CVE Database

47326+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-7222
7.2 HIGH

A vulnerability was found in Totolink X2000R 1.0.0-B20221212.1452. It has been declared as critical. This vulnerability affects the function formTmultiAP of the file /bin/boa of …

Jan 9, 2024
CVE-2022-36765
7.0 HIGH

EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local network. …

Jan 9, 2024
CVE-2022-36764
7.0 HIGH

EDK2 is susceptible to a vulnerability in the Tcg2MeasurePeImage() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation …

Jan 9, 2024
CVE-2022-36763
7.0 HIGH

EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation …

Jan 9, 2024
CVE-2024-0213
8.2 HIGH

A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause …

Jan 9, 2024
CVE-2024-0206
7.1 HIGH

A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation …

Jan 9, 2024
CVE-2023-5376
8.6 HIGH

An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware version 2024/01.

Jan 9, 2024
CVE-2023-51746
7.8 HIGH

A vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < V13.3.0.13), Teamcenter Visualization V14.1 (All versions < V14.1.0.12), …

Jan 9, 2024
CVE-2023-51745
7.8 HIGH

A vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < V13.3.0.13), Teamcenter Visualization V14.1 (All versions < V14.1.0.12), …

Jan 9, 2024
CVE-2023-51439
7.8 HIGH

A vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < V13.3.0.13), Teamcenter Visualization V14.1 (All versions < V14.1.0.12), …

Jan 9, 2024
CVE-2023-49722
8.3 HIGH

Network port 8899 open in WiFi firmware of BCC101/BCC102/BCC50 products, that allows an attacker to connect to the device via same WiFi network.

Jan 9, 2024
CVE-2023-49252
7.5 HIGH

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The affected application allows IP configuration change without authentication to the device. …

Jan 9, 2024
CVE-2023-49251
8.8 HIGH

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application allows an attacker …

Jan 9, 2024
CVE-2023-49132
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to uninitialized pointer access while …

Jan 9, 2024
CVE-2023-49131
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to uninitialized pointer access while …

Jan 9, 2024
CVE-2023-49130
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to uninitialized pointer access while …

Jan 9, 2024
CVE-2023-49129
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected applications contain a stack overflow vulnerability while parsing …

Jan 9, 2024
CVE-2023-49128
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application contains an out of bounds write past …

Jan 9, 2024
CVE-2023-49127
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected applications contain an out of bounds read past …

Jan 9, 2024
CVE-2023-49126
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected applications contain an out of bounds read past …

Jan 9, 2024
CVE-2023-49124
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected applications contain an out of bounds read past …

Jan 9, 2024
CVE-2023-49123
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to heap-based buffer overflow while …

Jan 9, 2024
CVE-2023-49122
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to heap-based buffer overflow while …

Jan 9, 2024
CVE-2023-49121
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to heap-based buffer overflow while …

Jan 9, 2024
CVE-2023-44120
7.8 HIGH

A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q4). The affected product's sudo configuration permits the local administrative account to execute …

Jan 9, 2024
CVE-2023-50932
8.3 HIGH

An issue was discovered in savignano S/Notify before 4.0.2 for Confluence. While an administrative user is logged on, the configuration settings of S/Notify can be …

Jan 9, 2024
CVE-2023-50931
8.3 HIGH

An issue was discovered in savignano S/Notify before 2.0.1 for Bitbucket. While an administrative user is logged on, the configuration settings of S/Notify can be …

Jan 9, 2024
CVE-2023-50930
8.3 HIGH

An issue was discovered in savignano S/Notify before 4.0.2 for Jira. While an administrative user is logged on, the configuration settings of S/Notify can be …

Jan 9, 2024
CVE-2023-7219
7.2 HIGH

A vulnerability has been found in Totolink N350RT 9.3.5u.6139_B202012 and classified as critical. Affected by this vulnerability is the function loginAuth of the file /cgi-bin/cstecgi.cgi. …

Jan 9, 2024
CVE-2024-22125
7.4 HIGH

Under certain conditions the Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge) - version 1.0, allows an attacker to access highly sensitive information …

Jan 9, 2024
CVE-2024-21737
8.4 HIGH

In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to traverse through various layers and …

Jan 9, 2024
CVE-2023-39336
8.8 HIGH

An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal network to …

Jan 9, 2024
CVE-2023-27098
7.5 HIGH

TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.

Jan 9, 2024
CVE-2024-21735
7.3 HIGH

SAP LT Replication Server - version S4CORE 103, S4CORE 104, S4CORE 105, S4CORE 106, S4CORE 107, S4CORE 108, does not perform necessary authorization checks. This …

Jan 9, 2024
CVE-2024-21651
7.5 HIGH

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to attach a file to …

Jan 9, 2024
CVE-2024-21648
8.0 HIGH

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The rollback action is missing a right protection, …

Jan 9, 2024
CVE-2023-50162
7.2 HIGH

SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function.

Jan 9, 2024
CVE-2023-52074
8.8 HIGH

FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component system/site/webconfig_updagte.

Jan 8, 2024
CVE-2023-52073
8.8 HIGH

FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/config_footer_updagte.

Jan 8, 2024
CVE-2023-52072
8.8 HIGH

FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/userconfig_updagte.

Jan 8, 2024
CVE-2023-7218
7.2 HIGH

A vulnerability, which was classified as critical, was found in Totolink N350RT 9.3.5u.6139_B202012. Affected is the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jan 8, 2024
CVE-2023-52201
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brian D. Goad pTypeConverter.This issue affects pTypeConverter: from n/a through 0.2.8.1.

Jan 8, 2024
CVE-2023-52196
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phil Ewels CPT Bootstrap Carousel allows Reflected XSS.This issue affects CPT Bootstrap Carousel: …

Jan 8, 2024
CVE-2023-52142
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cool Plugins Events Shortcodes For The Events Calendar.This issue affects Events …

Jan 8, 2024
CVE-2023-49961
7.5 HIGH

WALLIX Bastion 7.x, 8.x, 9.x and 10.x and WALLIX Access Manager 3.x and 4.x have Incorrect Access Control which can lead to sensitive data exposure.

Jan 8, 2024
CVE-2023-52213
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VideoWhisper Rate Star Review – AJAX Reviews for Content, with Star Ratings allows …

Jan 8, 2024
CVE-2023-52206
7.7 HIGH

Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder.This issue affects Page Builder: Live Composer: from n/a through 1.5.25.

Jan 8, 2024
CVE-2023-52204
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Javik Randomize.This issue affects Randomize: from n/a through 1.4.3.

Jan 8, 2024
CVE-2023-47890
8.8 HIGH

pyLoad 0.5.0 is vulnerable to Unrestricted File Upload.

Jan 8, 2024
CVE-2023-6845
8.8 HIGH

The CommentTweets WordPress plugin through 0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted …

Jan 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.