CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0222
8.8 HIGH

Use after free in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap …

Jan 4, 2024
CVE-2024-21634
7.5 HIGH

Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service issue exists in `ion-java` for applications that …

Jan 3, 2024
CVE-2023-50256
7.5 HIGH

Froxlor is open source server administration software. Prior to version 2.1.2, it was possible to submit the registration form with the essential fields, such as …

Jan 3, 2024
CVE-2023-6338
7.8 HIGH

Uncontrolled search path vulnerabilities were reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with …

Jan 3, 2024
CVE-2023-5881
8.2 HIGH

Unauthenticated access permitted to web interface page The Genie Company Aladdin Connect (Retrofit-Kit Model ALDCM) "Garage Door Control Module Setup" and modify the Garage door's …

Jan 3, 2024
CVE-2023-5880
8.8 HIGH

When the Genie Company Aladdin Connect garage door opener (Retrofit-Kit Model ALDCM) is placed into configuration mode the web servers “Garage Door Control Module Setup” …

Jan 3, 2024
CVE-2023-46929
7.5 HIGH

An issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui /afltest/gpac/src/media_tools/av_parsers.c:6872:55 allows attackers to crash the application.

Jan 3, 2024
CVE-2024-21633
7.8 HIGH

Apktool is a tool for reverse engineering Android APK files. In versions 2.9.1 and prior, Apktool infers resource files' output path according to their resource …

Jan 3, 2024
CVE-2024-21909
7.5 HIGH

PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of service vulnerability. An attacker may trigger the denial of service condition by providing crafted …

Jan 3, 2024
CVE-2024-21907
7.5 HIGH

Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a …

Jan 3, 2024
CVE-2023-45559
8.2 HIGH

An issue in Tamaki_hamanoki Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.

Jan 3, 2024
CVE-2023-37607
7.5 HIGH

Directory Traversal in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information via csvServer.php?file= with a .. in the …

Jan 3, 2024
CVE-2023-37608
7.5 HIGH

An issue in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information because there is an automaticsystems super admin …

Jan 3, 2024
CVE-2023-51785
7.5 HIGH

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a arbitrary file read attack …

Jan 3, 2024
CVE-2023-52309
8.2 HIGH

Heap buffer overflow in paddle.repeat_interleave in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, information disclosure, or more damage is possible.

Jan 3, 2024
CVE-2023-52307
8.2 HIGH

Stack overflow in paddle.linalg.lu_unpack in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage.

Jan 3, 2024
CVE-2023-52304
8.2 HIGH

Stack overflow in paddle.searchsorted in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage.

Jan 3, 2024
CVE-2024-0211
7.8 HIGH

DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file

Jan 3, 2024
CVE-2024-0210
7.8 HIGH

Zigbee TLV dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file

Jan 3, 2024
CVE-2024-0209
7.8 HIGH

IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file

Jan 3, 2024
CVE-2024-0208
7.8 HIGH

GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file

Jan 3, 2024
CVE-2024-0207
7.8 HIGH

HTTP3 dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file

Jan 3, 2024
CVE-2023-50922
7.2 HIGH

An issue was discovered on GL.iNet devices through 4.5.0. Attackers who are able to steal the AdminToken cookie can execute arbitrary code by uploading a …

Jan 3, 2024
CVE-2023-47473
7.5 HIGH

Directory Traversal vulnerability in fuwushe.org iFair versions 23.8_ad0 and before allows an attacker to obtain sensitive information via a crafted script.

Jan 3, 2024
CVE-2023-6600
8.6 HIGH

The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting due to …

Jan 3, 2024
CVE-2023-42358
7.7 HIGH

An issue was discovered in O-RAN Software Community ric-plt-e2mgr in the G-Release environment, allows remote attackers to cause a denial of service (DoS) via a …

Jan 3, 2024
CVE-2023-7027
7.2 HIGH

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jan 3, 2024
CVE-2023-50343
8.3 HIGH

HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints are accessible to Customer Admin Users that can allow …

Jan 3, 2024
CVE-2023-50342
7.1 HIGH

HCL DRYiCE MyXalytics is impacted by an Insecure Direct Object Reference (IDOR) vulnerability. A user can obtain certain details about another user as a result …

Jan 3, 2024
CVE-2023-50341
7.6 HIGH

HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated and accessible web pages, reflects a "Missing Access Control" …

Jan 3, 2024
CVE-2023-45724
8.2 HIGH

HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file without requiring user authentication.

Jan 3, 2024
CVE-2023-45723
7.6 HIGH

HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability. Certain endpoints permit users to manipulate the path (including the file …

Jan 3, 2024
CVE-2023-45722
8.8 HIGH

HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to …

Jan 3, 2024
CVE-2023-50351
8.2 HIGH

HCL DRYiCE MyXalytics is impacted by the use of an insecure key rotation mechanism which can allow an attacker to compromise the confidentiality or integrity …

Jan 3, 2024
CVE-2023-50350
8.2 HIGH

HCL DRYiCE MyXalytics is impacted by the use of a broken cryptographic algorithm for encryption, potentially giving an attacker ability to decrypt sensitive information.

Jan 3, 2024
CVE-2023-49553
7.5 HIGH

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_destroy function in the msj.c file.

Jan 2, 2024
CVE-2023-49552
7.5 HIGH

An Out of Bounds Write in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_stringify function in the …

Jan 2, 2024
CVE-2023-49551
7.5 HIGH

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_parse function in the msj.c file.

Jan 2, 2024
CVE-2023-49550
7.5 HIGH

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component.

Jan 2, 2024
CVE-2023-49549
7.5 HIGH

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_getretvalpos function in the msj.c file.

Jan 2, 2024
CVE-2024-21632
8.6 HIGH

omniauth-microsoft_graph provides an Omniauth strategy for the Microsoft Graph API. Prior to versions 2.0.0, the implementation did not validate the legitimacy of the `email` attribute …

Jan 2, 2024
CVE-2023-50020
7.5 HIGH

An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.

Jan 2, 2024
CVE-2023-4164
8.4 HIGH

There is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of health data with no additional …

Jan 2, 2024
CVE-2024-21627
8.1 HIGH

PrestaShop is an open-source e-commerce platform. Prior to versions 8.1.3 and 1.7.8.11, some event attributes are not detected by the `isCleanHTML` method. Some modules using …

Jan 2, 2024
CVE-2023-45893
7.5 HIGH

An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unauthenticated remote attacker to view sensitive …

Jan 2, 2024
CVE-2023-45892
7.5 HIGH

An issue discovered in the Order and Invoice pages in Floorsight Insights Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.

Jan 2, 2024
CVE-2022-3010
7.5 HIGH

The Priva TopControl Suite contains predictable credentials for the SSH service, based on the Serial number. Which makes it possible for an attacker to calculate …

Jan 2, 2024
CVE-2024-0193
7.8 HIGH

A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, …

Jan 2, 2024
CVE-2023-47039
7.8 HIGH

A vulnerability was found in Perl. This security issue occurs while Perl for Windows relies on the system path environment variable to find the shell …

Jan 2, 2024
CVE-2023-43514
8.4 HIGH

Memory corruption while invoking IOCTLs calls from user space for internal mem MAP and internal mem UNMAP.

Jan 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.