CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-48730
8.5 HIGH

A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can …

Jan 10, 2024
CVE-2023-45139
7.5 HIGH

fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker …

Jan 10, 2024
CVE-2023-41056
8.1 HIGH

Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to …

Jan 10, 2024
CVE-2023-48266
8.1 HIGH

The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

Jan 10, 2024
CVE-2023-48265
8.1 HIGH

The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

Jan 10, 2024
CVE-2023-48264
8.1 HIGH

The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

Jan 10, 2024
CVE-2023-48263
8.1 HIGH

The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

Jan 10, 2024
CVE-2023-48262
8.1 HIGH

The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

Jan 10, 2024
CVE-2023-48257
7.8 HIGH

The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) with root privileges on …

Jan 10, 2024
CVE-2023-48253
8.8 HIGH

The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication database via a crafted HTTP request. By abusing this …

Jan 10, 2024
CVE-2023-48252
8.8 HIGH

The vulnerability allows an authenticated remote attacker to perform actions exceeding their authorized access via crafted HTTP requests.

Jan 10, 2024
CVE-2023-48251
8.1 HIGH

The vulnerability allows a remote attacker to authenticate to the SSH service with root privileges through a hidden hard-coded account.

Jan 10, 2024
CVE-2023-48250
8.1 HIGH

The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded accounts.

Jan 10, 2024
CVE-2023-48243
8.1 HIGH

The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) …

Jan 10, 2024
CVE-2023-49471
8.8 HIGH

Blind Server-Side Request Forgery (SSRF) vulnerability in karlomikus Bar Assistant before version 3.2.0 does not validate a parameter before making a request through Image::make(), which …

Jan 10, 2024
CVE-2023-49427
7.5 HIGH

Buffer Overflow vulnerability in Tenda AX12 V22.03.01.46, allows remote attackers to cause a denial of service (DoS) via list parameter in SetNetControlList function.

Jan 10, 2024
CVE-2023-48864
7.5 HIGH

SEMCMS v4.8 was discovered to contain a SQL injection vulnerability via the languageID parameter in /web_inc.php.

Jan 10, 2024
CVE-2024-21643
7.1 HIGH

IdentityModel Extensions for .NET provide assemblies for web developers that wish to use federated identity providers for establishing the caller's identity. Anyone leveraging the `SignedHttpRequest`protocol …

Jan 10, 2024
CVE-2024-0359
7.3 HIGH

A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the …

Jan 10, 2024
CVE-2024-0352
7.3 HIGH

A vulnerability classified as critical was found in Likeshop up to 2.5.7.20210311. This vulnerability affects the function FileServer::userFormImage of the file server/application/api/controller/File.php of the component …

Jan 9, 2024
CVE-2023-47994
8.8 HIGH

An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows attackers to obtain sensitive information, cause a denial of service and/or run …

Jan 9, 2024
CVE-2023-47992
8.8 HIGH

An integer overflow vulnerability in FreeImageIO.cpp::_MemoryReadProc in FreeImage 3.18.0 allows attackers to obtain sensitive information, cause a denial-of-service attacks and/or run arbitrary code.

Jan 9, 2024
CVE-2023-37297
8.3 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of …

Jan 9, 2024
CVE-2023-37296
8.3 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack memory corruption via an adjacent network. A successful exploitation of …

Jan 9, 2024
CVE-2023-37295
8.3 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of …

Jan 9, 2024
CVE-2023-37294
8.3 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of …

Jan 9, 2024
CVE-2023-34333
7.8 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause an untrusted pointer to dereference via a local network. A successful exploitation …

Jan 9, 2024
CVE-2023-34332
7.8 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause an untrusted pointer to dereference by a local network. A successful exploitation …

Jan 9, 2024
CVE-2023-7032
7.8 HIGH

A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain higher privileges by …

Jan 9, 2024
CVE-2024-21325
7.8 HIGH

Microsoft Printer Metadata Troubleshooter Tool Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-21318
8.8 HIGH

Microsoft SharePoint Server Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-21312
7.5 HIGH

.NET Framework Denial of Service Vulnerability

Jan 9, 2024
CVE-2024-21310
7.8 HIGH

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Jan 9, 2024
CVE-2024-21309
7.8 HIGH

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

Jan 9, 2024
CVE-2024-21307
7.5 HIGH

Remote Desktop Client Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-20700
7.5 HIGH

Windows Hyper-V Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-20698
7.8 HIGH

Windows Kernel Elevation of Privilege Vulnerability

Jan 9, 2024
CVE-2024-20697
7.3 HIGH

Windows libarchive Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-20696
7.3 HIGH

Windows libarchive Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-20687
7.5 HIGH

Microsoft AllJoyn API Denial of Service Vulnerability

Jan 9, 2024
CVE-2024-20686
7.8 HIGH

Win32k Elevation of Privilege Vulnerability

Jan 9, 2024
CVE-2024-20683
7.8 HIGH

Win32k Elevation of Privilege Vulnerability

Jan 9, 2024
CVE-2024-20682
7.8 HIGH

Windows Cryptographic Services Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-20681
7.8 HIGH

Windows Subsystem for Linux Elevation of Privilege Vulnerability

Jan 9, 2024
CVE-2024-20677
7.8 HIGH

A security vulnerability exists in FBX that could lead to remote code execution. To mitigate this vulnerability, the ability to insert FBX files has been …

Jan 9, 2024
CVE-2024-20676
8.0 HIGH

Azure Storage Mover Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-20674
8.8 HIGH

Windows Kerberos Security Feature Bypass Vulnerability

Jan 9, 2024
CVE-2024-20672
7.5 HIGH

.NET Denial of Service Vulnerability

Jan 9, 2024
CVE-2024-20661
7.5 HIGH

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

Jan 9, 2024
CVE-2024-20658
7.8 HIGH

Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability

Jan 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.