnerable to a reflected Cross-Site Scripting vulnerability via JavaScript-URIs in OpenID Connect flows with `response_mode=form_post`. This …

Jan 11, 2024
CVE-2023-5448
8.8 HIGH

The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.9. This is due …

Jan 11, 2024
CVE-2023-51073
8.1 HIGH

An issue in Buffalo LS210D v.1.78-0.03 allows a remote attacker to execute arbitrary code via the Firmware Update Script at /etc/init.d/update_notifications.sh.

Jan 11, 2024
CVE-2023-31003
8.4 HIGH

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user …

Jan 11, 2024
CVE-2024-22190
7.8 HIGH

GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search …

Jan 11, 2024
CVE-2024-21833
8.8 HIGH

Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitrary OS commands. The affected device, with the initial configuration, …

Jan 11, 2024
CVE-2024-21821
8.0 HIGH

Multiple TP-LINK products allow a network-adjacent authenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands.

Jan 11, 2024
CVE-2024-21773
8.8 HIGH

Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands on …

Jan 11, 2024
CVE-2022-45794
8.6 HIGH

An attacker with network access to the affected PLC (CJ-series and CS-series PLCs, all versions) may use a network protocol to read and write files …

Jan 10, 2024
CVE-2023-42933
7.8 HIGH

This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to gain elevated privileges.

Jan 10, 2024
CVE-2023-42876
7.1 HIGH

The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14. Processing a file may lead to a denial-of-service or …

Jan 10, 2024
CVE-2023-42871
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app may be …

Jan 10, 2024
CVE-2023-42870
7.8 HIGH

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app may …

Jan 10, 2024
CVE-2023-42869
7.5 HIGH

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Ventura 13.4, iOS 16.5 and iPadOS 16.5. Multiple issues …

Jan 10, 2024
CVE-2023-42866
8.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, tvOS 16.6, Safari 16.6, …

Jan 10, 2024
CVE-2023-42833
8.8 HIGH

A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. Processing web …

Jan 10, 2024
CVE-2023-42832
7.0 HIGH

A race condition was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.7.9, macOS Monterey 12.6.8, macOS Ventura 13.5. An …

Jan 10, 2024
CVE-2023-42828
7.8 HIGH

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.5. An app may be able to gain root …

Jan 10, 2024
CVE-2023-42826
7.8 HIGH

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing a file may lead to arbitrary code execution.

Jan 10, 2024
CVE-2023-41974
7.8 HIGH KEV

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An …

Jan 10, 2024
CVE-2023-41075
7.8 HIGH

A type confusion issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7.5, macOS Ventura 13.3, iOS 16.4 and iPadOS …

Jan 10, 2024
CVE-2023-41060
8.8 HIGH

A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. A remote user …

Jan 10, 2024
CVE-2023-40393
7.5 HIGH

An authentication issue was addressed with improved state management. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. Photos in the …

Jan 10, 2024
CVE-2023-38610
7.1 HIGH

A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An …

Jan 10, 2024
CVE-2023-32436
7.1 HIGH

The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system …

Jan 10, 2024
CVE-2023-32401
7.8 HIGH

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.6.6, macOS Big Sur 11.7.7, macOS Ventura 13.4. Parsing …

Jan 10, 2024
CVE-2023-32383
7.8 HIGH

This issue was addressed by forcing hardened runtime on the affected binaries at the system level. This issue is fixed in macOS Monterey 12.6.6, macOS …

Jan 10, 2024
CVE-2023-32378
7.8 HIGH

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.3, macOS Big Sur 11.7.5, macOS Monterey 12.6.4. An …

Jan 10, 2024
CVE-2023-32366
7.8 HIGH

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.7.5, macOS Ventura 13.3, iOS 16.4 and …

Jan 10, 2024
CVE-2022-47965
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13. An app may be able to execute arbitrary code …

Jan 10, 2024
CVE-2022-47915
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13. An app may be able to execute arbitrary code …

Jan 10, 2024
CVE-2022-46721
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13. An app may be able to execute arbitrary code …

Jan 10, 2024
CVE-2023-51127
7.5 HIGH

FLIR AX8 thermal sensor cameras up to and including 1.46.16 are vulnerable to Directory Traversal due to improper access restriction. This vulnerability allows an unauthenticated, …

Jan 10, 2024
CVE-2023-29445
7.8 HIGH

An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM.

Jan 10, 2024
CVE-2023-50916
7.2 HIGH

Kyocera Device Manager before 3.1.1213.0 allows NTLM credential exposure during UNC path authentication via a crafted change from a local path to a UNC path. …

Jan 10, 2024
CVE-2023-46712
7.2 HIGH

A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via specifically …

Jan 10, 2024
CVE-2023-44250
8.8 HIGH

An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy HA cluster version …

Jan 10, 2024
CVE-2023-49810
7.3 HIGH

A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead …

Jan 10, 2024
CVE-2023-49738
7.5 HIGH

An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary …

Jan 10, 2024
CVE-2023-49589
8.8 HIGH

An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead …

Jan 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.