CVE Database

47326+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-29051
8.1 HIGH

User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the …

Jan 8, 2024
CVE-2023-29050
7.6 HIGH

The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the intended …

Jan 8, 2024
CVE-2023-29048
8.8 HIGH

A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user. Users and …

Jan 8, 2024
CVE-2024-0299
7.3 HIGH

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been declared as critical. Affected by this vulnerability is the function setTracerouteCfg of the file …

Jan 8, 2024
CVE-2024-0298
7.3 HIGH

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been classified as critical. Affected is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jan 8, 2024
CVE-2024-0297
7.3 HIGH

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. This issue affects the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jan 8, 2024
CVE-2024-0296
7.3 HIGH

A vulnerability has been found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. This vulnerability affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jan 8, 2024
CVE-2024-0295
7.3 HIGH

A vulnerability, which was classified as critical, was found in Totolink LR1200GB 9.1.0u.6619_B20230130. This affects the function setWanCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jan 8, 2024
CVE-2024-0294
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected by this issue is the function setUssd of the file …

Jan 8, 2024
CVE-2023-47145
8.4 HIGH

IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privileges to the SYSTEM user …

Jan 7, 2024
CVE-2023-7210
7.3 HIGH

A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of the file /index.php?c=api of …

Jan 7, 2024
CVE-2023-7209
7.5 HIGH

A vulnerability was found in Uniway Router up to 2.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jan 7, 2024
CVE-2024-0268
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Kashipara Hospital Management System up to 1.0. Affected by this issue is some unknown …

Jan 7, 2024
CVE-2023-7208
8.0 HIGH

A vulnerability classified as critical was found in Totolink X2000R_V2 2.0.0-B20230727.10434. This vulnerability affects the function formTmultiAP of the file /bin/boa. The manipulation leads to …

Jan 7, 2024
CVE-2024-0267
7.3 HIGH

A vulnerability classified as critical was found in Kashipara Hospital Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the …

Jan 7, 2024
CVE-2024-0264
7.3 HIGH

A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /LoginRegistration.php. …

Jan 7, 2024
CVE-2023-51441
7.2 HIGH

** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the admin service to perform possible SSRF This …

Jan 6, 2024
CVE-2023-50612
7.8 HIGH

Insecure Permissions vulnerability in fit2cloud Cloud Explorer Lite version 1.4.1, allow local attackers to escalate privileges and obtain sensitive information via the cloud accounts parameter.

Jan 6, 2024
CVE-2024-21642
7.5 HIGH

D-Tale is a visualizer for Pandas data structures. Users hosting versions D-Tale prior to 3.9.0 publicly can be vulnerable to server-side request forgery (SSRF), allowing …

Jan 5, 2024
CVE-2024-0247
7.3 HIGH

A vulnerability classified as critical was found in CodeAstro Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /admin/ of the …

Jan 5, 2024
CVE-2023-47560
7.4 HIGH

An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute commands via a network. …

Jan 5, 2024
CVE-2023-41288
8.8 HIGH

An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to execute commands via a network. …

Jan 5, 2024
CVE-2023-39296
7.5 HIGH

A prototype pollution vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to override existing attributes …

Jan 5, 2024
CVE-2023-34326
7.8 HIGH

The caching invalidation guidelines from the AMD-Vi specification (48882—Rev 3.07-PUB—Oct 2022) is incorrect on some hardware, as devices will malfunction (see stale DMA mappings) if …

Jan 5, 2024
CVE-2023-34325
7.8 HIGH

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] libfsimage contains parsing code for several filesystems, most …

Jan 5, 2024
CVE-2023-34322
7.8 HIGH

For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. Since Xen …

Jan 5, 2024
CVE-2023-52143
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Naa986 WP Stripe Checkout.This issue affects WP Stripe Checkout: from n/a through 1.2.2.37.

Jan 5, 2024
CVE-2023-50991
7.5 HIGH

Buffer Overflow vulnerability in Tenda i29 versions 1.0 V1.0.0.5 and 1.0 V1.0.0.2, allows remote attackers to cause a denial of service (DoS) via the pingIp …

Jan 5, 2024
CVE-2023-52150
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Ovation S.R.L. Dynamic Content for Elementor.This issue affects Dynamic Content for Elementor: from n/a before 2.12.5.

Jan 5, 2024
CVE-2023-51502
7.5 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.6.1.

Jan 5, 2024
CVE-2024-22050
7.5 HIGH

Path traversal in the static file service in Iodine less than 0.7.33 allows an unauthenticated, remote attacker to read files outside the public folder via …

Jan 4, 2024
CVE-2024-0241
7.5 HIGH

encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacker might cause a denial of service condition by …

Jan 4, 2024
CVE-2023-6270
7.0 HIGH

A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, …

Jan 4, 2024
CVE-2024-21625
8.8 HIGH

SideQuest is a place to get virtual reality applications for Oculus Quest. The SideQuest desktop application uses deep links with a custom protocol (`sidequest://`) to …

Jan 4, 2024
CVE-2023-50760
8.8 HIGH

Online Notice Board System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'f' parameter of user/update_profile_pic.php page, allowing an authenticated attacker to …

Jan 4, 2024
CVE-2021-45465
7.8 HIGH

A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied data when parsing BMP files. This could …

Jan 4, 2024
CVE-2021-42028
7.8 HIGH

A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied data when parsing BMP files. This could …

Jan 4, 2024
CVE-2021-40367
7.8 HIGH

A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied data when parsing DICOM files. This could …

Jan 4, 2024
CVE-2022-2081
7.5 HIGH

A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is enabled and configured, …

Jan 4, 2024
CVE-2023-50082
7.5 HIGH

Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via session leakage allows a user to avoid …

Jan 4, 2024
CVE-2024-0225
8.8 HIGH

Use after free in WebGPU in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jan 4, 2024
CVE-2024-0224
8.8 HIGH

Use after free in WebAudio in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jan 4, 2024
CVE-2024-0223
8.8 HIGH

Heap buffer overflow in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jan 4, 2024
CVE-2024-0222
8.8 HIGH

Use after free in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap …

Jan 4, 2024
CVE-2024-21634
7.5 HIGH

Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service issue exists in `ion-java` for applications that …

Jan 3, 2024
CVE-2023-50256
7.5 HIGH

Froxlor is open source server administration software. Prior to version 2.1.2, it was possible to submit the registration form with the essential fields, such as …

Jan 3, 2024
CVE-2023-6338
7.8 HIGH

Uncontrolled search path vulnerabilities were reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with …

Jan 3, 2024
CVE-2023-5881
8.2 HIGH

Unauthenticated access permitted to web interface page The Genie Company Aladdin Connect (Retrofit-Kit Model ALDCM) "Garage Door Control Module Setup" and modify the Garage door's …

Jan 3, 2024
CVE-2023-5880
8.8 HIGH

When the Genie Company Aladdin Connect garage door opener (Retrofit-Kit Model ALDCM) is placed into configuration mode the web servers “Garage Door Control Module Setup” …

Jan 3, 2024
CVE-2023-46929
7.5 HIGH

An issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui /afltest/gpac/src/media_tools/av_parsers.c:6872:55 allows attackers to crash the application.

Jan 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.