CVE Database

47326+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0576
8.8 HIGH

A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been declared as critical. This vulnerability affects the function setIpPortFilterRules of the file /cgi-bin/cstecgi.cgi. The …

Jan 16, 2024
CVE-2023-6373
8.8 HIGH

The ArtPlacer Widget WordPress plugin before 2.20.7 does not sanitize and escape the "id" parameter before submitting the query, leading to a SQLI exploitable by …

Jan 16, 2024
CVE-2023-5922
7.5 HIGH

The Royal Elementor Addons and Templates WordPress plugin before 1.3.81 does not ensure that users accessing posts via an AJAX action (and REST endpoint, currently …

Jan 16, 2024
CVE-2023-4797
7.2 HIGH

The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable …

Jan 16, 2024
CVE-2023-4703
7.5 HIGH

The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating user details, allowing an unauthenticated attacker to …

Jan 16, 2024
CVE-2023-4536
8.8 HIGH

The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber …

Jan 16, 2024
CVE-2023-45235
8.3 HIGH

EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be …

Jan 16, 2024
CVE-2023-45234
8.3 HIGH

EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited …

Jan 16, 2024
CVE-2023-45233
7.5 HIGH

EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can …

Jan 16, 2024
CVE-2023-45232
7.5 HIGH

EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be …

Jan 16, 2024
CVE-2023-45230
8.3 HIGH

EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by …

Jan 16, 2024
CVE-2023-2655
7.2 HIGH

The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using it in a SQL statement, leading …

Jan 16, 2024
CVE-2023-1405
7.5 HIGH

The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is …

Jan 16, 2024
CVE-2022-3899
8.1 HIGH

The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing …

Jan 16, 2024
CVE-2022-3764
7.2 HIGH

The plugin does not filter the "delete_entries" parameter from user requests, leading to an SQL Injection vulnerability.

Jan 16, 2024
CVE-2022-3604
7.8 HIGH

The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.

Jan 16, 2024
CVE-2022-1538
7.2 HIGH

Theme Demo Import WordPress plugin before 1.1.1 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as …

Jan 16, 2024
CVE-2021-24869
8.8 HIGH

The WP Fastest Cache WordPress plugin before 0.9.5 does not escape user input in the set_urls_with_terms method before using it in a SQL statement, leading …

Jan 16, 2024
CVE-2021-24566
8.8 HIGH

The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.

Jan 16, 2024
CVE-2021-24151
7.2 HIGH

The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via …

Jan 16, 2024
CVE-2024-0582
7.8 HIGH

A memory leak flaw was found in the Linux kernel’s io_uring functionality in how a user registers a buffer ring with IORING_REGISTER_PBUF_RING, mmap() it, and …

Jan 16, 2024
CVE-2024-0575
8.8 HIGH

A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been classified as critical. This affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jan 16, 2024
CVE-2024-0574
8.8 HIGH

A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130 and classified as critical. Affected by this issue is the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The …

Jan 16, 2024
CVE-2024-0573
8.8 HIGH

A vulnerability has been found in Totolink LR1200GB 9.1.0u.6619_B20230130 and classified as critical. Affected by this vulnerability is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. …

Jan 16, 2024
CVE-2024-0572
8.8 HIGH

A vulnerability, which was classified as critical, was found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jan 16, 2024
CVE-2024-0571
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. This issue affects the function setSmsCfg of the file /cgi-bin/cstecgi.cgi. The …

Jan 16, 2024
CVE-2024-0570
7.3 HIGH

A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6265. This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. …

Jan 16, 2024
CVE-2024-0567
7.5 HIGH

A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a …

Jan 16, 2024
CVE-2024-0553
7.5 HIGH

A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 …

Jan 16, 2024
CVE-2024-0556
7.1 HIGH

A Weak Cryptography for Passwords vulnerability has been detected on WIC200 affecting version 1.1. This vulnerability allows a remote user to intercept the traffic and …

Jan 16, 2024
CVE-2023-52105
7.5 HIGH

The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability.

Jan 16, 2024
CVE-2023-52104
7.5 HIGH

Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-52102
7.5 HIGH

Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-52100
7.5 HIGH

The Celia Keyboard module has a vulnerability in access control. Successful exploitation of this vulnerability may affect availability.

Jan 16, 2024
CVE-2023-52099
7.5 HIGH

Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-52116
7.5 HIGH

Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.

Jan 16, 2024
CVE-2023-52115
7.5 HIGH

The iaware module has a Use-After-Free (UAF) vulnerability. Successful exploitation of this vulnerability may affect the system functions.

Jan 16, 2024
CVE-2023-52114
7.5 HIGH

Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity.

Jan 16, 2024
CVE-2023-52108
7.5 HIGH

Vulnerability of process priorities being raised in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.

Jan 16, 2024
CVE-2023-52107
7.5 HIGH

Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-52098
7.5 HIGH

Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability.

Jan 16, 2024
CVE-2023-52113
7.5 HIGH

launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.

Jan 16, 2024
CVE-2023-52111
7.5 HIGH

Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.

Jan 16, 2024
CVE-2023-52110
7.5 HIGH

The sensor module has an out-of-bounds access vulnerability.Successful exploitation of this vulnerability may affect availability.

Jan 16, 2024
CVE-2023-52109
7.5 HIGH

Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-4566
7.5 HIGH

Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-44117
7.5 HIGH

Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-44112
7.5 HIGH

Out-of-bounds access vulnerability in the device authentication module. Successful exploitation of this vulnerability may affect confidentiality.

Jan 16, 2024
CVE-2024-21674
7.5 HIGH

This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with …

Jan 16, 2024
CVE-2024-21673
8.8 HIGH

This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with …

Jan 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.